2026-06-17 23:34:13 +02:00
---
id: WARDEN-WP-0008
type: workplan
title: "Production SSH Path and Stewardship Closeout"
domain: custodian
repo: ops-warden
2026-06-18 01:28:49 +02:00
status: finished
2026-06-17 23:34:13 +02:00
owner: codex
topic_slug: custodian
planning_priority: high
planning_order: 8
created: "2026-06-17"
2026-06-18 01:06:43 +02:00
updated: "2026-06-18"
2026-06-17 23:34:51 +02:00
state_hub_workstream_id: "a174963a-4ff1-4565-b19f-896cd4ff14a0"
2026-06-17 23:34:13 +02:00
---
2026-07-08 20:26:36 +02:00
> **Terminology note:** Historical text in this archived workplan may use the legacy term "workstream". The fleet term is **workplan** (`canon/standards/workplan-terminology-fleet_v0.1.md`).
2026-06-17 23:34:13 +02:00
# WARDEN-WP-0008 — Production SSH Path and Stewardship Closeout
**Scope:** Close the reliability gap left after WARDEN-WP-0007 — prove the
production OpenBao SSH signing path end-to-end, refresh INTENT/SCOPE canon for
the shipped flex-auth policy gate, adapt repo docs to State Hub task-status
canon, and archive finished workplans.
**Out of scope:** OpenBao cluster deploy or SSH engine bootstrap (operator /
`railiance-platform` ), flex-auth policy package authoring, NK-WP-0009 joint
tutorial (coordinate separately), populating non-SSH secrets (e.g. OpenRouter
API keys — route to OpenBao per `wiki/CredentialRouting.md` ).
---
## Goal
Move ops-warden from **documented + code-shipped** (WP-0006/0007) to
**production-verified SSH issuance** with up-to-date stewardship canon:
1. A scoped operator can run `warden sign` against `https://bao.coulomb.social`
and record non-secret evidence.
2. `SCOPE.md` and reassessment history reflect WP-0007 policy gate as implemented.
3. Agent/workplan docs use State Hub task lifecycle (`wait` / `todo` / `progress`
/ `done` / `cancel` ).
4. Finished workplans WP-0004– 0007 are archived under `workplans/archived/` .
---
## Tasks
### T1 — Post-WP-0007 INTENT/SCOPE reassessment
```task
id: WARDEN-WP-0008-T01
2026-06-17 23:51:12 +02:00
status: done
2026-06-17 23:34:13 +02:00
priority: high
2026-06-17 23:34:51 +02:00
state_hub_task_id: "05379da4-79d0-4742-8638-9e9565cccf72"
2026-06-17 23:34:13 +02:00
```
2026-06-17 23:51:12 +02:00
- [x] Write `history/2026-06-17-post-wp0007-reassessment.md` (vector D5/A3/C4/R2)
- [x] Update `SCOPE.md` — policy gate implemented, WP-0008 active
- [x] Resolve remaining `PolicyGatedSigning.md (not implemented)` references in SCOPE/README
2026-06-17 23:34:13 +02:00
### T2 — Production OpenBao end-to-end sign verification
```task
id: WARDEN-WP-0008-T02
2026-06-18 01:18:57 +02:00
status: done
2026-06-17 23:34:13 +02:00
priority: high
2026-06-17 23:34:51 +02:00
state_hub_task_id: "b1a1831d-b2b3-4204-95f6-04dc7f29f67c"
2026-06-17 23:34:13 +02:00
```
2026-06-18 01:18:57 +02:00
- [x] Operator provides scoped `VAULT_TOKEN` (warden-sign policy token)
- [x] Confirm SSH engine mounted and roles per `wiki/OpenBaoSshEngineChecklist.md`
- [x] Run `warden sign` + `warden status` + `warden log` against production OpenBao
- [x] Append pass/fail evidence to `history/2026-06-17-openbao-production-verify.md`
2026-06-18 01:28:49 +02:00
- [ ] Optional: cert_command smoke via ops-bridge tunnel — deferred; tunnels still
static-key mode (`agt-claude-*` ); wire when ops-bridge adopts `cert_command` for
`agt-state-hub-bridge`
2026-06-17 23:34:13 +02:00
### T3 — State Hub task status canon migration
```task
id: WARDEN-WP-0008-T03
2026-06-17 23:51:12 +02:00
status: done
2026-06-17 23:34:13 +02:00
priority: medium
2026-06-17 23:34:51 +02:00
state_hub_task_id: "876827c4-4a86-4e58-9a1f-ac87045dc903"
2026-06-17 23:34:13 +02:00
```
2026-06-17 23:51:12 +02:00
- [x] Update `AGENTS.md` task status values and examples (`progress` , `wait` , `cancel` )
- [x] Update `.claude/rules/workplan-convention.md` task block examples
- [x] Mark state-hub interface change `649102a2-4373-4621-9848-cc257e67c262` resolved
- [x] Reply to inbox message `c4072e5a-2afb-44ba-bfa2-7d4cb9979c6e` (read + note adaptation)
2026-06-17 23:34:13 +02:00
### T4 — Production config example and archive hygiene
```task
id: WARDEN-WP-0008-T04
2026-06-17 23:51:12 +02:00
status: done
2026-06-17 23:34:13 +02:00
priority: medium
2026-06-17 23:34:51 +02:00
state_hub_task_id: "75b9f366-3d7a-419d-98ad-bc10ab90a697"
2026-06-17 23:34:13 +02:00
```
2026-06-17 23:51:12 +02:00
- [x] Add `examples/warden.production.example.yaml` (no secrets; OpenBao addr + policy off)
- [x] Archive finished workplans → `workplans/archived/260617-WARDEN-WP-000{4,5,6,7}-*.md`
- [x] `make fix-consistency REPO=ops-warden` after archive
2026-06-17 23:34:13 +02:00
### T5 — flex-auth policy gate production readiness (coordination)
```task
id: WARDEN-WP-0008-T05
2026-06-18 01:28:49 +02:00
status: cancel
2026-06-17 23:34:13 +02:00
priority: low
2026-06-17 23:34:51 +02:00
state_hub_task_id: "03b412a5-5b99-42df-a154-733dd4156000"
2026-06-17 23:34:13 +02:00
```
2026-06-18 01:28:49 +02:00
Spun out to **WARDEN-WP-0009** (flex-auth owner dependency). ops-warden gate code
and docs shipped in WP-0007; production enablement waits on flex-auth policies.
2026-06-17 23:34:13 +02:00
---
## Acceptance Criteria
2026-06-17 23:51:12 +02:00
- [x] Post-WP-0007 reassessment on file; SCOPE current
2026-06-18 01:28:49 +02:00
- [x] Production `warden sign` evidence recorded (`history/2026-06-17-openbao-production-verify.md` )
2026-06-17 23:51:12 +02:00
- [x] AGENTS.md uses canonical task statuses
- [x] WP-0004– 0007 archived; hub consistency pass
- [x] Production example config committed (no secrets)
2026-06-17 23:34:13 +02:00
---
2026-06-18 01:28:49 +02:00
## Closeout (2026-06-18)
T1– T4 and T2 complete. T5 cancelled — continued in WARDEN-WP-0009. Optional
ops-bridge `cert_command` smoke deferred until tunnel configs adopt warden signing.
---
2026-06-17 23:34:13 +02:00
## Dependencies
| Dependency | Owner | Blocks |
| --- | --- | --- |
2026-06-18 00:51:48 +02:00
| OpenBao SSH engine + host CA automation | NET-WP-0020 / railiance-* | T2 |
2026-06-17 23:34:13 +02:00
| flex-auth ssh-certificate policies | flex-auth | T5 |
| NK-WP-0009 SSH tutorial | net-kingdom + ops-warden | — (parallel track) |
---
## See also
- `history/2026-06-17-openbao-production-verify.md` — health probe (WP-0007)
2026-06-17 23:51:12 +02:00
- `history/2026-06-17-post-wp0007-reassessment.md` — latest assessment
- `examples/warden.production.example.yaml` — operator config template
2026-06-17 23:34:13 +02:00
- `wiki/OpenBaoSshEngineChecklist.md`
- `wiki/PolicyGatedSigning.md` — opt-in gate (implemented WP-0007)