Reconcile infrastructure workplans and retire stale flex-auth references
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
This commit is contained in:
parent
019e8f21a7
commit
9383b94019
12 changed files with 494 additions and 149 deletions
|
|
@ -10,7 +10,7 @@ owner: codex
|
|||
topic_slug: netkingdom
|
||||
planning_priority: P1
|
||||
created: "2026-08-23"
|
||||
updated: "2026-08-23"
|
||||
updated: "2026-09-28"
|
||||
state_hub_workstream_id: "9d7b04f9-3803-5613-b7a5-8bd606c77f5a"
|
||||
---
|
||||
|
||||
|
|
@ -116,3 +116,20 @@ Verification on 2026-08-23:
|
|||
|
||||
Local implementation is complete. The workplan remains blocked only on T04's
|
||||
externally owned audit-core declaration adoption.
|
||||
|
||||
## Infrastructure review — 2026-09-28
|
||||
|
||||
`audit-core/tenancy.yaml` still lacks machine-readable authoritative owner
|
||||
and E2 freshness metadata. Its E2 prose retains the August 22 receipt and
|
||||
24-hour replacement deadline; report freshness as `unknown` until the required
|
||||
fields exist, without renewing that evidence from prose. The September 24
|
||||
receiver/database recreate evidence supports V1 only and cannot refresh E2.
|
||||
T04 remains `wait`; request the source declaration update and evaluate it with
|
||||
an explicit current `--as-of` before closure.
|
||||
|
||||
The same declaration still describes flex-auth as unauthenticated A0, whereas
|
||||
today all six live flex-auth Deployments pass `--caller-auth-mode enforce`.
|
||||
The audit-core owner should reconcile that rationale against actual caller
|
||||
bindings and policy evidence; deployment flags alone do not prove a new A level.
|
||||
|
||||
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue