Commit graph

275 commits

Author SHA1 Message Date
0cec8eef76 WARDEN-WP-0027: backlog with cancelled deferred tasks
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
C-23 forces active when tasks are wait/progress; C-15 preferred wait over
todo. Park Strand B as backlog and cancel T01–T03 until an activation gate
fires (then re-open as todo).
2026-07-17 00:45:51 +02:00
custodian-sync
54fd31aa5c chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-07-17:
  - WARDEN-WP-0027-T03: todo → wait
2026-07-17 00:45:35 +02:00
custodian-sync
6fe5034a65 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-17:
  - WARDEN-WP-0027-T02: todo → wait
2026-07-17 00:45:35 +02:00
custodian-sync
ffff2eff4f chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-17:
  - WARDEN-WP-0027-T01: todo → wait
2026-07-17 00:45:35 +02:00
custodian-sync
885e362daa chore(consistency): renormalize lifecycle state [auto]
Updated by fix-consistency on 2026-07-17:
  - workplan status: backlog → active
2026-07-17 00:45:35 +02:00
25a691d49a WARDEN-WP-0027: park Strand B as backlog (C-23-safe)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Set workplan status backlog and tasks todo (not wait) so fix-consistency
does not re-promote to active. Activate only when a gate fires.
2026-07-17 00:45:03 +02:00
custodian-sync
0433481e94 chore(consistency): renormalize lifecycle state [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-07-17:
  - workplan status: backlog → active
2026-07-17 00:44:16 +02:00
6bfbf64108 WARDEN-WP-0027: move Strand B to backlog
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
No activation gate met after WP-0026/0028 closeout. Keep capture only;
promote to ready only when mass-rotate or policy-reconcile is justified.
2026-07-17 00:43:42 +02:00
custodian-sync
59f0277f20 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-07-17:
  - update .custodian-brief.md for ops-warden
2026-07-17 00:34:39 +02:00
c5ec9bdaa6 WARDEN-WP-0028: mark workplan finished after T05
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 8s
2026-07-17 00:34:00 +02:00
custodian-sync
b6861e4b62 chore(consistency): sync task status from DB [auto]
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Has been cancelled
Updated by fix-consistency on 2026-07-17:
  - update .custodian-brief.md for ops-warden
2026-07-17 00:33:55 +02:00
053a1d7cee WARDEN-WP-0028: promote binky-company-email-imap active
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Founder provisioned IMAP on tenants/ (KV v2); capabilities-safe verify
pass. Catalog resolvable; workplan finished.
2026-07-17 00:33:20 +02:00
6b5432229f playbook: IONOS IMAP endpoints for binky-company-email-imap
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Document non-secret provider host/port from founder; point at binky-control
mailbox config. Password custody unchanged (OpenBao tenants/).
2026-07-17 00:15:27 +02:00
custodian-sync
80ce5eb2df chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-07-17:
  - update .custodian-brief.md for ops-warden
2026-07-17 00:10:25 +02:00
98a2339b81 WARDEN-WP-0028: tenant secrets on mount tenants/ (first lane draft)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Adopt tenants/<tenant>/… custody (not platform/workloads). Document
onboarding, add draft binky-company-email-imap catalog entry, and mark
T01–T04/T06–T07 done. Founder Red provision remains T05.
2026-07-17 00:09:28 +02:00
b971403dad WARDEN-WP-0026 finish Strand A (T04/T05/T07)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Promote railiance-backup-offsite-lane to active/resolvable after
capabilities-safe re-verify. Add catalog risk=high, agent read-boundary
(exit 7 + OpenBao policy companion), EXPOSED taint via warden taint, and
close WP-0026.
2026-07-16 23:26:26 +02:00
custodian-sync
7d0c7c7684 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-07-16:
  - update .custodian-brief.md for ops-warden
2026-07-16 23:22:05 +02:00
custodian-sync
0eb2126311 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 0s
Updated by fix-consistency on 2026-07-16:
  - update .custodian-brief.md for ops-warden
2026-07-16 14:55:24 +02:00
fc0f18aa5c WARDEN-WP-0026 T03: masking display filter (defense-in-depth)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
- warden/mask.py: fingerprint()/mask_value() — presence, length, 8-char sha256
  prefix; never the value.
- proxy.proxy_fetch_fingerprint + `warden access --fingerprint`: masked status view
  (presence/length/hash) that emits no value, so it bypasses the T02 stdout guard.
  Lets two parties compare sha256 prefixes to confirm a shared value without seeing
  it (e.g. rotation landed).
- documented as defense-in-depth (raw bao bypasses it) in OperatorAccessAssist.md
  and the module docstring.
- tests: tests/test_mask.py + CLI fingerprint test. 299 pass.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 14:54:55 +02:00
custodian-sync
04c8b2ab1d chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 0s
Updated by fix-consistency on 2026-07-16:
  - update .custodian-brief.md for ops-warden
2026-07-16 14:52:28 +02:00
359ca1bd0e WARDEN-WP-0026 T02: safe access transports (no secret values on stdout)
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
- proxy.py: proxy_fetch_to_file (mode-0600 file), build_wrapped_fetch +
  proxy_fetch_wrapped (single-use OpenBao response-wrapping token), _capture_value
  helper, is_bao_kv_fetch.
- warden access: --out FILE, --wrap [--wrap-ttl], --unsafe-stdout. Raw --fetch to a
  non-TTY stdout is refused (exit 6) — captured/piped output is the disclosure risk;
  sanctioned transports are --out / --exec / --wrap.
- canon: anti-pattern (secret value onto captured stdout) + transport table in
  .claude/rules/credential-routing.md; OperatorAccessAssist.md examples + G2 updated.
- tests: file/wrap/build + stdout-guard in tests/test_proxy.py. 293 pass.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 14:51:56 +02:00
custodian-sync
c749561b75 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-07-16:
  - update .custodian-brief.md for ops-warden
2026-07-16 14:41:02 +02:00
c3eb59ea04 WARDEN-WP-0026 T06: rotation guidance registry + warden rotate-guide
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
- routing model: RotationGuide (method rotate|re-establish, steps, owner,
  automatable), RouteEntry.rotation + has_rotation + vends_secret.
- catalog parser: validate rotation block; secret-material screen gains a
  prose-safe mode (high-entropy detector only) so authored steps aren't tripped
  by substrings like "s."/"exists.".
- CLI: `warden rotate-guide <id>` (human + --json); route show --json now
  carries has_rotation + rotation.
- scorecard: catalog_rotation_coverage — every active secret-vending lane must
  carry a rotation block (SSH/login/pointer lanes exempt). Promotion checklist
  criterion 9.
- data: rotation blocks for all 7 active vending lanes + the draft
  railiance-backup lane (re-establish: age keypair regen + re-encrypt).
- fix pre-existing collision: bare `npm` keyword on forgejo-admin -> forgejo-npm
  so "npm token" routes to the generic lane (restores test_access expectations).
- tests: rotation parse/coverage/prose-screen/CLI in tests/test_routing.py;
  scorecard count 6 -> 7.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 14:40:30 +02:00
custodian-sync
ac09f21ad3 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-07-16:
  - update .custodian-brief.md for ops-warden
2026-07-16 14:26:39 +02:00
custodian-sync
fb4251bab6 chore(consistency): renormalize lifecycle state [auto]
Updated by fix-consistency on 2026-07-16:
  - workplan status: backlog → active
2026-07-16 14:26:36 +02:00
custodian-sync
03ffa27b08 chore(consistency): renormalize lifecycle state [auto]
Updated by fix-consistency on 2026-07-16:
  - workplan status: ready → active
2026-07-16 14:26:35 +02:00
ea98d6bf39 WARDEN-WP-0026 T01: capabilities-safe lane verification + incident note
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
T01 (done): canonical capabilities-based verify pattern in the fleet promotion
checklist (catalog-lane-promotion.md) and applied to the railiance-backup and
forgejo-admin lane playbooks. Verification proves allow/deny via
`bao token capabilities` against the KV v2 data path, never `bao kv get`; a denied
default-policy token-create is a pass, not a privileged-fallback trigger.

T07 (progress): lessons-learned note for the 2026-07-16 CCR-2026-0004 disclosure
(three root causes). Live re-verify + rotation block remain (depend on T06).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 14:26:05 +02:00
2ad8a53781 Add WARDEN-WP-0027: Strand B credential governance/lockdown (backlog)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 28s
Captures the heavyweight governance work deliberately deferred from WP-0026
(Strand A): executable mass rotation, graded lockdown/break-glass with a
designed trust-root, and tamper-evident policy governance + reconcile.
Status backlog with an explicit activation gate — captured, not scheduled;
implemented only when the gate is met and promoted to ready.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 14:22:38 +02:00
167e29de99 chore(consistency): write state-hub IDs into WARDEN-WP-0026 [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 16s
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 01:43:19 +02:00
custodian-sync
5615b94649 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-16:
  - update .custodian-brief.md for ops-warden
2026-07-16 01:42:29 +02:00
7e0789ab0d WARDEN-WP-0026: credential disclosure hygiene + rotation guidance (Strand A)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Follow-up to the 2026-07-16 CCR-2026-0004 verify disclosure incident. Strand A:
capabilities-based verification, safe access transport, masking (defense-in-depth),
agent read-boundary, EXPOSED taint convention, and a structured-but-advisory
rotation/re-establishment guidance registry surfaced via warden. Strand B deferred.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 01:41:39 +02:00
custodian-sync
a8adb9c2c5 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-07-13:
  - update .custodian-brief.md for ops-warden
2026-07-13 01:52:13 +02:00
19cd215d0b WARDEN-WP-0025 complete: T05 downstream notify sent, workplan finished
Some checks failed
CI Smoke / host-smoke (push) Successful in 4s
CI Smoke / container-smoke (push) Has been cancelled
Notified the-custodian (949e8ed1) + railiance-platform (5be8e500) /
activity-core (9ed1af98) / railiance-apps (2e47b6e5) that the
forgejo-admin-api-token OpenBao lane is active. No secret values shared.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-13 01:49:44 +02:00
custodian-sync
ce469c93b3 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-07-13:
  - update .custodian-brief.md for ops-warden
2026-07-13 01:48:42 +02:00
171efa83fe Promote forgejo-admin-api-token lane to active (WARDEN-WP-0025 T04)
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Has been cancelled
PAT attended-minted and stored at platform/workloads/forgejo/forgejo-admin
under field API_TOKEN (re-stored from initial Token field to match
CCR/catalog/playbook fetch_command). Positive fetch verified: PAT valid
against forgejo.coulomb.social (/api/v1/user -> login=tegwick, is_admin=true).

- catalog: draft -> active, resolvable: true, verification evidence, reviewed 2026-07-13
- playbook: header active/resolvable, drop post-promotion caveat
- workplan: T04 done

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-13 01:47:52 +02:00
custodian-sync
a5f1d2aad7 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-07-12:
  - update .custodian-brief.md for ops-warden
2026-07-12 16:41:59 +02:00
ddeac8bf9c Update WARDEN-WP-0025 after CCR-2026-0006 metadata apply
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Mark T03 done, T04 in progress; document forgejo-admin-pat-provision.sh
in the worker playbook.
2026-07-12 16:07:32 +02:00
custodian-sync
caaa40ce7e chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-07-12:
  - update .custodian-brief.md for ops-warden
2026-07-12 16:02:42 +02:00
fd231fac0d Add forgejo-admin-api-token catalog lane (CCR-2026-0006)
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 18s
Draft routing entry and worker playbook for Forgejo site-admin PAT custody
in OpenBao. Workplan WARDEN-WP-0025 tracks approval, apply, and verification.
2026-07-12 16:01:53 +02:00
48b21ab85c CUST-WP-0055 T07: add archive workplan terminology grandfather note
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 8s
2026-07-08 20:26:36 +02:00
8f3ce50e7b docs: workplan-first agent guidance prose (CUST-WP-0055 T04 batch 2)
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
2026-07-08 16:41:15 +02:00
07b564309e Regenerate agent instructions from state-hub templates (CUST-WP-0055 T01)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Sync AGENTS.md, CLAUDE.md, and .claude/rules from updated project_rules
templates: workplan-first session protocol, legacy terminology footnote,
and GET /workplans/ examples.
2026-07-08 14:50:32 +02:00
7906a731fc Adhoc finished
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-08 14:47:36 +02:00
7fbfae0fe1 Add Forgejo CI smoke workflow (enablement template)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
2026-07-08 12:35:30 +02:00
4b0f771cbd Link reuse-surface playbook to rotation runbook (T04)
Point lifecycle and rotation procedures at railiance-platform docs for
CCR-2026-0005.
2026-07-08 00:01:22 +02:00
1e6c4eedf1 Migrate reuse-surface hub token lane to OpenBao handoff
RAILIANCE-WP-0011-T03: point reuse-surface-hub-write-token catalog,
playbook, and tests at bao kv get on platform/workloads/reuse/reuse-surface/runtime-secrets;
kubectl documented as break-glass only.
2026-07-07 22:38:45 +02:00
3ddccaf701 Document reuse-surface webhook secret in hub token playbook
Note the sibling REUSE_SURFACE_FORGEJO_WEBHOOK_SECRET key, Forgejo webhook
rollout command, and the RAILIANCE-WP-0011 OpenBao migration backlog item.
2026-07-07 21:28:46 +02:00
d12fdb6112 Add draft catalog lane for railiance backup offsite credentials.
Points at CCR-2026-0004 OpenBao path; playbook documents bao login and
fetch shapes for railiance-backup and forgejo-backup tooling.
2026-07-07 17:16:30 +02:00
07c5cf18ea Release v0.1.2.
Bump version; sync uv.lock; README upgrade examples point at v0.1.2.
2026-07-07 16:59:22 +02:00
4976002f9c Document Forgejo clone, install, and upgrade steps in README.
Canonical source is forgejo.coulomb.social; includes SSH remote config,
make install-all, release upgrade path, and stale-wheel recovery.
2026-07-07 16:57:39 +02:00