ops-warden/history
tegwick 654c05dece
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
WARDEN-WP-0031 T04: prove ops-warden's caller identity against the live pin
flex-auth's binding names system:serviceaccount:ops-warden:ops-warden, and that
ServiceAccount did not exist. deploy/kubernetes/caller-identity.yaml creates it
plus its namespace — no RBAC, automount off; it is never used to call the
Kubernetes API, only to be TokenReviewed. Applied to the railiance01 cluster.

Operator warden.yaml now uses caller_auth mode: command (kubectl create token,
audience flex-auth, 10m). Gate exits 0 live against a port-forward of the pin:
HTTP 200, effect=allow, decision:f3f7c88f9585582a.

The evidence is not that allow — warn allows anonymous callers too. It is that
the pin's "caller authentication warning" count held at 4 across two
authenticated runs. That is the ADHOC-2026-08-17-T01 condition.

Also gives the readiness probe a structurally complete context, so a deny means
the policy said no rather than the probe being malformed.

policy.enabled stays false. T05 waits on flex-auth setting callerAuth.mode:
enforce (their FLEX-WP-0016 T03).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 19:06:04 +02:00
..
2026-06-17-intent-scope-assessment.md Define INTENT, refresh SCOPE, and plan NetKingdom stewardship 2026-06-17 08:20:32 +02:00
2026-06-17-intent-scope-reassessment.md WARDEN-WP-0006: NetKingdom stewardship docs and alignment 2026-06-17 08:22:45 +02:00
2026-06-17-openbao-production-verify.md chore(WP-0008): finish and archive production SSH path closeout 2026-06-18 01:28:49 +02:00
2026-06-17-post-wp0007-reassessment.md chore(WP-0008): finish and archive production SSH path closeout 2026-06-18 01:28:49 +02:00
2026-06-18-access-routing-intent-shift-assessment.md docs(WP-0010): rewire INTENT to "issue SSH, route the rest"; add access-routing plan 2026-06-18 20:07:01 +02:00
2026-06-18-post-wp0008-intent-scope-reassessment.md docs: post-WP-0008 INTENT↔SCOPE reassessment and gap snapshot 2026-06-18 01:36:23 +02:00
2026-06-23-flex-auth-policy-gate-local-smoke.md feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
2026-06-23-flex-auth-policy-gate-production-smoke.md feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
2026-06-23-flex-auth-production-pickup-suggestion.md feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
2026-06-24-intent-scope-gap-analysis.md feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
2026-06-24-ops-bridge-cert-command-pilot-coordination.md feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
2026-06-27-operator-access-assist-charter.md docs(WARDEN-WP-0014): T5 — assist-layer docs, security model, INTENT/SCOPE 2026-06-27 17:35:57 +02:00
2026-06-27-workload-security-posture-charter.md Clarify workload secret posture stewardship 2026-06-27 18:22:09 +02:00
2026-07-01-intent-scope-gap-analysis.md Add July INTENT↔SCOPE gap analysis and WARDEN-WP-0023 alignment closeout 2026-07-01 23:27:14 +02:00
2026-07-16-credential-disclosure-lessons.md WARDEN-WP-0026 T01: capabilities-safe lane verification + incident note 2026-07-16 14:26:05 +02:00
2026-08-11-delegation-surface-assessment.md Classify 5 proxy lanes interim; hold 6 pending secrets-engine 2026-08-12 01:33:29 +02:00
2026-08-19-flex-auth-caller-identity-evidence.md WARDEN-WP-0031 T04: prove ops-warden's caller identity against the live pin 2026-08-19 19:06:04 +02:00