docs: record live zone config migration
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a0291a-1e87-7151-9934-fcbfe3f65eb1
This commit is contained in:
parent
bebcdf929c
commit
e24d2d5bd0
3 changed files with 11 additions and 15 deletions
|
|
@ -166,17 +166,10 @@ explicit `unknown` profile and its configured failure mode.
|
|||
stance over every v0.1 zone plus `unknown`, preserves native enforcement for
|
||||
`not-applicable`, and returns `audit_only` for advisory decisions. The required
|
||||
live caller check passed through the existing tunnel with command-mode caller
|
||||
identity and decision `decision:f3f7c88f9585582a`; the check used a temporary
|
||||
migrated copy because the operator's persistent config still carries the two
|
||||
retired keys. Full repo tests pass and sign/audit evidence records zone,
|
||||
failure mode, outcome, and decision id.
|
||||
|
||||
The required readiness recheck was run on 2026-08-22 after `warden plan`
|
||||
returned `autonomous`. It correctly returned **NOT READY** before obtaining or
|
||||
printing any token because the active operator `warden.yaml` still contains
|
||||
the two retired global keys. Operator configuration migration is therefore an
|
||||
explicit remaining acceptance step, followed by the value-safe live
|
||||
`/v1/check` smoke. Do not ask flex-auth to enforce caller authentication yet.
|
||||
identity and decision `decision:f3f7c88f9585582a`. The operator config was then
|
||||
migrated from the two rejected global keys to `zone_registry_path`, and the
|
||||
same live check passed against that real config. Full repo tests pass and
|
||||
sign/audit evidence records zone, failure mode, outcome, and decision id.
|
||||
|
||||
```task
|
||||
id: WARDEN-WP-0032-T03
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue