Commit graph

59 commits

Author SHA1 Message Date
3fd1258d11 fix(workplans): declare type: workplan on records the hub already holds
These files carried no type field at all. Selection is by 'type: workplan', so
they were invisible to every projection while the hub held a record for each —
and a forge-derived reset read those correct records as no longer deriving and
queued them for retirement.

Only the type line is added.

Refs STATE-WP-0083-T05

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-26 20:56:05 +02:00
50d70004ea docs(agents): repoint remote State Hub URL to the in-cluster address
The remote row pointed at 127.0.0.1:18000, a reverse tunnel back to the
workstation. On railiance01 the State Hub runs in the cluster on that same
machine, so the request left the box and came back to reach a local service.

Refs CUST-WP-0067-T07

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-25 00:21:30 +02:00
7a45e5f249 Close legacy identifier intake
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 23:21:23 +02:00
77ac35f727 close: finish MASON-WP-0002 with governed residual
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 11:36:13 +02:00
custodian-sync
484afb35d8 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-22:
  - update .custodian-brief.md for ops-mason

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 11:36:03 +02:00
a5865b4703 chore(registrar): bind MASON-IN-0001 residual
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 11:34:25 +02:00
8b4405caf3 intake: hand off legacy MASON identifier scheme
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 11:33:34 +02:00
cc9946c873 chore: reconcile ops-mason repository records
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 11:32:34 +02:00
c26a6e59de build: provision and verify Whitehat foundational plane
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 11:26:49 +02:00
acab22ff25 chore(consistency): sync MASON-WP-0002 task status
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 11:24:12 +02:00
custodian-sync
b2d67a8899 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-22:
  - update .custodian-brief.md for ops-mason

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 11:23:57 +02:00
2b318634b6 build: add guarded Kubernetes plane executor
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 11:23:38 +02:00
1dd98b4f27 docs: capture ops-mason consistency debt in T04
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 10:10:14 +02:00
df4d0fba5b docs: keep MASON-WP-0002 review metadata stable
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 10:08:46 +02:00
6c2cfebcc1 docs: record MASON-WP-0002 readiness assessment
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 10:08:03 +02:00
5a203214ec chore(registrar): bind MASON-WP-0002 identifiers
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 10:06:43 +02:00
c7fd599546 plan: govern Whitehat foundational plane provisioning
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02878-7c21-7692-bcd6-ce2838c4b448
2026-08-22 10:05:42 +02:00
24c6b433ed build: backup-object-storage AppRole lane delivered 2026-08-14 20:00:16 +02:00
deb8f4e119 note: backup object-storage KV exists; policy apply still deferred 2026-08-14 19:34:41 +02:00
a6cb560d01 retarget: mason plan backup-object-storage replaces Barman draft 2026-08-14 19:19:56 +02:00
cbe19c9bb0 plan: draft OpenBao lane for platform-pg Barman key 2026-08-14 19:01:11 +02:00
95aaea5488 plan: mark Scaleway bootstrap lane built with placeholders
Empty-structure plus xxx example fields. Founder replaces values
in the OpenBao UI before any bucket create.
2026-08-14 17:40:09 +02:00
15c155dd96 plan: reef-storage Scaleway bootstrap KV lane
Map Terraform access_key/secret_key/organization_id/project_id onto
the reserved OpenBao path. Structure only; founder pastes values.
2026-08-14 17:36:17 +02:00
8e41f85121 Build audit-core AppRole lane after founder approval
reuse_policy leaves external-secrets-audit-core intact so database
leases keep working. AppRole delivered to Kubernetes; interim static
ESO token retired.
2026-08-13 10:42:59 +02:00
93b9c1a027 Review construction plan for audit-core OpenBao runtime custody
Awaiting founder approve. Receiver already runs on the interim ESO token;
phase 4 replaces it with an AppRole and an empty senders KV path.
2026-08-13 10:27:13 +02:00
dcc933abd5 Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout)
Maintainer decision, 2026-07-29: adopts TRSL V1C1 as this repo's preliminary governing license, per target-revenue's workplans/TREV-WP-0008-governance-and-pilot-rollout.md T05. Full specialist legal review is deferred until out of beta (target-revenue SCOPE.md section 1). No Phase is yet declared for this repo.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-30 00:42:40 +02:00
ecba442fe6 Record built user-engine custody plan 2026-07-30 00:40:49 +02:00
8578a0074d Plan user-engine runtime secret custody 2026-07-30 00:22:35 +02:00
26cb011141 Record verified Qonto AppRole bridge 2026-07-27 03:13:46 +02:00
239776974b Revise Qonto secret lane for cross-cluster topology 2026-07-27 02:37:26 +02:00
8d89611b22 Plan Qonto Kubernetes credential lane 2026-07-27 02:06:59 +02:00
3125e94219 Regenerate WORK-RECORDS.md
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 02:04:17 +02:00
custodian-sync
e8eb989a0e chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-27:
  - update .custodian-brief.md for ops-mason
2026-07-27 02:03:59 +02:00
910aa75d96 Mark MASON-0001 bootstrap workplan finished
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 02:03:45 +02:00
custodian-sync
711bbbed8a chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-27:
  - update .custodian-brief.md for ops-mason
2026-07-27 02:00:46 +02:00
5459a8467f Mark MASON-WP-0001 finished
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 02:00:33 +02:00
custodian-sync
607dde6bbd chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-27:
  - update .custodian-brief.md for ops-mason
2026-07-27 01:50:33 +02:00
9bcb5819de Fix KV v2 policy path shape; live end-to-end verification succeeded
Two more real bugs found completing this lane for real:

1. platform-admin's own policy had no entry for the new reins/ mount --
   the founder's paste-once-provision write 403'd because the admin
   identity that created the mount was never granted access to operate
   on it. Fixed live (added path "reins/*" matching every other mount
   already in that policy).

2. _policy_hcl wrote the bare KV-v1-shaped path
   (reins/rein-openweights/openrouter) instead of KV v2's data/+metadata/
   sub-paths -- bao token capabilities on the bare path even reported
   full access, but the actual kv get still 403'd, because OpenBao
   evaluates the real request against the data/-prefixed path. Caught
   when the AppRole's own read failed during live verification. Fixed
   in code (now emits both data/ and metadata/ paths), locked in with a
   dedicated unit test, and re-applied to the live policy.

Live end-to-end verification succeeded after both fixes: real AppRole
login, real KV v2 read via the corrected policy, real OpenRouter call,
real commit -- with OPENROUTER_API_KEY unset the whole time. Plan status:
catalogued. glas-harness/GLAS-WP-0002-T02 is closed by this.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 01:50:18 +02:00
846ef0561c Regenerate WORK-RECORDS.md
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 01:25:50 +02:00
custodian-sync
559be9dcf0 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-27:
  - update .custodian-brief.md for ops-mason
2026-07-27 01:25:29 +02:00
33573a35a1 Real build executed for real (MASON-WP-0001-T05, MASON-WP-0001 done 5/5)
Ran the whole approved pipeline against real OpenBao: created the reins/
KV v2 mount (after pausing for explicit founder confirmation -- a bigger
action than the executive summary's blast-radius framing disclosed),
the read-only policy, the AppRole, delivered role_id/secret_id. Caught
and fixed a real bug in the same pass: built with token_num_uses=0
(OpenBao's default = unlimited) instead of the plan's own stated 8;
fixed live and removed the executor's silently-permissive default so it
can't recur. Catalog entry proposed and merged in ops-warden (c0a50bc).

Corrected a real misreading in this repo's own INTENT.md along the way:
pointer fields (auth_method/fetch_command/rotation.steps) are normal on
non-SSH catalog entries; only a bare top-level steps:+cert_command:
pair is SSH-only -- verified against ops-warden's real entries and its
full test suite (326 tests, green).

Plan status: built. Catalog entry status: draft until the founder's
paste-once-provision and glas-harness/GLAS-WP-0002-T02's live
verification succeed.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 01:25:14 +02:00
ae75a6c4d9 Regenerate WORK-RECORDS.md
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 01:00:06 +02:00
custodian-sync
ce6febb8f5 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-27:
  - update .custodian-brief.md for ops-mason
2026-07-27 00:59:48 +02:00
custodian-sync
36f3874b9c chore(consistency): renormalize lifecycle state [auto]
Updated by fix-consistency on 2026-07-27:
  - workplan status: proposed → active
2026-07-27 00:59:45 +02:00
116db485d9 Record founder approval on the rein-openweights AppRole plan
status: approved, approved_by: Bernd Worsch, approved_at: 2026-07-27.
Verified against the real executor code: ConstructionPlan.load(...)
.is_approved() returns True for this file. MASON-WP-0001-T05 moves from
todo to wait -- the approval gate is cleared, phase 4 execution is
blocked only on a real OpenBao session existing somewhere (bao token
lookup still 403 from this workstation).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 00:59:37 +02:00
233bcef478 Regenerate WORK-RECORDS.md
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 00:57:02 +02:00
custodian-sync
5abea5d549 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-27:
  - update .custodian-brief.md for ops-mason
2026-07-27 00:56:46 +02:00
0d62ac501d Review/optimize checklist, executive-summary format, build executor (T02-T04)
docs/review-optimize-checklist.md: six checks (naming, TTL/scoping,
redundancy, compaction, ease of use, posture), applied for real to the
rein-openweights plan's section 4 -- including a genuinely useful
finding (credentials.py already expects this exact path/delivery shape,
zero code changes needed to consume it).

docs/executive-summary-format.md: six fixed fields, no bao syntax, no
restating earlier sections, explicit approve/reject/revise decision.
Rendered for real into the plan's section 5 -- ready for an actual
decision.

src/ops_mason/{plan,executor,audit}.py: the phase-4 build executor for
credential_type openbao-approle-kv. Refuses to run against anything but
an approved plan -- verified the refusal never even calls subprocess.run.
role_id/secret_id (the AppRole's own access credential, not the
downstream secret) land as 0600 files, never logged; the HCL policy
goes over stdin, never argv; the audit trail is metadata-only. 12 tests,
all mocked at the bao boundary (no live OpenBao access from this
session).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 00:56:34 +02:00
123ccfe20c Regenerate WORK-RECORDS.md
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 00:47:40 +02:00
custodian-sync
adb387cf99 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-27:
  - update .custodian-brief.md for ops-mason
2026-07-27 00:47:26 +02:00