Reframe the secrets-engine blocker on seven interim lanes
The blocker asked whether `secrets-engine exec --catalog` generalizes over arbitrary OpenBao lanes. Asked 2026-08-11, chased 08-15, never answered. Rather than chase a third time, read their code. It generalizes by construction: catalog.py takes mount and path as plain fields, `kv` is a general kind, and six delivery modes are supported. What exists is two catalog entries -- warden-sign and whynot-design-npm-publish -- which are exactly the two lanes this register already marks native. So the blocker was misframed for ten days. Not "can the engine do this" but "who authors the entries and who operates them", which is smaller and had never been put to them. Register now says that, and ops-warden has offered to author all seven entries against their schema for them to accept or reject. Applying the rule this repo already had and missed twice this week: re-read a blocker before trusting it. A blocker is a claim about the world at a date. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
0dafb53e84
commit
06d0a1e690
1 changed files with 14 additions and 14 deletions
|
|
@ -107,8 +107,8 @@ entries:
|
|||
delegation:
|
||||
mode: interim
|
||||
intended_owner: secrets-engine
|
||||
blocked_on: "secrets-engine has not confirmed whether exec --catalog generalizes over arbitrary OpenBao lanes (asked 2026-08-11, msg 7d55d332)"
|
||||
reviewed: "2026-08-11"
|
||||
blocked_on: "secrets-engine has not accepted the lane. Reframed 2026-08-21: exec --catalog does generalize — catalog.py takes mount/path as plain fields with six delivery modes — so the blocker is entry authoring and operation, not capability. Two entries exist, both already-native lanes. ops-warden offered to author all seven (msg cbd312f8); asked 2026-08-11, 08-15, 08-21"
|
||||
reviewed: "2026-08-21"
|
||||
# Structured handoff (WP-0014) — reference example. Templates only, no values.
|
||||
# ops-warden does not own this secret; it advises and (exec_capable) proxies the
|
||||
# fetch *as the caller* via `warden access`, never holding or persisting the value.
|
||||
|
|
@ -202,8 +202,8 @@ entries:
|
|||
delegation:
|
||||
mode: interim
|
||||
intended_owner: secrets-engine
|
||||
blocked_on: "secrets-engine has not confirmed whether exec --catalog generalizes over arbitrary OpenBao lanes (asked 2026-08-11, msg 7d55d332)"
|
||||
reviewed: "2026-08-11"
|
||||
blocked_on: "secrets-engine has not accepted the lane. Reframed 2026-08-21: exec --catalog does generalize — catalog.py takes mount/path as plain fields with six delivery modes — so the blocker is entry authoring and operation, not capability. Two entries exist, both already-native lanes. ops-warden offered to author all seven (msg cbd312f8); asked 2026-08-11, 08-15, 08-21"
|
||||
reviewed: "2026-08-21"
|
||||
# Login lane (WP-0014 T4) — interactive auth bootstrap, not a secret read. No
|
||||
# secret-read gate (you have no identity yet) and no caller-auth precheck (the
|
||||
# point is to obtain one). warden runs it interactively as the caller and never
|
||||
|
|
@ -297,8 +297,8 @@ entries:
|
|||
delegation:
|
||||
mode: interim
|
||||
intended_owner: secrets-engine
|
||||
blocked_on: "secrets-engine has not confirmed whether exec --catalog generalizes over arbitrary OpenBao lanes (asked 2026-08-11, msg 7d55d332)"
|
||||
reviewed: "2026-08-11"
|
||||
blocked_on: "secrets-engine has not accepted the lane. Reframed 2026-08-21: exec --catalog does generalize — catalog.py takes mount/path as plain fields with six delivery modes — so the blocker is entry authoring and operation, not capability. Two entries exist, both already-native lanes. ops-warden offered to author all seven (msg cbd312f8); asked 2026-08-11, 08-15, 08-21"
|
||||
reviewed: "2026-08-21"
|
||||
# Concrete, owner-confirmed lane — railiance-platform CCR-2026-0002 / RAILIANCE-WP-0009
|
||||
# (promoted 2026-07-02): policy workload-kv-read-issue-core-runtime and k8s auth role
|
||||
# external-secrets-issue-core applied; ExternalSecret issue-core/issue-core-runtime
|
||||
|
|
@ -337,8 +337,8 @@ entries:
|
|||
delegation:
|
||||
mode: interim
|
||||
intended_owner: secrets-engine
|
||||
blocked_on: "secrets-engine has not confirmed whether exec --catalog generalizes over arbitrary OpenBao lanes (asked 2026-08-11, msg 7d55d332)"
|
||||
reviewed: "2026-08-11"
|
||||
blocked_on: "secrets-engine has not accepted the lane. Reframed 2026-08-21: exec --catalog does generalize — catalog.py takes mount/path as plain fields with six delivery modes — so the blocker is entry authoring and operation, not capability. Two entries exist, both already-native lanes. ops-warden offered to author all seven (msg cbd312f8); asked 2026-08-11, 08-15, 08-21"
|
||||
reviewed: "2026-08-21"
|
||||
# Concrete, owner-confirmed lane — railiance-platform CCR-2026-0005 / RAILIANCE-WP-0011
|
||||
# (promoted 2026-07-07): policy workload-kv-read-reuse-surface-runtime; ExternalSecret
|
||||
# reuse/reuse-surface-runtime SecretSynced to reuse-surface-env on Railiance01;
|
||||
|
|
@ -374,8 +374,8 @@ entries:
|
|||
delegation:
|
||||
mode: interim
|
||||
intended_owner: secrets-engine
|
||||
blocked_on: "secrets-engine has not confirmed whether exec --catalog generalizes over arbitrary OpenBao lanes (asked 2026-08-11, msg 7d55d332)"
|
||||
reviewed: "2026-08-11"
|
||||
blocked_on: "secrets-engine has not accepted the lane. Reframed 2026-08-21: exec --catalog does generalize — catalog.py takes mount/path as plain fields with six delivery modes — so the blocker is entry authoring and operation, not capability. Two entries exist, both already-native lanes. ops-warden offered to author all seven (msg cbd312f8); asked 2026-08-11, 08-15, 08-21"
|
||||
reviewed: "2026-08-21"
|
||||
# High-risk: provider API key with spend impact + prompt-adjacent (WP-0026 T04).
|
||||
risk: high
|
||||
# Concrete, owner-confirmed lane — railiance-platform CCR-2026-0003 / RAILIANCE-WP-0010
|
||||
|
|
@ -459,8 +459,8 @@ entries:
|
|||
delegation:
|
||||
mode: interim
|
||||
intended_owner: secrets-engine
|
||||
blocked_on: "secrets-engine has not confirmed whether exec --catalog generalizes over arbitrary OpenBao lanes (asked 2026-08-11, msg 7d55d332)"
|
||||
reviewed: "2026-08-11"
|
||||
blocked_on: "secrets-engine has not accepted the lane. Reframed 2026-08-21: exec --catalog does generalize — catalog.py takes mount/path as plain fields with six delivery modes — so the blocker is entry authoring and operation, not capability. Two entries exist, both already-native lanes. ops-warden offered to author all seven (msg cbd312f8); asked 2026-08-11, 08-15, 08-21"
|
||||
reviewed: "2026-08-21"
|
||||
# High-risk: site-admin PAT (WP-0026 T04).
|
||||
risk: high
|
||||
# CCR-2026-0006: approved by platform-operator 2026-07-12; policy
|
||||
|
|
@ -822,8 +822,8 @@ entries:
|
|||
delegation:
|
||||
mode: interim
|
||||
intended_owner: secrets-engine
|
||||
blocked_on: "secrets-engine has not confirmed whether exec --catalog generalizes over arbitrary OpenBao lanes (asked 2026-08-11, msg 7d55d332)"
|
||||
reviewed: "2026-08-15"
|
||||
blocked_on: "secrets-engine has not accepted the lane. Reframed 2026-08-21: exec --catalog does generalize — catalog.py takes mount/path as plain fields with six delivery modes — so the blocker is entry authoring and operation, not capability. Two entries exist, both already-native lanes. ops-warden offered to author all seven (msg cbd312f8); asked 2026-08-11, 08-15, 08-21"
|
||||
reviewed: "2026-08-21"
|
||||
risk: high
|
||||
# CCR-2026-0010 approved 2026-08-12; applied same day (EMAIL-WP-0004-T03):
|
||||
# policies external-secrets-email-connect + workload-kv-read-email-connect-transactional,
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue