ops-warden/history
tegwick 5b1a508610
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
docs: mark the unknown cell, measure the coverage we asked to publish
gate-house ruled the v0.8 assent round (GH-DEC-2026-011, net-kingdom@64394e9):
ask 1 declined, ask 2 adopted.

Ask 1's refusal is accepted without reservation and the reason is better than
the ask -- a sanctioned transitional fail_open is indistinguishable at runtime
from the stance the rule forbids, and would make the rule optional at the only
moment it costs anything.

Ask 2 gave §13.1 a Coverage column with this repo's figures as its first
entries. Since we asked for the column, we owe it accuracy:
scripts/report_coverage.py measures both populations from the artifacts the
runtime uses (reusing the workload-join build rather than re-deriving it), and
a test asserts pep-stance.yaml's published block equals what it measures.
A hand-counted number in a register that explicitly does not recompute it
decays silently, and a stale figure beside a marked cell is worse than the
blank the other four rows carry.

pep-stance.yaml marks the unknown cell inline as a declared gap -- assent, the
measured reason for not flipping, the declined ask, WARDEN-WP-0040 as route --
and a second test keeps it marked while it is fail_open, failing when it is
flipped. standard_version stays 0.7 because that is what binds; v0.8 is
proposed, so it gains standard_version_reviewed rather than pre-adopting.

Separately, gate-house corrected GH-DEC-2026-008: the claim/decision digest
comparison it originally required is unimplementable and a fail-closed
consumer obeying it would have denied permanently. We had never copied the
wording, so nothing to unwind -- but everything they have sent about this lane
was living in an inbox thread, a bad home for a correction that only matters
when someone finally wires the consume. Now wiki/ApprovalConsumption.md,
leading with "nothing is wired", carrying the corrected target and the
attribution gap that digest matching does not discharge.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013EPuTc18FjU5WFqoSEKH3C

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1276224@bnt-lap001
Assistant-Session: 426ec497-e1c4-4dd3-b417-dfce1ca1dbc3
2026-09-10 08:02:10 +02:00
..
2026-06-17-intent-scope-assessment.md Define INTENT, refresh SCOPE, and plan NetKingdom stewardship 2026-06-17 08:20:32 +02:00
2026-06-17-intent-scope-reassessment.md WARDEN-WP-0006: NetKingdom stewardship docs and alignment 2026-06-17 08:22:45 +02:00
2026-06-17-openbao-production-verify.md chore(WP-0008): finish and archive production SSH path closeout 2026-06-18 01:28:49 +02:00
2026-06-17-post-wp0007-reassessment.md chore(WP-0008): finish and archive production SSH path closeout 2026-06-18 01:28:49 +02:00
2026-06-18-access-routing-intent-shift-assessment.md docs(WP-0010): rewire INTENT to "issue SSH, route the rest"; add access-routing plan 2026-06-18 20:07:01 +02:00
2026-06-18-post-wp0008-intent-scope-reassessment.md docs: post-WP-0008 INTENT↔SCOPE reassessment and gap snapshot 2026-06-18 01:36:23 +02:00
2026-06-23-flex-auth-policy-gate-local-smoke.md feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
2026-06-23-flex-auth-policy-gate-production-smoke.md feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
2026-06-23-flex-auth-production-pickup-suggestion.md feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
2026-06-24-intent-scope-gap-analysis.md feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
2026-06-24-ops-bridge-cert-command-pilot-coordination.md feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
2026-06-27-operator-access-assist-charter.md docs(WARDEN-WP-0014): T5 — assist-layer docs, security model, INTENT/SCOPE 2026-06-27 17:35:57 +02:00
2026-06-27-workload-security-posture-charter.md Clarify workload secret posture stewardship 2026-06-27 18:22:09 +02:00
2026-07-01-intent-scope-gap-analysis.md Add July INTENT↔SCOPE gap analysis and WARDEN-WP-0023 alignment closeout 2026-07-01 23:27:14 +02:00
2026-07-16-credential-disclosure-lessons.md WARDEN-WP-0026 T01: capabilities-safe lane verification + incident note 2026-07-16 14:26:05 +02:00
2026-08-11-delegation-surface-assessment.md Classify 5 proxy lanes interim; hold 6 pending secrets-engine 2026-08-12 01:33:29 +02:00
2026-08-19-flex-auth-caller-identity-evidence.md Retire CoulombCore references; correct the 16443 diagnosis 2026-08-19 19:31:41 +02:00
2026-08-28-security-layer-model-assent.md Assent to the NetKingdom security layer model (WARDEN-IN-0001) 2026-08-28 21:47:44 +02:00
2026-08-29-layer-model-v04-review.md Review layer model v0.4; correct an unsound audit claim it exposes 2026-08-29 02:46:50 +02:00
2026-08-29-layer-model-v06-review.md Review layer model v0.6; publish the PEP stance map §6.4 requires 2026-08-29 10:20:49 +02:00
2026-08-29-v07-scope-intent-assessment.md Align INTENT and SCOPE to layer model v0.7; assess gaps; open WARDEN-WP-0034 2026-08-29 14:50:55 +02:00
2026-09-09-layer-model-v08-review.md docs: mark the unknown cell, measure the coverage we asked to publish 2026-09-10 08:02:10 +02:00