ops-warden/workplans
tegwick 0812d7303d feat(WARDEN-WP-0015): T2 — machine-readable posture descriptors + warden policy
Adds registry/policy/security-posture.yaml (Axis A env postures, Axis B
maturity levels M0-M3, dataclass_floor, lattice rule — no secret
material) and src/warden/posture.py: typed loader with validation
(unique/contiguous ranks, floor references known levels) and the pure
can_deliver() lattice helper (no-write-down: prod posture + workload
maturity >= secret required_maturity + dataclass floor). New `warden
policy list|show` read-only lookup mirroring `warden route`.
tests/test_posture.py covers load, the allow/deny lattice matrix,
validation rejections, and CLI. 184 passed, lint clean.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-27 18:10:54 +02:00
..
archived feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
WARDEN-WP-0012-routing-scenario-playbooks.md Complete WARDEN-WP-0012 routing scenario playbooks 2026-06-25 10:27:23 +02:00
WARDEN-WP-0014-operator-access-assist.md docs(WARDEN-WP-0014): T5 — assist-layer docs, security model, INTENT/SCOPE 2026-06-27 17:35:57 +02:00
WARDEN-WP-0015-secret-lifecycle-tiering.md feat(WARDEN-WP-0015): T2 — machine-readable posture descriptors + warden policy 2026-06-27 18:10:54 +02:00