Enforce readiness tiers and reconcile blocked workplans

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e75a-fc5c-7913-9dba-9846210c766d
This commit is contained in:
tegwick 2026-09-28 11:40:57 +02:00
parent 370e1f84c7
commit 36445ae679
14 changed files with 652 additions and 39 deletions

View file

@ -4,11 +4,12 @@ type: workplan
title: "Describe every stored credential so the store is navigable"
domain: infotech
repo: ops-mason
status: proposed
status: blocked
flavor: planning
owner: codex
topic_slug: custodian
created: "2026-08-28"
updated: "2026-09-28"
related:
- MASON-WP-0003
- NK-WP-0033
@ -48,7 +49,7 @@ read, and `ops-mason-build` cannot read one.
```task
id: MASON-WP-0004-T01
status: todo
status: wait
priority: medium
state_hub_task_id: "5bda75f2-f780-579e-9d44-cc4011662b9a"
```
@ -68,7 +69,7 @@ listed as unknown with the question that would settle it.
```task
id: MASON-WP-0004-T02
status: todo
status: wait
priority: medium
state_hub_task_id: "a6a944d7-21c5-5043-a78d-b3809de0ee64"
```
@ -121,3 +122,9 @@ the report has a reader.
Acceptance: an undescribed path added today surfaces without anyone
remembering to look.
## Loose-end review — 2026-09-28
T01–T04 remain wait: no valid scoped metadata grant/current inventory or complete owner/recovery confirmations are available. Inventory failure handling and the private-tunnel defaults are fixed and tested; scheduled reporting still needs its reader and credential.
Evidence and precise resumption conditions: [review](../docs/evidence/2026-09-28-loose-end-review.md). Existing tasks retain all remaining obligations; no new task or workplan was opened.

View file

@ -4,13 +4,12 @@ type: workplan
title: "Construct the fluid-telegram operator credential lane"
domain: infotech
repo: ops-mason
status: proposed
status: blocked
flavor: planning
owner: codex
topic_slug: helix-forge
created: "2026-09-04"
updated: "2026-09-04"
state_hub_workstream_id: "483e56d6-6601-5377-9066-66225214c046"
updated: "2026-09-28"
state_hub_workstream_id: "483e56d6-6601-5377-9066-66225214c046"
---
@ -65,7 +64,7 @@ from the current disk-only survey.
```task
id: MASON-WP-0005-T02
status: todo
status: wait
priority: high
state_hub_task_id: "69c558d9-664f-5ce0-80b2-d2e7544353a3"
```
@ -86,7 +85,7 @@ parent access, and the create-only salt shape.
```task
id: MASON-WP-0005-T03
status: todo
status: wait
priority: high
state_hub_task_id: "48a2b4ec-8e66-5b98-b039-c17fd8d820ab"
```
@ -103,7 +102,7 @@ adapter separation for explicit human approval. Only the plan's
```task
id: MASON-WP-0005-T04
status: todo
status: wait
priority: high
state_hub_task_id: "0e3d1333-ffc3-5f67-8528-50a9551c4949"
```
@ -122,7 +121,7 @@ a provisioner capability.
```task
id: MASON-WP-0005-T05
status: todo
status: wait
priority: high
state_hub_task_id: "4c205be7-4f1f-5dd1-aafa-fc112fdd640e"
```
@ -147,7 +146,7 @@ operator/platform flow and return metadata-only evidence to ops-mason.
```task
id: MASON-WP-0005-T06
status: todo
status: wait
priority: medium
state_hub_task_id: "09eae088-808d-5342-b100-292e13958ee3"
```
@ -163,3 +162,9 @@ The adapter lane is tracked separately as `MASON-IN-0003`, tied to
`redaction-salt`; it must be denied `operator-app` and `operator-session` and
must use the adapter's own runtime identity rather than this attended OIDC
role.
## Loose-end review — 2026-09-28
T01–T06 remain wait: accepted tenant/matrix, confirmed identity/MFA/callbacks, approved matching writer contracts, live survey, explicit construction approval and verification are outstanding. The platform design remains proposed. No lane was built or activated.
Evidence and precise resumption conditions: [review](../docs/evidence/2026-09-28-loose-end-review.md). Existing tasks retain all remaining obligations; no new task or workplan was opened.

View file

@ -4,12 +4,12 @@ type: workplan
title: "Check the target's readiness tier before a direct Kubernetes apply"
domain: infotech
repo: ops-mason
status: proposed
status: blocked
flavor: implementation
owner: claude
topic_slug: ops-mason
created: "2026-09-21"
updated: "2026-09-21"
updated: "2026-09-28"
state_hub_workstream_id: "1b900161-51ff-544f-8412-ba7fcab64bb5"
---
@ -97,7 +97,7 @@ policy-nexus rule was used.
```task
id: MASON-WP-0006-T01
status: wait
status: done
priority: high
state_hub_task_id: "7b6fe7b4-08f7-5ad0-899d-a4862b5ddb00"
```
@ -120,11 +120,15 @@ question ops-mason can answer for itself. The founder chooses one of:
T03 must not merge before this is answered.
**Resolved 2026-09-21; implemented 2026-09-28.** The founder chose explicit
non-production placement for namespace whitehat. Decision and inbox receipt
are recorded in the September 28 review. This unblocks T03.
## Extend the bundle schema with the readiness block
```task
id: MASON-WP-0006-T02
status: todo
status: done
priority: high
state_hub_task_id: "89d07bd5-5a92-5a06-9ecb-441799c14dd7"
```
@ -135,11 +139,15 @@ is included in the bundle digest, as the bundle file already is. Add a
`APPROVED`, and a `--readiness-repo` option. `BREAK_GLASS` requires a
`--break-glass-reason` string. No existing refusal is relaxed.
**Done 2026-09-28.** Schema/CLI implemented; the mapping also requires an
explicit namespace matching the bundle. Whitehat now pins the source used to
check whether a binding supersedes its explicit placement.
## Enforce the tier in preflight and apply
```task
id: MASON-WP-0006-T03
status: todo
status: done
priority: high
state_hub_task_id: "163a807b-29aa-5eb7-a9a8-ef1ac70c89d3"
```
@ -163,11 +171,17 @@ Tests, all against the injected runner:
- the existing forbidden-kind, `data`/`stringData` and namespace tests still pass
unchanged.
**Done 2026-09-28.** Source digest, ancestry, local freshness and complete
binding history are checked. Historical production approval remains production;
deprecation retains the last known tier. Unknowns fail closed. The policy-nexus
transition stops on December 21 itself. Preflight reports; apply refuses before
Kubernetes commands. Covered by injected-runner regression tests.
## Record BREAK_GLASS and its reconcile-back obligation
```task
id: MASON-WP-0006-T04
status: todo
status: done
priority: medium
state_hub_task_id: "66349531-09ee-55b9-be47-537842c80f3b"
```
@ -177,11 +191,15 @@ record and prints the follow-up that is owed: the same change, committed to the
manifest repository that ArgoCD reconciles. ops-mason does not open that change
itself.
**Done 2026-09-28.** Apply evidence and printed JSON include the emergency
reason, local account, UTC time and GitOps reconciliation obligation. Empty
reasons are refused without invoking the runner.
## Update the docs and the declaration
```task
id: MASON-WP-0006-T05
status: todo
status: done
priority: medium
state_hub_task_id: "6d64e7f5-9cff-5bf9-9851-97d318d1df0a"
```
@ -190,6 +208,10 @@ Update `docs/kubernetes-plane.md` with the tier table and the readiness block,
and change the `enforcement` line of the `kubernetes-plane-apply` entry in
`INTENT.md` from "not yet in code" to point at the check.
**Done 2026-09-28.** Documented tiers, pins, mapping, history, checkout
freshness limits and emergency procedure; removed the withdrawn
rail-kubernetes ownership/layer assertion from INTENT.md.
## Review on 2026-12-21
```task
@ -203,3 +225,9 @@ On 2026-12-21 the policy-nexus transition ends and the plan-approval exception
comes up for review. Confirm with railiance-platform that policy-nexus is
onboarded to ArgoCD. The date check in T03 ends the transition in code on that
date either way.
## Loose-end review — 2026-09-28
T01–T05 are done: the founder resolved the whitehat placement and the guarded readiness implementation, tests, emergency evidence and docs are complete. T06 remains wait until the 2026-12-21 platform/exception review; this workplan is blocked on that dated review.
Evidence and precise resumption conditions: [review](../docs/evidence/2026-09-28-loose-end-review.md). Existing tasks retain all remaining obligations; no new task or workplan was opened.