diff --git a/.claude/rules/architecture.md b/.claude/rules/architecture.md index 6f6cde3..ee357fb 100644 --- a/.claude/rules/architecture.md +++ b/.claude/rules/architecture.md @@ -16,6 +16,8 @@ distinction that matters here. | `ADR-0006` | Enforcement is zone-scoped, never a global flag | | `ADR-0007` | Build-stage permissiveness stops at credential disclosure; every lane carries an explicit `risk` grade | | `ADR-0008` | A lane's risk grade covers every field its path discloses, not just the field it is named after | +| `ADR-0009` | Adopt security-zones v0.1 as a consumer; membership is compiled, never inferred | +| `ADR-0010` | ops-warden is Staff: it owns access lanes, never access rules; doctrine belongs to gate-house | ### Owned versus inherited — check `owner:` before changing anything diff --git a/.repo-manager/index.json b/.repo-manager/index.json new file mode 100644 index 0000000..a0e6bd2 --- /dev/null +++ b/.repo-manager/index.json @@ -0,0 +1,2215 @@ +{ + "schema": "repo_manager.index.v1", + "slug": "layer-model-assent", + "repo_root": "/home/worsch/ops-warden", + "head_sha": "467635e84b99757336ee49d7f0dbf107607d0560", + "observed_at": "2026-08-28T19:30:29.828983Z", + "source_fingerprint": "7dfae4f3d33f6a9503a2c7326b925efb378613e772b39c4dd9b0640a35b85654", + "source_files": [ + ".repo-classification.yaml", + "INTENT.md", + "intakes/intakes.md", + "workplans/ADHOC-2026-06-27.md", + "workplans/ADHOC-2026-06-29.md", + "workplans/ADHOC-2026-08-11.md", + "workplans/ADHOC-2026-08-17.md", + "workplans/WARDEN-WP-0016-ops-bridge-tunnel-cert-pilot.md", + "workplans/WARDEN-WP-0017-access-front-door-discoverability.md", + "workplans/WARDEN-WP-0018-whynot-design-npm-lane-activation.md", + "workplans/WARDEN-WP-0019-route-to-secrets-engine.md", + "workplans/WARDEN-WP-0020-ops-warden-worker.md", + "workplans/WARDEN-WP-0021-enable-scheduled-worker-tick.md", + "workplans/WARDEN-WP-0022-audit-trail-and-activity.md", + "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md", + "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md", + "workplans/WARDEN-WP-0025-forgejo-admin-api-token-lane.md", + "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md", + "workplans/WARDEN-WP-0027-credential-governance-lockdown.md", + "workplans/WARDEN-WP-0028-tenant-secret-custody.md", + "workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md", + "workplans/WARDEN-WP-0030-delegation-register.md", + "workplans/WARDEN-WP-0031-policy-caller-identity.md", + "workplans/WARDEN-WP-0032-security-zones.md", + "workplans/WARDEN-WP-0033-native-lane-handoff.md", + "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md", + "workplans/archived/260515-WARDEN-WP-0002-correctness-and-completeness.md", + "workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md", + "workplans/archived/260617-WARDEN-WP-0004-repo-hygiene-and-hub-sync.md", + "workplans/archived/260617-WARDEN-WP-0005-openbao-doc-alignment.md", + "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md", + "workplans/archived/260617-WARDEN-WP-0007-policy-gate-and-production-verify.md", + "workplans/archived/260618-WARDEN-WP-0008-production-ssh-path-and-stewardship-closeout.md", + "workplans/archived/260623-WARDEN-WP-0009-flex-auth-policy-gate-production.md", + "workplans/archived/260624-WARDEN-WP-0010-access-routing-charter.md", + "workplans/archived/260624-WARDEN-WP-0011-routing-guide-cli.md", + "workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md", + "workplans/archived/260627-WARDEN-WP-0012-routing-scenario-playbooks.md", + "workplans/archived/260627-WARDEN-WP-0014-operator-access-assist.md", + "workplans/archived/260627-WARDEN-WP-0015-secret-lifecycle-tiering.md", + "workplans/archived/260707-ADHOC-2026-07-07.md" + ], + "work_records": [ + { + "kind": "workplan", + "id": "WARDEN-WP-ADHOC-2026-06-27", + "status": "finished", + "title": "Ad Hoc Tasks \u2014 2026-06-27", + "source_path": "workplans/ADHOC-2026-06-27.md", + "uuid": null, + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-ADHOC-2026-06-27-T01", + "status": "done", + "title": "T01 \u2014 Fix stale `warden` CLI install + make it usable outside the repo", + "source_path": "workplans/ADHOC-2026-06-27.md", + "uuid": null, + "parent_id": "WARDEN-WP-ADHOC-2026-06-27", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-ADHOC-2026-06-29", + "status": "finished", + "title": "Ad Hoc Tasks \u2014 2026-06-29", + "source_path": "workplans/ADHOC-2026-06-29.md", + "uuid": null, + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-ADHOC-2026-06-29-T01", + "status": "done", + "title": "T01 \u2014 Joint-smoke mode for the deployed flex-auth (assist FLEX-WP-0007 T4)", + "source_path": "workplans/ADHOC-2026-06-29.md", + "uuid": null, + "parent_id": "WARDEN-WP-ADHOC-2026-06-29", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-ADHOC-2026-08-11", + "status": "finished", + "title": "Ad Hoc Tasks \u2014 2026-08-11", + "source_path": "workplans/ADHOC-2026-08-11.md", + "uuid": null, + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-ADHOC-2026-08-11-T01", + "status": "done", + "title": "T01 \u2014 Repair stale `rapp-qonto-keycape-client` wiki anchor (restore green routing suite)", + "source_path": "workplans/ADHOC-2026-08-11.md", + "uuid": null, + "parent_id": "WARDEN-WP-ADHOC-2026-08-11", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-ADHOC-2026-08-11-T02", + "status": "done", + "title": "T02 \u2014 Triage the stale ops-warden inbox (11 unread, C-28/C-29)", + "source_path": "workplans/ADHOC-2026-08-11.md", + "uuid": null, + "parent_id": "WARDEN-WP-ADHOC-2026-08-11", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-ADHOC-2026-08-11-T03", + "status": "done", + "title": "T03 \u2014 warden-sign AppRole: PARKED pending WP-0027 break-glass + ops-bridge cutover", + "source_path": "workplans/ADHOC-2026-08-11.md", + "uuid": null, + "parent_id": "WARDEN-WP-ADHOC-2026-08-11", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-ADHOC-2026-08-17", + "status": "finished", + "title": "Ad Hoc Tasks \u2014 2026-08-17", + "source_path": "workplans/ADHOC-2026-08-17.md", + "uuid": null, + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-ADHOC-2026-08-17-T01", + "status": "done", + "title": "T01 \u2014 Answer flex-auth: how should `/v1/check` authenticate its callers?", + "source_path": "workplans/ADHOC-2026-08-17.md", + "uuid": null, + "parent_id": "WARDEN-WP-ADHOC-2026-08-17", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-ADHOC-2026-08-17-T02", + "status": "done", + "title": "T02 \u2014 user-engine: USER_ENGINE_PROXY_SECRET stays railiance-apps; record consumer-only", + "source_path": "workplans/ADHOC-2026-08-17.md", + "uuid": null, + "parent_id": "WARDEN-WP-ADHOC-2026-08-17", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-ADHOC-2026-08-17-T03", + "status": "done", + "title": "T03 \u2014 key-cape: `rapp-qonto-keycape-client` interim accepted; refresh the blocker", + "source_path": "workplans/ADHOC-2026-08-17.md", + "uuid": null, + "parent_id": "WARDEN-WP-ADHOC-2026-08-17", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-ADHOC-2026-08-17-T04", + "status": "done", + "title": "T04 \u2014 Session hygiene", + "source_path": "workplans/ADHOC-2026-08-17.md", + "uuid": null, + "parent_id": "WARDEN-WP-ADHOC-2026-08-17", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0016", + "status": "finished", + "title": "ops-bridge cert_command pilot \u2014 readiness gate + handoff", + "source_path": "workplans/WARDEN-WP-0016-ops-bridge-tunnel-cert-pilot.md", + "uuid": "a56da8db-38bc-4bbe-8671-823360ec9245", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0016-T01", + "status": "done", + "title": "T1 \u2014 Read-only `cert_command` readiness preflight", + "source_path": "workplans/WARDEN-WP-0016-ops-bridge-tunnel-cert-pilot.md", + "uuid": "fea84495-dbec-480a-b42b-90e39f414b78", + "parent_id": "WARDEN-WP-0016", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0016-T02", + "status": "done", + "title": "T2 \u2014 Offline cert_command contract smoke", + "source_path": "workplans/WARDEN-WP-0016-ops-bridge-tunnel-cert-pilot.md", + "uuid": "e34ae1a8-2ba9-4324-8d1a-005d61dae478", + "parent_id": "WARDEN-WP-0016", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0016-T03", + "status": "done", + "title": "T3 \u2014 Playbook gate + ops-bridge handoff", + "source_path": "workplans/WARDEN-WP-0016-ops-bridge-tunnel-cert-pilot.md", + "uuid": "330e01f4-4927-4280-b0e0-49d35b4416d6", + "parent_id": "WARDEN-WP-0016", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0016-T04", + "status": "done", + "title": "T4 \u2014 INTENT/SCOPE alignment", + "source_path": "workplans/WARDEN-WP-0016-ops-bridge-tunnel-cert-pilot.md", + "uuid": "4726f5bb-4ffd-484f-8674-91ee5658434f", + "parent_id": "WARDEN-WP-0016", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0017", + "status": "finished", + "title": "Access front-door discoverability \u2014 stop reading as SSH-only", + "source_path": "workplans/WARDEN-WP-0017-access-front-door-discoverability.md", + "uuid": "cf8b392e-7624-4585-8935-a85e29202935", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0017-T01", + "status": "done", + "title": "T1 \u2014 CLI discoverability: route role + access framing", + "source_path": "workplans/WARDEN-WP-0017-access-front-door-discoverability.md", + "uuid": "6e98df42-b5b4-49f8-a444-3c6346c8abd7", + "parent_id": "WARDEN-WP-0017", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0017-T02", + "status": "done", + "title": "T2 \u2014 Agent rule + SCOPE reframe", + "source_path": "workplans/WARDEN-WP-0017-access-front-door-discoverability.md", + "uuid": "6e2a7067-1afc-4f38-8d99-4d5c36a4661c", + "parent_id": "WARDEN-WP-0017", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0017-T03", + "status": "done", + "title": "T3 \u2014 Federated capability registration", + "source_path": "workplans/WARDEN-WP-0017-access-front-door-discoverability.md", + "uuid": "7199625b-e78e-4495-8ca0-076100ae9f08", + "parent_id": "WARDEN-WP-0017", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0018", + "status": "finished", + "title": "Activate whynot-design npm publish lane + resolvable readiness flag", + "source_path": "workplans/WARDEN-WP-0018-whynot-design-npm-lane-activation.md", + "uuid": "1256aca2-5979-4d21-818e-0de42c5d811b", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0018-T01", + "status": "done", + "title": "T1 \u2014 Concrete catalog entry + playbook", + "source_path": "workplans/WARDEN-WP-0018-whynot-design-npm-lane-activation.md", + "uuid": "189d0883-22b9-42dc-bda0-89460509a87d", + "parent_id": "WARDEN-WP-0018", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0018-T02", + "status": "done", + "title": "T2 \u2014 `resolvable` readiness flag + stable-id resolution", + "source_path": "workplans/WARDEN-WP-0018-whynot-design-npm-lane-activation.md", + "uuid": "b5dc1013-5334-43ff-afd6-1f99d521358f", + "parent_id": "WARDEN-WP-0018", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0018-T03", + "status": "done", + "title": "T3 \u2014 Close the loop", + "source_path": "workplans/WARDEN-WP-0018-whynot-design-npm-lane-activation.md", + "uuid": "95b00ef8-477a-4f0d-bd71-6154fba401f5", + "parent_id": "WARDEN-WP-0018", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0019", + "status": "finished", + "title": "Route secret-exec lanes to secrets-engine (route-primary, proxy fallback)", + "source_path": "workplans/WARDEN-WP-0019-route-to-secrets-engine.md", + "uuid": "5e49abb6-497f-4640-a484-2da5f39a7c4e", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0019-T01", + "status": "done", + "title": "T1 \u2014 Catalog + CLI: surface the owner-native exec front door", + "source_path": "workplans/WARDEN-WP-0019-route-to-secrets-engine.md", + "uuid": "ea153605-7a14-4db7-8bce-d780ea143f8a", + "parent_id": "WARDEN-WP-0019", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0019-T02", + "status": "done", + "title": "T2 \u2014 Agent rule, SCOPE, playbook", + "source_path": "workplans/WARDEN-WP-0019-route-to-secrets-engine.md", + "uuid": "96059b8a-8938-4763-b3d0-cc5a0eb2465c", + "parent_id": "WARDEN-WP-0019", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0020", + "status": "finished", + "title": "ops-warden worker \u2014 autonomous coordination via llm-connect", + "source_path": "workplans/WARDEN-WP-0020-ops-warden-worker.md", + "uuid": "c906ba1d-f991-4fb0-b113-59432ddf87c0", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0020-T01", + "status": "done", + "title": "T1 \u2014 Worker scaffold (llm-connect-independent, safe)", + "source_path": "workplans/WARDEN-WP-0020-ops-warden-worker.md", + "uuid": "979c2d9b-0803-442f-aa2e-acb02bac07e9", + "parent_id": "WARDEN-WP-0020", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0020-T02", + "status": "done", + "title": "T2 \u2014 llm-connect brain", + "source_path": "workplans/WARDEN-WP-0020-ops-warden-worker.md", + "uuid": "52d281b2-7d48-44f5-b77e-80e3ed500b5f", + "parent_id": "WARDEN-WP-0020", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0020-T03", + "status": "done", + "title": "T3 \u2014 Action dispatch + guardrails (full-auto in-scope)", + "source_path": "workplans/WARDEN-WP-0020-ops-warden-worker.md", + "uuid": "3a71965e-42d5-4258-9761-aced804c88e7", + "parent_id": "WARDEN-WP-0020", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0020-T04", + "status": "done", + "title": "T4 \u2014 Scheduled trigger", + "source_path": "workplans/WARDEN-WP-0020-ops-warden-worker.md", + "uuid": "7f77ea6d-c281-42c5-ad25-2a0bb9fd68de", + "parent_id": "WARDEN-WP-0020", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0020-T05", + "status": "done", + "title": "T5 \u2014 Docs / SCOPE / INTENT", + "source_path": "workplans/WARDEN-WP-0020-ops-warden-worker.md", + "uuid": "6e7ae317-7f8b-468a-bb5c-b08093ed43a0", + "parent_id": "WARDEN-WP-0020", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0021", + "status": "finished", + "title": "Enable the scheduled worker tick \u2014 conservative inbox triage, unattended", + "source_path": "workplans/WARDEN-WP-0021-enable-scheduled-worker-tick.md", + "uuid": "8c487014-b630-4016-a4f0-31b971a473d2", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0021-T01", + "status": "done", + "title": "T1 \u2014 Scheduler install + enablement + kill switch", + "source_path": "workplans/WARDEN-WP-0021-enable-scheduled-worker-tick.md", + "uuid": "10451fe6-7fab-4ae0-8494-e6cfdfbcf8cf", + "parent_id": "WARDEN-WP-0021", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0021-T02", + "status": "done", + "title": "T2 \u2014 Scheduled-run robustness (graceful degradation)", + "source_path": "workplans/WARDEN-WP-0021-enable-scheduled-worker-tick.md", + "uuid": "1f35f816-1af5-46ff-b48c-1715f3ae5784", + "parent_id": "WARDEN-WP-0021", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0021-T03", + "status": "done", + "title": "T3 \u2014 Operator visibility (see new drafts)", + "source_path": "workplans/WARDEN-WP-0021-enable-scheduled-worker-tick.md", + "uuid": "3c7f6423-8db0-4bc6-b67d-078d9d929c6d", + "parent_id": "WARDEN-WP-0021", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0021-T04", + "status": "done", + "title": "T4 \u2014 Review\u2192send loop (`warden worker approve`)", + "source_path": "workplans/WARDEN-WP-0021-enable-scheduled-worker-tick.md", + "uuid": "dabc9fc0-abb1-4e9d-b87e-5f0c5950693c", + "parent_id": "WARDEN-WP-0021", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0021-T05", + "status": "done", + "title": "T5 \u2014 Runbook + SCOPE", + "source_path": "workplans/WARDEN-WP-0021-enable-scheduled-worker-tick.md", + "uuid": "9915da96-1b33-4d0f-b752-408ea8d43333", + "parent_id": "WARDEN-WP-0021", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0022", + "status": "finished", + "title": "Audit trail + `warden activity` \u2014 one place to see what ops-warden did", + "source_path": "workplans/WARDEN-WP-0022-audit-trail-and-activity.md", + "uuid": "fc8afa28-68a7-4250-a19e-9754829f0cd5", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0022-T01", + "status": "done", + "title": "T1 \u2014 Unified audit event log", + "source_path": "workplans/WARDEN-WP-0022-audit-trail-and-activity.md", + "uuid": "7f8f768a-4c62-4096-bad8-912cea0f35a7", + "parent_id": "WARDEN-WP-0022", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0022-T02", + "status": "done", + "title": "T2 \u2014 Instrument the actions", + "source_path": "workplans/WARDEN-WP-0022-audit-trail-and-activity.md", + "uuid": "e7ae4037-ca79-4557-81f0-bfb8478ff647", + "parent_id": "WARDEN-WP-0022", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0022-T03", + "status": "done", + "title": "T3 \u2014 `warden activity` command", + "source_path": "workplans/WARDEN-WP-0022-audit-trail-and-activity.md", + "uuid": "4439bdd8-1461-47df-8b0b-048df7384a68", + "parent_id": "WARDEN-WP-0022", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0022-T04", + "status": "done", + "title": "T4 \u2014 Tests, runbook, SCOPE", + "source_path": "workplans/WARDEN-WP-0022-audit-trail-and-activity.md", + "uuid": "bdfb8703-7a79-43e7-913b-19d61722f164", + "parent_id": "WARDEN-WP-0022", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0023", + "status": "finished", + "title": "INTENT\u2013SCOPE Alignment Closeout", + "source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md", + "uuid": "7bad1ec4-a7c2-4980-b8f9-49a7f5408574", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0023-T01", + "status": "done", + "title": "T01 \u2014 Persist gap analysis", + "source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md", + "uuid": "52485c90-87fe-40b1-9db5-a51ebb957dd5", + "parent_id": "WARDEN-WP-0023", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0023-T02", + "status": "done", + "title": "T02 \u2014 Refresh INTENT.md", + "source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md", + "uuid": "9a9b3631-8948-45af-ace1-c19ee74ace4d", + "parent_id": "WARDEN-WP-0023", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0023-T03", + "status": "done", + "title": "T03 \u2014 Production integration coordination pack", + "source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md", + "uuid": "26f23798-494b-45fc-baa8-af27bdffa038", + "parent_id": "WARDEN-WP-0023", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0023-T04", + "status": "done", + "title": "T04 \u2014 `warden sign` broker hint when `VAULT_TOKEN` unset", + "source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md", + "uuid": "85e324f9-273d-4740-a202-9c4e8fb122ae", + "parent_id": "WARDEN-WP-0023", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0023-T05", + "status": "done", + "title": "T05 \u2014 Catalog draft-lane promotion checklist", + "source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md", + "uuid": "82608692-2845-41e1-a498-90ed53780748", + "parent_id": "WARDEN-WP-0023", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0023-T06", + "status": "done", + "title": "T06 \u2014 SCOPE and workplan consistency", + "source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md", + "uuid": "79ca7b9a-554e-4952-9393-a29b100f6190", + "parent_id": "WARDEN-WP-0023", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0023-T07", + "status": "done", + "title": "T07 \u2014 Sequence WP-0022 audit implementation", + "source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md", + "uuid": "1f3b3b33-974e-49bf-be4a-9d50b702c2a4", + "parent_id": "WARDEN-WP-0023", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0024", + "status": "finished", + "title": "Experiential Memory Across Worker, Agent Sessions, And OpenRouter", + "source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md", + "uuid": "5d9fafb3-f9b6-43bf-b259-5f5301daa2e9", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0024-T01", + "status": "done", + "title": "T01 - Canonical memory store and discovery", + "source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md", + "uuid": "6305f1bc-c016-4298-adc2-a07d52b6aca5", + "parent_id": "WARDEN-WP-0024", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0024-T02", + "status": "done", + "title": "T02 - Session recording hooks in CLI commands", + "source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md", + "uuid": "242a4d9a-5375-4df8-8d43-063b0491d202", + "parent_id": "WARDEN-WP-0024", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0024-T03", + "status": "done", + "title": "T03 - Memory-aware worker tick", + "source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md", + "uuid": "176fcae1-e4e5-481f-9a83-e9a7000fac1a", + "parent_id": "WARDEN-WP-0024", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0024-T04", + "status": "done", + "title": "T04 - Agent session activation helper", + "source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md", + "uuid": "16501557-6cde-44ea-bc6f-1726cb7ec070", + "parent_id": "WARDEN-WP-0024", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0024-T05", + "status": "done", + "title": "T05 - Cross-runtime continuity", + "source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md", + "uuid": "55ae679c-c08f-4afd-8646-9f5f3019f86e", + "parent_id": "WARDEN-WP-0024", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0024-T06", + "status": "done", + "title": "T06 - OpenRouter efficiency layer", + "source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md", + "uuid": "fc2dffcf-7184-4f3d-8653-d26dc18a9afc", + "parent_id": "WARDEN-WP-0024", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0024-T07", + "status": "done", + "title": "T07 - Operator and agent documentation", + "source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md", + "uuid": "ca2aaf23-833f-49a6-a49b-a0b659208f5f", + "parent_id": "WARDEN-WP-0024", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0025", + "status": "finished", + "title": "Forgejo admin PAT OpenBao lane (CCR-2026-0006)", + "source_path": "workplans/WARDEN-WP-0025-forgejo-admin-api-token-lane.md", + "uuid": "70c11222-d8e7-5936-99f7-7d626a4a5deb", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0025-T01", + "status": "done", + "title": "T1 \u2014 Draft CCR + policy metadata", + "source_path": "workplans/WARDEN-WP-0025-forgejo-admin-api-token-lane.md", + "uuid": "2c288bf0-b39c-5f5b-ad25-eed3da826dc3", + "parent_id": "WARDEN-WP-0025", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0025-T02", + "status": "done", + "title": "T2 \u2014 ops-warden catalog + playbook", + "source_path": "workplans/WARDEN-WP-0025-forgejo-admin-api-token-lane.md", + "uuid": "01b81595-f9e5-5746-b0dd-2075189cb00e", + "parent_id": "WARDEN-WP-0025", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0025-T03", + "status": "done", + "title": "T3 \u2014 Platform-operator approval + metadata apply", + "source_path": "workplans/WARDEN-WP-0025-forgejo-admin-api-token-lane.md", + "uuid": "279b74d7-3240-5ca0-897d-b1ddffd23c4e", + "parent_id": "WARDEN-WP-0025", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0025-T04", + "status": "done", + "title": "T4 \u2014 Attended PAT provision + verification", + "source_path": "workplans/WARDEN-WP-0025-forgejo-admin-api-token-lane.md", + "uuid": "4e21232c-62a1-5115-acce-edfbcfa84e48", + "parent_id": "WARDEN-WP-0025", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0025-T05", + "status": "done", + "title": "T5 \u2014 Notify downstream consumers", + "source_path": "workplans/WARDEN-WP-0025-forgejo-admin-api-token-lane.md", + "uuid": "f8c7c70b-b9b6-5980-a25b-7f11033b81a2", + "parent_id": "WARDEN-WP-0025", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0026", + "status": "finished", + "title": "Credential disclosure hygiene + rotation guidance (Strand A)", + "source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md", + "uuid": "331c7620-bd34-5acd-9135-591985b568e5", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0026-T01", + "status": "done", + "title": "Task: Capabilities-based lane verification", + "source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md", + "uuid": "1cb22a40-b7c6-560a-a805-7766a5786dcc", + "parent_id": "WARDEN-WP-0026", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0026-T02", + "status": "done", + "title": "Task: Safe access transport (no stdout values)", + "source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md", + "uuid": "bcb7da96-0a28-5484-bf3e-06e97acf5873", + "parent_id": "WARDEN-WP-0026", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0026-T03", + "status": "done", + "title": "Task: Masking display filter (defense-in-depth)", + "source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md", + "uuid": "d90b0628-fa1d-527d-99c3-28a7ed933e52", + "parent_id": "WARDEN-WP-0026", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0026-T04", + "status": "done", + "title": "Task: Agent read-boundary on high-risk lanes", + "source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md", + "uuid": "827fa67d-5f69-5fac-bdce-9903b1b909fb", + "parent_id": "WARDEN-WP-0026", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0026-T05", + "status": "done", + "title": "Task: EXPOSED taint convention", + "source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md", + "uuid": "09ef8727-31da-59ac-aac7-2d47924569fe", + "parent_id": "WARDEN-WP-0026", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0026-T06", + "status": "done", + "title": "Task: Rotation / re-establishment guidance registry", + "source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md", + "uuid": "a2e1544e-e501-57eb-a40e-9a2147cef12a", + "parent_id": "WARDEN-WP-0026", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0026-T07", + "status": "done", + "title": "Task: Incident lessons + first worked lane (CCR-2026-0004)", + "source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md", + "uuid": "62d8286f-7954-52a8-bce6-6a16072e5246", + "parent_id": "WARDEN-WP-0026", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0027", + "status": "active", + "title": "Tamper-resistant credential governance + mass rotation/lockdown (Strand B)", + "source_path": "workplans/WARDEN-WP-0027-credential-governance-lockdown.md", + "uuid": "21528e8d-a049-523d-9ae1-da7a27cb8bbf", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0027-T01", + "status": "cancel", + "title": "Task: Executable mass rotation driver", + "source_path": "workplans/WARDEN-WP-0027-credential-governance-lockdown.md", + "uuid": "b5691939-9d84-5115-9618-0f8839010d14", + "parent_id": "WARDEN-WP-0027", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0027-T02", + "status": "progress", + "title": "Task: Graded lockdown / break-glass with explicit trust-root", + "source_path": "workplans/WARDEN-WP-0027-credential-governance-lockdown.md", + "uuid": "cae498ee-6307-5d32-9f1b-a471cfcc2536", + "parent_id": "WARDEN-WP-0027", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0027-T03", + "status": "cancel", + "title": "Task: Tamper-evident policy governance + reconcile", + "source_path": "workplans/WARDEN-WP-0027-credential-governance-lockdown.md", + "uuid": "7dbedcdc-dd5a-551c-bff1-0702fea0a9cf", + "parent_id": "WARDEN-WP-0027", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0028", + "status": "finished", + "title": "Tenant secret custody \u2014 NetKingdom pattern for client/tenant secrets", + "source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md", + "uuid": "6b66228a-199a-5b85-b5e2-a7afeaab903b", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0028-T01", + "status": "done", + "title": "T01 \u2014 Canon note: tenant secret path + ownership", + "source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md", + "uuid": "9982a884-7a50-593e-861e-cc8d2343a0ba", + "parent_id": "WARDEN-WP-0028", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0028-T02", + "status": "done", + "title": "T02 \u2014 Align binky-control integration plan to production path", + "source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md", + "uuid": "d7d7ee9d-2ecf-5492-8a13-0b747d899456", + "parent_id": "WARDEN-WP-0028", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0028-T03", + "status": "done", + "title": "T03 \u2014 Enable `tenants` mount + extend CCR tooling + policy/role", + "source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md", + "uuid": "e0b675ef-9c08-5f89-8f13-ef4249ca2364", + "parent_id": "WARDEN-WP-0028", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0028-T04", + "status": "done", + "title": "T04 \u2014 ops-warden catalog + playbook + rotation", + "source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md", + "uuid": "9405b13d-4045-519b-8e3f-79a891323397", + "parent_id": "WARDEN-WP-0028", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0028-T05", + "status": "done", + "title": "T05 \u2014 Founder provision (Red) + first scan evidence", + "source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md", + "uuid": "f17bba95-bc53-5c2a-8b44-7df9e42b2341", + "parent_id": "WARDEN-WP-0028", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0028-T06", + "status": "done", + "title": "T06 \u2014 Generalize \"tenant secret onboarding\" playbook", + "source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md", + "uuid": "76bd01a0-1d03-5ff9-8f59-a1b44763979d", + "parent_id": "WARDEN-WP-0028", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0028-T07", + "status": "done", + "title": "T07 \u2014 secrets-engine alignment decision (record only)", + "source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md", + "uuid": "46c8f8a9-3bbe-568f-8a45-07b690874273", + "parent_id": "WARDEN-WP-0028", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0029", + "status": "finished", + "title": "Policy front door: posture-aware access planning + founder interaction surface", + "source_path": "workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md", + "uuid": "bbb3d9ec-d88d-5088-b4c0-55bfba0a10cf", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0029-T02", + "status": "done", + "title": "T02 \u2014 Declared organization posture (build phase)", + "source_path": "workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md", + "uuid": "6c213024-6601-5116-b52f-d6711dc0587d", + "parent_id": "WARDEN-WP-0029", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0029-T05", + "status": "done", + "title": "T05 \u2014 Catalog freshness + agent guidance", + "source_path": "workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md", + "uuid": "c82d8745-4af4-5b89-ab49-06d8a902e592", + "parent_id": "WARDEN-WP-0029", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0029-T01", + "status": "done", + "title": "T01 \u2014 `warden plan` decision front door", + "source_path": "workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md", + "uuid": "34db38fa-cb99-5ced-9a12-85176a7f2b44", + "parent_id": "WARDEN-WP-0029", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0029-T04", + "status": "done", + "title": "T04 \u2014 Retire file-drop patterns from playbooks", + "source_path": "workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md", + "uuid": "717f57da-fbc4-5a4d-9f8c-c1c3fa75e0ee", + "parent_id": "WARDEN-WP-0029", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0029-T03", + "status": "done", + "title": "T03 \u2014 Founder interaction surface (local web approval page)", + "source_path": "workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md", + "uuid": "47c781d2-768b-5777-b971-b5227fe41f5c", + "parent_id": "WARDEN-WP-0029", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0030", + "status": "finished", + "title": "Delegation register \u2014 make gap-covering interim, visible, and retirable", + "source_path": "workplans/WARDEN-WP-0030-delegation-register.md", + "uuid": "da3367d5-890c-52c6-aa54-1bdd0f277342", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0030-T01", + "status": "done", + "title": "T01 \u2014 Interim custodianship doctrine", + "source_path": "workplans/WARDEN-WP-0030-delegation-register.md", + "uuid": "6f88876e-434c-5718-9c8d-ec6bf64ae4aa", + "parent_id": "WARDEN-WP-0030", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0030-T02", + "status": "done", + "title": "T02 \u2014 `delegation:` metadata + backfill", + "source_path": "workplans/WARDEN-WP-0030-delegation-register.md", + "uuid": "b02e8da6-57ca-5f9f-9405-9b0624498e3a", + "parent_id": "WARDEN-WP-0030", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0030-T03", + "status": "done", + "title": "T03 \u2014 `warden route gaps` + conformance test", + "source_path": "workplans/WARDEN-WP-0030-delegation-register.md", + "uuid": "f5e0f5af-45d8-5c82-9de2-d640d7d0a1f7", + "parent_id": "WARDEN-WP-0030", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0030-T04", + "status": "done", + "title": "T04 \u2014 Promotion gate", + "source_path": "workplans/WARDEN-WP-0030-delegation-register.md", + "uuid": "b808a749-e1d7-5708-aabf-91732dd76abd", + "parent_id": "WARDEN-WP-0030", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0030-T05", + "status": "done", + "title": "T05 \u2014 Publish the register to the owners", + "source_path": "workplans/WARDEN-WP-0030-delegation-register.md", + "uuid": "b0188ec4-4860-57c8-8030-45904a132190", + "parent_id": "WARDEN-WP-0030", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0031", + "status": "finished", + "title": "Calling-side identity for flex-auth, so policy.enabled can flip", + "source_path": "workplans/WARDEN-WP-0031-policy-caller-identity.md", + "uuid": "739bad25-2345-5f4f-aaa3-cc4cd8c71f6c", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0031-T01", + "status": "done", + "title": "Tasks", + "source_path": "workplans/WARDEN-WP-0031-policy-caller-identity.md", + "uuid": "d3b7c701-bcdd-53f9-aa72-6f289bf5909b", + "parent_id": "WARDEN-WP-0031", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0031-T02", + "status": "done", + "title": "Tasks", + "source_path": "workplans/WARDEN-WP-0031-policy-caller-identity.md", + "uuid": "b77b3c80-a168-564a-9b7f-3063aefc3c2e", + "parent_id": "WARDEN-WP-0031", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0031-T03", + "status": "done", + "title": "Tasks", + "source_path": "workplans/WARDEN-WP-0031-policy-caller-identity.md", + "uuid": "4245155e-6c71-5425-b574-11f61e1d4461", + "parent_id": "WARDEN-WP-0031", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0031-T04", + "status": "done", + "title": "Tasks", + "source_path": "workplans/WARDEN-WP-0031-policy-caller-identity.md", + "uuid": "f3834af7-2a08-51dd-bf31-8ce8550de699", + "parent_id": "WARDEN-WP-0031", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0031-T05", + "status": "cancel", + "title": "Tasks", + "source_path": "workplans/WARDEN-WP-0031-policy-caller-identity.md", + "uuid": "3f6dc609-89db-52eb-a6f9-d2fd271be821", + "parent_id": "WARDEN-WP-0031", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0032", + "status": "finished", + "title": "Adopt security zones as a consumer \u2014 retire the global policy.enabled", + "source_path": "workplans/WARDEN-WP-0032-security-zones.md", + "uuid": "38c6a5f3-fb0d-5230-be85-f9e3ffc850f6", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0032-T01", + "status": "done", + "title": "Tasks", + "source_path": "workplans/WARDEN-WP-0032-security-zones.md", + "uuid": "b03a5caa-0bb5-5cdd-bb99-32c694b0da29", + "parent_id": "WARDEN-WP-0032", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0032-T02", + "status": "done", + "title": "Tasks", + "source_path": "workplans/WARDEN-WP-0032-security-zones.md", + "uuid": "b3f41c85-a293-58ad-ac27-9f8110c51266", + "parent_id": "WARDEN-WP-0032", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0032-T03", + "status": "done", + "title": "Tasks", + "source_path": "workplans/WARDEN-WP-0032-security-zones.md", + "uuid": "d04a737b-ecdf-5747-ba25-20dadd99d3bc", + "parent_id": "WARDEN-WP-0032", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0032-T04", + "status": "done", + "title": "Tasks", + "source_path": "workplans/WARDEN-WP-0032-security-zones.md", + "uuid": "c7879127-3dba-55c0-853c-a10775736873", + "parent_id": "WARDEN-WP-0032", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0032-T05", + "status": "done", + "title": "Tasks", + "source_path": "workplans/WARDEN-WP-0032-security-zones.md", + "uuid": "1d968627-83f4-59cd-84ca-0f9f35e435ff", + "parent_id": "WARDEN-WP-0032", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0032-T06", + "status": "done", + "title": "Tasks", + "source_path": "workplans/WARDEN-WP-0032-security-zones.md", + "uuid": "4294084c-bf3f-5aa6-b84d-5173121882ff", + "parent_id": "WARDEN-WP-0032", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0032-T07", + "status": "done", + "title": "Tasks", + "source_path": "workplans/WARDEN-WP-0032-security-zones.md", + "uuid": "6b4bbbed-2864-5fe9-82be-22ff9543f6f4", + "parent_id": "WARDEN-WP-0032", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0033", + "status": "active", + "title": "Native lane handoff \u2014 review secrets-engine's catalog admission, and fix what it exposed", + "source_path": "workplans/WARDEN-WP-0033-native-lane-handoff.md", + "uuid": "4627d89b-4b00-562a-81e9-76e96f90fa7e", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0033-T01", + "status": "done", + "title": "Tasks", + "source_path": "workplans/WARDEN-WP-0033-native-lane-handoff.md", + "uuid": "154f2f03-387d-5fe6-a0f5-1929c46a2bd8", + "parent_id": "WARDEN-WP-0033", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0033-T02", + "status": "done", + "title": "Tasks", + "source_path": "workplans/WARDEN-WP-0033-native-lane-handoff.md", + "uuid": "6996d07f-63bb-5708-a171-68c4b1bbddde", + "parent_id": "WARDEN-WP-0033", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0033-T03", + "status": "done", + "title": "Tasks", + "source_path": "workplans/WARDEN-WP-0033-native-lane-handoff.md", + "uuid": "a736f983-94da-5a4a-aaf9-5114485518a6", + "parent_id": "WARDEN-WP-0033", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0033-T04", + "status": "wait", + "title": "Tasks", + "source_path": "workplans/WARDEN-WP-0033-native-lane-handoff.md", + "uuid": "5acac140-a586-5db3-b231-bbf236710786", + "parent_id": "WARDEN-WP-0033", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0033-T05", + "status": "done", + "title": "Tasks", + "source_path": "workplans/WARDEN-WP-0033-native-lane-handoff.md", + "uuid": "75051d17-399b-5129-860b-ae00dae91c47", + "parent_id": "WARDEN-WP-0033", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0033-T06", + "status": "done", + "title": "Tasks", + "source_path": "workplans/WARDEN-WP-0033-native-lane-handoff.md", + "uuid": "94f77f5a-f919-5328-832c-ba1d24c6431b", + "parent_id": "WARDEN-WP-0033", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0001", + "status": "archived", + "title": "OpsWarden Initial Implementation", + "source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md", + "uuid": "c3118cc6-adfb-428c-a9c6-edd0ee152ae6", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0001-T1", + "status": "done", + "title": "T1 \u2014 Repository bootstrap", + "source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md", + "uuid": "6d643e9d-5e97-4224-9d82-87267b5ba6bc", + "parent_id": "WARDEN-WP-0001", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0001-T2", + "status": "done", + "title": "T2 \u2014 Models and config", + "source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md", + "uuid": "c66fc65a-0b16-4ba2-9e70-a83d875572ec", + "parent_id": "WARDEN-WP-0001", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0001-T3", + "status": "done", + "title": "T3 \u2014 LocalCA backend", + "source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md", + "uuid": "a5a41e58-1c6d-42a9-9b11-2088f17c29b5", + "parent_id": "WARDEN-WP-0001", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0001-T4", + "status": "done", + "title": "T4 \u2014 VaultCA backend", + "source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md", + "uuid": "b2067ee6-c9ce-423b-9d60-0d28069fb304", + "parent_id": "WARDEN-WP-0001", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0001-T5", + "status": "done", + "title": "T5 \u2014 Principals inventory", + "source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md", + "uuid": "6d13f8cd-1850-44c9-b769-b21250348319", + "parent_id": "WARDEN-WP-0001", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0001-T6", + "status": "done", + "title": "T6 \u2014 CLI commands", + "source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md", + "uuid": "656a4615-92bb-4b5d-9406-e86d24fa15d0", + "parent_id": "WARDEN-WP-0001", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0001-T7", + "status": "done", + "title": "T7 \u2014 Scorecard runner", + "source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md", + "uuid": "7818bcc5-f40e-4793-b117-d36f653ffeed", + "parent_id": "WARDEN-WP-0001", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0001-T8", + "status": "done", + "title": "T8 \u2014 ops-ssh-wrapper script", + "source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md", + "uuid": "e9c28152-5785-4995-83a5-439985ed3db9", + "parent_id": "WARDEN-WP-0001", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0001-T9", + "status": "done", + "title": "T9 \u2014 Tests", + "source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md", + "uuid": "950139ab-cc17-4f1d-9a17-d5744e402ddf", + "parent_id": "WARDEN-WP-0001", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0001-T10", + "status": "done", + "title": "T10 \u2014 Documentation", + "source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md", + "uuid": "271d6759-e359-41ce-80e4-76c574634a87", + "parent_id": "WARDEN-WP-0001", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0002", + "status": "archived", + "title": "OpsWarden Correctness and Operational Completeness", + "source_path": "workplans/archived/260515-WARDEN-WP-0002-correctness-and-completeness.md", + "uuid": "5a9fba2c-6161-49a4-a231-e750fa4ab572", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0002-T1", + "status": "done", + "title": "T1 \u2014 TTL max enforcement per ActorType", + "source_path": "workplans/archived/260515-WARDEN-WP-0002-correctness-and-completeness.md", + "uuid": "b0d0b5f7-a181-4590-be26-c48ae28cd964", + "parent_id": "WARDEN-WP-0002", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0002-T2", + "status": "done", + "title": "T2 \u2014 Stale cert cleanup command", + "source_path": "workplans/archived/260515-WARDEN-WP-0002-correctness-and-completeness.md", + "uuid": "aeeefbad-c0bd-4ae8-a3fe-9f72321b4caa", + "parent_id": "WARDEN-WP-0002", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0002-T3", + "status": "done", + "title": "T3 \u2014 Outgoing signatures log", + "source_path": "workplans/archived/260515-WARDEN-WP-0002-correctness-and-completeness.md", + "uuid": "0194d24f-a8fe-4f6d-88e6-addea3542c0e", + "parent_id": "WARDEN-WP-0002", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0003", + "status": "archived", + "title": "OpsWarden Test Coverage and Code Quality", + "source_path": "workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md", + "uuid": "cb2bbf3c-848a-4af6-ba64-8361e64cd4d7", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0003-T1", + "status": "done", + "title": "T1 \u2014 VaultCA tests", + "source_path": "workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md", + "uuid": "eff074ce-c027-4df5-8006-0990296592ac", + "parent_id": "WARDEN-WP-0003", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0003-T2", + "status": "done", + "title": "T2 \u2014 LocalCA.generate_keypair tests", + "source_path": "workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md", + "uuid": "ddfe5331-0a3b-4783-bdf4-f5ebcdf7965c", + "parent_id": "WARDEN-WP-0003", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0003-T3", + "status": "done", + "title": "T3 \u2014 CLI tests", + "source_path": "workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md", + "uuid": "040ce3a1-0efb-4816-a2d9-357162dd1612", + "parent_id": "WARDEN-WP-0003", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0003-T4", + "status": "done", + "title": "T4 \u2014 Real ssh-keygen integration test", + "source_path": "workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md", + "uuid": "434fb008-103f-410c-85fd-e77b33e61fe4", + "parent_id": "WARDEN-WP-0003", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0003-T5", + "status": "done", + "title": "T5 \u2014 File permissions enforcement (mode 600)", + "source_path": "workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md", + "uuid": "ac146fe6-d1fd-4186-91bd-6f098de72449", + "parent_id": "WARDEN-WP-0003", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0003-T6", + "status": "done", + "title": "T6 \u2014 warden status --state-dir override", + "source_path": "workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md", + "uuid": "1c9f1987-7b11-43c1-a5e3-c2fd8d1c1589", + "parent_id": "WARDEN-WP-0003", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0004", + "status": "archived", + "title": "OpsWarden Repo Hygiene and Hub Sync", + "source_path": "workplans/archived/260617-WARDEN-WP-0004-repo-hygiene-and-hub-sync.md", + "uuid": "3c4b6e68-550a-4fc6-a804-95f1f68936c3", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0004-T01", + "status": "done", + "title": "T1 \u2014 Update orientation docs", + "source_path": "workplans/archived/260617-WARDEN-WP-0004-repo-hygiene-and-hub-sync.md", + "uuid": "f9d3926c-8637-411c-a477-2960b754704c", + "parent_id": "WARDEN-WP-0004", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0004-T02", + "status": "done", + "title": "T2 \u2014 Fill agent rules", + "source_path": "workplans/archived/260617-WARDEN-WP-0004-repo-hygiene-and-hub-sync.md", + "uuid": "86c764a5-62fc-45fe-a8d2-332d6554a976", + "parent_id": "WARDEN-WP-0004", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0004-T03", + "status": "done", + "title": "T3 \u2014 Archive finished workplans", + "source_path": "workplans/archived/260617-WARDEN-WP-0004-repo-hygiene-and-hub-sync.md", + "uuid": "d3e54e63-ce98-4632-bc08-0e2667f19f12", + "parent_id": "WARDEN-WP-0004", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0004-T04", + "status": "done", + "title": "T4 \u2014 Sync State Hub", + "source_path": "workplans/archived/260617-WARDEN-WP-0004-repo-hygiene-and-hub-sync.md", + "uuid": "51729695-262f-4fe4-9c38-f99ee046d32a", + "parent_id": "WARDEN-WP-0004", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0005", + "status": "archived", + "title": "OpsWarden OpenBao-First Documentation Alignment", + "source_path": "workplans/archived/260617-WARDEN-WP-0005-openbao-doc-alignment.md", + "uuid": "57f6ebf8-0ef3-4686-9a73-3f9d38288be9", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0005-T01", + "status": "done", + "title": "T1 \u2014 OpsWardenConfig.md", + "source_path": "workplans/archived/260617-WARDEN-WP-0005-openbao-doc-alignment.md", + "uuid": "bbbc4dda-9634-4c04-86e5-94b96c021b43", + "parent_id": "WARDEN-WP-0005", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0005-T02", + "status": "done", + "title": "T2 \u2014 Cross-reference updates", + "source_path": "workplans/archived/260617-WARDEN-WP-0005-openbao-doc-alignment.md", + "uuid": "6391cb82-896e-405a-a59b-36640e6480ba", + "parent_id": "WARDEN-WP-0005", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0006", + "status": "archived", + "title": "NetKingdom Alignment and Operational Access Stewardship", + "source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md", + "uuid": "a5c9f24b-1ad4-46da-bc8e-b99897f8e302", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0006-T01", + "status": "done", + "title": "T1 \u2014 Credential routing runbook", + "source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md", + "uuid": "ffc6a0c2-4312-4584-be7a-c8411cb01899", + "parent_id": "WARDEN-WP-0006", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0006-T02", + "status": "done", + "title": "T2 \u2014 Actor inventory patterns", + "source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md", + "uuid": "3816463d-7dfd-469d-9324-fd7880b50608", + "parent_id": "WARDEN-WP-0006", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0006-T03", + "status": "done", + "title": "T3 \u2014 NetKingdom cross-links (ops-warden side)", + "source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md", + "uuid": "f158366a-5746-48b8-acce-472dce8f925e", + "parent_id": "WARDEN-WP-0006", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0006-T04", + "status": "done", + "title": "T4 \u2014 NetKingdom canon patch (coordination)", + "source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md", + "uuid": "e40e4395-8f01-4f79-a539-d0de8e427321", + "parent_id": "WARDEN-WP-0006", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0006-T05", + "status": "done", + "title": "T5 \u2014 OpenBao SSH engine operational checklist", + "source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md", + "uuid": "a94e20a2-970b-4a0c-bd23-8510b841b938", + "parent_id": "WARDEN-WP-0006", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0006-T06", + "status": "done", + "title": "T6 \u2014 Policy-gated signing design (design only)", + "source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md", + "uuid": "b10a4b4d-bfa1-4f49-b6a5-f339f1e6a2e1", + "parent_id": "WARDEN-WP-0006", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0006-T07", + "status": "done", + "title": "T7 \u2014 Re-assess INTENT \u2194 SCOPE", + "source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md", + "uuid": "ef8b5c57-2343-4cfc-9fee-48db1e56f69a", + "parent_id": "WARDEN-WP-0006", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0007", + "status": "archived", + "title": "Policy Gate and Production OpenBao Verification", + "source_path": "workplans/archived/260617-WARDEN-WP-0007-policy-gate-and-production-verify.md", + "uuid": "3718ac07-2fa2-47d0-a02a-c9a7b83a5ba9", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0007-T01", + "status": "done", + "title": "T1 \u2014 Production OpenBao verification evidence", + "source_path": "workplans/archived/260617-WARDEN-WP-0007-policy-gate-and-production-verify.md", + "uuid": "344540ad-5912-4118-b406-450b96e13c40", + "parent_id": "WARDEN-WP-0007", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0007-T02", + "status": "done", + "title": "T2 \u2014 Policy config and flex-auth client", + "source_path": "workplans/archived/260617-WARDEN-WP-0007-policy-gate-and-production-verify.md", + "uuid": "05424ddf-5fe9-43a1-a2f8-c47235a012c8", + "parent_id": "WARDEN-WP-0007", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0007-T03", + "status": "done", + "title": "T3 \u2014 Wire policy gate into sign/issue", + "source_path": "workplans/archived/260617-WARDEN-WP-0007-policy-gate-and-production-verify.md", + "uuid": "f5ae8e6e-8cce-4526-b18c-0452a135af49", + "parent_id": "WARDEN-WP-0007", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0007-T04", + "status": "done", + "title": "T4 \u2014 Tests and docs", + "source_path": "workplans/archived/260617-WARDEN-WP-0007-policy-gate-and-production-verify.md", + "uuid": "ea921d56-033b-4619-8032-61af7992e610", + "parent_id": "WARDEN-WP-0007", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0008", + "status": "finished", + "title": "Production SSH Path and Stewardship Closeout", + "source_path": "workplans/archived/260618-WARDEN-WP-0008-production-ssh-path-and-stewardship-closeout.md", + "uuid": "a174963a-4ff1-4565-b19f-896cd4ff14a0", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0008-T01", + "status": "done", + "title": "T1 \u2014 Post-WP-0007 INTENT/SCOPE reassessment", + "source_path": "workplans/archived/260618-WARDEN-WP-0008-production-ssh-path-and-stewardship-closeout.md", + "uuid": "05379da4-79d0-4742-8638-9e9565cccf72", + "parent_id": "WARDEN-WP-0008", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0008-T02", + "status": "done", + "title": "T2 \u2014 Production OpenBao end-to-end sign verification", + "source_path": "workplans/archived/260618-WARDEN-WP-0008-production-ssh-path-and-stewardship-closeout.md", + "uuid": "b1a1831d-b2b3-4204-95f6-04dc7f29f67c", + "parent_id": "WARDEN-WP-0008", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0008-T03", + "status": "done", + "title": "T3 \u2014 State Hub task status canon migration", + "source_path": "workplans/archived/260618-WARDEN-WP-0008-production-ssh-path-and-stewardship-closeout.md", + "uuid": "876827c4-4a86-4e58-9a1f-ac87045dc903", + "parent_id": "WARDEN-WP-0008", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0008-T04", + "status": "done", + "title": "T4 \u2014 Production config example and archive hygiene", + "source_path": "workplans/archived/260618-WARDEN-WP-0008-production-ssh-path-and-stewardship-closeout.md", + "uuid": "75b9f366-3d7a-419d-98ad-bc10ab90a697", + "parent_id": "WARDEN-WP-0008", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0008-T05", + "status": "cancel", + "title": "T5 \u2014 flex-auth policy gate production readiness (coordination)", + "source_path": "workplans/archived/260618-WARDEN-WP-0008-production-ssh-path-and-stewardship-closeout.md", + "uuid": "03b412a5-5b99-42df-a154-733dd4156000", + "parent_id": "WARDEN-WP-0008", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0009", + "status": "archived", + "title": "flex-auth Policy Gate Production Readiness", + "source_path": "workplans/archived/260623-WARDEN-WP-0009-flex-auth-policy-gate-production.md", + "uuid": "9213b262-e2f5-480e-a5bc-56635d5eb4c9", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0009-T01", + "status": "done", + "title": "T1 \u2014 flex-auth policy package confirmation", + "source_path": "workplans/archived/260623-WARDEN-WP-0009-flex-auth-policy-gate-production.md", + "uuid": "f988ed2e-0f63-4e89-abc4-183a7f23ddc2", + "parent_id": "WARDEN-WP-0009", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0009-T02", + "status": "done", + "title": "T2 \u2014 Production enablement and smoke", + "source_path": "workplans/archived/260623-WARDEN-WP-0009-flex-auth-policy-gate-production.md", + "uuid": "9d0fabc2-10ef-426d-a3d2-d4970d377029", + "parent_id": "WARDEN-WP-0009", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0010", + "status": "archived", + "title": "Access Routing \u2014 Charter and Pointer Catalog", + "source_path": "workplans/archived/260624-WARDEN-WP-0010-access-routing-charter.md", + "uuid": "e93de9fd-0192-4d02-bb7c-5e859fb76b9b", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0010-T01", + "status": "done", + "title": "T1 \u2014 INTENT wording", + "source_path": "workplans/archived/260624-WARDEN-WP-0010-access-routing-charter.md", + "uuid": "589081a6-d1f5-47b4-bec0-e82d9c3444f4", + "parent_id": "WARDEN-WP-0010", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0010-T02", + "status": "done", + "title": "T2 \u2014 Routing-role wiki page", + "source_path": "workplans/archived/260624-WARDEN-WP-0010-access-routing-charter.md", + "uuid": "9ac333f7-5fc4-4fa2-82f3-d5ece8ff0d92", + "parent_id": "WARDEN-WP-0010", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0010-T03", + "status": "done", + "title": "T3 \u2014 Pointer catalog schema + seed", + "source_path": "workplans/archived/260624-WARDEN-WP-0010-access-routing-charter.md", + "uuid": "59e0f480-694a-482a-b35e-b7bc4930aa41", + "parent_id": "WARDEN-WP-0010", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0010-T04", + "status": "done", + "title": "T4 \u2014 Routing index in CredentialRouting.md", + "source_path": "workplans/archived/260624-WARDEN-WP-0010-access-routing-charter.md", + "uuid": "aabd28c0-db2d-4267-be98-95be272c687d", + "parent_id": "WARDEN-WP-0010", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0010-T05", + "status": "done", + "title": "T5 \u2014 Registry and repo-boundary alignment", + "source_path": "workplans/archived/260624-WARDEN-WP-0010-access-routing-charter.md", + "uuid": "3335a689-922c-4319-98d0-4263ab13790b", + "parent_id": "WARDEN-WP-0010", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0011", + "status": "archived", + "title": "Routing Lookup CLI", + "source_path": "workplans/archived/260624-WARDEN-WP-0011-routing-guide-cli.md", + "uuid": "0a520f8e-01b4-48f1-9af3-2f3f69fd0672", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0011-T01", + "status": "done", + "title": "T1 \u2014 Catalog loader and models", + "source_path": "workplans/archived/260624-WARDEN-WP-0011-routing-guide-cli.md", + "uuid": "55b8422c-ad3c-4084-9e00-acaa4c360906", + "parent_id": "WARDEN-WP-0011", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0011-T02", + "status": "done", + "title": "T2 \u2014 `warden route list` and `show`", + "source_path": "workplans/archived/260624-WARDEN-WP-0011-routing-guide-cli.md", + "uuid": "60b679c5-79bd-4186-b5a6-ac576931f06c", + "parent_id": "WARDEN-WP-0011", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0011-T03", + "status": "done", + "title": "T3 \u2014 `warden route find`", + "source_path": "workplans/archived/260624-WARDEN-WP-0011-routing-guide-cli.md", + "uuid": "d307701f-0117-44f0-80fd-ca6f7ae06f42", + "parent_id": "WARDEN-WP-0011", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0011-T04", + "status": "done", + "title": "T4 \u2014 Tests", + "source_path": "workplans/archived/260624-WARDEN-WP-0011-routing-guide-cli.md", + "uuid": "00a76e0f-8ab6-4f9a-ac6a-00eae633342c", + "parent_id": "WARDEN-WP-0011", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0011-T05", + "status": "done", + "title": "T5 \u2014 Doc consistency + drift guard", + "source_path": "workplans/archived/260624-WARDEN-WP-0011-routing-guide-cli.md", + "uuid": "bf848375-eca7-4116-bb1d-fb7df6395c70", + "parent_id": "WARDEN-WP-0011", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0013", + "status": "archived", + "title": "Production Integration & Stewardship Closeout", + "source_path": "workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md", + "uuid": "4678c41a-c1d0-48cd-9988-4ea0380e8258", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0013-T01", + "status": "done", + "title": "T1 \u2014 Post-gap reassessment and SCOPE refresh", + "source_path": "workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md", + "uuid": "de46f9a2-bf11-4651-a23c-430c63f396c8", + "parent_id": "WARDEN-WP-0013", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0013-T02", + "status": "done", + "title": "T2 \u2014 Archive hygiene (WP-0010, WP-0011)", + "source_path": "workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md", + "uuid": "1b35321d-63ad-40da-a1aa-0b66190a0733", + "parent_id": "WARDEN-WP-0013", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0013-T03", + "status": "done", + "title": "T3 \u2014 ops-bridge cert_command migration playbook", + "source_path": "workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md", + "uuid": "ad8588b2-9ae9-4f94-bd77-8025851a38f5", + "parent_id": "WARDEN-WP-0013", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0013-T04", + "status": "done", + "title": "T4 \u2014 Operator OpenBao token hygiene runbook", + "source_path": "workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md", + "uuid": "5cb35829-32eb-4d59-97a1-f4d92ce8e239", + "parent_id": "WARDEN-WP-0013", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0013-T05", + "status": "done", + "title": "T5 \u2014 Principals inventory drift check", + "source_path": "workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md", + "uuid": "4025cd32-89f8-42c3-b1e8-eaf78497d91f", + "parent_id": "WARDEN-WP-0013", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0013-T06", + "status": "done", + "title": "T6 \u2014 Policy gate production enablement checklist", + "source_path": "workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md", + "uuid": "51663f65-79cb-4108-87c8-9721f9476259", + "parent_id": "WARDEN-WP-0013", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0012", + "status": "finished", + "title": "Routing Scenario Playbooks", + "source_path": "workplans/archived/260627-WARDEN-WP-0012-routing-scenario-playbooks.md", + "uuid": "a7e712a0-02f8-4f83-944e-6b207e77bc4c", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0012-T01", + "status": "done", + "title": "T1 \u2014 issue-core ingestion key playbook", + "source_path": "workplans/archived/260627-WARDEN-WP-0012-routing-scenario-playbooks.md", + "uuid": "830bb512-0288-4dba-9dd4-ccfd28a4921f", + "parent_id": "WARDEN-WP-0012", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0012-T02", + "status": "done", + "title": "T2 \u2014 Inter-Hub and bootstrap lanes", + "source_path": "workplans/archived/260627-WARDEN-WP-0012-routing-scenario-playbooks.md", + "uuid": "7726a703-6e00-4e49-9380-ed3fb3268827", + "parent_id": "WARDEN-WP-0012", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0012-T03", + "status": "done", + "title": "T3 \u2014 ops-bridge tunnel migration", + "source_path": "workplans/archived/260627-WARDEN-WP-0012-routing-scenario-playbooks.md", + "uuid": "9fb397f0-0abb-48f5-bb62-7e77edae93bb", + "parent_id": "WARDEN-WP-0012", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0012-T04", + "status": "done", + "title": "T4 \u2014 Platform secret scenarios (LLM, STS, DB)", + "source_path": "workplans/archived/260627-WARDEN-WP-0012-routing-scenario-playbooks.md", + "uuid": "edcf4ed7-f18d-4a92-a42d-8cc7ca0ab792", + "parent_id": "WARDEN-WP-0012", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0012-T05", + "status": "done", + "title": "T5 \u2014 Drift review cadence", + "source_path": "workplans/archived/260627-WARDEN-WP-0012-routing-scenario-playbooks.md", + "uuid": "db98d655-8551-487b-9413-41bf97fc06e1", + "parent_id": "WARDEN-WP-0012", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0014", + "status": "finished", + "title": "Operator Access Assist \u2014 warden access front door", + "source_path": "workplans/archived/260627-WARDEN-WP-0014-operator-access-assist.md", + "uuid": "3c30b2ed-6ede-4b95-a438-fde6da6f6633", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0014-T01", + "status": "done", + "title": "T1 \u2014 Catalog schema: structured handoff fields", + "source_path": "workplans/archived/260627-WARDEN-WP-0014-operator-access-assist.md", + "uuid": "abb0e722-6524-4224-8638-6ee1573ed3e0", + "parent_id": "WARDEN-WP-0014", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0014-T02", + "status": "done", + "title": "T2 \u2014 `warden access` advisory surface", + "source_path": "workplans/archived/260627-WARDEN-WP-0014-operator-access-assist.md", + "uuid": "c1497263-7124-459f-b63a-d0c0c7005c86", + "parent_id": "WARDEN-WP-0014", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0014-T03", + "status": "done", + "title": "T3 \u2014 OpenBao proxy lane (`--fetch` / `--exec`)", + "source_path": "workplans/archived/260627-WARDEN-WP-0014-operator-access-assist.md", + "uuid": "6d3eb0e4-309c-4065-893e-6c4053fb0db2", + "parent_id": "WARDEN-WP-0014", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0014-T04", + "status": "done", + "title": "T4 \u2014 key-cape / login orchestration lane", + "source_path": "workplans/archived/260627-WARDEN-WP-0014-operator-access-assist.md", + "uuid": "481997e4-193d-4724-84a6-61cbc2940153", + "parent_id": "WARDEN-WP-0014", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0014-T05", + "status": "done", + "title": "T5 \u2014 Docs, security model, and INTENT/SCOPE alignment", + "source_path": "workplans/archived/260627-WARDEN-WP-0014-operator-access-assist.md", + "uuid": "a5eb616e-4edf-42db-a4fb-bf296cdb92bc", + "parent_id": "WARDEN-WP-0014", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-0015", + "status": "finished", + "title": "Workload Security Posture \u2014 env posture \u00d7 maturity + conformance", + "source_path": "workplans/archived/260627-WARDEN-WP-0015-secret-lifecycle-tiering.md", + "uuid": "99f4a0e1-853c-456f-8aa7-8ff0f318ea65", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0015-T01", + "status": "done", + "title": "T1 \u2014 Author the two-axis Workload Security Posture standard (canon-bound)", + "source_path": "workplans/archived/260627-WARDEN-WP-0015-secret-lifecycle-tiering.md", + "uuid": "85aeb676-a593-4056-986a-db14d4c5209f", + "parent_id": "WARDEN-WP-0015", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0015-T02", + "status": "done", + "title": "T2 \u2014 Machine-readable posture descriptors (both axes)", + "source_path": "workplans/archived/260627-WARDEN-WP-0015-secret-lifecycle-tiering.md", + "uuid": "011fb0af-154d-40f4-a03e-3172c325321a", + "parent_id": "WARDEN-WP-0015", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0015-T03", + "status": "done", + "title": "T3 \u2014 Conformance checker (incl. secret-flow lattice)", + "source_path": "workplans/archived/260627-WARDEN-WP-0015-secret-lifecycle-tiering.md", + "uuid": "c1a0e987-19d0-478e-ac08-2dbe98e64e09", + "parent_id": "WARDEN-WP-0015", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0015-T04", + "status": "done", + "title": "T4 \u2014 Dev-tier contract-double fixture library", + "source_path": "workplans/archived/260627-WARDEN-WP-0015-secret-lifecycle-tiering.md", + "uuid": "e556fd2e-4e39-4c7d-bd94-b4330e4bef45", + "parent_id": "WARDEN-WP-0015", + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-0015-T05", + "status": "done", + "title": "T5 \u2014 INTENT/SCOPE alignment + canon contributions", + "source_path": "workplans/archived/260627-WARDEN-WP-0015-secret-lifecycle-tiering.md", + "uuid": "298c9b09-4a5a-41bf-a3bd-6c572385236b", + "parent_id": "WARDEN-WP-0015", + "extra": {} + }, + { + "kind": "workplan", + "id": "WARDEN-WP-ADHOC-2026-07-07", + "status": "finished", + "title": "Ad Hoc Tasks \u2014 2026-07-07", + "source_path": "workplans/archived/260707-ADHOC-2026-07-07.md", + "uuid": null, + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "WARDEN-WP-ADHOC-2026-07-07-T01", + "status": "done", + "title": "T01 \u2014 Roll out proxy pipe fix (be3b4a2)", + "source_path": "workplans/archived/260707-ADHOC-2026-07-07.md", + "uuid": null, + "parent_id": "WARDEN-WP-ADHOC-2026-07-07", + "extra": {} + }, + { + "kind": "intake", + "id": "WARDEN-IN-0001", + "status": "open", + "title": "Assent requested: Staff layer, doctrine vs runbook, and the access lane/rule demarcation", + "source_path": "intakes/intakes.md", + "uuid": null, + "parent_id": null, + "extra": { + "record": { + "id": "WARDEN-IN-0001", + "kind": "intake", + "title": "Assent requested: Staff layer, doctrine vs runbook, and the access lane/rule demarcation", + "status": "open", + "origin": "cross-repo", + "origin_ref": "gate-house GH-DEC-2026-001", + "priority": "medium", + "owner": "ops-warden", + "requested_by": "gate-house", + "standard": "net-kingdom/canon/standards/security-layer-model_v0.1.md", + "description": "gate-house asks ops-warden to assent to three boundary items. (1) ops-warden is Staff, bound by the rule that Staff acts only through Engine APIs and never touches Tooling directly (standard section 5). (2) Doctrine versus runbook: the NetKingdom Security Literacy section in ops-warden INTENT is evidence the security curriculum had no owner; it now has one in gate-house. Proposal is that doctrine and curriculum move to gate-house and that section becomes lane-specific runbooks referencing gate-house doctrine rather than restating it. ops-warden keeps the lanes it stewards and everything operational about them. (3) The access lane/rule demarcation, normative in standard section 8: ops-warden and ops-mason own access lanes \u2014 how a worker reaches a host; access-engine owns access rules \u2014 whether they may. This demarcation is the condition attached to renaming flex-auth to access-engine, so ops-warden effectively holds a veto on that name. Also requested: add gate-house to the Security Literacy and routing tables \u2014 currently every plane is listed and gate-house appears nowhere \u2014 routing doctrine and authority-model questions there while continuing to route policy decisions to access-engine. If moving the curriculum out leaves ops-warden unable to instruct its own workers, say so; the boundary is wrong if it does.", + "created": "2026-08-28T19:30:28.087109Z", + "updated": "2026-08-28T19:30:28.087109Z" + } + } + } + ], + "events": [ + { + "type": "repo.command.applied", + "command": "repo.work.create_intake", + "operation": "create", + "correlation_id": "65d40cdd-5894-440e-9c95-c6bcfe259b66", + "kind": "intake", + "id": "WARDEN-IN-0001", + "git_sha": "467635e84b99757336ee49d7f0dbf107607d0560", + "files_touched": [ + "intakes/intakes.md" + ], + "source": "repo-manager", + "emitted_at": "2026-08-28T19:30:29.829125Z" + } + ] +} diff --git a/INTENT.md b/INTENT.md index caa3c68..d1c0a97 100644 --- a/INTENT.md +++ b/INTENT.md @@ -1,19 +1,26 @@ # INTENT -> **NetKingdom layering review — 2026-08-28.** This repository's role was reviewed -> against the NetKingdom IT-security layer model: **Taxonomy → Tooling → Engines → -> Staff**, layered by determinism and by the kind of artifact each layer produces. -> Findings and the argument behind them: -> `gate-house/history/2026-08-28-security-layer-model-and-gate-house-recut.md`. -> The model is `net-kingdom/canon/standards/security-layer-model_v0.1.md` (proposed), -> ratified by `gate-house/decisions/decisions.md` GH-DEC-2026-001. +> **Layer: Staff.** ops-warden is a Staff repository under the NetKingdom +> IT-security layer model (Taxonomy -> Tooling -> Engines -> Staff, layered by +> determinism and by the kind of artifact each layer produces): +> `net-kingdom/canon/standards/security-layer-model_v0.1.md`, owned by gate-house, +> ratified as `gate-house/decisions/decisions.md` GH-DEC-2026-001. > -> The layer rule that binds every repository: **Staff never touches tooling -> directly. It acts only through engine APIs.** +> **The binding rule: Staff never touches Tooling directly. It acts only through +> Engine APIs.** ops-warden holds no state another layer depends on at runtime and +> renders no authorization decision — it consumes them from access-engine. > -> **This repository is Staff — interactive, non-deterministic; operational stewardship.** Add the layer label and the Staff invariant. Two substantive changes. (1) The **"NetKingdom Security Literacy"** section is evidence that the security curriculum had no owner; it now has one. Doctrine and curriculum move to gate-house, and this section becomes lane-specific runbooks that reference gate-house doctrine rather than restating it. The boundary is **doctrine versus runbook**. (2) The literacy and routing tables should add gate-house — currently every plane is listed and gate-house appears nowhere — routing doctrine and authority-model questions there, while continuing to route policy decisions to access-engine. Record the lane/rule demarcation as in ops-mason. +> **Declared exception (standard section 5).** `src/warden/vault.py` (`VaultCA`) is a +> direct OpenBao client that performs a write, and `warden desk` shells `bao kv put` +> for paste-once provisioning. Both are non-conformant. Intended owner: +> **secrets-engine**; blocked on: no engine exposes an SSH certificate signing +> surface; reviewed quarterly. `src/warden/taint.py` reads KV metadata only, declared +> under the read-only observation allowance. `warden access --fetch/--exec/--wrap` +> runs the owner's tool under **the caller's** identity and supplies no authority of +> its own (`ADR-0002`). > -> *This note records what should change. The body below is not yet adapted.* +> Assent, reasoning, and the amendment offered back to gate-house: +> `history/2026-08-28-security-layer-model-assent.md` and `ADR-0010`. > This file captures **why this repository exists**, the **direction it is > moving toward**, and the **kind of system it is meant to become**. @@ -92,30 +99,51 @@ owns one lane and points at the rest: --- -## NetKingdom Security Literacy +## Lane routing — who owns which need -ops-warden should be fluent in the platform architecture documented in -`net-kingdom` — especially: +**This is a runbook, not doctrine.** Security doctrine, the authority model, and the +security curriculum are **gate-house's** (`security-layer-model_v0.1` section 8). +ops-warden references them and does not restate them. What follows is lane +stewardship: which subsystem owns which need, and what ops-warden does about it. -| Plane / component | Role in access | ops-warden relationship | -| --- | --- | --- | -| **key-cape / Keycloak** | Identity — who is the actor, MFA, IAM Profile claims | Instruct identity path; do not re-implement OIDC | -| **flex-auth + Topaz** | Authorization — may this actor perform this action | Caller-side policy gate shipped (opt-in); production flip is flex-auth's | -| **OpenBao** | Runtime secrets — API keys, dynamic creds, leases, audit | Instruct custody paths; SSH engine is signing backend only; proxy reads as caller when `exec_capable` | -| **secrets-engine** | Owner-native secret-exec (`secrets-engine exec`) | Route provisioned exec lanes (e.g. npm publish); ops-warden does not hold tokens | -| **railiance-platform** (credential broker) | Scoped lease grants (`credential exec`) | Route `warden-sign` token needs; ops-warden does not mint OpenBao tokens | -| **tenant-engine** | Tenant/client secret custody and front door | Route tenant lanes once fronted; ops-warden's current tenant proxies are interim (§9) | -| **user-engine** | End-user identity and account lifecycle | No ops-warden lane today; route rather than absorb | -| **ops-warden** | Operational SSH certificates — short-lived host access | **Own and issue** this lane | -| **ops-bridge** | Tunnel transport — consumes certs via `cert_command` | Primary consumer; document integration | -| **railiance-infra** | Host principals, force-command, SSH hardening | Instruct host-side deployment; do not own Ansible | -| **railiance-platform** (deploy) | OpenBao/K8s/platform service deployment | Instruct production endpoints; do not deploy clusters | +The machine-readable form is `registry/routing/catalog.yaml`, and the executable form +is `warden plan ""` / `warden route find`. Prefer either over this table — it is +orientation, and the catalog is the source of truth (`ADR-0001`). + +| Component | Layer | Owns | ops-warden relationship | +| --- | --- | --- | --- | +| **gate-house** | Staff | Security doctrine, invariants, authority ceilings, authority context, conformance review, curriculum | **Route doctrine and authority-model questions here.** Not policy decisions — those go to access-engine | +| **access-engine** (`flex-auth`) | Engine | **The policy decision** — whether an actor may act. The only decision point in NetKingdom | Consume decisions; caller-side pre-sign gate. ops-warden never renders or caches one | +| **key-cape / Keycloak** | Tooling | Identity — who the actor is, MFA, IAM Profile claims | Instruct the identity path; do not re-implement OIDC | +| **OpenBao** | Tooling | Runtime secrets — API keys, dynamic creds, leases, audit | Instruct custody paths; proxy reads as the caller when `exec_capable`. Direct client use is the declared exception above | +| **secrets-engine** | Engine | Credential abstraction, custody, lifecycle; owner-native exec | Route provisioned exec lanes (e.g. npm publish). **Intended owner of the SSH-CA surface** | +| **tenant-engine** | Engine | Tenant/client secret custody and front door | Route tenant lanes once fronted; current tenant proxies are interim (section 9) | +| **user-engine** | Engine | Users, accounts, memberships | No ops-warden lane today; route rather than absorb | +| **zone-engine** | Engine | Zone identity and membership | Consume compiled membership; ops-warden declares `z1-operational` (`ADR-0009`) | +| **railiance-platform** (broker) | — | Scoped lease grants (`credential exec`) | Route `warden-sign` token needs; ops-warden does not mint OpenBao tokens | +| **ops-mason** | Staff | Building and tearing down access routes and perimeters | Peer lane owner; same lane/rule demarcation applies | +| **ops-warden** | Staff | **Operational access lanes** — short-lived SSH certificates, routing, stewardship, runbooks | **Own and issue** the SSH lane | +| **ops-bridge** | Staff | Tunnel transport — consumes certs via `cert_command` | Primary consumer; document integration | +| **railiance-infra** | — | Host principals, force-command, SSH hardening | Instruct host-side deployment; do not own Ansible | +| **kings-guard** | Staff | Adaptive defence, observation, containment; publishes posture | Posture may reduce authority, never manufacture it | + +### Access lane versus access rule + +Normative, per `security-layer-model_v0.1` section 8 and assented to in `ADR-0010`: + +- **access lane** — ops-warden and ops-mason. *How* a worker reaches a host. +- **access rule** — access-engine. *Whether* they may. + +ops-warden owns the route and never the decision. A question about whether an actor +may do something is not an ops-warden question, however it arrives. Canonical references: +- `net-kingdom/canon/standards/security-layer-model_v0.1.md` (layers, section 5, section 8) - `net-kingdom/docs/platform-identity-security-architecture.md` - `net-kingdom/docs/responsibility-map.md` - `wiki/AccessManagementDirective.md` (ops SSH actor model) +- `.claude/rules/credential-routing.md` (agent-facing runbook — stays inline by design) --- @@ -138,7 +166,8 @@ Canonical references: | Need | Route to | | --- | --- | | OIDC login, MFA, human identity claims | key-cape / Keycloak (NetKingdom IAM Profile) | -| Policy decision — may actor X access resource Y | flex-auth | +| Security doctrine, invariants, authority model | gate-house | +| Policy decision — may actor X access resource Y | access-engine (`flex-auth`) | | API keys, provider secrets, DB creds, object-storage STS | OpenBao (+ flex-auth policy where required) | | Inter-Hub operator keys, LLM provider credentials | OpenBao or approved operator secret store | | Tunnel lifecycle, port forwarding | ops-bridge | diff --git a/SCOPE.md b/SCOPE.md index ae19ee4..46c9eec 100644 --- a/SCOPE.md +++ b/SCOPE.md @@ -156,6 +156,7 @@ superseding ADR, never an in-place edit. | `ADR-0007` | Build-stage permissiveness stops at credential disclosure; every lane carries an explicit `risk` grade | | `ADR-0008` | A lane's risk grade covers every field its path discloses, not just the field it is named after | | `ADR-0009` | Adopt security-zones v0.1 and compile explicit workload membership; PEP failure mode is per zone | +| `ADR-0010` | ops-warden is Staff — it owns access lanes, never access rules; the direct OpenBao client is a declared engine gap, not an exemption | Rules we follow but do not own — NetKingdom canon, the IAM profile, the credential-management standard, the-custodian's ADR-001 workplan convention — are @@ -433,11 +434,12 @@ Downstream: `ops-bridge` (primary), kaizen agents, CI automations, human operato | Repo | Relationship | | --- | --- | +| `gate-house` | Owns security doctrine, invariants, authority context, and conformance review; ops-warden routes doctrine questions there and references rather than restates them (`ADR-0010`) | | `net-kingdom` | Canonical security architecture; ops-warden aligns to it | | `ops-bridge` | Primary cert_command consumer | | `railiance-infra` | Host-side SSH principals and hardening | | `railiance-platform` | OpenBao deployment and platform secrets | -| `flex-auth` | Authorization; policy package shipped (FLEX-WP-0006); runtime deploy FLEX-WP-0007 | +| `flex-auth` | Authorization — ruled name `access-engine`; the only policy decision point. Policy package shipped (FLEX-WP-0006); runtime deploy FLEX-WP-0007 | | `key-cape` | Identity / IAM Profile lightweight mode | | `secrets-engine` | Owner-native secret-exec front door (`secrets-engine exec/route`); ops-warden routes provisioned secret lanes to it (WP-0019) and holds 6 more as interim proxies pending its front doors | | `tenant-engine` | Intended owner of tenant/client secret front doors; ops-warden holds 3 tenant lanes as interim proxies (WP-0028 pattern, WP-0030 register) | diff --git a/docs/adr/ADR-0010-ops-warden-is-staff.md b/docs/adr/ADR-0010-ops-warden-is-staff.md new file mode 100644 index 0000000..65e4ed2 --- /dev/null +++ b/docs/adr/ADR-0010-ops-warden-is-staff.md @@ -0,0 +1,109 @@ +--- +id: ops-warden-adr-0010 +type: adr +title: "ADR-0010 — ops-warden is Staff: lanes, not rules, and one declared engine gap" +domain: infotech +repo: ops-warden +status: accepted +version: "1.0" +revision: "1" +owner: ops-warden +binds: "ops-warden" +created: "2026-08-28" +updated: "2026-08-28" +last_reviewed: "2026-08-28" +review_interval: 3m +enforced_by: "INTENT.md layer declaration; docs/adr/ADR-0002; docs/adr/ADR-0003; docs/adr/ADR-0005; registry/routing/catalog.yaml delegation fields" +supersedes: "" +successor: "" +--- + +# ADR-0010 — ops-warden is Staff: lanes, not rules, and one declared engine gap + +## Status + +Accepted 2026-08-28, answering intake `WARDEN-IN-0001` from gate-house, which +carries decision `GH-DEC-2026-001`. The standard being adopted — +`net-kingdom/canon/standards/security-layer-model_v0.1.md` — is `proposed`, and was +proposed pending assent from flex-auth, kings-guard, and ops-warden. This ADR is +ops-warden's half of that assent. + +## Context + +The estate acquired overlapping claims to the same responsibility, most visibly two +repositories describing themselves as the authorization control plane. The layer +model resolves the overlap by layering repositories on determinism — Taxonomy, +Tooling, Engines, Staff — and by two rules: Staff never touches Tooling directly +(§5), and `access-engine` is the only policy decision point (§6). + +ops-warden is assigned Staff. Two demarcations follow that touch this repository: +the security curriculum it had been carrying belongs to gate-house, and the words +*access lane* and *access rule* are bound to different owners. + +Full reasoning: `history/2026-08-28-security-layer-model-assent.md`. + +## Decision + +**1. ops-warden is Staff and declares it.** `INTENT.md` carries the layer label and +the §5 invariant. ops-warden holds no state another layer depends on at runtime and +renders no authorization decision — it consumes them. + +**2. Lanes, not rules.** ops-warden owns *how* a worker reaches a host: SSH +certificate issuance, the routing catalog, `warden access`, `warden plan`, +`cert_command`. It never owns *whether* a worker may — that is `access-engine` +(today `flex-auth`), and ops-warden neither renders nor caches that decision. This +restates what `ADR-0002` and `ADR-0005` already bind; it is recorded here because +the demarcation is now normative estate-wide and other repositories rely on +ops-warden holding to it. The ruled rename `flex-auth` → `access-engine` is assented +to; ops-warden asks only for a window in which both names resolve. + +**3. Doctrine goes to gate-house; runbooks stay here.** ops-warden does not restate +security doctrine, the authority model, or the curriculum. It references +gate-house's. It keeps everything operational about the lanes it stewards: which +subsystem owns which need, how to obtain a credential lane by lane, and conformance +evidence for its own lanes. `.claude/rules/credential-routing.md` is runbook, not +curriculum, and stays inlined in this and every other repository. + +**4. One declared engine gap, not an exemption.** `src/warden/vault.py` (`VaultCA`) +is a direct OpenBao client performing a write from a Staff repository. It is a §5 +non-conformance. ops-warden declares it rather than arguing it away: + +- **intended owner:** `secrets-engine` (credential abstraction, custody, lifecycle) +- **blocked on:** no engine exposes an SSH certificate signing surface +- **review:** with this ADR, every 3 months + +Until that surface exists, ops-warden continues to sign — refusing to would remove +production host access to close a documentation gap — and reports the position as +open. `warden desk`'s `bao kv put` is declared on the same terms. `taint.py` is +metadata-only observation, declared under §5's read-only allowance. `proxy.py` +supplies no authority of its own: it runs the owner's tool under the caller's +identity and is governed by `ADR-0002`. + +This is `ADR-0003` turned inward. ops-warden has required an intended owner and a +blocker on 27 catalog lanes it holds for other repositories; it holds itself to the +same record. + +## Consequences + +ops-warden's conformance under §10 is *declared non-conformant with a tracked +closure path*, not clean. That is the accurate state and it is the state that gets +fixed, because it names an owner who can fix it. + +An amendment to §5 has been offered to gate-house — a second sanctioned shape +alongside read-only diagnostics: a declared engine gap carrying intended owner, +blocker, and review date, machine-readable so §10 can tell a tracked gap from an +undeclared violation. It is offered, not assumed; §5 stays gate-house's to write. If +gate-house declines it, ops-warden's position is a plain non-conformance and is +reported as one. + +The `NetKingdom Security Literacy` section stops being a prose second source for +`registry/routing/catalog.yaml`, which `ADR-0001` had already ruled against for +catalog procedure. + +## Related + +- `net-kingdom/canon/standards/security-layer-model_v0.1.md` (proposed, gate-house) +- `gate-house/decisions/decisions.md` — `GH-DEC-2026-001` +- `history/2026-08-28-security-layer-model-assent.md` +- `ADR-0001`, `ADR-0002`, `ADR-0003`, `ADR-0005`, `ADR-0009` +- `WARDEN-IN-0001` diff --git a/docs/adr/README.md b/docs/adr/README.md index 9de6ae1..8678e25 100644 --- a/docs/adr/README.md +++ b/docs/adr/README.md @@ -71,3 +71,4 @@ and the publication is a defect. | `ADR-0007` | Build-stage permissiveness stops at credential disclosure | ops-warden | | `ADR-0008` | A lane's risk grade covers every field its path discloses | ops-warden | | `ADR-0009` | Adopt security-zones v0.1; compile explicit membership and select PEP failure mode per zone | ops-warden | +| `ADR-0010` | ops-warden is Staff: it owns access lanes, never access rules; the direct OpenBao client is a declared engine gap | ops-warden, and gate-house as the standard's owner | diff --git a/history/2026-08-28-security-layer-model-assent.md b/history/2026-08-28-security-layer-model-assent.md new file mode 100644 index 0000000..286b855 --- /dev/null +++ b/history/2026-08-28-security-layer-model-assent.md @@ -0,0 +1,171 @@ +# Security layer model — ops-warden's assent (WARDEN-IN-0001) + +**Date:** 2026-08-28 +**Intake:** `WARDEN-IN-0001` +**Requested by:** gate-house, ratified as `GH-DEC-2026-001` +**Standard:** `net-kingdom/canon/standards/security-layer-model_v0.1.md` (proposed) +**Outcome:** assent to all three items; one declared non-conformance and one +proposed amendment to the standard. + +--- + +## What was asked + +gate-house asked ops-warden to assent to three boundary items: + +1. **ops-warden is Staff**, bound by §5 — Staff acts only through Engine APIs and + never holds a direct Tooling client. +2. **Doctrine versus runbook** — the security curriculum moves to gate-house; the + `NetKingdom Security Literacy` section in `INTENT.md` becomes lane-specific + runbooks that reference gate-house doctrine rather than restating it. +3. **The access lane / access rule demarcation** (§8) — ops-warden and ops-mason own + *lanes* (how a worker reaches a host); access-engine owns *rules* (whether they + may). This is the condition attached to renaming flex-auth to access-engine, so + ops-warden effectively holds a veto on that name. + +Plus: add gate-house to the literacy and routing tables, and say so if moving the +curriculum out leaves ops-warden unable to instruct its own workers. + +--- + +## Item 1 — Staff, and the §5 problem it exposes + +**Assent to the layer.** Staff is the right assignment and not a demotion. +ops-warden's artifacts are exactly what §3.4 describes: routing decisions, +workplans, runbooks, an audit trail. Its one production lane is non-deterministic +in the sense that matters — it is an operator front door, not a contract. + +**But §5 is violated today, and by the one lane ops-warden permanently owns.** +The rule is deliberately greppable, so grepping is the honest response: + +| Path | Tooling contact | Kind | Whose credential | +| --- | --- | --- | --- | +| `src/warden/vault.py` (`VaultCA.sign`) | `POST /v1//sign/` | **write** | broker-issued token held by ops-warden's process | +| `src/warden/desk.py` | `bao kv put` (paste-once provisioning) | **write** | founder's, at the desk | +| `src/warden/taint.py` | `bao kv metadata get` | read (metadata only, never data) | caller's | +| `src/warden/proxy.py` (`warden access --fetch/--exec/--wrap`) | catalog `fetch_command` | read | **the caller's own** | + +Two of these are not really ops-warden's clients. `proxy.py` runs the owner's tool +under the caller's identity and supplies no authority of its own — that is +`ADR-0002`, conduit not broker, and it is arguably outside §5's target. `taint.py` +reads metadata only, and fits §5's read-only-observation allowance once declared. + +**`VaultCA` does not have that defence.** It is a direct OpenBao client, in a Staff +repository, performing a write, presenting a token from its own environment. It is +production-verified and it is the SSH lane — the single thing ops-warden owns +permanently. Under §5 as written, adopting this standard puts ops-warden's core +lane in violation on the day it is adopted. + +The escape hatch §5 offers does not fit: it covers *read-only observation for +diagnostics*, and signing is a write. The route §5 prescribes does fit — + +> *A Staff repository needing a capability no engine exposes MUST raise that as an +> engine gap, not solve it locally.* + +— and no engine exposes SSH certificate signing. `secrets-engine` owns credential +abstraction, custody and lifecycle, which is the layer this belongs in, but it +fronts no SSH-CA API today. + +**So ops-warden assents and declares the non-conformance rather than negotiating an +exemption.** `VaultCA` is recorded in `INTENT.md` as a declared §5 exception with a +named intended owner (`secrets-engine`), a blocker (no SSH-CA engine surface), and a +review date. That is `ADR-0003` — cover gaps, never silently own them — applied to +ops-warden itself instead of to someone else's lane. + +### Proposed amendment to the standard + +§5 has exactly one shape for a Staff repository that legitimately touches Tooling: +read-only diagnostics. That shape is too narrow to describe the estate as it exists, +and a rule with no lane for a real, sanctioned case gets satisfied by relabelling +rather than by closing the gap. + +Recommend §5 gain a second shape: a **declared engine gap** — a Staff repository MAY +hold a Tooling client for a capability no engine exposes, provided it is declared in +`INTENT.md` with an intended owner, the blocker, and a review date, and provided the +declaration is machine-readable so the conformance check in §10 can distinguish a +tracked gap from an undeclared violation. + +ops-warden already runs this machinery for other repositories' lanes: 27 catalog +entries carry `delegation:` with `intended_owner` and `blocked_on`, and +`warden route gaps` lists them (WP-0030). It is offered, not imposed — the standard +is gate-house's. + +--- + +## Item 2 — Doctrine versus runbook + +**Assent.** The `NetKingdom Security Literacy` section is what gate-house says it is: +evidence that the curriculum had no owner, so it accreted in whatever `INTENT.md` +was open. That is the same failure `risk-nexus` names for findings and the same one +`ADR-0001` prevents for catalog procedure. ops-warden has argued this rule twice +against other repositories; it applies here. + +The boundary, drawn precisely: + +| Moves to gate-house | Stays with ops-warden | +| --- | --- | +| Why the planes are separated; the authority model | Which subsystem owns which credential need | +| What "posture", "zone", "authority ceiling" mean | How to obtain a cert, a lease, a login — per lane | +| The security curriculum a worker is taught | The runbook a worker executes | +| Doctrine a lane must conform to | Evidence of conformance for ops-warden's lanes | + +**gate-house's test question, answered: no, it does not leave ops-warden unable to +instruct its workers — and the reason is worth recording.** What actually instructs +an ops-warden worker is not the prose in `INTENT.md`. It is `warden plan ""`, +`warden route find`, and `.claude/rules/credential-routing.md`, which is inlined into +every repository's agent instructions precisely because credential routing is +high-frequency and high-risk. That surface is executable, lane-specific, and +unambiguously runbook. It does not depend on the literacy table, and moving doctrine +out does not weaken it. + +If anything the move improves it: the literacy table has been a second, prose copy of +what `registry/routing/catalog.yaml` states machine-readably, which is the +double-source failure `ADR-0001` exists to stop. + +**One thing must not move with it.** `.claude/rules/credential-routing.md` stays +inline in this repository and in every other. It is not doctrine and not a +curriculum; it is the anti-pattern list an agent needs *before* it acts, and a +reference to a document in another repository would not be read in time. + +--- + +## Item 3 — Access lane versus access rule + +**Assent, unconditionally, and the veto on `access-engine` is not exercised.** + +ops-warden is already built this way. `ADR-0005` implements one lane narrowly and +routes everything else; `ADR-0002` makes it a conduit that never decides; `ADR-0009` +has ops-warden compile membership attributes and apply a zone's failure mode while +flex-auth owns the stance. ops-warden consumes decisions; it has never rendered one. +The demarcation costs nothing because it describes what is already true. + +`access-engine` is also the better name. ops-warden's own routing table has had to +say "authorization" for the decision and "access" for the route for a year, and the +collision is visible in every playbook. + +**One operational condition, on execution rather than on the ruling.** The rename is +598 references across 82 files in this repository alone — catalog `owner:` fields, +`registry/flex-auth/`, `src/warden/policy.py`, the production registry snapshot +builder, playbooks, and the `.claude/rules/` files that other repositories inline. +Ops-warden asks for a deprecation window in which both names resolve, rather than a +flag day; ops-warden will do its own migration inside that window. This is a request +about sequencing, not a reservation about the name. + +--- + +## Item 4 — gate-house is missing from every table + +Correct, and fixed in this pass. gate-house is added to the literacy/routing table +in `INTENT.md` as the owner of doctrine, invariants, authority context, and +conformance review — with the routing rule stated explicitly: **doctrine and +authority-model questions go to gate-house; policy decisions continue to go to +access-engine.** Those are different questions and the distinction is the whole +point of §6. + +--- + +## Recorded as + +- `ADR-0010` — ops-warden is Staff; lanes not rules; the declared §5 exception +- `INTENT.md` — layer declaration, reworked routing table, gate-house row +- `WARDEN-IN-0001` — closed, outcome `assented` diff --git a/intakes/intakes.md b/intakes/intakes.md index a7f4472..2535d91 100644 --- a/intakes/intakes.md +++ b/intakes/intakes.md @@ -7,7 +7,8 @@ id: WARDEN-IN-0001 kind: intake title: 'Assent requested: Staff layer, doctrine vs runbook, and the access lane/rule demarcation' -status: open +status: closed +outcome: assented origin: cross-repo origin_ref: gate-house GH-DEC-2026-001 priority: medium @@ -30,6 +31,24 @@ description: 'gate-house asks ops-warden to assent to three boundary items. (1) — routing doctrine and authority-model questions there while continuing to route policy decisions to access-engine. If moving the curriculum out leaves ops-warden unable to instruct its own workers, say so; the boundary is wrong if it does.' +notes: 'Assented to all three items in ADR-0010, with reasoning in + history/2026-08-28-security-layer-model-assent.md. (1) Staff accepted; the section 5 + binding rule exposed a real non-conformance — src/warden/vault.py is a direct + OpenBao client performing a write, as is warden desk''s bao kv put. Declared in + INTENT.md as an engine gap with intended owner secrets-engine and blocker "no engine + exposes an SSH-CA surface", not negotiated as an exemption; taint.py declared under + the read-only allowance; warden access proxies run under the caller''s identity. + An amendment is offered back to gate-house: a second sanctioned shape in section 5 for + a declared engine gap carrying intended owner, blocker and review date, machine-readable + so section 10 can tell a tracked gap from an undeclared violation. (2) Doctrine versus + runbook accepted; the literacy section is now a lane routing runbook referencing + gate-house doctrine. Answering gate-house''s test question: it does not leave ops-warden + unable to instruct its workers, because what instructs them is warden plan / warden route + and .claude/rules/credential-routing.md, which stays inline by design. (3) The lane/rule + demarcation assented unconditionally and the access-engine veto not exercised — ops-warden + already consumes decisions and renders none. One request on sequencing only: a deprecation + window in which both names resolve (598 references across 82 files here). gate-house added + to the routing tables in INTENT.md and SCOPE.md.' created: '2026-08-28T19:30:28.087109Z' -updated: '2026-08-28T19:30:28.087109Z' +updated: '2026-08-28T21:05:00Z' ```