diff --git a/registry/routing/catalog.yaml b/registry/routing/catalog.yaml index c060ef5..893a399 100644 --- a/registry/routing/catalog.yaml +++ b/registry/routing/catalog.yaml @@ -107,8 +107,8 @@ entries: delegation: mode: interim intended_owner: secrets-engine - blocked_on: "secrets-engine has not confirmed whether exec --catalog generalizes over arbitrary OpenBao lanes (asked 2026-08-11, msg 7d55d332)" - reviewed: "2026-08-11" + blocked_on: "secrets-engine has not accepted the lane. Reframed 2026-08-21: exec --catalog does generalize — catalog.py takes mount/path as plain fields with six delivery modes — so the blocker is entry authoring and operation, not capability. Two entries exist, both already-native lanes. ops-warden offered to author all seven (msg cbd312f8); asked 2026-08-11, 08-15, 08-21" + reviewed: "2026-08-21" # Structured handoff (WP-0014) — reference example. Templates only, no values. # ops-warden does not own this secret; it advises and (exec_capable) proxies the # fetch *as the caller* via `warden access`, never holding or persisting the value. @@ -202,8 +202,8 @@ entries: delegation: mode: interim intended_owner: secrets-engine - blocked_on: "secrets-engine has not confirmed whether exec --catalog generalizes over arbitrary OpenBao lanes (asked 2026-08-11, msg 7d55d332)" - reviewed: "2026-08-11" + blocked_on: "secrets-engine has not accepted the lane. Reframed 2026-08-21: exec --catalog does generalize — catalog.py takes mount/path as plain fields with six delivery modes — so the blocker is entry authoring and operation, not capability. Two entries exist, both already-native lanes. ops-warden offered to author all seven (msg cbd312f8); asked 2026-08-11, 08-15, 08-21" + reviewed: "2026-08-21" # Login lane (WP-0014 T4) — interactive auth bootstrap, not a secret read. No # secret-read gate (you have no identity yet) and no caller-auth precheck (the # point is to obtain one). warden runs it interactively as the caller and never @@ -297,8 +297,8 @@ entries: delegation: mode: interim intended_owner: secrets-engine - blocked_on: "secrets-engine has not confirmed whether exec --catalog generalizes over arbitrary OpenBao lanes (asked 2026-08-11, msg 7d55d332)" - reviewed: "2026-08-11" + blocked_on: "secrets-engine has not accepted the lane. Reframed 2026-08-21: exec --catalog does generalize — catalog.py takes mount/path as plain fields with six delivery modes — so the blocker is entry authoring and operation, not capability. Two entries exist, both already-native lanes. ops-warden offered to author all seven (msg cbd312f8); asked 2026-08-11, 08-15, 08-21" + reviewed: "2026-08-21" # Concrete, owner-confirmed lane — railiance-platform CCR-2026-0002 / RAILIANCE-WP-0009 # (promoted 2026-07-02): policy workload-kv-read-issue-core-runtime and k8s auth role # external-secrets-issue-core applied; ExternalSecret issue-core/issue-core-runtime @@ -337,8 +337,8 @@ entries: delegation: mode: interim intended_owner: secrets-engine - blocked_on: "secrets-engine has not confirmed whether exec --catalog generalizes over arbitrary OpenBao lanes (asked 2026-08-11, msg 7d55d332)" - reviewed: "2026-08-11" + blocked_on: "secrets-engine has not accepted the lane. Reframed 2026-08-21: exec --catalog does generalize — catalog.py takes mount/path as plain fields with six delivery modes — so the blocker is entry authoring and operation, not capability. Two entries exist, both already-native lanes. ops-warden offered to author all seven (msg cbd312f8); asked 2026-08-11, 08-15, 08-21" + reviewed: "2026-08-21" # Concrete, owner-confirmed lane — railiance-platform CCR-2026-0005 / RAILIANCE-WP-0011 # (promoted 2026-07-07): policy workload-kv-read-reuse-surface-runtime; ExternalSecret # reuse/reuse-surface-runtime SecretSynced to reuse-surface-env on Railiance01; @@ -374,8 +374,8 @@ entries: delegation: mode: interim intended_owner: secrets-engine - blocked_on: "secrets-engine has not confirmed whether exec --catalog generalizes over arbitrary OpenBao lanes (asked 2026-08-11, msg 7d55d332)" - reviewed: "2026-08-11" + blocked_on: "secrets-engine has not accepted the lane. Reframed 2026-08-21: exec --catalog does generalize — catalog.py takes mount/path as plain fields with six delivery modes — so the blocker is entry authoring and operation, not capability. Two entries exist, both already-native lanes. ops-warden offered to author all seven (msg cbd312f8); asked 2026-08-11, 08-15, 08-21" + reviewed: "2026-08-21" # High-risk: provider API key with spend impact + prompt-adjacent (WP-0026 T04). risk: high # Concrete, owner-confirmed lane — railiance-platform CCR-2026-0003 / RAILIANCE-WP-0010 @@ -459,8 +459,8 @@ entries: delegation: mode: interim intended_owner: secrets-engine - blocked_on: "secrets-engine has not confirmed whether exec --catalog generalizes over arbitrary OpenBao lanes (asked 2026-08-11, msg 7d55d332)" - reviewed: "2026-08-11" + blocked_on: "secrets-engine has not accepted the lane. Reframed 2026-08-21: exec --catalog does generalize — catalog.py takes mount/path as plain fields with six delivery modes — so the blocker is entry authoring and operation, not capability. Two entries exist, both already-native lanes. ops-warden offered to author all seven (msg cbd312f8); asked 2026-08-11, 08-15, 08-21" + reviewed: "2026-08-21" # High-risk: site-admin PAT (WP-0026 T04). risk: high # CCR-2026-0006: approved by platform-operator 2026-07-12; policy @@ -822,8 +822,8 @@ entries: delegation: mode: interim intended_owner: secrets-engine - blocked_on: "secrets-engine has not confirmed whether exec --catalog generalizes over arbitrary OpenBao lanes (asked 2026-08-11, msg 7d55d332)" - reviewed: "2026-08-15" + blocked_on: "secrets-engine has not accepted the lane. Reframed 2026-08-21: exec --catalog does generalize — catalog.py takes mount/path as plain fields with six delivery modes — so the blocker is entry authoring and operation, not capability. Two entries exist, both already-native lanes. ops-warden offered to author all seven (msg cbd312f8); asked 2026-08-11, 08-15, 08-21" + reviewed: "2026-08-21" risk: high # CCR-2026-0010 approved 2026-08-12; applied same day (EMAIL-WP-0004-T03): # policies external-secrets-email-connect + workload-kv-read-email-connect-transactional,