ops-warden/registry/generated/high-risk-data-paths.yaml

110 lines
5.4 KiB
YAML
Raw Normal View History

# GENERATED by scripts/emit_high_risk_paths.py -- do not edit by hand.
# Concrete KV data paths for lanes ops-warden grades `risk: high`.
#
# This is an INPUT, not a policy. ops-warden states which paths it grades
# high; railiance-platform owns what agent-high-risk-boundary denies and may
# deny more, deny less, or dispute a grade (ADR-0002, ADR-0008).
#
# Grades cover every field a read of the path discloses, not the field the
# lane is named after (ADR-0008). `fields` is recorded where an owning CCR
# declares it, and is null where the field set has not been established --
# null means unknown, never 'one field'.
docs: narrow qonto blocker, record key-cape lane ownership key-cape corrected two blockers that had stopped being true after our 2026-08-28 source-read: - rapp-qonto-keycape-client: `keycape service-token` (2026-09-05) is the native exchange the blocker recorded as absent, and `keycape verify-client` (2026-09-08) is rotation step 3 as one command. Narrowed to steps 1-2 -- successor generation and the CAS write -- rather than cleared, as they asked. rotation.automatable -> false so a future executable driver is not told a lane with no admitted custody transport is drivable; the per-step truth moves into the steps. - key-cape-oidc-login: ownership ACCEPTED by key-cape, so verified moves from asked-and-waiting to owner-confirmed. Lane stays interim -- acceptance covers the identity half, while the fetch_command yields an OpenBao token whose mount, role mapping and enforcement are not key-cape's. Two tests pinned `key-cape-oidc-login` to sitting `asked-and-waiting`, so answering the question broke them -- they failed on good news. Both now assert the property instead: an unverified blocker is stale regardless of date, over whatever lanes are in that state. Verifying the routing answer against our own front door turned up a defect: `warden plan` returns `autonomous` for a custody *write* and answers it with read transports, because it has no read-versus-mutate intent. Recorded as WARDEN-WP-0038 (proposed) -- the WP-0033-T06 shape, as a class this time. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013EPuTc18FjU5WFqoSEKH3C Assistant: claude-code Assistant-Model: opus Assistant-Process: 1276224@bnt-lap001 Assistant-Session: 426ec497-e1c4-4dd3-b417-dfce1ca1dbc3
2026-09-08 14:55:02 +02:00
generated_at: "2026-09-08T12:52:59Z"
source: ops-warden/registry/routing/catalog.yaml
catalog_revision: "00145d705e88eeb9a880a85a3cc15a5205dde2d6"
catalog_revision_date: "2026-09-05T01:19:48+02:00"
docs: narrow qonto blocker, record key-cape lane ownership key-cape corrected two blockers that had stopped being true after our 2026-08-28 source-read: - rapp-qonto-keycape-client: `keycape service-token` (2026-09-05) is the native exchange the blocker recorded as absent, and `keycape verify-client` (2026-09-08) is rotation step 3 as one command. Narrowed to steps 1-2 -- successor generation and the CAS write -- rather than cleared, as they asked. rotation.automatable -> false so a future executable driver is not told a lane with no admitted custody transport is drivable; the per-step truth moves into the steps. - key-cape-oidc-login: ownership ACCEPTED by key-cape, so verified moves from asked-and-waiting to owner-confirmed. Lane stays interim -- acceptance covers the identity half, while the fetch_command yields an OpenBao token whose mount, role mapping and enforcement are not key-cape's. Two tests pinned `key-cape-oidc-login` to sitting `asked-and-waiting`, so answering the question broke them -- they failed on good news. Both now assert the property instead: an unverified blocker is stale regardless of date, over whatever lanes are in that state. Verifying the routing answer against our own front door turned up a defect: `warden plan` returns `autonomous` for a custody *write* and answers it with read transports, because it has no read-versus-mutate intent. Recorded as WARDEN-WP-0038 (proposed) -- the WP-0033-T06 shape, as a class this time. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013EPuTc18FjU5WFqoSEKH3C Assistant: claude-code Assistant-Model: opus Assistant-Process: 1276224@bnt-lap001 Assistant-Session: 426ec497-e1c4-4dd3-b417-dfce1ca1dbc3
2026-09-08 14:55:02 +02:00
catalog_dirty: true
high_risk_lane_count: 24
concrete_path_count: 15
# Graded high but not a single KV address -- a routing pattern, a broker
# grant, or a non-KV lane. Nothing here for a policy to deny.
no_concrete_path:
- database-dynamic-credentials
- inter-hub-bootstrap-ssh
- net-kingdom-lldap-bind-credential
- net-kingdom-privacyidea-admin-token
- object-storage-sts
- openbao-api-key
- openbao-platform-admin-login
- openbao-shamir-recovery-ceremony
- ops-warden-warden-sign-token
paths:
- id: agent-harness-binky-mail-approle
data_path: tenants/data/binky/company-email/imap
metadata_path: tenants/metadata/binky/company-email/imap
owner_repo: railiance-platform
fields: null # field set not established -- unknown, not one
- id: agent-harness-forgejo-deploy
data_path: platform/data/workloads/agent-harness/forgejo-deploy-key
metadata_path: platform/metadata/workloads/agent-harness/forgejo-deploy-key
owner_repo: railiance-platform
fields: null # field set not established -- unknown, not one
- id: audit-core-senders
data_path: platform/data/workloads/audit-core/senders
metadata_path: platform/metadata/workloads/audit-core/senders
owner_repo: ops-mason
fields: null # field set not established -- unknown, not one
- id: binky-company-email-imap
data_path: tenants/data/binky/company-email/imap
metadata_path: tenants/metadata/binky/company-email/imap
owner_repo: railiance-platform
fields: null # field set not established -- unknown, not one
- id: binky-qonto-api
data_path: tenants/data/binky/qonto-api
metadata_path: tenants/metadata/binky/qonto-api
owner_repo: railiance-platform
fields: null # field set not established -- unknown, not one
- id: email-connect-transactional
data_path: platform/data/workloads/email-connect/transactional
metadata_path: platform/metadata/workloads/email-connect/transactional
owner_repo: railiance-platform
fields: null # field set not established -- unknown, not one
- id: forgejo-admin-api-token
data_path: platform/data/workloads/forgejo/forgejo-admin
metadata_path: platform/metadata/workloads/forgejo/forgejo-admin
owner_repo: railiance-platform
fields: null # field set not established -- unknown, not one
- id: issue-core-ingestion-api-key
data_path: platform/data/workloads/issue-core/issue-core/issue-core-runtime
metadata_path: platform/metadata/workloads/issue-core/issue-core/issue-core-runtime
owner_repo: railiance-platform
fields: [ISSUE_CORE_API_KEY, GITEA_BACKEND_TOKEN]
- id: openrouter-llm-connect
data_path: platform/data/workloads/activity-core/llm-connect/llm-connect-provider-secrets
metadata_path: platform/metadata/workloads/activity-core/llm-connect/llm-connect-provider-secrets
owner_repo: railiance-platform
fields: null # field set not established -- unknown, not one
- id: policy-nexus-forgejo-source-read
data_path: platform/data/workloads/policy-nexus/forgejo-source-read
metadata_path: platform/metadata/workloads/policy-nexus/forgejo-source-read
owner_repo: railiance-platform
fields: null # field set not established -- unknown, not one
- id: railiance-backup-offsite-lane
data_path: platform/data/workloads/railiance/backup/offsite-lane
metadata_path: platform/metadata/workloads/railiance/backup/offsite-lane
owner_repo: railiance-platform
fields: null # field set not established -- unknown, not one
- id: rapp-qonto-keycape-client
data_path: platform/data/workloads/rapp-qonto/keycape-client
metadata_path: platform/metadata/workloads/rapp-qonto/keycape-client
owner_repo: key-cape
fields: null # field set not established -- unknown, not one
- id: reuse-surface-hub-write-token
data_path: platform/data/workloads/reuse/reuse-surface/runtime-secrets
metadata_path: platform/metadata/workloads/reuse/reuse-surface/runtime-secrets
owner_repo: railiance-platform
fields: [REUSE_SURFACE_TOKEN, REUSE_SURFACE_FORGEJO_WEBHOOK_SECRET]
- id: scaleway-bootstrap
data_path: platform/data/workloads/railiance/scaleway/bootstrap
metadata_path: platform/metadata/workloads/railiance/scaleway/bootstrap
owner_repo: railiance-platform
fields: null # field set not established -- unknown, not one
- id: whynot-design-npm-publish
data_path: platform/data/workloads/coulomb/whynot-design/npm-publish
metadata_path: platform/metadata/workloads/coulomb/whynot-design/npm-publish
owner_repo: railiance-platform
fields: null # field set not established -- unknown, not one