Reframe the secrets-engine blocker on seven interim lanes
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

The blocker asked whether `secrets-engine exec --catalog` generalizes over
arbitrary OpenBao lanes. Asked 2026-08-11, chased 08-15, never answered. Rather
than chase a third time, read their code.

It generalizes by construction: catalog.py takes mount and path as plain fields,
`kv` is a general kind, and six delivery modes are supported. What exists is two
catalog entries -- warden-sign and whynot-design-npm-publish -- which are exactly
the two lanes this register already marks native.

So the blocker was misframed for ten days. Not "can the engine do this" but "who
authors the entries and who operates them", which is smaller and had never been
put to them. Register now says that, and ops-warden has offered to author all
seven entries against their schema for them to accept or reject.

Applying the rule this repo already had and missed twice this week: re-read a
blocker before trusting it. A blocker is a claim about the world at a date.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-08-21 01:26:07 +02:00
parent 0dafb53e84
commit 06d0a1e690

View file

@ -107,8 +107,8 @@ entries:
delegation:
mode: interim
intended_owner: secrets-engine
blocked_on: "secrets-engine has not confirmed whether exec --catalog generalizes over arbitrary OpenBao lanes (asked 2026-08-11, msg 7d55d332)"
reviewed: "2026-08-11"
blocked_on: "secrets-engine has not accepted the lane. Reframed 2026-08-21: exec --catalog does generalize — catalog.py takes mount/path as plain fields with six delivery modes — so the blocker is entry authoring and operation, not capability. Two entries exist, both already-native lanes. ops-warden offered to author all seven (msg cbd312f8); asked 2026-08-11, 08-15, 08-21"
reviewed: "2026-08-21"
# Structured handoff (WP-0014) — reference example. Templates only, no values.
# ops-warden does not own this secret; it advises and (exec_capable) proxies the
# fetch *as the caller* via `warden access`, never holding or persisting the value.
@ -202,8 +202,8 @@ entries:
delegation:
mode: interim
intended_owner: secrets-engine
blocked_on: "secrets-engine has not confirmed whether exec --catalog generalizes over arbitrary OpenBao lanes (asked 2026-08-11, msg 7d55d332)"
reviewed: "2026-08-11"
blocked_on: "secrets-engine has not accepted the lane. Reframed 2026-08-21: exec --catalog does generalize — catalog.py takes mount/path as plain fields with six delivery modes — so the blocker is entry authoring and operation, not capability. Two entries exist, both already-native lanes. ops-warden offered to author all seven (msg cbd312f8); asked 2026-08-11, 08-15, 08-21"
reviewed: "2026-08-21"
# Login lane (WP-0014 T4) — interactive auth bootstrap, not a secret read. No
# secret-read gate (you have no identity yet) and no caller-auth precheck (the
# point is to obtain one). warden runs it interactively as the caller and never
@ -297,8 +297,8 @@ entries:
delegation:
mode: interim
intended_owner: secrets-engine
blocked_on: "secrets-engine has not confirmed whether exec --catalog generalizes over arbitrary OpenBao lanes (asked 2026-08-11, msg 7d55d332)"
reviewed: "2026-08-11"
blocked_on: "secrets-engine has not accepted the lane. Reframed 2026-08-21: exec --catalog does generalize — catalog.py takes mount/path as plain fields with six delivery modes — so the blocker is entry authoring and operation, not capability. Two entries exist, both already-native lanes. ops-warden offered to author all seven (msg cbd312f8); asked 2026-08-11, 08-15, 08-21"
reviewed: "2026-08-21"
# Concrete, owner-confirmed lane — railiance-platform CCR-2026-0002 / RAILIANCE-WP-0009
# (promoted 2026-07-02): policy workload-kv-read-issue-core-runtime and k8s auth role
# external-secrets-issue-core applied; ExternalSecret issue-core/issue-core-runtime
@ -337,8 +337,8 @@ entries:
delegation:
mode: interim
intended_owner: secrets-engine
blocked_on: "secrets-engine has not confirmed whether exec --catalog generalizes over arbitrary OpenBao lanes (asked 2026-08-11, msg 7d55d332)"
reviewed: "2026-08-11"
blocked_on: "secrets-engine has not accepted the lane. Reframed 2026-08-21: exec --catalog does generalize — catalog.py takes mount/path as plain fields with six delivery modes — so the blocker is entry authoring and operation, not capability. Two entries exist, both already-native lanes. ops-warden offered to author all seven (msg cbd312f8); asked 2026-08-11, 08-15, 08-21"
reviewed: "2026-08-21"
# Concrete, owner-confirmed lane — railiance-platform CCR-2026-0005 / RAILIANCE-WP-0011
# (promoted 2026-07-07): policy workload-kv-read-reuse-surface-runtime; ExternalSecret
# reuse/reuse-surface-runtime SecretSynced to reuse-surface-env on Railiance01;
@ -374,8 +374,8 @@ entries:
delegation:
mode: interim
intended_owner: secrets-engine
blocked_on: "secrets-engine has not confirmed whether exec --catalog generalizes over arbitrary OpenBao lanes (asked 2026-08-11, msg 7d55d332)"
reviewed: "2026-08-11"
blocked_on: "secrets-engine has not accepted the lane. Reframed 2026-08-21: exec --catalog does generalize — catalog.py takes mount/path as plain fields with six delivery modes — so the blocker is entry authoring and operation, not capability. Two entries exist, both already-native lanes. ops-warden offered to author all seven (msg cbd312f8); asked 2026-08-11, 08-15, 08-21"
reviewed: "2026-08-21"
# High-risk: provider API key with spend impact + prompt-adjacent (WP-0026 T04).
risk: high
# Concrete, owner-confirmed lane — railiance-platform CCR-2026-0003 / RAILIANCE-WP-0010
@ -459,8 +459,8 @@ entries:
delegation:
mode: interim
intended_owner: secrets-engine
blocked_on: "secrets-engine has not confirmed whether exec --catalog generalizes over arbitrary OpenBao lanes (asked 2026-08-11, msg 7d55d332)"
reviewed: "2026-08-11"
blocked_on: "secrets-engine has not accepted the lane. Reframed 2026-08-21: exec --catalog does generalize — catalog.py takes mount/path as plain fields with six delivery modes — so the blocker is entry authoring and operation, not capability. Two entries exist, both already-native lanes. ops-warden offered to author all seven (msg cbd312f8); asked 2026-08-11, 08-15, 08-21"
reviewed: "2026-08-21"
# High-risk: site-admin PAT (WP-0026 T04).
risk: high
# CCR-2026-0006: approved by platform-operator 2026-07-12; policy
@ -822,8 +822,8 @@ entries:
delegation:
mode: interim
intended_owner: secrets-engine
blocked_on: "secrets-engine has not confirmed whether exec --catalog generalizes over arbitrary OpenBao lanes (asked 2026-08-11, msg 7d55d332)"
reviewed: "2026-08-15"
blocked_on: "secrets-engine has not accepted the lane. Reframed 2026-08-21: exec --catalog does generalize — catalog.py takes mount/path as plain fields with six delivery modes — so the blocker is entry authoring and operation, not capability. Two entries exist, both already-native lanes. ops-warden offered to author all seven (msg cbd312f8); asked 2026-08-11, 08-15, 08-21"
reviewed: "2026-08-21"
risk: high
# CCR-2026-0010 approved 2026-08-12; applied same day (EMAIL-WP-0004-T03):
# policies external-secrets-email-connect + workload-kv-read-email-connect-transactional,