# Loose-end review — 2026-09-28 Reviewed every local workplan. MASON-0001 and MASON-WP-0001–0003 are finished; no open task in those files needs implementation. The three proposed workplans, MASON-WP-0004–0006, contain the remaining work. No new task or workplan was opened. Existing uncommitted intake, Telegram construction-plan, and lockfile work was left outside this change. ## MASON-WP-0006 T01 is answered by founder decision in `the-custodian/docs/kubernetes-change-gate-decision.md`, communicated by message `b41bd54f-a7a4-41e5-a1ee-aa9b0efa7dc5`: whitehat is explicitly non-production. The same decision and current agent orientation establish that ArgoCD has since been installed; the blanket absence-of-ArgoCD transition is obsolete. T02–T05 implemented in the readiness resolver, bundle, CLI, evidence and docs. Validation: 54 tests pass (`.venv/bin/pytest -q`), including a real temporary Git history that promotes then reverts a binding; `git diff --check` passes. Tests exercise approved and refused apply, explicit whitehat placement, binding supersession, stale/missing sources, namespace mapping, historical production approval, deprecation, the December 21 boundary, and emergency reason/evidence. Existing manifest and approval refusals remain covered. Secret-presence verification now requests object names, never Secret JSON. A read-only local source check resolves the actual whitehat bundle to non-production under APPROVED, using reef-railiance commit `e3c5ca2b74f6ae4f3b79f918708f3b573157a0c2`, bindings SHA-256 `796007c68f0eda1d50cebddf9e11a2c123a8814ebaf67f739ed5d2af2d6fa3f1`. No Kubernetes command or deployment was needed for this implementation. T06 stays wait: its review is due 2026-12-21 and requires platform confirmation of policy-nexus GitOps adoption and review of the accepted plan-approval exception. The workplan remains blocked, not finished; the existing task holds this obligation. ## MASON-WP-0004 The session check at `http://127.0.0.1:18200` reports no valid caller session and no scoped ops-mason grant. No credential value was requested. The original 21-path/17-undescribed inventory has no saved path-level snapshot in this repo; source documents cannot prove the current live path set or completeness. T01–T03 therefore remain wait for an attended scoped metadata grant, current inventory, and owner confirmations. No ownership or recovery story is invented. Source-backed candidates for the next T01 inventory comparison: | Path or family | Proposed responsible repo | Evidence / unresolved question | | --- | --- | --- | | operators/lldap/admin | net-kingdom | platform-root-custody.md; confirm current consumers and recovery | | operators/privacyidea/pi-admin | net-kingdom | platform-root-custody.md and verify-t06.md; confirm recovery ownership | | operators/forgejo/state-hub-svc | railiance-platform | MASON-WP-0003 construction/delivery record; confirm active metadata | | platform/workloads/railiance/backup/object-storage | railiance-platform | plans/backup-object-storage.md | | platform/workloads/railiance/backup/offsite-lane | railiance-platform | ops-warden catalog railiance-backup-offsite-lane | | platform/workloads/railiance/scaleway/bootstrap | railiance-platform | plans/reef-storage-scaleway-bootstrap.md | | user-engine/runtime and rapp-qonto families | owning consumer plus railiance-platform custody | corresponding plans in this repo; exact current paths need live inventory | | reuse-surface/runtime-secrets | reuse-surface plus railiance-platform custody | cited by T02; current owner procedure still needs confirmation | These are candidates, not accepted custom_metadata, and do not enumerate the missing seventeen. Every additional live path needs an owner or a named unknown before T01 can close. T04 preparation fixes an actual false-success defect: an unavailable/denied metadata request previously returned an empty list and exit 0. The inventory now exits 2 on missing grant, command failure or malformed response, exits 1 for missing descriptions, and reserves 0 for a completed inventory. It refuses to fall back silently to the user's default token. The default Bao address in both helpers now follows the private tunnel. Tests cover failure reporting and metadata-only traversal. Running it without a grant returned the expected explicit error, not a fictitious healthy inventory. Scheduled reporting remains blocked on T03 and a named reader plus a non-interactive metadata-only credential. No existing scheduler for this repo was found; a 45-minute interactive grant cannot support a durable schedule. ## MASON-WP-0005 The September 9 platform reply (`c0977d84-9a63-421d-8ee1-98587fc60b1b`) and `railiance-platform/docs/credential-lane-designs/fluid-telegram-operator-kv.md` confirm a proposed matrix, not an accepted writer contract. Tenant/path, field/capability acceptance, actual OIDC group/MFA and callbacks, named writer authority, matching platform validator/renderer, and live survey remain open. The existing ops-mason grant does not authorize auth/netkingdom role changes; it must not be widened to bypass this boundary. T01–T05 remain wait for those inputs and explicit construction approval. T02 cannot be called done by shipping an unapproved engine shape: the owner requires matching approved CCR and builder contracts before any writer. T06 also waits for verification and routing-owner acceptance; no live lane or resolvable pointer is claimed. Local draft preparation remains in the existing construction plan. The separate adapter demand stays in its existing intake.