The 90-day --stale-days default on `warden route gaps` was not a loose threshold, it was an inert one: the delegation register was created 2026-08-15, so it could not have fired before November. It was inherited from the catalog pointer cadence and applied to a claim with a completely different half-life. Two changes. DEFAULT_BLOCKER_STALE_DAYS = 14 now governs interim blockers, while DEFAULT_STALE_DAYS = 90 keeps governing pointer freshness -- "is this the right owner and page" is quarterly, "has the owner answered" is not. 14 is calibrated on blockers that actually cost something: ten days for the secrets-engine lanes, one for RISK-F-0001, roughly fifty for FLEX-WP-0007. The second change matters more. `reviewed` records when someone touched an entry, which is indistinguishable from re-checking it -- six lanes read as freshly reviewed today because I typed in them. `verified:` now says how the claim was established, and asked-and-waiting explicitly does NOT count: that is the state the secrets-engine blocker sat in for ten days while looking current. A lane in that state is stale at zero days old, and key-cape-oidc-login proves it works. 8 of 14 interim lanes are honestly marked unverified rather than given a fresh date they did not earn. --fail-on-stale exits 3 for a cron or gate. No CI test on age: a date-triggered failure breaks the build for whoever commits next instead of whoever owns the blocker. The CI test is structural -- every interim lane must record how it was verified -- so it fails on the commit that introduces the omission. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
100 lines
4.9 KiB
YAML
100 lines
4.9 KiB
YAML
# GENERATED by scripts/emit_high_risk_paths.py -- do not edit by hand.
|
|
# Concrete KV data paths for lanes ops-warden grades `risk: high`.
|
|
#
|
|
# This is an INPUT, not a policy. ops-warden states which paths it grades
|
|
# high; railiance-platform owns what agent-high-risk-boundary denies and may
|
|
# deny more, deny less, or dispute a grade (ADR-0002, ADR-0008).
|
|
#
|
|
# Grades cover every field a read of the path discloses, not the field the
|
|
# lane is named after (ADR-0008). `fields` is recorded where an owning CCR
|
|
# declares it, and is null where the field set has not been established --
|
|
# null means unknown, never 'one field'.
|
|
|
|
generated_at: "2026-08-21T11:24:43Z"
|
|
source: ops-warden/registry/routing/catalog.yaml
|
|
catalog_revision: "675e04e8e67869f0e47a3ae55ab37b00112582f2"
|
|
catalog_revision_date: "2026-08-21T09:04:54+02:00"
|
|
catalog_dirty: true
|
|
high_risk_lane_count: 19
|
|
concrete_path_count: 14
|
|
|
|
# Graded high but not a single KV address -- a routing pattern, a broker
|
|
# grant, or a non-KV lane. Nothing here for a policy to deny.
|
|
no_concrete_path:
|
|
- database-dynamic-credentials
|
|
- inter-hub-bootstrap-ssh
|
|
- object-storage-sts
|
|
- openbao-api-key
|
|
- ops-warden-warden-sign-token
|
|
|
|
paths:
|
|
- id: agent-harness-binky-mail-approle
|
|
data_path: tenants/data/binky/company-email/imap
|
|
metadata_path: tenants/metadata/binky/company-email/imap
|
|
owner_repo: railiance-platform
|
|
fields: null # field set not established -- unknown, not one
|
|
- id: agent-harness-forgejo-deploy
|
|
data_path: platform/data/workloads/agent-harness/forgejo-deploy-key
|
|
metadata_path: platform/metadata/workloads/agent-harness/forgejo-deploy-key
|
|
owner_repo: railiance-platform
|
|
fields: null # field set not established -- unknown, not one
|
|
- id: audit-core-senders
|
|
data_path: platform/data/workloads/audit-core/senders
|
|
metadata_path: platform/metadata/workloads/audit-core/senders
|
|
owner_repo: ops-mason
|
|
fields: null # field set not established -- unknown, not one
|
|
- id: binky-company-email-imap
|
|
data_path: tenants/data/binky/company-email/imap
|
|
metadata_path: tenants/metadata/binky/company-email/imap
|
|
owner_repo: railiance-platform
|
|
fields: null # field set not established -- unknown, not one
|
|
- id: binky-qonto-api
|
|
data_path: tenants/data/binky/qonto-api
|
|
metadata_path: tenants/metadata/binky/qonto-api
|
|
owner_repo: railiance-platform
|
|
fields: null # field set not established -- unknown, not one
|
|
- id: email-connect-transactional
|
|
data_path: platform/data/workloads/email-connect/transactional
|
|
metadata_path: platform/metadata/workloads/email-connect/transactional
|
|
owner_repo: railiance-platform
|
|
fields: null # field set not established -- unknown, not one
|
|
- id: forgejo-admin-api-token
|
|
data_path: platform/data/workloads/forgejo/forgejo-admin
|
|
metadata_path: platform/metadata/workloads/forgejo/forgejo-admin
|
|
owner_repo: railiance-platform
|
|
fields: null # field set not established -- unknown, not one
|
|
- id: issue-core-ingestion-api-key
|
|
data_path: platform/data/workloads/issue-core/issue-core/issue-core-runtime
|
|
metadata_path: platform/metadata/workloads/issue-core/issue-core/issue-core-runtime
|
|
owner_repo: railiance-platform
|
|
fields: [ISSUE_CORE_API_KEY, GITEA_BACKEND_TOKEN]
|
|
- id: openrouter-llm-connect
|
|
data_path: platform/data/workloads/activity-core/llm-connect/llm-connect-provider-secrets
|
|
metadata_path: platform/metadata/workloads/activity-core/llm-connect/llm-connect-provider-secrets
|
|
owner_repo: railiance-platform
|
|
fields: null # field set not established -- unknown, not one
|
|
- id: railiance-backup-offsite-lane
|
|
data_path: platform/data/workloads/railiance/backup/offsite-lane
|
|
metadata_path: platform/metadata/workloads/railiance/backup/offsite-lane
|
|
owner_repo: railiance-platform
|
|
fields: null # field set not established -- unknown, not one
|
|
- id: rapp-qonto-keycape-client
|
|
data_path: platform/data/workloads/rapp-qonto/keycape-client
|
|
metadata_path: platform/metadata/workloads/rapp-qonto/keycape-client
|
|
owner_repo: key-cape
|
|
fields: null # field set not established -- unknown, not one
|
|
- id: reuse-surface-hub-write-token
|
|
data_path: platform/data/workloads/reuse/reuse-surface/runtime-secrets
|
|
metadata_path: platform/metadata/workloads/reuse/reuse-surface/runtime-secrets
|
|
owner_repo: railiance-platform
|
|
fields: [REUSE_SURFACE_TOKEN, REUSE_SURFACE_FORGEJO_WEBHOOK_SECRET]
|
|
- id: scaleway-bootstrap
|
|
data_path: platform/data/workloads/railiance/scaleway/bootstrap
|
|
metadata_path: platform/metadata/workloads/railiance/scaleway/bootstrap
|
|
owner_repo: railiance-platform
|
|
fields: null # field set not established -- unknown, not one
|
|
- id: whynot-design-npm-publish
|
|
data_path: platform/data/workloads/coulomb/whynot-design/npm-publish
|
|
metadata_path: platform/metadata/workloads/coulomb/whynot-design/npm-publish
|
|
owner_repo: railiance-platform
|
|
fields: null # field set not established -- unknown, not one
|