Enforce readiness tiers and reconcile blocked workplans
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e75a-fc5c-7913-9dba-9846210c766d
This commit is contained in:
parent
370e1f84c7
commit
36445ae679
14 changed files with 652 additions and 39 deletions
|
|
@ -4,12 +4,12 @@ type: workplan
|
|||
title: "Check the target's readiness tier before a direct Kubernetes apply"
|
||||
domain: infotech
|
||||
repo: ops-mason
|
||||
status: proposed
|
||||
status: blocked
|
||||
flavor: implementation
|
||||
owner: claude
|
||||
topic_slug: ops-mason
|
||||
created: "2026-09-21"
|
||||
updated: "2026-09-21"
|
||||
updated: "2026-09-28"
|
||||
state_hub_workstream_id: "1b900161-51ff-544f-8412-ba7fcab64bb5"
|
||||
---
|
||||
|
||||
|
|
@ -97,7 +97,7 @@ policy-nexus rule was used.
|
|||
|
||||
```task
|
||||
id: MASON-WP-0006-T01
|
||||
status: wait
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "7b6fe7b4-08f7-5ad0-899d-a4862b5ddb00"
|
||||
```
|
||||
|
|
@ -120,11 +120,15 @@ question ops-mason can answer for itself. The founder chooses one of:
|
|||
|
||||
T03 must not merge before this is answered.
|
||||
|
||||
**Resolved 2026-09-21; implemented 2026-09-28.** The founder chose explicit
|
||||
non-production placement for namespace whitehat. Decision and inbox receipt
|
||||
are recorded in the September 28 review. This unblocks T03.
|
||||
|
||||
## Extend the bundle schema with the readiness block
|
||||
|
||||
```task
|
||||
id: MASON-WP-0006-T02
|
||||
status: todo
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "89d07bd5-5a92-5a06-9ecb-441799c14dd7"
|
||||
```
|
||||
|
|
@ -135,11 +139,15 @@ is included in the bundle digest, as the bundle file already is. Add a
|
|||
`APPROVED`, and a `--readiness-repo` option. `BREAK_GLASS` requires a
|
||||
`--break-glass-reason` string. No existing refusal is relaxed.
|
||||
|
||||
**Done 2026-09-28.** Schema/CLI implemented; the mapping also requires an
|
||||
explicit namespace matching the bundle. Whitehat now pins the source used to
|
||||
check whether a binding supersedes its explicit placement.
|
||||
|
||||
## Enforce the tier in preflight and apply
|
||||
|
||||
```task
|
||||
id: MASON-WP-0006-T03
|
||||
status: todo
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "163a807b-29aa-5eb7-a9a8-ef1ac70c89d3"
|
||||
```
|
||||
|
|
@ -163,11 +171,17 @@ Tests, all against the injected runner:
|
|||
- the existing forbidden-kind, `data`/`stringData` and namespace tests still pass
|
||||
unchanged.
|
||||
|
||||
**Done 2026-09-28.** Source digest, ancestry, local freshness and complete
|
||||
binding history are checked. Historical production approval remains production;
|
||||
deprecation retains the last known tier. Unknowns fail closed. The policy-nexus
|
||||
transition stops on December 21 itself. Preflight reports; apply refuses before
|
||||
Kubernetes commands. Covered by injected-runner regression tests.
|
||||
|
||||
## Record BREAK_GLASS and its reconcile-back obligation
|
||||
|
||||
```task
|
||||
id: MASON-WP-0006-T04
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
state_hub_task_id: "66349531-09ee-55b9-be47-537842c80f3b"
|
||||
```
|
||||
|
|
@ -177,11 +191,15 @@ record and prints the follow-up that is owed: the same change, committed to the
|
|||
manifest repository that ArgoCD reconciles. ops-mason does not open that change
|
||||
itself.
|
||||
|
||||
**Done 2026-09-28.** Apply evidence and printed JSON include the emergency
|
||||
reason, local account, UTC time and GitOps reconciliation obligation. Empty
|
||||
reasons are refused without invoking the runner.
|
||||
|
||||
## Update the docs and the declaration
|
||||
|
||||
```task
|
||||
id: MASON-WP-0006-T05
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
state_hub_task_id: "6d64e7f5-9cff-5bf9-9851-97d318d1df0a"
|
||||
```
|
||||
|
|
@ -190,6 +208,10 @@ Update `docs/kubernetes-plane.md` with the tier table and the readiness block,
|
|||
and change the `enforcement` line of the `kubernetes-plane-apply` entry in
|
||||
`INTENT.md` from "not yet in code" to point at the check.
|
||||
|
||||
**Done 2026-09-28.** Documented tiers, pins, mapping, history, checkout
|
||||
freshness limits and emergency procedure; removed the withdrawn
|
||||
rail-kubernetes ownership/layer assertion from INTENT.md.
|
||||
|
||||
## Review on 2026-12-21
|
||||
|
||||
```task
|
||||
|
|
@ -203,3 +225,9 @@ On 2026-12-21 the policy-nexus transition ends and the plan-approval exception
|
|||
comes up for review. Confirm with railiance-platform that policy-nexus is
|
||||
onboarded to ArgoCD. The date check in T03 ends the transition in code on that
|
||||
date either way.
|
||||
|
||||
## Loose-end review — 2026-09-28
|
||||
|
||||
T01–T05 are done: the founder resolved the whitehat placement and the guarded readiness implementation, tests, emergency evidence and docs are complete. T06 remains wait until the 2026-12-21 platform/exception review; this workplan is blocked on that dated review.
|
||||
|
||||
Evidence and precise resumption conditions: [review](../docs/evidence/2026-09-28-loose-end-review.md). Existing tasks retain all remaining obligations; no new task or workplan was opened.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue