456fdc4b4f
Repair stale rapp-qonto-keycape-client wiki anchor
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
The catalog pointed at wiki/CredentialRouting.md#credential-routing-catalog,
which does not exist; the live heading is "Routing catalog index". Restores
tests/test_routing.py to 61/61.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 10:27:12 +02:00
a9086ad6b6
Route dynamic database credentials to rapp-postgres
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-10 19:37:05 +02:00
350f66472c
Note apps-pg live and coulomb-social DB connectivity in playbook
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Cluster healthy; role/database present; env Secret keys established.
2026-08-09 02:18:17 +02:00
d8d3d5b1a0
Route coulomb-social runtime env credentials via ops-warden catalog
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Add coulomb-social-runtime-env lane and playbook. Points operators at
railiance-apps env-secret assembly; ops-warden never holds values.
2026-08-09 02:11:34 +02:00
979c6f68b4
Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout)
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Maintainer decision, 2026-07-29: adopts TRSL V1C1 as this repo's
preliminary governing license, per target-revenue's
workplans/TREV-WP-0008-governance-and-pilot-rollout.md T05. Full
specialist legal review is deferred until out of beta (target-revenue
SCOPE.md §1). No Phase is yet declared for this repo.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-30 00:42:48 +02:00
2e862bbff0
Route rapp-qonto workload identity
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-27 20:37:09 +02:00
d961da1ef2
Promote rein-openweights-openrouter-approle: draft -> active
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Founder completed paste-once-provision; glas-harness/GLAS-WP-0002-T02's
live verification succeeded for real (AppRole login, KV v2 read, real
OpenRouter call, real commit, OPENROUTER_API_KEY unset throughout).
Two real fixes recorded along the way: platform-admin's policy needed
a new reins/* entry (every other KV mount was already listed there),
and the consumer policy itself needed the KV v2 data/+metadata/ path
shape instead of the bare KV v1 path it was originally written against.
Full account in ops-mason/plans/rein-openweights-openrouter-approle.md
section 7.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 01:51:57 +02:00
c0a50bc1bf
Catalog: rein-openweights AppRole for non-interactive OpenRouter key read
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Proposed by ops-mason (MASON-WP-0001-T05), built and approved 2026-07-27
(Bernd Worsch). New pointer-only entry mirroring
agent-harness-binky-mail-approle's shape: AppRole login, no operator
present, scoped to exactly one KV path (reins/rein-openweights/openrouter,
new reins/ KV v2 mount -- no existing mount fit without widening scope
beyond what was approved). status: draft until the founder completes
paste-once-provision and glas-harness/GLAS-WP-0002-T02's live
verification succeeds.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 01:22:59 +02:00
cb6e9a73f4
catalog: promote binky-qonto-api to active (CCR-2026-0008)
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Point at live tenants/binky/qonto-api fields API_KEY/API_USER; playbook and
CredentialRouting index updated after first BINKY-WP-0005 read-only pull.
2026-07-21 21:42:10 +02:00
5d30220cc5
catalog: draft binky-qonto-api lane + playbook (CCR-2026-0008)
...
Tenant Qonto bank API front door for binky-control read-only MCP; stays
draft until policy apply, founder provision, and capabilities-safe verify.
2026-07-21 21:26:25 +02:00
custodian-sync
507bbef6ea
chore(consistency): sync task status from DB [auto]
...
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 20s
Updated by fix-consistency on 2026-07-18:
- update .custodian-brief.md for ops-warden
2026-07-18 17:00:26 +02:00
5149946a4c
WARDEN-WP-0029: implement plan front door, org posture, desk, freshness
...
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
Ship posture-aware access planning: organization_posture=build (axis C),
catalog freshness warnings, warden plan verdicts, localhost founder desk,
and playbook/agent guidance that retire /tmp file-drop patterns.
Compose route catalog + handoff rather than a second routing layer.
2026-07-18 16:59:37 +02:00
5c6b71b83b
WARDEN-WP-0029: optimize workplan sequence, constraints, reuse map
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Reorder for delivery (T02/T05 → T01 → T04 → T03), raise T05 priority for
catalog-staleness root cause, add compose/third-axis/desk non-goals, and
document reuse.coulomb.social building blocks.
2026-07-18 16:50:23 +02:00
cb762e06cb
WARDEN-WP-0029: hub workstream/task id write-back
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 16:40:16 +02:00
custodian-sync
7a08171dab
chore(consistency): sync task status from DB [auto]
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-07-18:
- update .custodian-brief.md for ops-warden
2026-07-18 14:26:51 +02:00
29645c9303
INTENT §7/§8 + WARDEN-WP-0029: policy front door, build-phase posture, founder surface
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Founder directive 2026-07-18: agents ask ops-warden what a credential
need requires; the founder is escalated to only for policy-required
decisions/identity acts, preferably via a local web interaction surface
— never tasked with raw mechanics (UI clicks, /tmp file drops).
Organization posture 'build' becomes declared configuration. Workplan:
warden plan front door, posture declaration, warden desk, file-drop
retirement, catalog freshness + agent guidance.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 14:26:15 +02:00
5219104809
feat(catalog): agent-harness forgejo deploy + binky mail AppRole lanes
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Register agent-harness-forgejo-deploy and agent-harness-binky-mail-approle
with playbook pointers; provisioned 2026-07-17 (metadata only).
2026-07-17 23:57:55 +02:00
custodian-sync
ffc3b22fb0
chore(consistency): sync task status from DB [auto]
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-07-17:
- update .custodian-brief.md for ops-warden
2026-07-17 00:46:37 +02:00
0cec8eef76
WARDEN-WP-0027: backlog with cancelled deferred tasks
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
C-23 forces active when tasks are wait/progress; C-15 preferred wait over
todo. Park Strand B as backlog and cancel T01–T03 until an activation gate
fires (then re-open as todo).
2026-07-17 00:45:51 +02:00
custodian-sync
54fd31aa5c
chore(consistency): sync task status from DB [auto]
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-07-17:
- WARDEN-WP-0027-T03: todo → wait
2026-07-17 00:45:35 +02:00
custodian-sync
6fe5034a65
chore(consistency): sync task status from DB [auto]
...
Updated by fix-consistency on 2026-07-17:
- WARDEN-WP-0027-T02: todo → wait
2026-07-17 00:45:35 +02:00
custodian-sync
ffff2eff4f
chore(consistency): sync task status from DB [auto]
...
Updated by fix-consistency on 2026-07-17:
- WARDEN-WP-0027-T01: todo → wait
2026-07-17 00:45:35 +02:00
custodian-sync
885e362daa
chore(consistency): renormalize lifecycle state [auto]
...
Updated by fix-consistency on 2026-07-17:
- workplan status: backlog → active
2026-07-17 00:45:35 +02:00
25a691d49a
WARDEN-WP-0027: park Strand B as backlog (C-23-safe)
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Set workplan status backlog and tasks todo (not wait) so fix-consistency
does not re-promote to active. Activate only when a gate fires.
2026-07-17 00:45:03 +02:00
custodian-sync
0433481e94
chore(consistency): renormalize lifecycle state [auto]
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-07-17:
- workplan status: backlog → active
2026-07-17 00:44:16 +02:00
6bfbf64108
WARDEN-WP-0027: move Strand B to backlog
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
No activation gate met after WP-0026/0028 closeout. Keep capture only;
promote to ready only when mass-rotate or policy-reconcile is justified.
2026-07-17 00:43:42 +02:00
custodian-sync
59f0277f20
chore(consistency): sync task status from DB [auto]
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-07-17:
- update .custodian-brief.md for ops-warden
2026-07-17 00:34:39 +02:00
c5ec9bdaa6
WARDEN-WP-0028: mark workplan finished after T05
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 8s
2026-07-17 00:34:00 +02:00
custodian-sync
b6861e4b62
chore(consistency): sync task status from DB [auto]
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Has been cancelled
Updated by fix-consistency on 2026-07-17:
- update .custodian-brief.md for ops-warden
2026-07-17 00:33:55 +02:00
053a1d7cee
WARDEN-WP-0028: promote binky-company-email-imap active
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Founder provisioned IMAP on tenants/ (KV v2); capabilities-safe verify
pass. Catalog resolvable; workplan finished.
2026-07-17 00:33:20 +02:00
6b5432229f
playbook: IONOS IMAP endpoints for binky-company-email-imap
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Document non-secret provider host/port from founder; point at binky-control
mailbox config. Password custody unchanged (OpenBao tenants/).
2026-07-17 00:15:27 +02:00
custodian-sync
80ce5eb2df
chore(consistency): sync task status from DB [auto]
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-07-17:
- update .custodian-brief.md for ops-warden
2026-07-17 00:10:25 +02:00
98a2339b81
WARDEN-WP-0028: tenant secrets on mount tenants/ (first lane draft)
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Adopt tenants/<tenant>/… custody (not platform/workloads). Document
onboarding, add draft binky-company-email-imap catalog entry, and mark
T01–T04/T06–T07 done. Founder Red provision remains T05.
2026-07-17 00:09:28 +02:00
b971403dad
WARDEN-WP-0026 finish Strand A (T04/T05/T07)
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Promote railiance-backup-offsite-lane to active/resolvable after
capabilities-safe re-verify. Add catalog risk=high, agent read-boundary
(exit 7 + OpenBao policy companion), EXPOSED taint via warden taint, and
close WP-0026.
2026-07-16 23:26:26 +02:00
custodian-sync
7d0c7c7684
chore(consistency): sync task status from DB [auto]
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-07-16:
- update .custodian-brief.md for ops-warden
2026-07-16 23:22:05 +02:00
custodian-sync
0eb2126311
chore(consistency): sync task status from DB [auto]
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 0s
Updated by fix-consistency on 2026-07-16:
- update .custodian-brief.md for ops-warden
2026-07-16 14:55:24 +02:00
fc0f18aa5c
WARDEN-WP-0026 T03: masking display filter (defense-in-depth)
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
- warden/mask.py: fingerprint()/mask_value() — presence, length, 8-char sha256
prefix; never the value.
- proxy.proxy_fetch_fingerprint + `warden access --fingerprint`: masked status view
(presence/length/hash) that emits no value, so it bypasses the T02 stdout guard.
Lets two parties compare sha256 prefixes to confirm a shared value without seeing
it (e.g. rotation landed).
- documented as defense-in-depth (raw bao bypasses it) in OperatorAccessAssist.md
and the module docstring.
- tests: tests/test_mask.py + CLI fingerprint test. 299 pass.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 14:54:55 +02:00
custodian-sync
04c8b2ab1d
chore(consistency): sync task status from DB [auto]
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 0s
Updated by fix-consistency on 2026-07-16:
- update .custodian-brief.md for ops-warden
2026-07-16 14:52:28 +02:00
359ca1bd0e
WARDEN-WP-0026 T02: safe access transports (no secret values on stdout)
...
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
- proxy.py: proxy_fetch_to_file (mode-0600 file), build_wrapped_fetch +
proxy_fetch_wrapped (single-use OpenBao response-wrapping token), _capture_value
helper, is_bao_kv_fetch.
- warden access: --out FILE, --wrap [--wrap-ttl], --unsafe-stdout. Raw --fetch to a
non-TTY stdout is refused (exit 6) — captured/piped output is the disclosure risk;
sanctioned transports are --out / --exec / --wrap.
- canon: anti-pattern (secret value onto captured stdout) + transport table in
.claude/rules/credential-routing.md; OperatorAccessAssist.md examples + G2 updated.
- tests: file/wrap/build + stdout-guard in tests/test_proxy.py. 293 pass.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 14:51:56 +02:00
custodian-sync
c749561b75
chore(consistency): sync task status from DB [auto]
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-07-16:
- update .custodian-brief.md for ops-warden
2026-07-16 14:41:02 +02:00
c3eb59ea04
WARDEN-WP-0026 T06: rotation guidance registry + warden rotate-guide
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
- routing model: RotationGuide (method rotate|re-establish, steps, owner,
automatable), RouteEntry.rotation + has_rotation + vends_secret.
- catalog parser: validate rotation block; secret-material screen gains a
prose-safe mode (high-entropy detector only) so authored steps aren't tripped
by substrings like "s."/"exists.".
- CLI: `warden rotate-guide <id>` (human + --json); route show --json now
carries has_rotation + rotation.
- scorecard: catalog_rotation_coverage — every active secret-vending lane must
carry a rotation block (SSH/login/pointer lanes exempt). Promotion checklist
criterion 9.
- data: rotation blocks for all 7 active vending lanes + the draft
railiance-backup lane (re-establish: age keypair regen + re-encrypt).
- fix pre-existing collision: bare `npm` keyword on forgejo-admin -> forgejo-npm
so "npm token" routes to the generic lane (restores test_access expectations).
- tests: rotation parse/coverage/prose-screen/CLI in tests/test_routing.py;
scorecard count 6 -> 7.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 14:40:30 +02:00
custodian-sync
ac09f21ad3
chore(consistency): sync task status from DB [auto]
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-07-16:
- update .custodian-brief.md for ops-warden
2026-07-16 14:26:39 +02:00
custodian-sync
fb4251bab6
chore(consistency): renormalize lifecycle state [auto]
...
Updated by fix-consistency on 2026-07-16:
- workplan status: backlog → active
2026-07-16 14:26:36 +02:00
custodian-sync
03ffa27b08
chore(consistency): renormalize lifecycle state [auto]
...
Updated by fix-consistency on 2026-07-16:
- workplan status: ready → active
2026-07-16 14:26:35 +02:00
ea98d6bf39
WARDEN-WP-0026 T01: capabilities-safe lane verification + incident note
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
T01 (done): canonical capabilities-based verify pattern in the fleet promotion
checklist (catalog-lane-promotion.md) and applied to the railiance-backup and
forgejo-admin lane playbooks. Verification proves allow/deny via
`bao token capabilities` against the KV v2 data path, never `bao kv get`; a denied
default-policy token-create is a pass, not a privileged-fallback trigger.
T07 (progress): lessons-learned note for the 2026-07-16 CCR-2026-0004 disclosure
(three root causes). Live re-verify + rotation block remain (depend on T06).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 14:26:05 +02:00
2ad8a53781
Add WARDEN-WP-0027: Strand B credential governance/lockdown (backlog)
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 28s
Captures the heavyweight governance work deliberately deferred from WP-0026
(Strand A): executable mass rotation, graded lockdown/break-glass with a
designed trust-root, and tamper-evident policy governance + reconcile.
Status backlog with an explicit activation gate — captured, not scheduled;
implemented only when the gate is met and promoted to ready.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 14:22:38 +02:00
167e29de99
chore(consistency): write state-hub IDs into WARDEN-WP-0026 [auto]
...
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 16s
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 01:43:19 +02:00
custodian-sync
5615b94649
chore(consistency): sync task status from DB [auto]
...
Updated by fix-consistency on 2026-07-16:
- update .custodian-brief.md for ops-warden
2026-07-16 01:42:29 +02:00
7e0789ab0d
WARDEN-WP-0026: credential disclosure hygiene + rotation guidance (Strand A)
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Follow-up to the 2026-07-16 CCR-2026-0004 verify disclosure incident. Strand A:
capabilities-based verification, safe access transport, masking (defense-in-depth),
agent read-boundary, EXPOSED taint convention, and a structured-but-advisory
rotation/re-establishment guidance registry surfaced via warden. Strand B deferred.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 01:41:39 +02:00
custodian-sync
a8adb9c2c5
chore(consistency): sync task status from DB [auto]
...
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-07-13:
- update .custodian-brief.md for ops-warden
2026-07-13 01:52:13 +02:00