ops-warden/workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md
codex 186fa99f58
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
fix(workplans): adopt ADR-007 derived identifiers for unregistered records
These workplans exist only in the retired local hub. Their random pre-ADR-007
identifiers are refused by C-06 as stale references, so they cannot be
registered. Deriving from the canonical record id takes no identity from
anything: central does not hold them and the old ids die with the cache.

Records central already holds were deliberately left untouched.

Refs CUST-WP-0068-T06

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-25 20:16:12 +02:00

159 lines
5.9 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

---
id: WARDEN-WP-0029
type: workplan
title: "Policy front door: posture-aware access planning + founder interaction surface"
domain: infotech
repo: ops-warden
status: finished
owner: codex
topic_slug: custodian
planning_priority: high
planning_order: 29
created: "2026-07-18"
updated: "2026-07-18"
state_hub_workstream_id: "bbb3d9ec-d88d-5088-b4c0-55bfba0a10cf"
---
# WARDEN-WP-0029 — Policy front door + founder interaction surface
## Origin
Founder directive 2026-07-18 (binky-control cutover prep): agents proposed
raw credential mechanics to the founder ("attach the deploy key in the
forgejo UI", "save the PAT to /tmp/...") although a catalogued lane
(`forgejo-admin-api-token`, WARDEN-WP-0025) already covered the need — the
installed CLI's catalog was stale, and nothing forced the ask-warden-first
step. Directive: **ops-warden is the service to ask what can and needs to be
done** per NetKingdom policy; the founder is bothered only when policy makes
it absolutely necessary, and then preferably via a purpose-built interaction
surface, not CLI/file handoffs. The organization is in **build phase** and
ops-warden must know that posture. INTENT.md principles 7 and 8 (added with
this workplan) capture the direction.
## Goal
1. `warden plan "<need>"` — a policy decision front door: given a need, answer
*autonomous / founder-act-required / unroutable*, with the exact commands
or the exact founder act, posture-stated.
2. Declared **organization posture** (`build`) as a **third axis** beside env
posture (dev/test/prod) and workload maturity (M0M3).
3. A **founder interaction surface**: local web page for the rare founder
acts (approve, OIDC-login prompt, paste-once secret capture straight into
OpenBao) — no values through CLI history or files.
4. Catalog freshness + agent guidance so ask-warden-first is the enforced
default.
## Design constraints (optimized 2026-07-18)
- **Compose, do not fork:** `warden plan` must call the routing catalog +
`expand_handoff` / `resolvable`; it must not re-implement keyword matching
or invent a second catalog.
- **Org posture is a third axis:** do not overload env posture or maturity.
- **Desk MVP is build-phase only:** localhost, OS-session trust, stdlib HTTP
server (pattern: net-kingdom `security-bootstrap-console`). No core-hub /
whynot dependency for v1.
- **Reuse map (reuse.coulomb.social):** flex-auth (policy-evaluate), key-cape
(OIDC act), net-kingdom bootstrap console (localhost desk shape),
railiance-platform (OpenBao custody). Do not rebuild those owners.
## Delivery sequence
```text
T02 (org posture) ─┐
T05 (catalog freshness) ─┼─→ T01 (warden plan composes both)
T04 (playbook sweep) ───┘ (parallel once plan shape known)
T03 (desk) ← after T01 can emit founder_required with a typed act
```
T05 is high priority: catalog staleness was the incident root cause.
## Tasks
### T02 — Declared organization posture (build phase)
```task
id: WARDEN-WP-0029-T02
status: done
priority: high
state_hub_task_id: "6c213024-6601-5116-b52f-d6711dc0587d"
```
Added `organization_posture: build` as axis C in
`registry/policy/security-posture.yaml` (relaxations + graduation triggers).
Surfaced in `warden policy list/show`, scorecard, and `warden plan` output.
### T05 — Catalog freshness + agent guidance
```task
id: WARDEN-WP-0029-T05
status: done
priority: high
state_hub_task_id: "c82d8745-4af4-5b89-ab49-06d8a902e592"
```
`Catalog.freshness()` reports source (repo/bundled/override), content hash,
mtime, package version, stale entry count, and warnings for bundled fallback.
Human `warden route list` prints catalog line; plan JSON embeds `catalog`.
Scorecard check `catalog_freshness`. AGENTS.md + credential-routing rules
require `warden plan` before founder credential steps.
### T01 — `warden plan` decision front door
```task
id: WARDEN-WP-0029-T01
status: done
priority: high
state_hub_task_id: "34db38fa-cb99-5ced-9a12-85176a7f2b44"
```
`warden plan "<need>" [--actor] [--domain] [--json]` composes catalog find +
handoff + org posture + policy gate. Verdicts: `autonomous` /
`founder_required` (`oidc_login` | `approve` | `paste_once_provision`) /
`unroutable` (CCR stub). Metadata-only audit. Module: `src/warden/plan.py`.
### T04 — Retire file-drop patterns from playbooks
```task
id: WARDEN-WP-0029-T04
status: done
priority: medium
state_hub_task_id: "717f57da-fbc4-5a4d-9f8c-c1c3fa75e0ee"
```
`wiki/playbooks/forgejo-admin-api-token.md` rewritten: plan-first, sanctioned
transports (`--exec`/`--out`/`--wrap`), desk paste-once for provision; `/tmp`
file drops marked retired. Consumer follow-ups noted for railiance-platform
and binky-control docs.
### T03 — Founder interaction surface (local web approval page)
```task
id: WARDEN-WP-0029-T03
status: done
priority: medium
state_hub_task_id: "47c781d2-768b-5777-b971-b5227fe41f5c"
```
`warden desk` — loopback `ThreadingHTTPServer`, short-lived token URL, acts
approve / oidc_login / paste_once_provision (bao kv put via stdin, dry-run
supported). Metadata-only audit open/close. Module: `src/warden/desk.py`.
## Acceptance
- [x] `warden plan "forgejo deploy key for binky-control"``autonomous` /
`agent-harness-forgejo-deploy` with access commands
- [x] Provision-style needs → `founder_required` with typed founder act
- [x] Posture `build` in plan + policy + scorecard
- [x] Desk approve flow (unit) with zero secrets in audit
- [x] No in-repo playbook instructs founder file drop as steady state
- [x] Catalog freshness on `warden route list` / plan JSON
## See also
- INTENT.md §7 (founder escalated, never tasked) and §8 (build-phase posture)
- WARDEN-WP-0025 (forgejo admin token lane), WARDEN-WP-0026/0027 (disclosure
hygiene, governance lockdown)
- reuse.coulomb.social: `capability.authorization.policy-evaluate`,
`capability.iam.key-cape`, `capability.security.iam-tooling-suite`
- binky-control DEC-2026-003 (first consumer: cutover without founder
mechanics)