build: add guarded Kubernetes plane executor

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
This commit is contained in:
tegwick 2026-08-22 11:23:38 +02:00
parent 1dd98b4f27
commit 2b318634b6
13 changed files with 1240 additions and 3 deletions

View file

@ -4,7 +4,7 @@ type: workplan
title: "Provision the Whitehat foundational plane and reconcile intake drift"
domain: infotech
repo: ops-mason
status: ready
status: active
owner: codex
topic_slug: whitehat-foundational-plane
created: "2026-08-22"
@ -55,7 +55,7 @@ set. No unresolved dependency makes the first implementation step guesswork.
```task
id: MASON-WP-0002-T01
status: todo
status: done
priority: high
state_hub_task_id: "067451e4-50f7-59d9-b804-50f348e22508"
```
@ -82,11 +82,19 @@ Whitehat to align its README. Do not mint an engagement ID here.
four allowed objects, passes dry-run validation, and has an explicit exclusion
list and rollback procedure.
**Done (2026-08-22):** added the byte-identical source pins, approved
construction plan, declarative bundle, guarded CLI, safety documentation, and
rollback generator. Thirty tests pass. Live read-only preflight reports all
four objects absent and validates the matching audit-core Service/policy.
Bundle digest: `9636f48f0b994118ff60a8c014e0099486945d66a2b3d3582dc57a09862b2035`.
Whitehat README alignment request: State Hub message
`47032e07-5086-449f-8251-0f69df6cd934`.
## Provision and verify the foundational plane
```task
id: MASON-WP-0002-T02
status: todo
status: progress
priority: high
state_hub_task_id: "23f78bc5-4185-5181-9f3c-fd718641d2a5"
```