Enforce readiness tiers and reconcile blocked workplans
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e75a-fc5c-7913-9dba-9846210c766d
This commit is contained in:
parent
370e1f84c7
commit
36445ae679
14 changed files with 652 additions and 39 deletions
|
|
@ -4,11 +4,12 @@ type: workplan
|
|||
title: "Describe every stored credential so the store is navigable"
|
||||
domain: infotech
|
||||
repo: ops-mason
|
||||
status: proposed
|
||||
status: blocked
|
||||
flavor: planning
|
||||
owner: codex
|
||||
topic_slug: custodian
|
||||
created: "2026-08-28"
|
||||
updated: "2026-09-28"
|
||||
related:
|
||||
- MASON-WP-0003
|
||||
- NK-WP-0033
|
||||
|
|
@ -48,7 +49,7 @@ read, and `ops-mason-build` cannot read one.
|
|||
|
||||
```task
|
||||
id: MASON-WP-0004-T01
|
||||
status: todo
|
||||
status: wait
|
||||
priority: medium
|
||||
state_hub_task_id: "5bda75f2-f780-579e-9d44-cc4011662b9a"
|
||||
```
|
||||
|
|
@ -68,7 +69,7 @@ listed as unknown with the question that would settle it.
|
|||
|
||||
```task
|
||||
id: MASON-WP-0004-T02
|
||||
status: todo
|
||||
status: wait
|
||||
priority: medium
|
||||
state_hub_task_id: "a6a944d7-21c5-5043-a78d-b3809de0ee64"
|
||||
```
|
||||
|
|
@ -121,3 +122,9 @@ the report has a reader.
|
|||
|
||||
Acceptance: an undescribed path added today surfaces without anyone
|
||||
remembering to look.
|
||||
|
||||
## Loose-end review — 2026-09-28
|
||||
|
||||
T01–T04 remain wait: no valid scoped metadata grant/current inventory or complete owner/recovery confirmations are available. Inventory failure handling and the private-tunnel defaults are fixed and tested; scheduled reporting still needs its reader and credential.
|
||||
|
||||
Evidence and precise resumption conditions: [review](../docs/evidence/2026-09-28-loose-end-review.md). Existing tasks retain all remaining obligations; no new task or workplan was opened.
|
||||
|
|
|
|||
|
|
@ -4,13 +4,12 @@ type: workplan
|
|||
title: "Construct the fluid-telegram operator credential lane"
|
||||
domain: infotech
|
||||
repo: ops-mason
|
||||
status: proposed
|
||||
status: blocked
|
||||
flavor: planning
|
||||
owner: codex
|
||||
topic_slug: helix-forge
|
||||
created: "2026-09-04"
|
||||
updated: "2026-09-04"
|
||||
state_hub_workstream_id: "483e56d6-6601-5377-9066-66225214c046"
|
||||
updated: "2026-09-28"
|
||||
state_hub_workstream_id: "483e56d6-6601-5377-9066-66225214c046"
|
||||
---
|
||||
|
||||
|
|
@ -65,7 +64,7 @@ from the current disk-only survey.
|
|||
|
||||
```task
|
||||
id: MASON-WP-0005-T02
|
||||
status: todo
|
||||
status: wait
|
||||
priority: high
|
||||
state_hub_task_id: "69c558d9-664f-5ce0-80b2-d2e7544353a3"
|
||||
```
|
||||
|
|
@ -86,7 +85,7 @@ parent access, and the create-only salt shape.
|
|||
|
||||
```task
|
||||
id: MASON-WP-0005-T03
|
||||
status: todo
|
||||
status: wait
|
||||
priority: high
|
||||
state_hub_task_id: "48a2b4ec-8e66-5b98-b039-c17fd8d820ab"
|
||||
```
|
||||
|
|
@ -103,7 +102,7 @@ adapter separation for explicit human approval. Only the plan's
|
|||
|
||||
```task
|
||||
id: MASON-WP-0005-T04
|
||||
status: todo
|
||||
status: wait
|
||||
priority: high
|
||||
state_hub_task_id: "0e3d1333-ffc3-5f67-8528-50a9551c4949"
|
||||
```
|
||||
|
|
@ -122,7 +121,7 @@ a provisioner capability.
|
|||
|
||||
```task
|
||||
id: MASON-WP-0005-T05
|
||||
status: todo
|
||||
status: wait
|
||||
priority: high
|
||||
state_hub_task_id: "4c205be7-4f1f-5dd1-aafa-fc112fdd640e"
|
||||
```
|
||||
|
|
@ -147,7 +146,7 @@ operator/platform flow and return metadata-only evidence to ops-mason.
|
|||
|
||||
```task
|
||||
id: MASON-WP-0005-T06
|
||||
status: todo
|
||||
status: wait
|
||||
priority: medium
|
||||
state_hub_task_id: "09eae088-808d-5342-b100-292e13958ee3"
|
||||
```
|
||||
|
|
@ -163,3 +162,9 @@ The adapter lane is tracked separately as `MASON-IN-0003`, tied to
|
|||
`redaction-salt`; it must be denied `operator-app` and `operator-session` and
|
||||
must use the adapter's own runtime identity rather than this attended OIDC
|
||||
role.
|
||||
|
||||
## Loose-end review — 2026-09-28
|
||||
|
||||
T01–T06 remain wait: accepted tenant/matrix, confirmed identity/MFA/callbacks, approved matching writer contracts, live survey, explicit construction approval and verification are outstanding. The platform design remains proposed. No lane was built or activated.
|
||||
|
||||
Evidence and precise resumption conditions: [review](../docs/evidence/2026-09-28-loose-end-review.md). Existing tasks retain all remaining obligations; no new task or workplan was opened.
|
||||
|
|
|
|||
|
|
@ -4,12 +4,12 @@ type: workplan
|
|||
title: "Check the target's readiness tier before a direct Kubernetes apply"
|
||||
domain: infotech
|
||||
repo: ops-mason
|
||||
status: proposed
|
||||
status: blocked
|
||||
flavor: implementation
|
||||
owner: claude
|
||||
topic_slug: ops-mason
|
||||
created: "2026-09-21"
|
||||
updated: "2026-09-21"
|
||||
updated: "2026-09-28"
|
||||
state_hub_workstream_id: "1b900161-51ff-544f-8412-ba7fcab64bb5"
|
||||
---
|
||||
|
||||
|
|
@ -97,7 +97,7 @@ policy-nexus rule was used.
|
|||
|
||||
```task
|
||||
id: MASON-WP-0006-T01
|
||||
status: wait
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "7b6fe7b4-08f7-5ad0-899d-a4862b5ddb00"
|
||||
```
|
||||
|
|
@ -120,11 +120,15 @@ question ops-mason can answer for itself. The founder chooses one of:
|
|||
|
||||
T03 must not merge before this is answered.
|
||||
|
||||
**Resolved 2026-09-21; implemented 2026-09-28.** The founder chose explicit
|
||||
non-production placement for namespace whitehat. Decision and inbox receipt
|
||||
are recorded in the September 28 review. This unblocks T03.
|
||||
|
||||
## Extend the bundle schema with the readiness block
|
||||
|
||||
```task
|
||||
id: MASON-WP-0006-T02
|
||||
status: todo
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "89d07bd5-5a92-5a06-9ecb-441799c14dd7"
|
||||
```
|
||||
|
|
@ -135,11 +139,15 @@ is included in the bundle digest, as the bundle file already is. Add a
|
|||
`APPROVED`, and a `--readiness-repo` option. `BREAK_GLASS` requires a
|
||||
`--break-glass-reason` string. No existing refusal is relaxed.
|
||||
|
||||
**Done 2026-09-28.** Schema/CLI implemented; the mapping also requires an
|
||||
explicit namespace matching the bundle. Whitehat now pins the source used to
|
||||
check whether a binding supersedes its explicit placement.
|
||||
|
||||
## Enforce the tier in preflight and apply
|
||||
|
||||
```task
|
||||
id: MASON-WP-0006-T03
|
||||
status: todo
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "163a807b-29aa-5eb7-a9a8-ef1ac70c89d3"
|
||||
```
|
||||
|
|
@ -163,11 +171,17 @@ Tests, all against the injected runner:
|
|||
- the existing forbidden-kind, `data`/`stringData` and namespace tests still pass
|
||||
unchanged.
|
||||
|
||||
**Done 2026-09-28.** Source digest, ancestry, local freshness and complete
|
||||
binding history are checked. Historical production approval remains production;
|
||||
deprecation retains the last known tier. Unknowns fail closed. The policy-nexus
|
||||
transition stops on December 21 itself. Preflight reports; apply refuses before
|
||||
Kubernetes commands. Covered by injected-runner regression tests.
|
||||
|
||||
## Record BREAK_GLASS and its reconcile-back obligation
|
||||
|
||||
```task
|
||||
id: MASON-WP-0006-T04
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
state_hub_task_id: "66349531-09ee-55b9-be47-537842c80f3b"
|
||||
```
|
||||
|
|
@ -177,11 +191,15 @@ record and prints the follow-up that is owed: the same change, committed to the
|
|||
manifest repository that ArgoCD reconciles. ops-mason does not open that change
|
||||
itself.
|
||||
|
||||
**Done 2026-09-28.** Apply evidence and printed JSON include the emergency
|
||||
reason, local account, UTC time and GitOps reconciliation obligation. Empty
|
||||
reasons are refused without invoking the runner.
|
||||
|
||||
## Update the docs and the declaration
|
||||
|
||||
```task
|
||||
id: MASON-WP-0006-T05
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
state_hub_task_id: "6d64e7f5-9cff-5bf9-9851-97d318d1df0a"
|
||||
```
|
||||
|
|
@ -190,6 +208,10 @@ Update `docs/kubernetes-plane.md` with the tier table and the readiness block,
|
|||
and change the `enforcement` line of the `kubernetes-plane-apply` entry in
|
||||
`INTENT.md` from "not yet in code" to point at the check.
|
||||
|
||||
**Done 2026-09-28.** Documented tiers, pins, mapping, history, checkout
|
||||
freshness limits and emergency procedure; removed the withdrawn
|
||||
rail-kubernetes ownership/layer assertion from INTENT.md.
|
||||
|
||||
## Review on 2026-12-21
|
||||
|
||||
```task
|
||||
|
|
@ -203,3 +225,9 @@ On 2026-12-21 the policy-nexus transition ends and the plan-approval exception
|
|||
comes up for review. Confirm with railiance-platform that policy-nexus is
|
||||
onboarded to ArgoCD. The date check in T03 ends the transition in code on that
|
||||
date either way.
|
||||
|
||||
## Loose-end review — 2026-09-28
|
||||
|
||||
T01–T05 are done: the founder resolved the whitehat placement and the guarded readiness implementation, tests, emergency evidence and docs are complete. T06 remains wait until the 2026-12-21 platform/exception review; this workplan is blocked on that dated review.
|
||||
|
||||
Evidence and precise resumption conditions: [review](../docs/evidence/2026-09-28-loose-end-review.md). Existing tasks retain all remaining obligations; no new task or workplan was opened.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue