ops-mason/workplans
codex 9ffa279d1f feat(workplan): open MASON-WP-0003 for the state-hub forge read lane
Nine private repositories are invisible to the hub's derivation: the pod clones
Forgejo anonymously, so ADR-012's premise that the forge is the projection
source holds only for repositories central can read.

warden route find returns no lane for this need, and the nearest entry is an
operator admin PAT owned by railiance-platform — more authority than derivation
requires. ops-mason owns AppRoles, policies and KV paths, which is what is
missing.

Six tasks: settle scope and breadth, create the AppRole and KV path, register
the routing entry, deliver the credential to the pod, teach the derivation to
use it, and confirm the nine. Token creation stays operator-executed; this
workplan describes the lane rather than performing it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-26 21:09:34 +02:00
..
MASON-0001-statehub-bootstrap.md Mark MASON-0001 bootstrap workplan finished 2026-07-27 02:03:45 +02:00
MASON-WP-0001-foundation.md fix(workplans): declare type: workplan on records the hub already holds 2026-08-26 20:56:05 +02:00
MASON-WP-0002-whitehat-foundational-plane.md close: finish MASON-WP-0002 with governed residual 2026-08-22 11:36:13 +02:00
MASON-WP-0003-state-hub-forge-read-lane.md feat(workplan): open MASON-WP-0003 for the state-hub forge read lane 2026-08-26 21:09:34 +02:00