Enforce readiness tiers and reconcile blocked workplans

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e75a-fc5c-7913-9dba-9846210c766d
This commit is contained in:
tegwick 2026-09-28 11:40:57 +02:00
parent 370e1f84c7
commit 36445ae679
14 changed files with 652 additions and 39 deletions

View file

@ -130,13 +130,13 @@ tooling_contacts:
# gate on ADMINISTER @ realm:kubernetes/railiance01 is a quality gate, not
# an authorization decision, tiered by the target's railiance-master
# ADR-0006 readiness_state. The owner question above is answered: the
# Kubernetes API stays a Tooling contact owned by rail-kubernetes.
# contact is with realm:kubernetes/railiance01; no layer is assigned.
change_gate:
decision: the-custodian/docs/kubernetes-change-gate-decision.md
decided_by: "Bernd Worsch (founder), GOVERN @ estate"
decided_at: "2026-09-21"
engine_owner: none
tooling_owner: rail-kubernetes
realm: "realm:kubernetes/railiance01"
tiers:
- readiness_state: [declared, installed, verified]
path: "direct ADMINISTER @ realm:kubernetes by ops-mason"
@ -156,7 +156,7 @@ tooling_contacts:
until: "2026-12-21"
rule: "Direct ADMINISTER under activation=APPROVED, each change recorded as production-tier, until ArgoCD onboarding."
relies_on_limits: "One expected namespace per plan; Pod and Secret kinds refused; no data or stringData. Widening them is a new decision."
enforcement: "Not yet in code: phase 4 does not check readiness_state. Planned in workplans/MASON-WP-0006-readiness-tier-check.md."
enforcement: "src/ops_mason/readiness.py: inspect_readiness and resolve_tier; kubernetes_plane.apply refuses before Kubernetes writes. Source/history verification, explicit whitehat placement, dated policy-nexus transition, and recorded BREAK_GLASS."
- id: bao-session-grant
shape: "5.2"
module: scripts/bao-session.sh