--- id: WARDEN-WP-0035 type: workplan title: "Register the Policy Nexus Forgejo source-read route" domain: infotech repo: ops-warden status: finished owner: codex topic_slug: policy-nexus-forgejo-source-read created: "2026-09-01" updated: "2026-09-01" state_hub_workstream_id: "45aec8d3-94b3-586e-b019-a47e656efafa" --- ## Register the exact high-risk lane ```task id: WARDEN-WP-0035-T01 status: done priority: high state_hub_task_id: "dd84f2be-0143-540c-9c16-74f0fd129260" ``` Add the exact OpenBao path, field, OIDC role, owner pointer, and rotation boundary from railiance-platform CCR-2026-0014. The entry must be concrete and resolvable while remaining subject to Warden's high-risk agent read boundary. ## Verify routing and governed use ```task id: WARDEN-WP-0035-T02 status: done priority: high state_hub_task_id: "1fa8f778-3e46-5f44-86c4-cab8628b7e60" ``` Pass catalog, route-selection, proxy, and policy tests; reinstall the CLI; prove the installed route resolves and can hand the value only to a sanctioned child transport without printing or persisting it. Completed 2026-09-01. All 406 selected tests passed, including the generated high-risk data-path boundary. The no-cache installed CLI resolves the exact lane, and `warden plan` returns only sanctioned `--exec`, `--out`, and `--wrap` transports for an agent caller. Policy Nexus Actions run 32 separately proved the installed credential against the complete private-source fetch and release path without exposing the value.