WARDEN-WP-0027: park Strand B as backlog (C-23-safe)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Set workplan status backlog and tasks todo (not wait) so fix-consistency
does not re-promote to active. Activate only when a gate fires.
This commit is contained in:
tegwick 2026-07-17 00:45:03 +02:00
parent 0433481e94
commit 25a691d49a

View file

@ -4,7 +4,7 @@ type: workplan
title: "Tamper-resistant credential governance + mass rotation/lockdown (Strand B)" title: "Tamper-resistant credential governance + mass rotation/lockdown (Strand B)"
domain: infotech domain: infotech
repo: ops-warden repo: ops-warden
status: active status: backlog
owner: codex owner: codex
topic_slug: custodian topic_slug: custodian
planning_priority: medium planning_priority: medium
@ -30,11 +30,13 @@ governance against silent drift or malicious change.
## Status: backlog (captured, not scheduled) ## Status: backlog (captured, not scheduled)
Frontmatter `status: backlog` as of 2026-07-17 (Strand A / WP-0026 and tenant Frontmatter `status: backlog` as of 2026-07-17 (Strand A / WP-0026 and tenant
custody WP-0028 are finished; no activation gate has fired). This is custody WP-0028 are finished; no activation gate has fired). Tasks remain
deliberately **not `ready`**. It carries real cost and blast radius `todo` (not `wait`/`progress`) so hub consistency **C-23** does not force the
(break-glass re-key, trust-root design) that is not justified until a concrete workplan back to `active`. This is deliberately **not `ready`**. It carries
trigger appears. See **Activation gate** below. Nothing here is implemented real cost and blast radius (break-glass re-key, trust-root design) that is not
until the gate is met and Bernd promotes it to `ready`. justified until a concrete trigger appears. See **Activation gate** below.
Nothing here is implemented until the gate is met and Bernd promotes it to
`ready` (then move tasks `todo``progress` as work starts).
## Activation gate (promote to `ready` only when ≥1 holds) ## Activation gate (promote to `ready` only when ≥1 holds)
@ -62,7 +64,7 @@ path; ops-warden sequences and verifies it.
```task ```task
id: WARDEN-WP-0027-T01 id: WARDEN-WP-0027-T01
status: wait status: todo
priority: high priority: high
state_hub_task_id: "604aad14-d398-4c02-85e5-7ff37a905a1b" state_hub_task_id: "604aad14-d398-4c02-85e5-7ff37a905a1b"
``` ```
@ -83,7 +85,7 @@ each verified capabilities-safe, taint cleared only on success.
```task ```task
id: WARDEN-WP-0027-T02 id: WARDEN-WP-0027-T02
status: wait status: todo
priority: medium priority: medium
state_hub_task_id: "9d004d8f-6215-4178-bd13-5785d24fd152" state_hub_task_id: "9d004d8f-6215-4178-bd13-5785d24fd152"
``` ```
@ -102,7 +104,7 @@ policy toggles.
```task ```task
id: WARDEN-WP-0027-T03 id: WARDEN-WP-0027-T03
status: wait status: todo
priority: medium priority: medium
state_hub_task_id: "94d5dcaf-abf0-417c-a6ef-26e8c50905a8" state_hub_task_id: "94d5dcaf-abf0-417c-a6ef-26e8c50905a8"
``` ```