feat(mason): approve the forge read lane and draft its catalog entry
Plan approved 2026-08-26, breadth organisation-wide repository read. The §4 contingency was satisfied first: STATE-WP-0084-T01 landed the same day, so a missing grant now surfaces as a named unreadable condition rather than as silence — which is what the breadth argument rested on. T01 done. T03 drafted in ops-warden on a branch (entry + playbook + regenerated high-risk artifact). T02 needs an operator: no valid OpenBao session here, and the token is the forge owner's to mint. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 3377672@bnt-lap001 Assistant-Session: 15463ccf-238f-4e13-b163-93aa25c6d166
This commit is contained in:
parent
2e9d1c3e67
commit
7018137c01
2 changed files with 64 additions and 4 deletions
|
|
@ -78,7 +78,7 @@ or without this credential.
|
|||
|
||||
```task
|
||||
id: MASON-WP-0003-T01
|
||||
status: todo
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "36d26000-ae71-5a58-a563-a07ff5be664f"
|
||||
```
|
||||
|
|
@ -106,11 +106,20 @@ Acceptance: the plan reaches `status: reviewed`, the founder decision is
|
|||
recorded with its reasoning rather than as a bare value, and the plan carries
|
||||
`approved_by`/`approved_at`.
|
||||
|
||||
**Done (2026-08-26).** Approved by Bernd Worsch, breadth **organisation-wide
|
||||
repository read**. The §4 contingency was satisfied first: `STATE-WP-0084-T01`
|
||||
landed 2026-08-26, so a repository central may not read now reports as
|
||||
unreadable and a source that produced no records cannot retire anything even
|
||||
when retirement is acknowledged — which is what makes a missing grant visible
|
||||
and, in turn, what the breadth argument rested on. Rotation was not separately
|
||||
ruled on; build-phase posture stands as proposed. Reasoning in
|
||||
`plans/state-hub-forge-derivation-read.md` §6.
|
||||
|
||||
## Build the AppRole, policy, and KV path structure
|
||||
|
||||
```task
|
||||
id: MASON-WP-0003-T02
|
||||
status: wait
|
||||
status: todo
|
||||
priority: high
|
||||
state_hub_task_id: "68a1c8e4-c12b-550e-962c-06a90ab8c1c2"
|
||||
```
|
||||
|
|
@ -135,7 +144,7 @@ approved plan.
|
|||
|
||||
```task
|
||||
id: MASON-WP-0003-T03
|
||||
status: wait
|
||||
status: progress
|
||||
priority: high
|
||||
state_hub_task_id: "e14f0eb3-a920-5623-b4c1-c20858dbb45d"
|
||||
```
|
||||
|
|
@ -152,6 +161,21 @@ contribution to `ops-warden`, not a live API call.
|
|||
Acceptance: `warden route find` returns the lane; `warden route show` gives an
|
||||
operator enough to act without reading this workplan.
|
||||
|
||||
**Drafted 2026-08-26**, awaiting contribution to `ops-warden` (branch
|
||||
`mason/state-hub-forge-derivation-read`, commit `3a4333d`). Entry
|
||||
`state-hub-forge-derivation-read`: pointer-only, `warden_executes: false`,
|
||||
`status: draft`, `risk: high` — graded on breadth rather than write authority,
|
||||
since the token is read-only but organisation-wide. Playbook at
|
||||
`wiki/playbooks/state-hub-forge-derivation-read.md`, whose verification section
|
||||
leads with the *negative* check: the AppRole must be denied on
|
||||
`platform/workloads/forgejo/forgejo-admin`, because not being able to do what
|
||||
the admin lane can is the entire argument for building this one.
|
||||
|
||||
`registry/generated/high-risk-data-paths.yaml` regenerated (21 → 24 lanes); it
|
||||
had been stale since 2026-08-23, so the regeneration also picks up two
|
||||
unrelated lanes. Promote the entry to `active` once T02 has built the structure
|
||||
and the negative check passes.
|
||||
|
||||
## Handoff
|
||||
|
||||
Once T02 and T03 are done, notify `state-hub` so `STATE-WP-0084-T02` can
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue