Commit graph

62 commits

Author SHA1 Message Date
1fdd8896f4 refactor(workplan): split MASON-WP-0003 to the lane ops-mason owns
Trim MASON-WP-0003 to T01-T03 — decide, build the AppRole/policy/KV path
structure, register the catalog entry — and route it through the
four-phase pipeline via plans/state-hub-forge-derivation-read.md, which
supplies the phase-3 executive summary the workplan was bypassing.

T02 no longer mints or holds the token value: SCOPE.md puts secret
values out of scope, so the forge owner mints and ops-warden's
paste_once_provision desk delivers.

Deployment plumbing, derive_from_forge(), and the fleet re-run move to
state-hub/STATE-WP-0084.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 3377672@bnt-lap001
Assistant-Session: 15463ccf-238f-4e13-b163-93aa25c6d166
2026-08-26 21:25:43 +02:00
repo-manager
463c47faf6 chore(registrar): assign State Hub identifiers
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-26 21:10:12 +02:00
9ffa279d1f feat(workplan): open MASON-WP-0003 for the state-hub forge read lane
Nine private repositories are invisible to the hub's derivation: the pod clones
Forgejo anonymously, so ADR-012's premise that the forge is the projection
source holds only for repositories central can read.

warden route find returns no lane for this need, and the nearest entry is an
operator admin PAT owned by railiance-platform — more authority than derivation
requires. ops-mason owns AppRoles, policies and KV paths, which is what is
missing.

Six tasks: settle scope and breadth, create the AppRole and KV path, register
the routing entry, deliver the credential to the pod, teach the derivation to
use it, and confirm the nine. Token creation stays operator-executed; this
workplan describes the lane rather than performing it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-26 21:09:34 +02:00
3fd1258d11 fix(workplans): declare type: workplan on records the hub already holds
These files carried no type field at all. Selection is by 'type: workplan', so
they were invisible to every projection while the hub held a record for each —
and a forge-derived reset read those correct records as no longer deriving and
queued them for retirement.

Only the type line is added.

Refs STATE-WP-0083-T05

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-26 20:56:05 +02:00
50d70004ea docs(agents): repoint remote State Hub URL to the in-cluster address
The remote row pointed at 127.0.0.1:18000, a reverse tunnel back to the
workstation. On railiance01 the State Hub runs in the cluster on that same
machine, so the request left the box and came back to reach a local service.

Refs CUST-WP-0067-T07

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-25 00:21:30 +02:00
7a45e5f249 Close legacy identifier intake
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 23:21:23 +02:00
77ac35f727 close: finish MASON-WP-0002 with governed residual
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 11:36:13 +02:00
custodian-sync
484afb35d8 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-22:
  - update .custodian-brief.md for ops-mason

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 11:36:03 +02:00
a5865b4703 chore(registrar): bind MASON-IN-0001 residual
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 11:34:25 +02:00
8b4405caf3 intake: hand off legacy MASON identifier scheme
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 11:33:34 +02:00
cc9946c873 chore: reconcile ops-mason repository records
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 11:32:34 +02:00
c26a6e59de build: provision and verify Whitehat foundational plane
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 11:26:49 +02:00
acab22ff25 chore(consistency): sync MASON-WP-0002 task status
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 11:24:12 +02:00
custodian-sync
b2d67a8899 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-22:
  - update .custodian-brief.md for ops-mason

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 11:23:57 +02:00
2b318634b6 build: add guarded Kubernetes plane executor
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 11:23:38 +02:00
1dd98b4f27 docs: capture ops-mason consistency debt in T04
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 10:10:14 +02:00
df4d0fba5b docs: keep MASON-WP-0002 review metadata stable
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 10:08:46 +02:00
6c2cfebcc1 docs: record MASON-WP-0002 readiness assessment
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 10:08:03 +02:00
5a203214ec chore(registrar): bind MASON-WP-0002 identifiers
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 10:06:43 +02:00
c7fd599546 plan: govern Whitehat foundational plane provisioning
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 10:05:42 +02:00
24c6b433ed build: backup-object-storage AppRole lane delivered 2026-08-14 20:00:16 +02:00
deb8f4e119 note: backup object-storage KV exists; policy apply still deferred 2026-08-14 19:34:41 +02:00
a6cb560d01 retarget: mason plan backup-object-storage replaces Barman draft 2026-08-14 19:19:56 +02:00
cbe19c9bb0 plan: draft OpenBao lane for platform-pg Barman key 2026-08-14 19:01:11 +02:00
95aaea5488 plan: mark Scaleway bootstrap lane built with placeholders
Empty-structure plus xxx example fields. Founder replaces values
in the OpenBao UI before any bucket create.
2026-08-14 17:40:09 +02:00
15c155dd96 plan: reef-storage Scaleway bootstrap KV lane
Map Terraform access_key/secret_key/organization_id/project_id onto
the reserved OpenBao path. Structure only; founder pastes values.
2026-08-14 17:36:17 +02:00
8e41f85121 Build audit-core AppRole lane after founder approval
reuse_policy leaves external-secrets-audit-core intact so database
leases keep working. AppRole delivered to Kubernetes; interim static
ESO token retired.
2026-08-13 10:42:59 +02:00
93b9c1a027 Review construction plan for audit-core OpenBao runtime custody
Awaiting founder approve. Receiver already runs on the interim ESO token;
phase 4 replaces it with an AppRole and an empty senders KV path.
2026-08-13 10:27:13 +02:00
dcc933abd5 Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout)
Maintainer decision, 2026-07-29: adopts TRSL V1C1 as this repo's preliminary governing license, per target-revenue's workplans/TREV-WP-0008-governance-and-pilot-rollout.md T05. Full specialist legal review is deferred until out of beta (target-revenue SCOPE.md section 1). No Phase is yet declared for this repo.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-30 00:42:40 +02:00
ecba442fe6 Record built user-engine custody plan 2026-07-30 00:40:49 +02:00
8578a0074d Plan user-engine runtime secret custody 2026-07-30 00:22:35 +02:00
26cb011141 Record verified Qonto AppRole bridge 2026-07-27 03:13:46 +02:00
239776974b Revise Qonto secret lane for cross-cluster topology 2026-07-27 02:37:26 +02:00
8d89611b22 Plan Qonto Kubernetes credential lane 2026-07-27 02:06:59 +02:00
3125e94219 Regenerate WORK-RECORDS.md
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 02:04:17 +02:00
custodian-sync
e8eb989a0e chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-27:
  - update .custodian-brief.md for ops-mason
2026-07-27 02:03:59 +02:00
910aa75d96 Mark MASON-0001 bootstrap workplan finished
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 02:03:45 +02:00
custodian-sync
711bbbed8a chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-27:
  - update .custodian-brief.md for ops-mason
2026-07-27 02:00:46 +02:00
5459a8467f Mark MASON-WP-0001 finished
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 02:00:33 +02:00
custodian-sync
607dde6bbd chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-27:
  - update .custodian-brief.md for ops-mason
2026-07-27 01:50:33 +02:00
9bcb5819de Fix KV v2 policy path shape; live end-to-end verification succeeded
Two more real bugs found completing this lane for real:

1. platform-admin's own policy had no entry for the new reins/ mount --
   the founder's paste-once-provision write 403'd because the admin
   identity that created the mount was never granted access to operate
   on it. Fixed live (added path "reins/*" matching every other mount
   already in that policy).

2. _policy_hcl wrote the bare KV-v1-shaped path
   (reins/rein-openweights/openrouter) instead of KV v2's data/+metadata/
   sub-paths -- bao token capabilities on the bare path even reported
   full access, but the actual kv get still 403'd, because OpenBao
   evaluates the real request against the data/-prefixed path. Caught
   when the AppRole's own read failed during live verification. Fixed
   in code (now emits both data/ and metadata/ paths), locked in with a
   dedicated unit test, and re-applied to the live policy.

Live end-to-end verification succeeded after both fixes: real AppRole
login, real KV v2 read via the corrected policy, real OpenRouter call,
real commit -- with OPENROUTER_API_KEY unset the whole time. Plan status:
catalogued. glas-harness/GLAS-WP-0002-T02 is closed by this.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 01:50:18 +02:00
846ef0561c Regenerate WORK-RECORDS.md
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 01:25:50 +02:00
custodian-sync
559be9dcf0 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-27:
  - update .custodian-brief.md for ops-mason
2026-07-27 01:25:29 +02:00
33573a35a1 Real build executed for real (MASON-WP-0001-T05, MASON-WP-0001 done 5/5)
Ran the whole approved pipeline against real OpenBao: created the reins/
KV v2 mount (after pausing for explicit founder confirmation -- a bigger
action than the executive summary's blast-radius framing disclosed),
the read-only policy, the AppRole, delivered role_id/secret_id. Caught
and fixed a real bug in the same pass: built with token_num_uses=0
(OpenBao's default = unlimited) instead of the plan's own stated 8;
fixed live and removed the executor's silently-permissive default so it
can't recur. Catalog entry proposed and merged in ops-warden (c0a50bc).

Corrected a real misreading in this repo's own INTENT.md along the way:
pointer fields (auth_method/fetch_command/rotation.steps) are normal on
non-SSH catalog entries; only a bare top-level steps:+cert_command:
pair is SSH-only -- verified against ops-warden's real entries and its
full test suite (326 tests, green).

Plan status: built. Catalog entry status: draft until the founder's
paste-once-provision and glas-harness/GLAS-WP-0002-T02's live
verification succeed.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 01:25:14 +02:00
ae75a6c4d9 Regenerate WORK-RECORDS.md
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 01:00:06 +02:00
custodian-sync
ce6febb8f5 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-27:
  - update .custodian-brief.md for ops-mason
2026-07-27 00:59:48 +02:00
custodian-sync
36f3874b9c chore(consistency): renormalize lifecycle state [auto]
Updated by fix-consistency on 2026-07-27:
  - workplan status: proposed → active
2026-07-27 00:59:45 +02:00
116db485d9 Record founder approval on the rein-openweights AppRole plan
status: approved, approved_by: Bernd Worsch, approved_at: 2026-07-27.
Verified against the real executor code: ConstructionPlan.load(...)
.is_approved() returns True for this file. MASON-WP-0001-T05 moves from
todo to wait -- the approval gate is cleared, phase 4 execution is
blocked only on a real OpenBao session existing somewhere (bao token
lookup still 403 from this workstation).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 00:59:37 +02:00
233bcef478 Regenerate WORK-RECORDS.md
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 00:57:02 +02:00
custodian-sync
5abea5d549 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-27:
  - update .custodian-brief.md for ops-mason
2026-07-27 00:56:46 +02:00