Bind OpenBao builds to approved inputs and secure credential delivery

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e75a-fc5c-7913-9dba-9846210c766d
This commit is contained in:
tegwick 2026-09-28 11:55:39 +02:00
parent ee1dc2b651
commit 2b83324c01
8 changed files with 622 additions and 84 deletions

View file

@ -36,7 +36,8 @@ id: MASON-IN-0002
kind: intake
title: 'Declaration requested: state this repository''s layer in INTENT.md (security
layer model §11)'
status: open
status: closed
outcome: absorbed
origin: cross-repo
origin_ref: net-kingdom security-layer-model_v0.4 §11
priority: low
@ -61,5 +62,12 @@ description: 'A conformance sweep on 2026-08-28 found this repository has no lay
If the proposed layer is wrong for what this repository actually does, that is more
useful to us than a label added to close a checkbox. Standard: net-kingdom/canon/standards/security-layer-model_v0.4.md.'
created: '2026-08-28T21:03:29.920563Z'
updated: '2026-08-28T21:03:29.920563Z'
updated: '2026-09-28T09:54:34.065401Z'
notes: >-
Closed against the repository-authored Staff / pep-shaped declaration in
INTENT.md, dated 2026-09-21. That declaration names access-engine as the
authorization decision point and explicitly records direct Tooling contacts
and the founder-accepted plan-approval exception. The declaration request is
fulfilled; the accepted conformance gaps and their 2026-12-21 review remain
declared and are not marked conformant by this intake closure.
```