feat: route Policy Nexus source credential

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
This commit is contained in:
tegwick 2026-09-01 00:46:28 +02:00
parent 8f01eefb1e
commit 4fee839b11
6 changed files with 160 additions and 3 deletions

View file

@ -4,7 +4,7 @@ type: workplan
title: "Accept contained OpenBao login output only after helper persistence"
domain: infotech
repo: ops-warden
status: active
status: finished
owner: codex
topic_slug: attended-login-openbao-output
created: "2026-09-01"
@ -28,9 +28,13 @@ failure.
```task
id: WARDEN-WP-0034-T02
status: progress
status: done
priority: high
```
Run the proxy regression suite, reinstall the CLI, and complete one governed
OpenBao platform-admin operation with deterministic self-revocation.
Completed 2026-09-01. The installed CLI completed the governed Policy Nexus
Forgejo source bootstrap with all child output contained, then revoked and
removed its isolated helper session.

View file

@ -0,0 +1,36 @@
---
id: WARDEN-WP-0035
type: workplan
title: "Register the Policy Nexus Forgejo source-read route"
domain: infotech
repo: ops-warden
status: active
owner: codex
topic_slug: policy-nexus-forgejo-source-read
created: "2026-09-01"
updated: "2026-09-01"
---
## Register the exact high-risk lane
```task
id: WARDEN-WP-0035-T01
status: done
priority: high
```
Add the exact OpenBao path, field, OIDC role, owner pointer, and rotation
boundary from railiance-platform CCR-2026-0014. The entry must be concrete and
resolvable while remaining subject to Warden's high-risk agent read boundary.
## Verify routing and governed use
```task
id: WARDEN-WP-0035-T02
status: progress
priority: high
```
Pass catalog, route-selection, proxy, and policy tests; reinstall the CLI; prove
the installed route resolves and can hand the value only to a sanctioned child
transport without printing or persisting it.