# WARDEN-WP-0027-T02 attended drill preparation checklist Status: `preparing` — `authorizes_execution: false`. ## Immutable scenario basis - Scenario: `WARDEN-WP-0027-T02-DRILL-20260822-01` - Scenario artifact: `docs/evidence/WARDEN-WP-0027-T02-drill-scenario-2026-08-22.md` - Scenario SHA-256: `ffa69764ad391db633f57ac70444e5781eee698bf9e362dfef31614fa43152dc` - Preparation approval decision: `9da57559-712a-4521-b46e-a4c69729f9d2` - Preparation approved at: `2026-08-22T21:43:11Z` - Scenario expires: `2026-08-23T20:00:00Z` - Maximum live duration after a later exact GO: 45 minutes The scenario artifact is intentionally unchanged after railiance-infra approved its pinned digest. This checklist records later preparation evidence without invalidating that receipt. ## Exact prepared live scope The only prepared live sequence is one intentional OpenBao seal followed by the existing attended 2-of-3 Shamir unseal ceremony and value-safe post-unseal verification. Preparation and owner receipts authorize no live action. The scope excludes a host reboot, re-key, snapshot restore, policy change, PVC mutation, credential disclosure, general workload restart, and every action not named above. ## Owner review gates | Gate | Contract | State | | --- | --- | --- | | Independent provider console and distinct abort authority | `WARDEN-WP-0027-T02-DRILL-20260822-01-INFRA` | satisfied; receipt `01a02b4b-7295-7836-b288-f29407008524` | | Fresh encrypted, verified, off-host Raft snapshot and platform driver acceptance | `WARDEN-WP-0027-T02-DRILL-20260822-01-PLATFORM` | pending | | Two distinct custodians available for the current 2-of-3 barrier | `WARDEN-WP-0027-T02-DRILL-20260822-01-QUORUM` | pending | Every receipt is metadata-only. No receipt may include a provider credential, OpenBao token, unseal share, recovery value, decrypted snapshot, custody location, custodian identity, or value-derived fingerprint. ## Final read-only preflight After both pending contracts are satisfied, ops-warden runs the platform-owned `scripts/audit-core-recovery-preflight.py node-reboot` interface with: - approved window id `WARDEN-WP-0027-T02-DRILL-20260822-01`; - the platform owner's current snapshot evidence file; - the railiance-master quorum attestation; - the accepted railiance-infra provider-console and abort role; - the existing RAILIANCE-WP-0024 procedure-owner acknowledgements. The interface name reflects its superset recovery checklist; it does not add a reboot to this scenario. Its result must report all of: - `preflight_only: true`; - `automated_checks_passed: true`; - `ready_for_live_execution: true`; - `secret_values_observed: false`. Any changed cluster identity, invalid/stale snapshot receipt, missing owner receipt, overlapping mutation, failed automated check, observed secret value, or expired scenario is a NO-GO. ## Final human hold point Only after the green preflight may ops-warden ask: `GO WARDEN-WP-0027-T02-DRILL-20260822-01?` No prior approval or conversational “go” crosses this hold point.