ops-warden/scripts
tegwick df48ee96e0 feat: assert flex-auth ceiling keys are declared, not assumed
flex-auth fixed enrichment so registry facts beat caller-supplied ones
(FLEX-DEC-2026-012) and asked each consumer to confirm the ceiling and
allowlist keys are actually declared -- the fix wins only where the registry
HAS a value, and a manifest omitting max_ttl_hours hands that ceiling back
to the caller.

Confirmed, and made durable rather than read once.
scripts/check_flex_auth_manifest_coverage.py audits both ways a ceiling
gets handed back: an actor with no manifest resource at all (warden sign
names ssh-cert:actor/<name> whether or not the snapshot was rebuilt --
an honour-system step in SCOPE.md), and a resource missing one of the
seven keys. A null is treated as absent, because for enrichment it is.

Also asserts the property their exploitability assessment rested on and
nothing here held: ops-warden sends no resource.attributes. It was true
when they read it, secrets-engine sends them on every request, and it was
one refactor from silently stopping being true.

Current state: no gap. 4 actors, 4 resources, all seven keys declared.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013EPuTc18FjU5WFqoSEKH3C

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1276224@bnt-lap001
Assistant-Session: 426ec497-e1c4-4dd3-b417-dfce1ca1dbc3
2026-09-09 14:40:05 +02:00
..
build_flex_auth_registry.py feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
check_agent_read_boundary.py feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
check_flex_auth_manifest_coverage.py feat: assert flex-auth ceiling keys are declared, not assumed 2026-09-09 14:40:05 +02:00
check_layer_conformance.py Implement §5.3 machine-readably — layer.yaml, checker, conformance tests 2026-08-29 02:45:29 +02:00
check_policy_caller_identity.py docs: record live zone config migration 2026-08-22 15:50:42 +02:00
check_principals_drift.py feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
check_secret_posture_conformance.py feat(WARDEN-WP-0015): T3 conformance checker + T4 dev-tier contract doubles 2026-06-27 19:30:30 +02:00
check_tunnel_cert_readiness.py feat(WARDEN-WP-0016): ops-bridge cert_command readiness gate + handoff 2026-06-27 19:50:28 +02:00
emit_high_risk_paths.py feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
install-worker-timer.sh feat(WARDEN-WP-0021): T1+T2 — scheduled worker tick enabled (systemd --user timer) 2026-06-30 15:19:23 +02:00
policy_gate_production_smoke.sh feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
report_workload_join.py chore: refresh generated security inputs 2026-08-22 15:37:33 +02:00
worker-tick.sh feat(WARDEN-WP-0021): T3-T5 — visibility, approve loop, runbook (scheduled worker complete) 2026-06-30 15:24:10 +02:00