Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2360 lines
86 KiB
JSON
2360 lines
86 KiB
JSON
{
|
|
"schema": "repo_manager.index.v1",
|
|
"slug": "ops-warden",
|
|
"repo_root": "/home/worsch/ops-warden",
|
|
"head_sha": "529feeac49a8cde94f68776fc45557c90e2a5a5a",
|
|
"observed_at": "2026-08-31T22:59:28.638497Z",
|
|
"source_fingerprint": "6f60b2dbcb864a3f8e45a97c247ab142a765487187e67edf52bdb57027087bd4",
|
|
"source_files": [
|
|
".repo-classification.yaml",
|
|
"INTENT.md",
|
|
"intakes/intakes.md",
|
|
"workplans/ADHOC-2026-06-27.md",
|
|
"workplans/ADHOC-2026-06-29.md",
|
|
"workplans/ADHOC-2026-08-11.md",
|
|
"workplans/ADHOC-2026-08-17.md",
|
|
"workplans/WARDEN-WP-0016-ops-bridge-tunnel-cert-pilot.md",
|
|
"workplans/WARDEN-WP-0017-access-front-door-discoverability.md",
|
|
"workplans/WARDEN-WP-0018-whynot-design-npm-lane-activation.md",
|
|
"workplans/WARDEN-WP-0019-route-to-secrets-engine.md",
|
|
"workplans/WARDEN-WP-0020-ops-warden-worker.md",
|
|
"workplans/WARDEN-WP-0021-enable-scheduled-worker-tick.md",
|
|
"workplans/WARDEN-WP-0022-audit-trail-and-activity.md",
|
|
"workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md",
|
|
"workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md",
|
|
"workplans/WARDEN-WP-0025-forgejo-admin-api-token-lane.md",
|
|
"workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md",
|
|
"workplans/WARDEN-WP-0027-credential-governance-lockdown.md",
|
|
"workplans/WARDEN-WP-0028-tenant-secret-custody.md",
|
|
"workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md",
|
|
"workplans/WARDEN-WP-0030-delegation-register.md",
|
|
"workplans/WARDEN-WP-0031-policy-caller-identity.md",
|
|
"workplans/WARDEN-WP-0032-security-zones.md",
|
|
"workplans/WARDEN-WP-0033-native-lane-handoff.md",
|
|
"workplans/WARDEN-WP-0034-layer-model-v07-conformance.md",
|
|
"workplans/WARDEN-WP-0035-policy-nexus-forgejo-source-read-route.md",
|
|
"workplans/WARDEN-WP-0036-attended-login-openbao-output.md",
|
|
"workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"workplans/archived/260515-WARDEN-WP-0002-correctness-and-completeness.md",
|
|
"workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md",
|
|
"workplans/archived/260617-WARDEN-WP-0004-repo-hygiene-and-hub-sync.md",
|
|
"workplans/archived/260617-WARDEN-WP-0005-openbao-doc-alignment.md",
|
|
"workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md",
|
|
"workplans/archived/260617-WARDEN-WP-0007-policy-gate-and-production-verify.md",
|
|
"workplans/archived/260618-WARDEN-WP-0008-production-ssh-path-and-stewardship-closeout.md",
|
|
"workplans/archived/260623-WARDEN-WP-0009-flex-auth-policy-gate-production.md",
|
|
"workplans/archived/260624-WARDEN-WP-0010-access-routing-charter.md",
|
|
"workplans/archived/260624-WARDEN-WP-0011-routing-guide-cli.md",
|
|
"workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md",
|
|
"workplans/archived/260627-WARDEN-WP-0012-routing-scenario-playbooks.md",
|
|
"workplans/archived/260627-WARDEN-WP-0014-operator-access-assist.md",
|
|
"workplans/archived/260627-WARDEN-WP-0015-secret-lifecycle-tiering.md",
|
|
"workplans/archived/260707-ADHOC-2026-07-07.md"
|
|
],
|
|
"work_records": [
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-ADHOC-2026-06-27",
|
|
"status": "finished",
|
|
"title": "Ad Hoc Tasks \u2014 2026-06-27",
|
|
"source_path": "workplans/ADHOC-2026-06-27.md",
|
|
"uuid": "a222c91f-3bb5-58a4-b6b2-f0fb18cdd5c3",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-ADHOC-2026-06-27-T01",
|
|
"status": "done",
|
|
"title": "T01 \u2014 Fix stale `warden` CLI install + make it usable outside the repo",
|
|
"source_path": "workplans/ADHOC-2026-06-27.md",
|
|
"uuid": "9176b560-8ca5-5143-888d-479857fe60f0",
|
|
"parent_id": "WARDEN-WP-ADHOC-2026-06-27",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-ADHOC-2026-06-29",
|
|
"status": "finished",
|
|
"title": "Ad Hoc Tasks \u2014 2026-06-29",
|
|
"source_path": "workplans/ADHOC-2026-06-29.md",
|
|
"uuid": "13fa845f-852e-55ec-a2a5-2296996e0216",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-ADHOC-2026-06-29-T01",
|
|
"status": "done",
|
|
"title": "T01 \u2014 Joint-smoke mode for the deployed flex-auth (assist FLEX-WP-0007 T4)",
|
|
"source_path": "workplans/ADHOC-2026-06-29.md",
|
|
"uuid": "62540533-f4ca-5176-9237-32adbeb292ee",
|
|
"parent_id": "WARDEN-WP-ADHOC-2026-06-29",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-ADHOC-2026-08-11",
|
|
"status": "finished",
|
|
"title": "Ad Hoc Tasks \u2014 2026-08-11",
|
|
"source_path": "workplans/ADHOC-2026-08-11.md",
|
|
"uuid": "9f99cc64-4682-5f20-b13e-89af2b6f7c70",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-ADHOC-2026-08-11-T01",
|
|
"status": "done",
|
|
"title": "T01 \u2014 Repair stale `rapp-qonto-keycape-client` wiki anchor (restore green routing suite)",
|
|
"source_path": "workplans/ADHOC-2026-08-11.md",
|
|
"uuid": "0771d121-278c-556e-9509-841cf6e657c3",
|
|
"parent_id": "WARDEN-WP-ADHOC-2026-08-11",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-ADHOC-2026-08-11-T02",
|
|
"status": "done",
|
|
"title": "T02 \u2014 Triage the stale ops-warden inbox (11 unread, C-28/C-29)",
|
|
"source_path": "workplans/ADHOC-2026-08-11.md",
|
|
"uuid": "0ed58145-732f-5102-b6a8-b931d9b6ba08",
|
|
"parent_id": "WARDEN-WP-ADHOC-2026-08-11",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-ADHOC-2026-08-11-T03",
|
|
"status": "done",
|
|
"title": "T03 \u2014 warden-sign AppRole: PARKED pending WP-0027 break-glass + ops-bridge cutover",
|
|
"source_path": "workplans/ADHOC-2026-08-11.md",
|
|
"uuid": "337ae793-c6b0-59e9-8a07-3a7ccba237aa",
|
|
"parent_id": "WARDEN-WP-ADHOC-2026-08-11",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-ADHOC-2026-08-17",
|
|
"status": "finished",
|
|
"title": "Ad Hoc Tasks \u2014 2026-08-17",
|
|
"source_path": "workplans/ADHOC-2026-08-17.md",
|
|
"uuid": "5c6c2bbb-b944-5afd-b89c-20d865518849",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-ADHOC-2026-08-17-T01",
|
|
"status": "done",
|
|
"title": "T01 \u2014 Answer flex-auth: how should `/v1/check` authenticate its callers?",
|
|
"source_path": "workplans/ADHOC-2026-08-17.md",
|
|
"uuid": "04a2f8f9-e70b-5eed-ad87-343c8f9ef501",
|
|
"parent_id": "WARDEN-WP-ADHOC-2026-08-17",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-ADHOC-2026-08-17-T02",
|
|
"status": "done",
|
|
"title": "T02 \u2014 user-engine: USER_ENGINE_PROXY_SECRET stays railiance-apps; record consumer-only",
|
|
"source_path": "workplans/ADHOC-2026-08-17.md",
|
|
"uuid": "0e815282-2fad-5c8d-be34-398e492737d0",
|
|
"parent_id": "WARDEN-WP-ADHOC-2026-08-17",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-ADHOC-2026-08-17-T03",
|
|
"status": "done",
|
|
"title": "T03 \u2014 key-cape: `rapp-qonto-keycape-client` interim accepted; refresh the blocker",
|
|
"source_path": "workplans/ADHOC-2026-08-17.md",
|
|
"uuid": "e21781d9-a35d-5916-b335-d12131f97a22",
|
|
"parent_id": "WARDEN-WP-ADHOC-2026-08-17",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-ADHOC-2026-08-17-T04",
|
|
"status": "done",
|
|
"title": "T04 \u2014 Session hygiene",
|
|
"source_path": "workplans/ADHOC-2026-08-17.md",
|
|
"uuid": "b15724e0-c27a-5260-a810-4dd25bff2228",
|
|
"parent_id": "WARDEN-WP-ADHOC-2026-08-17",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0016",
|
|
"status": "finished",
|
|
"title": "ops-bridge cert_command pilot \u2014 readiness gate + handoff",
|
|
"source_path": "workplans/WARDEN-WP-0016-ops-bridge-tunnel-cert-pilot.md",
|
|
"uuid": "a56da8db-38bc-4bbe-8671-823360ec9245",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0016-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Read-only `cert_command` readiness preflight",
|
|
"source_path": "workplans/WARDEN-WP-0016-ops-bridge-tunnel-cert-pilot.md",
|
|
"uuid": "fea84495-dbec-480a-b42b-90e39f414b78",
|
|
"parent_id": "WARDEN-WP-0016",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0016-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Offline cert_command contract smoke",
|
|
"source_path": "workplans/WARDEN-WP-0016-ops-bridge-tunnel-cert-pilot.md",
|
|
"uuid": "e34ae1a8-2ba9-4324-8d1a-005d61dae478",
|
|
"parent_id": "WARDEN-WP-0016",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0016-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 Playbook gate + ops-bridge handoff",
|
|
"source_path": "workplans/WARDEN-WP-0016-ops-bridge-tunnel-cert-pilot.md",
|
|
"uuid": "330e01f4-4927-4280-b0e0-49d35b4416d6",
|
|
"parent_id": "WARDEN-WP-0016",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0016-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 INTENT/SCOPE alignment",
|
|
"source_path": "workplans/WARDEN-WP-0016-ops-bridge-tunnel-cert-pilot.md",
|
|
"uuid": "4726f5bb-4ffd-484f-8674-91ee5658434f",
|
|
"parent_id": "WARDEN-WP-0016",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0017",
|
|
"status": "finished",
|
|
"title": "Access front-door discoverability \u2014 stop reading as SSH-only",
|
|
"source_path": "workplans/WARDEN-WP-0017-access-front-door-discoverability.md",
|
|
"uuid": "cf8b392e-7624-4585-8935-a85e29202935",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0017-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 CLI discoverability: route role + access framing",
|
|
"source_path": "workplans/WARDEN-WP-0017-access-front-door-discoverability.md",
|
|
"uuid": "6e98df42-b5b4-49f8-a444-3c6346c8abd7",
|
|
"parent_id": "WARDEN-WP-0017",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0017-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Agent rule + SCOPE reframe",
|
|
"source_path": "workplans/WARDEN-WP-0017-access-front-door-discoverability.md",
|
|
"uuid": "6e2a7067-1afc-4f38-8d99-4d5c36a4661c",
|
|
"parent_id": "WARDEN-WP-0017",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0017-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 Federated capability registration",
|
|
"source_path": "workplans/WARDEN-WP-0017-access-front-door-discoverability.md",
|
|
"uuid": "7199625b-e78e-4495-8ca0-076100ae9f08",
|
|
"parent_id": "WARDEN-WP-0017",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0018",
|
|
"status": "finished",
|
|
"title": "Activate whynot-design npm publish lane + resolvable readiness flag",
|
|
"source_path": "workplans/WARDEN-WP-0018-whynot-design-npm-lane-activation.md",
|
|
"uuid": "1256aca2-5979-4d21-818e-0de42c5d811b",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0018-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Concrete catalog entry + playbook",
|
|
"source_path": "workplans/WARDEN-WP-0018-whynot-design-npm-lane-activation.md",
|
|
"uuid": "189d0883-22b9-42dc-bda0-89460509a87d",
|
|
"parent_id": "WARDEN-WP-0018",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0018-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 `resolvable` readiness flag + stable-id resolution",
|
|
"source_path": "workplans/WARDEN-WP-0018-whynot-design-npm-lane-activation.md",
|
|
"uuid": "b5dc1013-5334-43ff-afd6-1f99d521358f",
|
|
"parent_id": "WARDEN-WP-0018",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0018-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 Close the loop",
|
|
"source_path": "workplans/WARDEN-WP-0018-whynot-design-npm-lane-activation.md",
|
|
"uuid": "95b00ef8-477a-4f0d-bd71-6154fba401f5",
|
|
"parent_id": "WARDEN-WP-0018",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0019",
|
|
"status": "finished",
|
|
"title": "Route secret-exec lanes to secrets-engine (route-primary, proxy fallback)",
|
|
"source_path": "workplans/WARDEN-WP-0019-route-to-secrets-engine.md",
|
|
"uuid": "5e49abb6-497f-4640-a484-2da5f39a7c4e",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0019-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Catalog + CLI: surface the owner-native exec front door",
|
|
"source_path": "workplans/WARDEN-WP-0019-route-to-secrets-engine.md",
|
|
"uuid": "ea153605-7a14-4db7-8bce-d780ea143f8a",
|
|
"parent_id": "WARDEN-WP-0019",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0019-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Agent rule, SCOPE, playbook",
|
|
"source_path": "workplans/WARDEN-WP-0019-route-to-secrets-engine.md",
|
|
"uuid": "96059b8a-8938-4763-b3d0-cc5a0eb2465c",
|
|
"parent_id": "WARDEN-WP-0019",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0020",
|
|
"status": "finished",
|
|
"title": "ops-warden worker \u2014 autonomous coordination via llm-connect",
|
|
"source_path": "workplans/WARDEN-WP-0020-ops-warden-worker.md",
|
|
"uuid": "c906ba1d-f991-4fb0-b113-59432ddf87c0",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0020-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Worker scaffold (llm-connect-independent, safe)",
|
|
"source_path": "workplans/WARDEN-WP-0020-ops-warden-worker.md",
|
|
"uuid": "979c2d9b-0803-442f-aa2e-acb02bac07e9",
|
|
"parent_id": "WARDEN-WP-0020",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0020-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 llm-connect brain",
|
|
"source_path": "workplans/WARDEN-WP-0020-ops-warden-worker.md",
|
|
"uuid": "52d281b2-7d48-44f5-b77e-80e3ed500b5f",
|
|
"parent_id": "WARDEN-WP-0020",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0020-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 Action dispatch + guardrails (full-auto in-scope)",
|
|
"source_path": "workplans/WARDEN-WP-0020-ops-warden-worker.md",
|
|
"uuid": "3a71965e-42d5-4258-9761-aced804c88e7",
|
|
"parent_id": "WARDEN-WP-0020",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0020-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Scheduled trigger",
|
|
"source_path": "workplans/WARDEN-WP-0020-ops-warden-worker.md",
|
|
"uuid": "7f77ea6d-c281-42c5-ad25-2a0bb9fd68de",
|
|
"parent_id": "WARDEN-WP-0020",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0020-T05",
|
|
"status": "done",
|
|
"title": "T5 \u2014 Docs / SCOPE / INTENT",
|
|
"source_path": "workplans/WARDEN-WP-0020-ops-warden-worker.md",
|
|
"uuid": "6e7ae317-7f8b-468a-bb5c-b08093ed43a0",
|
|
"parent_id": "WARDEN-WP-0020",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0021",
|
|
"status": "finished",
|
|
"title": "Enable the scheduled worker tick \u2014 conservative inbox triage, unattended",
|
|
"source_path": "workplans/WARDEN-WP-0021-enable-scheduled-worker-tick.md",
|
|
"uuid": "8c487014-b630-4016-a4f0-31b971a473d2",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0021-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Scheduler install + enablement + kill switch",
|
|
"source_path": "workplans/WARDEN-WP-0021-enable-scheduled-worker-tick.md",
|
|
"uuid": "10451fe6-7fab-4ae0-8494-e6cfdfbcf8cf",
|
|
"parent_id": "WARDEN-WP-0021",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0021-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Scheduled-run robustness (graceful degradation)",
|
|
"source_path": "workplans/WARDEN-WP-0021-enable-scheduled-worker-tick.md",
|
|
"uuid": "1f35f816-1af5-46ff-b48c-1715f3ae5784",
|
|
"parent_id": "WARDEN-WP-0021",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0021-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 Operator visibility (see new drafts)",
|
|
"source_path": "workplans/WARDEN-WP-0021-enable-scheduled-worker-tick.md",
|
|
"uuid": "3c7f6423-8db0-4bc6-b67d-078d9d929c6d",
|
|
"parent_id": "WARDEN-WP-0021",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0021-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Review\u2192send loop (`warden worker approve`)",
|
|
"source_path": "workplans/WARDEN-WP-0021-enable-scheduled-worker-tick.md",
|
|
"uuid": "dabc9fc0-abb1-4e9d-b87e-5f0c5950693c",
|
|
"parent_id": "WARDEN-WP-0021",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0021-T05",
|
|
"status": "done",
|
|
"title": "T5 \u2014 Runbook + SCOPE",
|
|
"source_path": "workplans/WARDEN-WP-0021-enable-scheduled-worker-tick.md",
|
|
"uuid": "9915da96-1b33-4d0f-b752-408ea8d43333",
|
|
"parent_id": "WARDEN-WP-0021",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0022",
|
|
"status": "finished",
|
|
"title": "Audit trail + `warden activity` \u2014 one place to see what ops-warden did",
|
|
"source_path": "workplans/WARDEN-WP-0022-audit-trail-and-activity.md",
|
|
"uuid": "fc8afa28-68a7-4250-a19e-9754829f0cd5",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0022-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Unified audit event log",
|
|
"source_path": "workplans/WARDEN-WP-0022-audit-trail-and-activity.md",
|
|
"uuid": "7f8f768a-4c62-4096-bad8-912cea0f35a7",
|
|
"parent_id": "WARDEN-WP-0022",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0022-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Instrument the actions",
|
|
"source_path": "workplans/WARDEN-WP-0022-audit-trail-and-activity.md",
|
|
"uuid": "e7ae4037-ca79-4557-81f0-bfb8478ff647",
|
|
"parent_id": "WARDEN-WP-0022",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0022-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 `warden activity` command",
|
|
"source_path": "workplans/WARDEN-WP-0022-audit-trail-and-activity.md",
|
|
"uuid": "4439bdd8-1461-47df-8b0b-048df7384a68",
|
|
"parent_id": "WARDEN-WP-0022",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0022-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Tests, runbook, SCOPE",
|
|
"source_path": "workplans/WARDEN-WP-0022-audit-trail-and-activity.md",
|
|
"uuid": "bdfb8703-7a79-43e7-913b-19d61722f164",
|
|
"parent_id": "WARDEN-WP-0022",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0023",
|
|
"status": "finished",
|
|
"title": "INTENT\u2013SCOPE Alignment Closeout",
|
|
"source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md",
|
|
"uuid": "7bad1ec4-a7c2-4980-b8f9-49a7f5408574",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0023-T01",
|
|
"status": "done",
|
|
"title": "T01 \u2014 Persist gap analysis",
|
|
"source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md",
|
|
"uuid": "52485c90-87fe-40b1-9db5-a51ebb957dd5",
|
|
"parent_id": "WARDEN-WP-0023",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0023-T02",
|
|
"status": "done",
|
|
"title": "T02 \u2014 Refresh INTENT.md",
|
|
"source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md",
|
|
"uuid": "9a9b3631-8948-45af-ace1-c19ee74ace4d",
|
|
"parent_id": "WARDEN-WP-0023",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0023-T03",
|
|
"status": "done",
|
|
"title": "T03 \u2014 Production integration coordination pack",
|
|
"source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md",
|
|
"uuid": "26f23798-494b-45fc-baa8-af27bdffa038",
|
|
"parent_id": "WARDEN-WP-0023",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0023-T04",
|
|
"status": "done",
|
|
"title": "T04 \u2014 `warden sign` broker hint when `VAULT_TOKEN` unset",
|
|
"source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md",
|
|
"uuid": "85e324f9-273d-4740-a202-9c4e8fb122ae",
|
|
"parent_id": "WARDEN-WP-0023",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0023-T05",
|
|
"status": "done",
|
|
"title": "T05 \u2014 Catalog draft-lane promotion checklist",
|
|
"source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md",
|
|
"uuid": "82608692-2845-41e1-a498-90ed53780748",
|
|
"parent_id": "WARDEN-WP-0023",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0023-T06",
|
|
"status": "done",
|
|
"title": "T06 \u2014 SCOPE and workplan consistency",
|
|
"source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md",
|
|
"uuid": "79ca7b9a-554e-4952-9393-a29b100f6190",
|
|
"parent_id": "WARDEN-WP-0023",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0023-T07",
|
|
"status": "done",
|
|
"title": "T07 \u2014 Sequence WP-0022 audit implementation",
|
|
"source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md",
|
|
"uuid": "1f3b3b33-974e-49bf-be4a-9d50b702c2a4",
|
|
"parent_id": "WARDEN-WP-0023",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0024",
|
|
"status": "finished",
|
|
"title": "Experiential Memory Across Worker, Agent Sessions, And OpenRouter",
|
|
"source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md",
|
|
"uuid": "5d9fafb3-f9b6-43bf-b259-5f5301daa2e9",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0024-T01",
|
|
"status": "done",
|
|
"title": "T01 - Canonical memory store and discovery",
|
|
"source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md",
|
|
"uuid": "6305f1bc-c016-4298-adc2-a07d52b6aca5",
|
|
"parent_id": "WARDEN-WP-0024",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0024-T02",
|
|
"status": "done",
|
|
"title": "T02 - Session recording hooks in CLI commands",
|
|
"source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md",
|
|
"uuid": "242a4d9a-5375-4df8-8d43-063b0491d202",
|
|
"parent_id": "WARDEN-WP-0024",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0024-T03",
|
|
"status": "done",
|
|
"title": "T03 - Memory-aware worker tick",
|
|
"source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md",
|
|
"uuid": "176fcae1-e4e5-481f-9a83-e9a7000fac1a",
|
|
"parent_id": "WARDEN-WP-0024",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0024-T04",
|
|
"status": "done",
|
|
"title": "T04 - Agent session activation helper",
|
|
"source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md",
|
|
"uuid": "16501557-6cde-44ea-bc6f-1726cb7ec070",
|
|
"parent_id": "WARDEN-WP-0024",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0024-T05",
|
|
"status": "done",
|
|
"title": "T05 - Cross-runtime continuity",
|
|
"source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md",
|
|
"uuid": "55ae679c-c08f-4afd-8646-9f5f3019f86e",
|
|
"parent_id": "WARDEN-WP-0024",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0024-T06",
|
|
"status": "done",
|
|
"title": "T06 - OpenRouter efficiency layer",
|
|
"source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md",
|
|
"uuid": "fc2dffcf-7184-4f3d-8653-d26dc18a9afc",
|
|
"parent_id": "WARDEN-WP-0024",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0024-T07",
|
|
"status": "done",
|
|
"title": "T07 - Operator and agent documentation",
|
|
"source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md",
|
|
"uuid": "ca2aaf23-833f-49a6-a49b-a0b659208f5f",
|
|
"parent_id": "WARDEN-WP-0024",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0025",
|
|
"status": "finished",
|
|
"title": "Forgejo admin PAT OpenBao lane (CCR-2026-0006)",
|
|
"source_path": "workplans/WARDEN-WP-0025-forgejo-admin-api-token-lane.md",
|
|
"uuid": "70c11222-d8e7-5936-99f7-7d626a4a5deb",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0025-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Draft CCR + policy metadata",
|
|
"source_path": "workplans/WARDEN-WP-0025-forgejo-admin-api-token-lane.md",
|
|
"uuid": "2c288bf0-b39c-5f5b-ad25-eed3da826dc3",
|
|
"parent_id": "WARDEN-WP-0025",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0025-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 ops-warden catalog + playbook",
|
|
"source_path": "workplans/WARDEN-WP-0025-forgejo-admin-api-token-lane.md",
|
|
"uuid": "01b81595-f9e5-5746-b0dd-2075189cb00e",
|
|
"parent_id": "WARDEN-WP-0025",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0025-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 Platform-operator approval + metadata apply",
|
|
"source_path": "workplans/WARDEN-WP-0025-forgejo-admin-api-token-lane.md",
|
|
"uuid": "279b74d7-3240-5ca0-897d-b1ddffd23c4e",
|
|
"parent_id": "WARDEN-WP-0025",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0025-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Attended PAT provision + verification",
|
|
"source_path": "workplans/WARDEN-WP-0025-forgejo-admin-api-token-lane.md",
|
|
"uuid": "4e21232c-62a1-5115-acce-edfbcfa84e48",
|
|
"parent_id": "WARDEN-WP-0025",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0025-T05",
|
|
"status": "done",
|
|
"title": "T5 \u2014 Notify downstream consumers",
|
|
"source_path": "workplans/WARDEN-WP-0025-forgejo-admin-api-token-lane.md",
|
|
"uuid": "f8c7c70b-b9b6-5980-a25b-7f11033b81a2",
|
|
"parent_id": "WARDEN-WP-0025",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0026",
|
|
"status": "finished",
|
|
"title": "Credential disclosure hygiene + rotation guidance (Strand A)",
|
|
"source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md",
|
|
"uuid": "331c7620-bd34-5acd-9135-591985b568e5",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0026-T01",
|
|
"status": "done",
|
|
"title": "Task: Capabilities-based lane verification",
|
|
"source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md",
|
|
"uuid": "1cb22a40-b7c6-560a-a805-7766a5786dcc",
|
|
"parent_id": "WARDEN-WP-0026",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0026-T02",
|
|
"status": "done",
|
|
"title": "Task: Safe access transport (no stdout values)",
|
|
"source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md",
|
|
"uuid": "bcb7da96-0a28-5484-bf3e-06e97acf5873",
|
|
"parent_id": "WARDEN-WP-0026",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0026-T03",
|
|
"status": "done",
|
|
"title": "Task: Masking display filter (defense-in-depth)",
|
|
"source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md",
|
|
"uuid": "d90b0628-fa1d-527d-99c3-28a7ed933e52",
|
|
"parent_id": "WARDEN-WP-0026",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0026-T04",
|
|
"status": "done",
|
|
"title": "Task: Agent read-boundary on high-risk lanes",
|
|
"source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md",
|
|
"uuid": "827fa67d-5f69-5fac-bdce-9903b1b909fb",
|
|
"parent_id": "WARDEN-WP-0026",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0026-T05",
|
|
"status": "done",
|
|
"title": "Task: EXPOSED taint convention",
|
|
"source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md",
|
|
"uuid": "09ef8727-31da-59ac-aac7-2d47924569fe",
|
|
"parent_id": "WARDEN-WP-0026",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0026-T06",
|
|
"status": "done",
|
|
"title": "Task: Rotation / re-establishment guidance registry",
|
|
"source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md",
|
|
"uuid": "a2e1544e-e501-57eb-a40e-9a2147cef12a",
|
|
"parent_id": "WARDEN-WP-0026",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0026-T07",
|
|
"status": "done",
|
|
"title": "Task: Incident lessons + first worked lane (CCR-2026-0004)",
|
|
"source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md",
|
|
"uuid": "62d8286f-7954-52a8-bce6-6a16072e5246",
|
|
"parent_id": "WARDEN-WP-0026",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0027",
|
|
"status": "active",
|
|
"title": "Tamper-resistant credential governance + mass rotation/lockdown (Strand B)",
|
|
"source_path": "workplans/WARDEN-WP-0027-credential-governance-lockdown.md",
|
|
"uuid": "21528e8d-a049-523d-9ae1-da7a27cb8bbf",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0027-T01",
|
|
"status": "cancel",
|
|
"title": "Task: Executable mass rotation driver",
|
|
"source_path": "workplans/WARDEN-WP-0027-credential-governance-lockdown.md",
|
|
"uuid": "b5691939-9d84-5115-9618-0f8839010d14",
|
|
"parent_id": "WARDEN-WP-0027",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0027-T02",
|
|
"status": "progress",
|
|
"title": "Task: Graded lockdown / break-glass with explicit trust-root",
|
|
"source_path": "workplans/WARDEN-WP-0027-credential-governance-lockdown.md",
|
|
"uuid": "cae498ee-6307-5d32-9f1b-a471cfcc2536",
|
|
"parent_id": "WARDEN-WP-0027",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0027-T03",
|
|
"status": "cancel",
|
|
"title": "Task: Tamper-evident policy governance + reconcile",
|
|
"source_path": "workplans/WARDEN-WP-0027-credential-governance-lockdown.md",
|
|
"uuid": "7dbedcdc-dd5a-551c-bff1-0702fea0a9cf",
|
|
"parent_id": "WARDEN-WP-0027",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0028",
|
|
"status": "finished",
|
|
"title": "Tenant secret custody \u2014 NetKingdom pattern for client/tenant secrets",
|
|
"source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md",
|
|
"uuid": "6b66228a-199a-5b85-b5e2-a7afeaab903b",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0028-T01",
|
|
"status": "done",
|
|
"title": "T01 \u2014 Canon note: tenant secret path + ownership",
|
|
"source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md",
|
|
"uuid": "9982a884-7a50-593e-861e-cc8d2343a0ba",
|
|
"parent_id": "WARDEN-WP-0028",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0028-T02",
|
|
"status": "done",
|
|
"title": "T02 \u2014 Align binky-control integration plan to production path",
|
|
"source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md",
|
|
"uuid": "d7d7ee9d-2ecf-5492-8a13-0b747d899456",
|
|
"parent_id": "WARDEN-WP-0028",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0028-T03",
|
|
"status": "done",
|
|
"title": "T03 \u2014 Enable `tenants` mount + extend CCR tooling + policy/role",
|
|
"source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md",
|
|
"uuid": "e0b675ef-9c08-5f89-8f13-ef4249ca2364",
|
|
"parent_id": "WARDEN-WP-0028",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0028-T04",
|
|
"status": "done",
|
|
"title": "T04 \u2014 ops-warden catalog + playbook + rotation",
|
|
"source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md",
|
|
"uuid": "9405b13d-4045-519b-8e3f-79a891323397",
|
|
"parent_id": "WARDEN-WP-0028",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0028-T05",
|
|
"status": "done",
|
|
"title": "T05 \u2014 Founder provision (Red) + first scan evidence",
|
|
"source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md",
|
|
"uuid": "f17bba95-bc53-5c2a-8b44-7df9e42b2341",
|
|
"parent_id": "WARDEN-WP-0028",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0028-T06",
|
|
"status": "done",
|
|
"title": "T06 \u2014 Generalize \"tenant secret onboarding\" playbook",
|
|
"source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md",
|
|
"uuid": "76bd01a0-1d03-5ff9-8f59-a1b44763979d",
|
|
"parent_id": "WARDEN-WP-0028",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0028-T07",
|
|
"status": "done",
|
|
"title": "T07 \u2014 secrets-engine alignment decision (record only)",
|
|
"source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md",
|
|
"uuid": "46c8f8a9-3bbe-568f-8a45-07b690874273",
|
|
"parent_id": "WARDEN-WP-0028",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0029",
|
|
"status": "finished",
|
|
"title": "Policy front door: posture-aware access planning + founder interaction surface",
|
|
"source_path": "workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md",
|
|
"uuid": "bbb3d9ec-d88d-5088-b4c0-55bfba0a10cf",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0029-T02",
|
|
"status": "done",
|
|
"title": "T02 \u2014 Declared organization posture (build phase)",
|
|
"source_path": "workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md",
|
|
"uuid": "6c213024-6601-5116-b52f-d6711dc0587d",
|
|
"parent_id": "WARDEN-WP-0029",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0029-T05",
|
|
"status": "done",
|
|
"title": "T05 \u2014 Catalog freshness + agent guidance",
|
|
"source_path": "workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md",
|
|
"uuid": "c82d8745-4af4-5b89-ab49-06d8a902e592",
|
|
"parent_id": "WARDEN-WP-0029",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0029-T01",
|
|
"status": "done",
|
|
"title": "T01 \u2014 `warden plan` decision front door",
|
|
"source_path": "workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md",
|
|
"uuid": "34db38fa-cb99-5ced-9a12-85176a7f2b44",
|
|
"parent_id": "WARDEN-WP-0029",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0029-T04",
|
|
"status": "done",
|
|
"title": "T04 \u2014 Retire file-drop patterns from playbooks",
|
|
"source_path": "workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md",
|
|
"uuid": "717f57da-fbc4-5a4d-9f8c-c1c3fa75e0ee",
|
|
"parent_id": "WARDEN-WP-0029",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0029-T03",
|
|
"status": "done",
|
|
"title": "T03 \u2014 Founder interaction surface (local web approval page)",
|
|
"source_path": "workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md",
|
|
"uuid": "47c781d2-768b-5777-b971-b5227fe41f5c",
|
|
"parent_id": "WARDEN-WP-0029",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0030",
|
|
"status": "finished",
|
|
"title": "Delegation register \u2014 make gap-covering interim, visible, and retirable",
|
|
"source_path": "workplans/WARDEN-WP-0030-delegation-register.md",
|
|
"uuid": "da3367d5-890c-52c6-aa54-1bdd0f277342",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0030-T01",
|
|
"status": "done",
|
|
"title": "T01 \u2014 Interim custodianship doctrine",
|
|
"source_path": "workplans/WARDEN-WP-0030-delegation-register.md",
|
|
"uuid": "6f88876e-434c-5718-9c8d-ec6bf64ae4aa",
|
|
"parent_id": "WARDEN-WP-0030",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0030-T02",
|
|
"status": "done",
|
|
"title": "T02 \u2014 `delegation:` metadata + backfill",
|
|
"source_path": "workplans/WARDEN-WP-0030-delegation-register.md",
|
|
"uuid": "b02e8da6-57ca-5f9f-9405-9b0624498e3a",
|
|
"parent_id": "WARDEN-WP-0030",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0030-T03",
|
|
"status": "done",
|
|
"title": "T03 \u2014 `warden route gaps` + conformance test",
|
|
"source_path": "workplans/WARDEN-WP-0030-delegation-register.md",
|
|
"uuid": "f5e0f5af-45d8-5c82-9de2-d640d7d0a1f7",
|
|
"parent_id": "WARDEN-WP-0030",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0030-T04",
|
|
"status": "done",
|
|
"title": "T04 \u2014 Promotion gate",
|
|
"source_path": "workplans/WARDEN-WP-0030-delegation-register.md",
|
|
"uuid": "b808a749-e1d7-5708-aabf-91732dd76abd",
|
|
"parent_id": "WARDEN-WP-0030",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0030-T05",
|
|
"status": "done",
|
|
"title": "T05 \u2014 Publish the register to the owners",
|
|
"source_path": "workplans/WARDEN-WP-0030-delegation-register.md",
|
|
"uuid": "b0188ec4-4860-57c8-8030-45904a132190",
|
|
"parent_id": "WARDEN-WP-0030",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0031",
|
|
"status": "finished",
|
|
"title": "Calling-side identity for flex-auth, so policy.enabled can flip",
|
|
"source_path": "workplans/WARDEN-WP-0031-policy-caller-identity.md",
|
|
"uuid": "739bad25-2345-5f4f-aaa3-cc4cd8c71f6c",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0031-T01",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0031-policy-caller-identity.md",
|
|
"uuid": "d3b7c701-bcdd-53f9-aa72-6f289bf5909b",
|
|
"parent_id": "WARDEN-WP-0031",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0031-T02",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0031-policy-caller-identity.md",
|
|
"uuid": "b77b3c80-a168-564a-9b7f-3063aefc3c2e",
|
|
"parent_id": "WARDEN-WP-0031",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0031-T03",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0031-policy-caller-identity.md",
|
|
"uuid": "4245155e-6c71-5425-b574-11f61e1d4461",
|
|
"parent_id": "WARDEN-WP-0031",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0031-T04",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0031-policy-caller-identity.md",
|
|
"uuid": "f3834af7-2a08-51dd-bf31-8ce8550de699",
|
|
"parent_id": "WARDEN-WP-0031",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0031-T05",
|
|
"status": "cancel",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0031-policy-caller-identity.md",
|
|
"uuid": "3f6dc609-89db-52eb-a6f9-d2fd271be821",
|
|
"parent_id": "WARDEN-WP-0031",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0032",
|
|
"status": "finished",
|
|
"title": "Adopt security zones as a consumer \u2014 retire the global policy.enabled",
|
|
"source_path": "workplans/WARDEN-WP-0032-security-zones.md",
|
|
"uuid": "38c6a5f3-fb0d-5230-be85-f9e3ffc850f6",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0032-T01",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0032-security-zones.md",
|
|
"uuid": "b03a5caa-0bb5-5cdd-bb99-32c694b0da29",
|
|
"parent_id": "WARDEN-WP-0032",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0032-T02",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0032-security-zones.md",
|
|
"uuid": "b3f41c85-a293-58ad-ac27-9f8110c51266",
|
|
"parent_id": "WARDEN-WP-0032",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0032-T03",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0032-security-zones.md",
|
|
"uuid": "d04a737b-ecdf-5747-ba25-20dadd99d3bc",
|
|
"parent_id": "WARDEN-WP-0032",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0032-T04",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0032-security-zones.md",
|
|
"uuid": "c7879127-3dba-55c0-853c-a10775736873",
|
|
"parent_id": "WARDEN-WP-0032",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0032-T05",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0032-security-zones.md",
|
|
"uuid": "1d968627-83f4-59cd-84ca-0f9f35e435ff",
|
|
"parent_id": "WARDEN-WP-0032",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0032-T06",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0032-security-zones.md",
|
|
"uuid": "4294084c-bf3f-5aa6-b84d-5173121882ff",
|
|
"parent_id": "WARDEN-WP-0032",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0032-T07",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0032-security-zones.md",
|
|
"uuid": "6b4bbbed-2864-5fe9-82be-22ff9543f6f4",
|
|
"parent_id": "WARDEN-WP-0032",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0033",
|
|
"status": "finished",
|
|
"title": "Native lane handoff \u2014 review secrets-engine's catalog admission, and fix what it exposed",
|
|
"source_path": "workplans/WARDEN-WP-0033-native-lane-handoff.md",
|
|
"uuid": "4627d89b-4b00-562a-81e9-76e96f90fa7e",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0033-T01",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0033-native-lane-handoff.md",
|
|
"uuid": "154f2f03-387d-5fe6-a0f5-1929c46a2bd8",
|
|
"parent_id": "WARDEN-WP-0033",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0033-T02",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0033-native-lane-handoff.md",
|
|
"uuid": "6996d07f-63bb-5708-a171-68c4b1bbddde",
|
|
"parent_id": "WARDEN-WP-0033",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0033-T03",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0033-native-lane-handoff.md",
|
|
"uuid": "a736f983-94da-5a4a-aaf9-5114485518a6",
|
|
"parent_id": "WARDEN-WP-0033",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0033-T04",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0033-native-lane-handoff.md",
|
|
"uuid": "5acac140-a586-5db3-b231-bbf236710786",
|
|
"parent_id": "WARDEN-WP-0033",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0033-T05",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0033-native-lane-handoff.md",
|
|
"uuid": "75051d17-399b-5129-860b-ae00dae91c47",
|
|
"parent_id": "WARDEN-WP-0033",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0033-T06",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0033-native-lane-handoff.md",
|
|
"uuid": "94f77f5a-f919-5328-832c-ba1d24c6431b",
|
|
"parent_id": "WARDEN-WP-0033",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0034",
|
|
"status": "ready",
|
|
"title": "Layer model v0.7 conformance \u2014 state the deadline, bind the agent boundary, steward the estate's newest rule",
|
|
"source_path": "workplans/WARDEN-WP-0034-layer-model-v07-conformance.md",
|
|
"uuid": "ae3ff76f-883d-5e2f-b6aa-144d61e8fdef",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0034-T01",
|
|
"status": "todo",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0034-layer-model-v07-conformance.md",
|
|
"uuid": "8b3bdb9f-d2c2-5b3e-89e2-417bf3e37484",
|
|
"parent_id": "WARDEN-WP-0034",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0034-T02",
|
|
"status": "todo",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0034-layer-model-v07-conformance.md",
|
|
"uuid": "3318ee1a-b5d9-5d39-baf7-9c42a8bc7b55",
|
|
"parent_id": "WARDEN-WP-0034",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0034-T03",
|
|
"status": "todo",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0034-layer-model-v07-conformance.md",
|
|
"uuid": "a891b32c-b0a7-59f6-a5cd-977be65c09ca",
|
|
"parent_id": "WARDEN-WP-0034",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0034-T04",
|
|
"status": "todo",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0034-layer-model-v07-conformance.md",
|
|
"uuid": "94e73daa-f74d-51fd-8639-68896a4066ee",
|
|
"parent_id": "WARDEN-WP-0034",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0034-T05",
|
|
"status": "todo",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0034-layer-model-v07-conformance.md",
|
|
"uuid": "7d1b3c82-9b96-5087-a53a-496212909029",
|
|
"parent_id": "WARDEN-WP-0034",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0035",
|
|
"status": "finished",
|
|
"title": "Register the Policy Nexus Forgejo source-read route",
|
|
"source_path": "workplans/WARDEN-WP-0035-policy-nexus-forgejo-source-read-route.md",
|
|
"uuid": "45aec8d3-94b3-586e-b019-a47e656efafa",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0035-T01",
|
|
"status": "done",
|
|
"title": "Register the exact high-risk lane",
|
|
"source_path": "workplans/WARDEN-WP-0035-policy-nexus-forgejo-source-read-route.md",
|
|
"uuid": "dd84f2be-0143-540c-9c16-74f0fd129260",
|
|
"parent_id": "WARDEN-WP-0035",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0035-T02",
|
|
"status": "done",
|
|
"title": "Verify routing and governed use",
|
|
"source_path": "workplans/WARDEN-WP-0035-policy-nexus-forgejo-source-read-route.md",
|
|
"uuid": "1fa8f778-3e46-5f44-86c4-cab8628b7e60",
|
|
"parent_id": "WARDEN-WP-0035",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0036",
|
|
"status": "finished",
|
|
"title": "Accept contained OpenBao login output only after helper persistence",
|
|
"source_path": "workplans/WARDEN-WP-0036-attended-login-openbao-output.md",
|
|
"uuid": "d844c96e-152d-53fa-bff6-e072125ef66c",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0036-T01",
|
|
"status": "done",
|
|
"title": "Repair attended-login handoff",
|
|
"source_path": "workplans/WARDEN-WP-0036-attended-login-openbao-output.md",
|
|
"uuid": "7eb8b9c9-1285-5ada-a17b-1d5bfbb8ba59",
|
|
"parent_id": "WARDEN-WP-0036",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0036-T02",
|
|
"status": "done",
|
|
"title": "Verify live contained operation",
|
|
"source_path": "workplans/WARDEN-WP-0036-attended-login-openbao-output.md",
|
|
"uuid": "d22bab05-c38b-561f-95de-6c146ce7c6cf",
|
|
"parent_id": "WARDEN-WP-0036",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0001",
|
|
"status": "archived",
|
|
"title": "OpsWarden Initial Implementation",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"uuid": "c3118cc6-adfb-428c-a9c6-edd0ee152ae6",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0001-T1",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Repository bootstrap",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"uuid": "6d643e9d-5e97-4224-9d82-87267b5ba6bc",
|
|
"parent_id": "WARDEN-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0001-T2",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Models and config",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"uuid": "c66fc65a-0b16-4ba2-9e70-a83d875572ec",
|
|
"parent_id": "WARDEN-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0001-T3",
|
|
"status": "done",
|
|
"title": "T3 \u2014 LocalCA backend",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"uuid": "a5a41e58-1c6d-42a9-9b11-2088f17c29b5",
|
|
"parent_id": "WARDEN-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0001-T4",
|
|
"status": "done",
|
|
"title": "T4 \u2014 VaultCA backend",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"uuid": "b2067ee6-c9ce-423b-9d60-0d28069fb304",
|
|
"parent_id": "WARDEN-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0001-T5",
|
|
"status": "done",
|
|
"title": "T5 \u2014 Principals inventory",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"uuid": "6d13f8cd-1850-44c9-b769-b21250348319",
|
|
"parent_id": "WARDEN-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0001-T6",
|
|
"status": "done",
|
|
"title": "T6 \u2014 CLI commands",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"uuid": "656a4615-92bb-4b5d-9406-e86d24fa15d0",
|
|
"parent_id": "WARDEN-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0001-T7",
|
|
"status": "done",
|
|
"title": "T7 \u2014 Scorecard runner",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"uuid": "7818bcc5-f40e-4793-b117-d36f653ffeed",
|
|
"parent_id": "WARDEN-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0001-T8",
|
|
"status": "done",
|
|
"title": "T8 \u2014 ops-ssh-wrapper script",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"uuid": "e9c28152-5785-4995-83a5-439985ed3db9",
|
|
"parent_id": "WARDEN-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0001-T9",
|
|
"status": "done",
|
|
"title": "T9 \u2014 Tests",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"uuid": "950139ab-cc17-4f1d-9a17-d5744e402ddf",
|
|
"parent_id": "WARDEN-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0001-T10",
|
|
"status": "done",
|
|
"title": "T10 \u2014 Documentation",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"uuid": "271d6759-e359-41ce-80e4-76c574634a87",
|
|
"parent_id": "WARDEN-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0002",
|
|
"status": "archived",
|
|
"title": "OpsWarden Correctness and Operational Completeness",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0002-correctness-and-completeness.md",
|
|
"uuid": "5a9fba2c-6161-49a4-a231-e750fa4ab572",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0002-T1",
|
|
"status": "done",
|
|
"title": "T1 \u2014 TTL max enforcement per ActorType",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0002-correctness-and-completeness.md",
|
|
"uuid": "b0d0b5f7-a181-4590-be26-c48ae28cd964",
|
|
"parent_id": "WARDEN-WP-0002",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0002-T2",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Stale cert cleanup command",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0002-correctness-and-completeness.md",
|
|
"uuid": "aeeefbad-c0bd-4ae8-a3fe-9f72321b4caa",
|
|
"parent_id": "WARDEN-WP-0002",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0002-T3",
|
|
"status": "done",
|
|
"title": "T3 \u2014 Outgoing signatures log",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0002-correctness-and-completeness.md",
|
|
"uuid": "0194d24f-a8fe-4f6d-88e6-addea3542c0e",
|
|
"parent_id": "WARDEN-WP-0002",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0003",
|
|
"status": "archived",
|
|
"title": "OpsWarden Test Coverage and Code Quality",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md",
|
|
"uuid": "cb2bbf3c-848a-4af6-ba64-8361e64cd4d7",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0003-T1",
|
|
"status": "done",
|
|
"title": "T1 \u2014 VaultCA tests",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md",
|
|
"uuid": "eff074ce-c027-4df5-8006-0990296592ac",
|
|
"parent_id": "WARDEN-WP-0003",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0003-T2",
|
|
"status": "done",
|
|
"title": "T2 \u2014 LocalCA.generate_keypair tests",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md",
|
|
"uuid": "ddfe5331-0a3b-4783-bdf4-f5ebcdf7965c",
|
|
"parent_id": "WARDEN-WP-0003",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0003-T3",
|
|
"status": "done",
|
|
"title": "T3 \u2014 CLI tests",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md",
|
|
"uuid": "040ce3a1-0efb-4816-a2d9-357162dd1612",
|
|
"parent_id": "WARDEN-WP-0003",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0003-T4",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Real ssh-keygen integration test",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md",
|
|
"uuid": "434fb008-103f-410c-85fd-e77b33e61fe4",
|
|
"parent_id": "WARDEN-WP-0003",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0003-T5",
|
|
"status": "done",
|
|
"title": "T5 \u2014 File permissions enforcement (mode 600)",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md",
|
|
"uuid": "ac146fe6-d1fd-4186-91bd-6f098de72449",
|
|
"parent_id": "WARDEN-WP-0003",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0003-T6",
|
|
"status": "done",
|
|
"title": "T6 \u2014 warden status --state-dir override",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md",
|
|
"uuid": "1c9f1987-7b11-43c1-a5e3-c2fd8d1c1589",
|
|
"parent_id": "WARDEN-WP-0003",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0004",
|
|
"status": "archived",
|
|
"title": "OpsWarden Repo Hygiene and Hub Sync",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0004-repo-hygiene-and-hub-sync.md",
|
|
"uuid": "3c4b6e68-550a-4fc6-a804-95f1f68936c3",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0004-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Update orientation docs",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0004-repo-hygiene-and-hub-sync.md",
|
|
"uuid": "f9d3926c-8637-411c-a477-2960b754704c",
|
|
"parent_id": "WARDEN-WP-0004",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0004-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Fill agent rules",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0004-repo-hygiene-and-hub-sync.md",
|
|
"uuid": "86c764a5-62fc-45fe-a8d2-332d6554a976",
|
|
"parent_id": "WARDEN-WP-0004",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0004-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 Archive finished workplans",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0004-repo-hygiene-and-hub-sync.md",
|
|
"uuid": "d3e54e63-ce98-4632-bc08-0e2667f19f12",
|
|
"parent_id": "WARDEN-WP-0004",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0004-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Sync State Hub",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0004-repo-hygiene-and-hub-sync.md",
|
|
"uuid": "51729695-262f-4fe4-9c38-f99ee046d32a",
|
|
"parent_id": "WARDEN-WP-0004",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0005",
|
|
"status": "archived",
|
|
"title": "OpsWarden OpenBao-First Documentation Alignment",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0005-openbao-doc-alignment.md",
|
|
"uuid": "57f6ebf8-0ef3-4686-9a73-3f9d38288be9",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0005-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 OpsWardenConfig.md",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0005-openbao-doc-alignment.md",
|
|
"uuid": "bbbc4dda-9634-4c04-86e5-94b96c021b43",
|
|
"parent_id": "WARDEN-WP-0005",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0005-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Cross-reference updates",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0005-openbao-doc-alignment.md",
|
|
"uuid": "6391cb82-896e-405a-a59b-36640e6480ba",
|
|
"parent_id": "WARDEN-WP-0005",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0006",
|
|
"status": "archived",
|
|
"title": "NetKingdom Alignment and Operational Access Stewardship",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md",
|
|
"uuid": "a5c9f24b-1ad4-46da-bc8e-b99897f8e302",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0006-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Credential routing runbook",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md",
|
|
"uuid": "ffc6a0c2-4312-4584-be7a-c8411cb01899",
|
|
"parent_id": "WARDEN-WP-0006",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0006-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Actor inventory patterns",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md",
|
|
"uuid": "3816463d-7dfd-469d-9324-fd7880b50608",
|
|
"parent_id": "WARDEN-WP-0006",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0006-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 NetKingdom cross-links (ops-warden side)",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md",
|
|
"uuid": "f158366a-5746-48b8-acce-472dce8f925e",
|
|
"parent_id": "WARDEN-WP-0006",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0006-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 NetKingdom canon patch (coordination)",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md",
|
|
"uuid": "e40e4395-8f01-4f79-a539-d0de8e427321",
|
|
"parent_id": "WARDEN-WP-0006",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0006-T05",
|
|
"status": "done",
|
|
"title": "T5 \u2014 OpenBao SSH engine operational checklist",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md",
|
|
"uuid": "a94e20a2-970b-4a0c-bd23-8510b841b938",
|
|
"parent_id": "WARDEN-WP-0006",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0006-T06",
|
|
"status": "done",
|
|
"title": "T6 \u2014 Policy-gated signing design (design only)",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md",
|
|
"uuid": "b10a4b4d-bfa1-4f49-b6a5-f339f1e6a2e1",
|
|
"parent_id": "WARDEN-WP-0006",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0006-T07",
|
|
"status": "done",
|
|
"title": "T7 \u2014 Re-assess INTENT \u2194 SCOPE",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md",
|
|
"uuid": "ef8b5c57-2343-4cfc-9fee-48db1e56f69a",
|
|
"parent_id": "WARDEN-WP-0006",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0007",
|
|
"status": "archived",
|
|
"title": "Policy Gate and Production OpenBao Verification",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0007-policy-gate-and-production-verify.md",
|
|
"uuid": "3718ac07-2fa2-47d0-a02a-c9a7b83a5ba9",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0007-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Production OpenBao verification evidence",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0007-policy-gate-and-production-verify.md",
|
|
"uuid": "344540ad-5912-4118-b406-450b96e13c40",
|
|
"parent_id": "WARDEN-WP-0007",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0007-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Policy config and flex-auth client",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0007-policy-gate-and-production-verify.md",
|
|
"uuid": "05424ddf-5fe9-43a1-a2f8-c47235a012c8",
|
|
"parent_id": "WARDEN-WP-0007",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0007-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 Wire policy gate into sign/issue",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0007-policy-gate-and-production-verify.md",
|
|
"uuid": "f5ae8e6e-8cce-4526-b18c-0452a135af49",
|
|
"parent_id": "WARDEN-WP-0007",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0007-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Tests and docs",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0007-policy-gate-and-production-verify.md",
|
|
"uuid": "ea921d56-033b-4619-8032-61af7992e610",
|
|
"parent_id": "WARDEN-WP-0007",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0008",
|
|
"status": "finished",
|
|
"title": "Production SSH Path and Stewardship Closeout",
|
|
"source_path": "workplans/archived/260618-WARDEN-WP-0008-production-ssh-path-and-stewardship-closeout.md",
|
|
"uuid": "a174963a-4ff1-4565-b19f-896cd4ff14a0",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0008-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Post-WP-0007 INTENT/SCOPE reassessment",
|
|
"source_path": "workplans/archived/260618-WARDEN-WP-0008-production-ssh-path-and-stewardship-closeout.md",
|
|
"uuid": "05379da4-79d0-4742-8638-9e9565cccf72",
|
|
"parent_id": "WARDEN-WP-0008",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0008-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Production OpenBao end-to-end sign verification",
|
|
"source_path": "workplans/archived/260618-WARDEN-WP-0008-production-ssh-path-and-stewardship-closeout.md",
|
|
"uuid": "b1a1831d-b2b3-4204-95f6-04dc7f29f67c",
|
|
"parent_id": "WARDEN-WP-0008",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0008-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 State Hub task status canon migration",
|
|
"source_path": "workplans/archived/260618-WARDEN-WP-0008-production-ssh-path-and-stewardship-closeout.md",
|
|
"uuid": "876827c4-4a86-4e58-9a1f-ac87045dc903",
|
|
"parent_id": "WARDEN-WP-0008",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0008-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Production config example and archive hygiene",
|
|
"source_path": "workplans/archived/260618-WARDEN-WP-0008-production-ssh-path-and-stewardship-closeout.md",
|
|
"uuid": "75b9f366-3d7a-419d-98ad-bc10ab90a697",
|
|
"parent_id": "WARDEN-WP-0008",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0008-T05",
|
|
"status": "cancel",
|
|
"title": "T5 \u2014 flex-auth policy gate production readiness (coordination)",
|
|
"source_path": "workplans/archived/260618-WARDEN-WP-0008-production-ssh-path-and-stewardship-closeout.md",
|
|
"uuid": "03b412a5-5b99-42df-a154-733dd4156000",
|
|
"parent_id": "WARDEN-WP-0008",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0009",
|
|
"status": "archived",
|
|
"title": "flex-auth Policy Gate Production Readiness",
|
|
"source_path": "workplans/archived/260623-WARDEN-WP-0009-flex-auth-policy-gate-production.md",
|
|
"uuid": "9213b262-e2f5-480e-a5bc-56635d5eb4c9",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0009-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 flex-auth policy package confirmation",
|
|
"source_path": "workplans/archived/260623-WARDEN-WP-0009-flex-auth-policy-gate-production.md",
|
|
"uuid": "f988ed2e-0f63-4e89-abc4-183a7f23ddc2",
|
|
"parent_id": "WARDEN-WP-0009",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0009-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Production enablement and smoke",
|
|
"source_path": "workplans/archived/260623-WARDEN-WP-0009-flex-auth-policy-gate-production.md",
|
|
"uuid": "9d0fabc2-10ef-426d-a3d2-d4970d377029",
|
|
"parent_id": "WARDEN-WP-0009",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0010",
|
|
"status": "archived",
|
|
"title": "Access Routing \u2014 Charter and Pointer Catalog",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0010-access-routing-charter.md",
|
|
"uuid": "e93de9fd-0192-4d02-bb7c-5e859fb76b9b",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0010-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 INTENT wording",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0010-access-routing-charter.md",
|
|
"uuid": "589081a6-d1f5-47b4-bec0-e82d9c3444f4",
|
|
"parent_id": "WARDEN-WP-0010",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0010-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Routing-role wiki page",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0010-access-routing-charter.md",
|
|
"uuid": "9ac333f7-5fc4-4fa2-82f3-d5ece8ff0d92",
|
|
"parent_id": "WARDEN-WP-0010",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0010-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 Pointer catalog schema + seed",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0010-access-routing-charter.md",
|
|
"uuid": "59e0f480-694a-482a-b35e-b7bc4930aa41",
|
|
"parent_id": "WARDEN-WP-0010",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0010-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Routing index in CredentialRouting.md",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0010-access-routing-charter.md",
|
|
"uuid": "aabd28c0-db2d-4267-be98-95be272c687d",
|
|
"parent_id": "WARDEN-WP-0010",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0010-T05",
|
|
"status": "done",
|
|
"title": "T5 \u2014 Registry and repo-boundary alignment",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0010-access-routing-charter.md",
|
|
"uuid": "3335a689-922c-4319-98d0-4263ab13790b",
|
|
"parent_id": "WARDEN-WP-0010",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0011",
|
|
"status": "archived",
|
|
"title": "Routing Lookup CLI",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0011-routing-guide-cli.md",
|
|
"uuid": "0a520f8e-01b4-48f1-9af3-2f3f69fd0672",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0011-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Catalog loader and models",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0011-routing-guide-cli.md",
|
|
"uuid": "55b8422c-ad3c-4084-9e00-acaa4c360906",
|
|
"parent_id": "WARDEN-WP-0011",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0011-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 `warden route list` and `show`",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0011-routing-guide-cli.md",
|
|
"uuid": "60b679c5-79bd-4186-b5a6-ac576931f06c",
|
|
"parent_id": "WARDEN-WP-0011",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0011-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 `warden route find`",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0011-routing-guide-cli.md",
|
|
"uuid": "d307701f-0117-44f0-80fd-ca6f7ae06f42",
|
|
"parent_id": "WARDEN-WP-0011",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0011-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Tests",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0011-routing-guide-cli.md",
|
|
"uuid": "00a76e0f-8ab6-4f9a-ac6a-00eae633342c",
|
|
"parent_id": "WARDEN-WP-0011",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0011-T05",
|
|
"status": "done",
|
|
"title": "T5 \u2014 Doc consistency + drift guard",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0011-routing-guide-cli.md",
|
|
"uuid": "bf848375-eca7-4116-bb1d-fb7df6395c70",
|
|
"parent_id": "WARDEN-WP-0011",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0013",
|
|
"status": "archived",
|
|
"title": "Production Integration & Stewardship Closeout",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md",
|
|
"uuid": "4678c41a-c1d0-48cd-9988-4ea0380e8258",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0013-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Post-gap reassessment and SCOPE refresh",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md",
|
|
"uuid": "de46f9a2-bf11-4651-a23c-430c63f396c8",
|
|
"parent_id": "WARDEN-WP-0013",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0013-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Archive hygiene (WP-0010, WP-0011)",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md",
|
|
"uuid": "1b35321d-63ad-40da-a1aa-0b66190a0733",
|
|
"parent_id": "WARDEN-WP-0013",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0013-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 ops-bridge cert_command migration playbook",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md",
|
|
"uuid": "ad8588b2-9ae9-4f94-bd77-8025851a38f5",
|
|
"parent_id": "WARDEN-WP-0013",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0013-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Operator OpenBao token hygiene runbook",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md",
|
|
"uuid": "5cb35829-32eb-4d59-97a1-f4d92ce8e239",
|
|
"parent_id": "WARDEN-WP-0013",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0013-T05",
|
|
"status": "done",
|
|
"title": "T5 \u2014 Principals inventory drift check",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md",
|
|
"uuid": "4025cd32-89f8-42c3-b1e8-eaf78497d91f",
|
|
"parent_id": "WARDEN-WP-0013",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0013-T06",
|
|
"status": "done",
|
|
"title": "T6 \u2014 Policy gate production enablement checklist",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md",
|
|
"uuid": "51663f65-79cb-4108-87c8-9721f9476259",
|
|
"parent_id": "WARDEN-WP-0013",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0012",
|
|
"status": "finished",
|
|
"title": "Routing Scenario Playbooks",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0012-routing-scenario-playbooks.md",
|
|
"uuid": "a7e712a0-02f8-4f83-944e-6b207e77bc4c",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0012-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 issue-core ingestion key playbook",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0012-routing-scenario-playbooks.md",
|
|
"uuid": "830bb512-0288-4dba-9dd4-ccfd28a4921f",
|
|
"parent_id": "WARDEN-WP-0012",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0012-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Inter-Hub and bootstrap lanes",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0012-routing-scenario-playbooks.md",
|
|
"uuid": "7726a703-6e00-4e49-9380-ed3fb3268827",
|
|
"parent_id": "WARDEN-WP-0012",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0012-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 ops-bridge tunnel migration",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0012-routing-scenario-playbooks.md",
|
|
"uuid": "9fb397f0-0abb-48f5-bb62-7e77edae93bb",
|
|
"parent_id": "WARDEN-WP-0012",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0012-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Platform secret scenarios (LLM, STS, DB)",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0012-routing-scenario-playbooks.md",
|
|
"uuid": "edcf4ed7-f18d-4a92-a42d-8cc7ca0ab792",
|
|
"parent_id": "WARDEN-WP-0012",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0012-T05",
|
|
"status": "done",
|
|
"title": "T5 \u2014 Drift review cadence",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0012-routing-scenario-playbooks.md",
|
|
"uuid": "db98d655-8551-487b-9413-41bf97fc06e1",
|
|
"parent_id": "WARDEN-WP-0012",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0014",
|
|
"status": "finished",
|
|
"title": "Operator Access Assist \u2014 warden access front door",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0014-operator-access-assist.md",
|
|
"uuid": "3c30b2ed-6ede-4b95-a438-fde6da6f6633",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0014-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Catalog schema: structured handoff fields",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0014-operator-access-assist.md",
|
|
"uuid": "abb0e722-6524-4224-8638-6ee1573ed3e0",
|
|
"parent_id": "WARDEN-WP-0014",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0014-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 `warden access` advisory surface",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0014-operator-access-assist.md",
|
|
"uuid": "c1497263-7124-459f-b63a-d0c0c7005c86",
|
|
"parent_id": "WARDEN-WP-0014",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0014-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 OpenBao proxy lane (`--fetch` / `--exec`)",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0014-operator-access-assist.md",
|
|
"uuid": "6d3eb0e4-309c-4065-893e-6c4053fb0db2",
|
|
"parent_id": "WARDEN-WP-0014",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0014-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 key-cape / login orchestration lane",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0014-operator-access-assist.md",
|
|
"uuid": "481997e4-193d-4724-84a6-61cbc2940153",
|
|
"parent_id": "WARDEN-WP-0014",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0014-T05",
|
|
"status": "done",
|
|
"title": "T5 \u2014 Docs, security model, and INTENT/SCOPE alignment",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0014-operator-access-assist.md",
|
|
"uuid": "a5eb616e-4edf-42db-a4fb-bf296cdb92bc",
|
|
"parent_id": "WARDEN-WP-0014",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0015",
|
|
"status": "finished",
|
|
"title": "Workload Security Posture \u2014 env posture \u00d7 maturity + conformance",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0015-secret-lifecycle-tiering.md",
|
|
"uuid": "99f4a0e1-853c-456f-8aa7-8ff0f318ea65",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0015-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Author the two-axis Workload Security Posture standard (canon-bound)",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0015-secret-lifecycle-tiering.md",
|
|
"uuid": "85aeb676-a593-4056-986a-db14d4c5209f",
|
|
"parent_id": "WARDEN-WP-0015",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0015-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Machine-readable posture descriptors (both axes)",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0015-secret-lifecycle-tiering.md",
|
|
"uuid": "011fb0af-154d-40f4-a03e-3172c325321a",
|
|
"parent_id": "WARDEN-WP-0015",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0015-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 Conformance checker (incl. secret-flow lattice)",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0015-secret-lifecycle-tiering.md",
|
|
"uuid": "c1a0e987-19d0-478e-ac08-2dbe98e64e09",
|
|
"parent_id": "WARDEN-WP-0015",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0015-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Dev-tier contract-double fixture library",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0015-secret-lifecycle-tiering.md",
|
|
"uuid": "e556fd2e-4e39-4c7d-bd94-b4330e4bef45",
|
|
"parent_id": "WARDEN-WP-0015",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0015-T05",
|
|
"status": "done",
|
|
"title": "T5 \u2014 INTENT/SCOPE alignment + canon contributions",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0015-secret-lifecycle-tiering.md",
|
|
"uuid": "298c9b09-4a5a-41bf-a3bd-6c572385236b",
|
|
"parent_id": "WARDEN-WP-0015",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-ADHOC-2026-07-07",
|
|
"status": "finished",
|
|
"title": "Ad Hoc Tasks \u2014 2026-07-07",
|
|
"source_path": "workplans/archived/260707-ADHOC-2026-07-07.md",
|
|
"uuid": "90568b1e-8395-5c67-9c69-851ed08ff3d3",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-ADHOC-2026-07-07-T01",
|
|
"status": "done",
|
|
"title": "T01 \u2014 Roll out proxy pipe fix (be3b4a2)",
|
|
"source_path": "workplans/archived/260707-ADHOC-2026-07-07.md",
|
|
"uuid": "bf985c95-bea6-5057-94f9-9cfa7e1c9dd8",
|
|
"parent_id": "WARDEN-WP-ADHOC-2026-07-07",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "intake",
|
|
"id": "WARDEN-IN-0001",
|
|
"status": "closed",
|
|
"title": "Assent requested: Staff layer, doctrine vs runbook, and the access lane/rule demarcation",
|
|
"source_path": "intakes/intakes.md",
|
|
"uuid": "01a049ed-bbbc-7520-bc7c-6b0912ca534a",
|
|
"parent_id": null,
|
|
"extra": {
|
|
"record": {
|
|
"id": "WARDEN-IN-0001",
|
|
"kind": "intake",
|
|
"title": "Assent requested: Staff layer, doctrine vs runbook, and the access lane/rule demarcation",
|
|
"status": "closed",
|
|
"outcome": "assented",
|
|
"origin": "cross-repo",
|
|
"origin_ref": "gate-house GH-DEC-2026-001",
|
|
"priority": "medium",
|
|
"owner": "ops-warden",
|
|
"requested_by": "gate-house",
|
|
"standard": "net-kingdom/canon/standards/security-layer-model_v0.1.md",
|
|
"description": "gate-house asks ops-warden to assent to three boundary items. (1) ops-warden is Staff, bound by the rule that Staff acts only through Engine APIs and never touches Tooling directly (standard section 5). (2) Doctrine versus runbook: the NetKingdom Security Literacy section in ops-warden INTENT is evidence the security curriculum had no owner; it now has one in gate-house. Proposal is that doctrine and curriculum move to gate-house and that section becomes lane-specific runbooks referencing gate-house doctrine rather than restating it. ops-warden keeps the lanes it stewards and everything operational about them. (3) The access lane/rule demarcation, normative in standard section 8: ops-warden and ops-mason own access lanes \u2014 how a worker reaches a host; access-engine owns access rules \u2014 whether they may. This demarcation is the condition attached to renaming flex-auth to access-engine, so ops-warden effectively holds a veto on that name. Also requested: add gate-house to the Security Literacy and routing tables \u2014 currently every plane is listed and gate-house appears nowhere \u2014 routing doctrine and authority-model questions there while continuing to route policy decisions to access-engine. If moving the curriculum out leaves ops-warden unable to instruct its own workers, say so; the boundary is wrong if it does.",
|
|
"notes": "Assented to all three items in ADR-0010, with reasoning in history/2026-08-28-security-layer-model-assent.md. (1) Staff accepted; the section 5 binding rule exposed a real non-conformance \u2014 src/warden/vault.py is a direct OpenBao client performing a write, as is warden desk's bao kv put. Declared in INTENT.md as an engine gap with intended owner secrets-engine and blocker \"no engine exposes an SSH-CA surface\", not negotiated as an exemption; taint.py declared under the read-only allowance; warden access proxies run under the caller's identity. An amendment is offered back to gate-house: a second sanctioned shape in section 5 for a declared engine gap carrying intended owner, blocker and review date, machine-readable so section 10 can tell a tracked gap from an undeclared violation. (2) Doctrine versus runbook accepted; the literacy section is now a lane routing runbook referencing gate-house doctrine. Answering gate-house's test question: it does not leave ops-warden unable to instruct its workers, because what instructs them is warden plan / warden route and .claude/rules/credential-routing.md, which stays inline by design. (3) The lane/rule demarcation assented unconditionally and the access-engine veto not exercised \u2014 ops-warden already consumes decisions and renders none. One request on sequencing only: a deprecation window in which both names resolve (598 references across 82 files here). gate-house added to the routing tables in INTENT.md and SCOPE.md.",
|
|
"created": "2026-08-28T19:30:28.087109Z",
|
|
"updated": "2026-08-28T21:05:00Z",
|
|
"state_hub_intake_id": "01a049ed-bbbc-7520-bc7c-6b0912ca534a"
|
|
}
|
|
}
|
|
},
|
|
{
|
|
"kind": "intake",
|
|
"id": "WARDEN-IN-0002",
|
|
"status": "open",
|
|
"title": "Review requested: security layer model v0.3 \u2014 and does maturity-engine absorb warden route gaps?",
|
|
"source_path": "intakes/intakes.md",
|
|
"uuid": "01a04d97-94cd-7b49-8019-a91c7fce8adb",
|
|
"parent_id": null,
|
|
"extra": {
|
|
"record": {
|
|
"id": "WARDEN-IN-0002",
|
|
"kind": "intake",
|
|
"title": "Review requested: security layer model v0.3 \u2014 and does maturity-engine absorb warden route gaps?",
|
|
"status": "open",
|
|
"origin": "cross-repo",
|
|
"origin_ref": "net-kingdom security-layer-model_v0.3",
|
|
"priority": "medium",
|
|
"owner": "ops-warden",
|
|
"requested_by": "gate-house",
|
|
"description": "v0.3 is proposed and changes sections 4, 9 and 13 only; the v0.2 assent record stands. Two new engines: approval-engine (section 9.4) and maturity-engine (section 9.5). THE QUESTION FOR YOU concerns section 5.3, which exists because you offered the amendment. v0.3 gives declared gaps an owner: maturity-engine takes the gap register with intended_owner, blocked_on and review dates, and section 13 now says the register in the standard is interim and should not outlive that engine. You offered warden route gaps and the 27 delegation catalog entries as reusable prior art. So the question is whether that machinery should MOVE, be MIRRORED, or STAY. Our tentative reading, which we want tested rather than accepted: routing is yours and stays yours \u2014 warden route find answers where a credential need goes, and that is lane knowledge, not maturity. What might move is the readiness half: whether a declared gap is still within its review date, and whether an intended owner has an engine surface yet. If splitting those creates two sources for one fact, that is worse than either option and we would rather hear it now. Your SSH-CA signing write would be tracked in maturity-engine as a declared gap with intended owner secrets-engine and a review date \u2014 that is reporting your own non-conformance to an engine, so we would rather you assent to it than discover it. Also note approval-engine (section 9.4): it owns the approval object, not the approval workflow, so ops-warden lanes needing approval consume a claim rather than implementing one. Assent, revision, or rejection acceptable.",
|
|
"created": "2026-08-28T20:40:24.957468Z",
|
|
"updated": "2026-08-28T20:40:24.957468Z",
|
|
"state_hub_intake_id": "01a04d97-94cd-7b49-8019-a91c7fce8adb"
|
|
}
|
|
}
|
|
}
|
|
],
|
|
"events": [
|
|
{
|
|
"type": "repo.reconciled",
|
|
"workplan_count": 41,
|
|
"task_count": 183,
|
|
"source": "repo-manager",
|
|
"emitted_at": "2026-08-31T22:59:28.638627Z"
|
|
}
|
|
]
|
|
}
|