Bind OpenBao builds to approved inputs and secure credential delivery
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e75a-fc5c-7913-9dba-9846210c766d
This commit is contained in:
parent
ee1dc2b651
commit
2b83324c01
8 changed files with 622 additions and 84 deletions
27
SCOPE.md
27
SCOPE.md
|
|
@ -28,7 +28,7 @@ decision gate, in plain terms; (4) build, only after approval.
|
|||
|
||||
- Deciding *whether* access should exist — that's architecture/founder,
|
||||
ops-mason builds what's already decided
|
||||
- Runtime authorization decisions — flex-auth
|
||||
- Runtime authorization decisions — access-engine
|
||||
- Identity/MFA — key-cape/Keycloak
|
||||
- Routing consumers to lanes once built — ops-warden
|
||||
- SSH certificate issuance — ops-warden
|
||||
|
|
@ -38,9 +38,28 @@ decision gate, in plain terms; (4) build, only after approval.
|
|||
|
||||
## Current State
|
||||
|
||||
Charter only (`INTENT.md`). `MASON-WP-0001` scopes the four-phase
|
||||
pipeline and its first real exercise: the `rein-openweights` OpenBao
|
||||
AppRole that `glas-harness/GLAS-WP-0002-T02` is blocked on. No code yet.
|
||||
The four-phase construction process, OpenBao AppRole/Kubernetes-auth builders,
|
||||
metadata inventory, and guarded Kubernetes-plane CLI are implemented and tested.
|
||||
Construction plans and build evidence live in `plans/` and `docs/evidence/`.
|
||||
|
||||
OpenBao builds require an approved plan whose machine-readable specification
|
||||
and approved digest match the supplied execution inputs. Existing policies are
|
||||
content-pinned before reuse. AppRole credentials are delivered through private,
|
||||
exclusive files; the builders do not read downstream KV values. See
|
||||
`docs/construction-plan-format.md` for review and execution requirements.
|
||||
|
||||
Kubernetes apply enforces pinned readiness tiers, the explicit whitehat
|
||||
placement, the dated policy-nexus transition, and recorded emergency activation.
|
||||
See `docs/kubernetes-plane.md`.
|
||||
|
||||
The layer declaration is `Staff`, with PEP-shaped behavior, in `INTENT.md`.
|
||||
The founder-approved plan-approval exception and direct-contact gaps remain
|
||||
explicitly declared; this is not a claim of full layer-model conformance.
|
||||
|
||||
Remaining work is held in existing blocked workplans: credential descriptions
|
||||
(MASON-WP-0004), the attended Telegram credential lane (MASON-WP-0005), and the
|
||||
2026-12-21 readiness/approval review (MASON-WP-0006-T06). `WORK-RECORDS.md` is
|
||||
the generated index; workplan files remain the source of task status.
|
||||
|
||||
## Getting Oriented
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue