ops-warden/wiki/playbooks
tegwick baf53602ca Revert the npm field, re-measure coverage, and hold the layer divergence
Five inbox items worked, none of which changed a credential value or moved a
secret.

whynot-design-npm-publish: field reverted npm_token -> NPM_AUTH_TOKEN and the
path confirmed, on railiance-platform's attended, read-only, no-value field
enumeration (their docs/evidence/2026-09-10-npm-lane-field-resolution.json).
Exactly one field is present at the governed path. The 2026-09-09 change was
adopted from a coordination message and would have failed at the WP-0037-T03
rotation. The ungoverned second location is recorded as an explicit non-lane,
not deleted and not tidied away.

pep-stance coverage: published figures were stale by eight lanes (unknown
18->20, not_applicable 12->15) while resolved stayed at 3 — the denominator
moved, the classification did not. Caught by the test that asserts the published
block equals what report_coverage.py measures. tests/test_workload_join.py held
the same stale counts; both now measure the same populations.

rapp-qonto-keycape-client: blocker character updated — authority exists and is
unexercised by owner decision ("not yet", offer open), which is not the same as
no authority existing. Reopen triggers are events, never elapsed time.

flex-auth -> access-engine rename (WARDEN-IN-0003): access-engine added to the
policy-check lane's keywords so routing resolves under both names from today.
owner_repo deliberately not flipped — policy.py sends it as resource.system on
every /v1/check, and FLEX-DEC-2026-013 keeps runtime names as flex-auth.

layer declaration: INTENT.md says Staff, layer.yaml says staff, section 11 does
not say which governs. Neither changed; gate-house holds the ruling. Position in
docs/layer-declaration-precedence.md, wait in WARDEN-WP-0034-T06, and a comment
in layer.yaml telling the next session not to "fix" it — the divergence is the
evidence the ruling is made against.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
2026-09-21 02:16:33 +02:00
..
activity-core-issue-sink.md Refresh the activity-core issue-sink lane; close WP-0032-T01 2026-08-21 00:43:42 +02:00
agent-harness-secrets.md WARDEN-WP-0029: implement plan front door, org posture, desk, freshness 2026-07-18 16:59:37 +02:00
agent-read-boundary.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
audit-core-senders.md Add draft routing entry audit-core-senders 2026-08-13 10:27:13 +02:00
binky-company-email-imap.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
binky-qonto-api.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
catalog-lane-promotion.md Ship WARDEN-WP-0030: delegation register for every catalog lane 2026-08-15 20:54:58 +02:00
coulomb-social-runtime-env.md Note apps-pg live and coulomb-social DB connectivity in playbook 2026-08-09 02:18:17 +02:00
database-dynamic-credentials.md Route dynamic database credentials to rapp-postgres 2026-08-10 19:37:05 +02:00
email-connect-transactional.md Route email-connect transactional SMTP and ingest token. 2026-08-12 13:32:11 +02:00
exposed-taint.md WARDEN-WP-0026 finish Strand A (T04/T05/T07) 2026-07-16 23:26:26 +02:00
flex-auth-decision-envelope-signing-key.md Draft the flex-auth envelope-signing credential route. 2026-09-14 09:59:11 +02:00
forgejo-admin-api-token.md WARDEN-WP-0029: implement plan front door, org posture, desk, freshness 2026-07-18 16:59:37 +02:00
informed-decision-sitting-requester-login.md Point sitting-create at the attended-exec wrapper. 2026-09-15 22:31:44 +02:00
issue-core-ingestion-api-key.md Promote issue-core-ingestion-api-key and openrouter-llm-connect lanes to active 2026-07-02 20:48:39 +02:00
net-kingdom-sso-bind-credentials.md Add NetKingdom SSO credential routing lanes 2026-08-23 21:43:12 +02:00
netkingdom-layer-declaration.md feat: complete local layer model v0.7 conformance work 2026-09-05 01:19:48 +02:00
object-storage-sts.md Complete WARDEN-WP-0012 routing scenario playbooks 2026-06-25 10:27:23 +02:00
openbao-platform-admin-login.md fix: contain attended OpenBao login output 2026-08-23 01:31:05 +02:00
openbao-shamir-recovery-ceremony.md fix: route OpenBao recovery ceremonies safely 2026-08-22 20:54:45 +02:00
openrouter-llm-connect.md Retire CoulombCore references; correct the 16443 diagnosis 2026-08-19 19:31:41 +02:00
operator-openbao-token-hygiene.md Add ops-warden-warden-sign-token routing lane for RAILIANCE-WP-0005 T08 2026-07-01 23:16:38 +02:00
ops-bridge-tunnel-cert.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
ops-warden-warden-sign-token.md Add ops-warden-warden-sign-token routing lane for RAILIANCE-WP-0005 T08 2026-07-01 23:16:38 +02:00
policy-nexus-forgejo-source-read.md feat: route Policy Nexus source credential 2026-09-01 00:46:28 +02:00
railiance-backup-offsite-lane.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
rein-openweights-openrouter-approle.md Promote rein-openweights-openrouter-approle: draft -> active 2026-07-27 01:51:57 +02:00
reuse-surface-hub-write-token.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
scaleway-bootstrap.md catalog: draft scaleway-bootstrap lane 2026-08-14 17:36:17 +02:00
scheduled-worker.md feat(WARDEN-WP-0021): T3-T5 — visibility, approve loop, runbook (scheduled worker complete) 2026-06-30 15:24:10 +02:00
secrets-engine-approval-client-login.md Route attended approval-client login to scoped OpenBao reader 2026-09-14 01:46:46 +02:00
secrets-engine-requester-login.md Route attended T03 requester login to scoped owner reader 2026-09-14 02:47:32 +02:00
state-hub-forge-derivation-read.md Register the State Hub Forgejo derivation-read routing lane. 2026-09-14 04:57:55 +02:00
tenant-secret-onboarding.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
whynot-design-npm-publish.md Revert the npm field, re-measure coverage, and hold the layer divergence 2026-09-21 02:16:33 +02:00