37 lines
898 B
Markdown
37 lines
898 B
Markdown
|
|
---
|
||
|
|
id: WARDEN-WP-0035
|
||
|
|
type: workplan
|
||
|
|
title: "Register the Policy Nexus Forgejo source-read route"
|
||
|
|
domain: infotech
|
||
|
|
repo: ops-warden
|
||
|
|
status: active
|
||
|
|
owner: codex
|
||
|
|
topic_slug: policy-nexus-forgejo-source-read
|
||
|
|
created: "2026-09-01"
|
||
|
|
updated: "2026-09-01"
|
||
|
|
---
|
||
|
|
|
||
|
|
## Register the exact high-risk lane
|
||
|
|
|
||
|
|
```task
|
||
|
|
id: WARDEN-WP-0035-T01
|
||
|
|
status: done
|
||
|
|
priority: high
|
||
|
|
```
|
||
|
|
|
||
|
|
Add the exact OpenBao path, field, OIDC role, owner pointer, and rotation
|
||
|
|
boundary from railiance-platform CCR-2026-0014. The entry must be concrete and
|
||
|
|
resolvable while remaining subject to Warden's high-risk agent read boundary.
|
||
|
|
|
||
|
|
## Verify routing and governed use
|
||
|
|
|
||
|
|
```task
|
||
|
|
id: WARDEN-WP-0035-T02
|
||
|
|
status: progress
|
||
|
|
priority: high
|
||
|
|
```
|
||
|
|
|
||
|
|
Pass catalog, route-selection, proxy, and policy tests; reinstall the CLI; prove
|
||
|
|
the installed route resolves and can hand the value only to a sanctioned child
|
||
|
|
transport without printing or persisting it.
|