gate-house asked ops-warden to assent to three boundary items ratified in GH-DEC-2026-001. All three are assented in ADR-0010. Staff: accepted. Grepping section 5 as it invites turned up a real non-conformance — src/warden/vault.py is a direct OpenBao client performing a write, and so is `warden desk`'s `bao kv put`. Section 5's only escape hatch is read-only diagnostics, which does not cover a signing write, so both are declared in INTENT.md as an engine gap with intended owner secrets-engine and the blocker "no engine exposes an SSH-CA surface" — ADR-0003 turned inward rather than an exemption argued for. taint.py is metadata-only and declared under the read-only allowance; `warden access` proxies run under the caller's identity and supply no authority of their own. Doctrine versus runbook: accepted. NetKingdom Security Literacy becomes a lane routing runbook that references gate-house doctrine instead of restating it. It had also become a prose second source for registry/routing/catalog.yaml, which ADR-0001 already rules against. Lane versus rule: assented unconditionally, and the access-engine veto is not exercised. One request on sequencing only — a window where both names resolve. gate-house added to the routing tables in INTENT.md and SCOPE.md. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YWBMovyFoy9RRrfL7zKvPJ Assistant: claude-code Assistant-Model: opus Assistant-Process: 4014535@bnt-lap001 Assistant-Session: d0036016-73e8-4da1-8e47-563e3ab39a3c
2215 lines
77 KiB
JSON
2215 lines
77 KiB
JSON
{
|
|
"schema": "repo_manager.index.v1",
|
|
"slug": "layer-model-assent",
|
|
"repo_root": "/home/worsch/ops-warden",
|
|
"head_sha": "467635e84b99757336ee49d7f0dbf107607d0560",
|
|
"observed_at": "2026-08-28T19:30:29.828983Z",
|
|
"source_fingerprint": "7dfae4f3d33f6a9503a2c7326b925efb378613e772b39c4dd9b0640a35b85654",
|
|
"source_files": [
|
|
".repo-classification.yaml",
|
|
"INTENT.md",
|
|
"intakes/intakes.md",
|
|
"workplans/ADHOC-2026-06-27.md",
|
|
"workplans/ADHOC-2026-06-29.md",
|
|
"workplans/ADHOC-2026-08-11.md",
|
|
"workplans/ADHOC-2026-08-17.md",
|
|
"workplans/WARDEN-WP-0016-ops-bridge-tunnel-cert-pilot.md",
|
|
"workplans/WARDEN-WP-0017-access-front-door-discoverability.md",
|
|
"workplans/WARDEN-WP-0018-whynot-design-npm-lane-activation.md",
|
|
"workplans/WARDEN-WP-0019-route-to-secrets-engine.md",
|
|
"workplans/WARDEN-WP-0020-ops-warden-worker.md",
|
|
"workplans/WARDEN-WP-0021-enable-scheduled-worker-tick.md",
|
|
"workplans/WARDEN-WP-0022-audit-trail-and-activity.md",
|
|
"workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md",
|
|
"workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md",
|
|
"workplans/WARDEN-WP-0025-forgejo-admin-api-token-lane.md",
|
|
"workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md",
|
|
"workplans/WARDEN-WP-0027-credential-governance-lockdown.md",
|
|
"workplans/WARDEN-WP-0028-tenant-secret-custody.md",
|
|
"workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md",
|
|
"workplans/WARDEN-WP-0030-delegation-register.md",
|
|
"workplans/WARDEN-WP-0031-policy-caller-identity.md",
|
|
"workplans/WARDEN-WP-0032-security-zones.md",
|
|
"workplans/WARDEN-WP-0033-native-lane-handoff.md",
|
|
"workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"workplans/archived/260515-WARDEN-WP-0002-correctness-and-completeness.md",
|
|
"workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md",
|
|
"workplans/archived/260617-WARDEN-WP-0004-repo-hygiene-and-hub-sync.md",
|
|
"workplans/archived/260617-WARDEN-WP-0005-openbao-doc-alignment.md",
|
|
"workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md",
|
|
"workplans/archived/260617-WARDEN-WP-0007-policy-gate-and-production-verify.md",
|
|
"workplans/archived/260618-WARDEN-WP-0008-production-ssh-path-and-stewardship-closeout.md",
|
|
"workplans/archived/260623-WARDEN-WP-0009-flex-auth-policy-gate-production.md",
|
|
"workplans/archived/260624-WARDEN-WP-0010-access-routing-charter.md",
|
|
"workplans/archived/260624-WARDEN-WP-0011-routing-guide-cli.md",
|
|
"workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md",
|
|
"workplans/archived/260627-WARDEN-WP-0012-routing-scenario-playbooks.md",
|
|
"workplans/archived/260627-WARDEN-WP-0014-operator-access-assist.md",
|
|
"workplans/archived/260627-WARDEN-WP-0015-secret-lifecycle-tiering.md",
|
|
"workplans/archived/260707-ADHOC-2026-07-07.md"
|
|
],
|
|
"work_records": [
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-ADHOC-2026-06-27",
|
|
"status": "finished",
|
|
"title": "Ad Hoc Tasks \u2014 2026-06-27",
|
|
"source_path": "workplans/ADHOC-2026-06-27.md",
|
|
"uuid": null,
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-ADHOC-2026-06-27-T01",
|
|
"status": "done",
|
|
"title": "T01 \u2014 Fix stale `warden` CLI install + make it usable outside the repo",
|
|
"source_path": "workplans/ADHOC-2026-06-27.md",
|
|
"uuid": null,
|
|
"parent_id": "WARDEN-WP-ADHOC-2026-06-27",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-ADHOC-2026-06-29",
|
|
"status": "finished",
|
|
"title": "Ad Hoc Tasks \u2014 2026-06-29",
|
|
"source_path": "workplans/ADHOC-2026-06-29.md",
|
|
"uuid": null,
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-ADHOC-2026-06-29-T01",
|
|
"status": "done",
|
|
"title": "T01 \u2014 Joint-smoke mode for the deployed flex-auth (assist FLEX-WP-0007 T4)",
|
|
"source_path": "workplans/ADHOC-2026-06-29.md",
|
|
"uuid": null,
|
|
"parent_id": "WARDEN-WP-ADHOC-2026-06-29",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-ADHOC-2026-08-11",
|
|
"status": "finished",
|
|
"title": "Ad Hoc Tasks \u2014 2026-08-11",
|
|
"source_path": "workplans/ADHOC-2026-08-11.md",
|
|
"uuid": null,
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-ADHOC-2026-08-11-T01",
|
|
"status": "done",
|
|
"title": "T01 \u2014 Repair stale `rapp-qonto-keycape-client` wiki anchor (restore green routing suite)",
|
|
"source_path": "workplans/ADHOC-2026-08-11.md",
|
|
"uuid": null,
|
|
"parent_id": "WARDEN-WP-ADHOC-2026-08-11",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-ADHOC-2026-08-11-T02",
|
|
"status": "done",
|
|
"title": "T02 \u2014 Triage the stale ops-warden inbox (11 unread, C-28/C-29)",
|
|
"source_path": "workplans/ADHOC-2026-08-11.md",
|
|
"uuid": null,
|
|
"parent_id": "WARDEN-WP-ADHOC-2026-08-11",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-ADHOC-2026-08-11-T03",
|
|
"status": "done",
|
|
"title": "T03 \u2014 warden-sign AppRole: PARKED pending WP-0027 break-glass + ops-bridge cutover",
|
|
"source_path": "workplans/ADHOC-2026-08-11.md",
|
|
"uuid": null,
|
|
"parent_id": "WARDEN-WP-ADHOC-2026-08-11",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-ADHOC-2026-08-17",
|
|
"status": "finished",
|
|
"title": "Ad Hoc Tasks \u2014 2026-08-17",
|
|
"source_path": "workplans/ADHOC-2026-08-17.md",
|
|
"uuid": null,
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-ADHOC-2026-08-17-T01",
|
|
"status": "done",
|
|
"title": "T01 \u2014 Answer flex-auth: how should `/v1/check` authenticate its callers?",
|
|
"source_path": "workplans/ADHOC-2026-08-17.md",
|
|
"uuid": null,
|
|
"parent_id": "WARDEN-WP-ADHOC-2026-08-17",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-ADHOC-2026-08-17-T02",
|
|
"status": "done",
|
|
"title": "T02 \u2014 user-engine: USER_ENGINE_PROXY_SECRET stays railiance-apps; record consumer-only",
|
|
"source_path": "workplans/ADHOC-2026-08-17.md",
|
|
"uuid": null,
|
|
"parent_id": "WARDEN-WP-ADHOC-2026-08-17",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-ADHOC-2026-08-17-T03",
|
|
"status": "done",
|
|
"title": "T03 \u2014 key-cape: `rapp-qonto-keycape-client` interim accepted; refresh the blocker",
|
|
"source_path": "workplans/ADHOC-2026-08-17.md",
|
|
"uuid": null,
|
|
"parent_id": "WARDEN-WP-ADHOC-2026-08-17",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-ADHOC-2026-08-17-T04",
|
|
"status": "done",
|
|
"title": "T04 \u2014 Session hygiene",
|
|
"source_path": "workplans/ADHOC-2026-08-17.md",
|
|
"uuid": null,
|
|
"parent_id": "WARDEN-WP-ADHOC-2026-08-17",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0016",
|
|
"status": "finished",
|
|
"title": "ops-bridge cert_command pilot \u2014 readiness gate + handoff",
|
|
"source_path": "workplans/WARDEN-WP-0016-ops-bridge-tunnel-cert-pilot.md",
|
|
"uuid": "a56da8db-38bc-4bbe-8671-823360ec9245",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0016-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Read-only `cert_command` readiness preflight",
|
|
"source_path": "workplans/WARDEN-WP-0016-ops-bridge-tunnel-cert-pilot.md",
|
|
"uuid": "fea84495-dbec-480a-b42b-90e39f414b78",
|
|
"parent_id": "WARDEN-WP-0016",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0016-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Offline cert_command contract smoke",
|
|
"source_path": "workplans/WARDEN-WP-0016-ops-bridge-tunnel-cert-pilot.md",
|
|
"uuid": "e34ae1a8-2ba9-4324-8d1a-005d61dae478",
|
|
"parent_id": "WARDEN-WP-0016",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0016-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 Playbook gate + ops-bridge handoff",
|
|
"source_path": "workplans/WARDEN-WP-0016-ops-bridge-tunnel-cert-pilot.md",
|
|
"uuid": "330e01f4-4927-4280-b0e0-49d35b4416d6",
|
|
"parent_id": "WARDEN-WP-0016",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0016-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 INTENT/SCOPE alignment",
|
|
"source_path": "workplans/WARDEN-WP-0016-ops-bridge-tunnel-cert-pilot.md",
|
|
"uuid": "4726f5bb-4ffd-484f-8674-91ee5658434f",
|
|
"parent_id": "WARDEN-WP-0016",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0017",
|
|
"status": "finished",
|
|
"title": "Access front-door discoverability \u2014 stop reading as SSH-only",
|
|
"source_path": "workplans/WARDEN-WP-0017-access-front-door-discoverability.md",
|
|
"uuid": "cf8b392e-7624-4585-8935-a85e29202935",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0017-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 CLI discoverability: route role + access framing",
|
|
"source_path": "workplans/WARDEN-WP-0017-access-front-door-discoverability.md",
|
|
"uuid": "6e98df42-b5b4-49f8-a444-3c6346c8abd7",
|
|
"parent_id": "WARDEN-WP-0017",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0017-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Agent rule + SCOPE reframe",
|
|
"source_path": "workplans/WARDEN-WP-0017-access-front-door-discoverability.md",
|
|
"uuid": "6e2a7067-1afc-4f38-8d99-4d5c36a4661c",
|
|
"parent_id": "WARDEN-WP-0017",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0017-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 Federated capability registration",
|
|
"source_path": "workplans/WARDEN-WP-0017-access-front-door-discoverability.md",
|
|
"uuid": "7199625b-e78e-4495-8ca0-076100ae9f08",
|
|
"parent_id": "WARDEN-WP-0017",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0018",
|
|
"status": "finished",
|
|
"title": "Activate whynot-design npm publish lane + resolvable readiness flag",
|
|
"source_path": "workplans/WARDEN-WP-0018-whynot-design-npm-lane-activation.md",
|
|
"uuid": "1256aca2-5979-4d21-818e-0de42c5d811b",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0018-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Concrete catalog entry + playbook",
|
|
"source_path": "workplans/WARDEN-WP-0018-whynot-design-npm-lane-activation.md",
|
|
"uuid": "189d0883-22b9-42dc-bda0-89460509a87d",
|
|
"parent_id": "WARDEN-WP-0018",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0018-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 `resolvable` readiness flag + stable-id resolution",
|
|
"source_path": "workplans/WARDEN-WP-0018-whynot-design-npm-lane-activation.md",
|
|
"uuid": "b5dc1013-5334-43ff-afd6-1f99d521358f",
|
|
"parent_id": "WARDEN-WP-0018",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0018-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 Close the loop",
|
|
"source_path": "workplans/WARDEN-WP-0018-whynot-design-npm-lane-activation.md",
|
|
"uuid": "95b00ef8-477a-4f0d-bd71-6154fba401f5",
|
|
"parent_id": "WARDEN-WP-0018",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0019",
|
|
"status": "finished",
|
|
"title": "Route secret-exec lanes to secrets-engine (route-primary, proxy fallback)",
|
|
"source_path": "workplans/WARDEN-WP-0019-route-to-secrets-engine.md",
|
|
"uuid": "5e49abb6-497f-4640-a484-2da5f39a7c4e",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0019-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Catalog + CLI: surface the owner-native exec front door",
|
|
"source_path": "workplans/WARDEN-WP-0019-route-to-secrets-engine.md",
|
|
"uuid": "ea153605-7a14-4db7-8bce-d780ea143f8a",
|
|
"parent_id": "WARDEN-WP-0019",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0019-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Agent rule, SCOPE, playbook",
|
|
"source_path": "workplans/WARDEN-WP-0019-route-to-secrets-engine.md",
|
|
"uuid": "96059b8a-8938-4763-b3d0-cc5a0eb2465c",
|
|
"parent_id": "WARDEN-WP-0019",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0020",
|
|
"status": "finished",
|
|
"title": "ops-warden worker \u2014 autonomous coordination via llm-connect",
|
|
"source_path": "workplans/WARDEN-WP-0020-ops-warden-worker.md",
|
|
"uuid": "c906ba1d-f991-4fb0-b113-59432ddf87c0",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0020-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Worker scaffold (llm-connect-independent, safe)",
|
|
"source_path": "workplans/WARDEN-WP-0020-ops-warden-worker.md",
|
|
"uuid": "979c2d9b-0803-442f-aa2e-acb02bac07e9",
|
|
"parent_id": "WARDEN-WP-0020",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0020-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 llm-connect brain",
|
|
"source_path": "workplans/WARDEN-WP-0020-ops-warden-worker.md",
|
|
"uuid": "52d281b2-7d48-44f5-b77e-80e3ed500b5f",
|
|
"parent_id": "WARDEN-WP-0020",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0020-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 Action dispatch + guardrails (full-auto in-scope)",
|
|
"source_path": "workplans/WARDEN-WP-0020-ops-warden-worker.md",
|
|
"uuid": "3a71965e-42d5-4258-9761-aced804c88e7",
|
|
"parent_id": "WARDEN-WP-0020",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0020-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Scheduled trigger",
|
|
"source_path": "workplans/WARDEN-WP-0020-ops-warden-worker.md",
|
|
"uuid": "7f77ea6d-c281-42c5-ad25-2a0bb9fd68de",
|
|
"parent_id": "WARDEN-WP-0020",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0020-T05",
|
|
"status": "done",
|
|
"title": "T5 \u2014 Docs / SCOPE / INTENT",
|
|
"source_path": "workplans/WARDEN-WP-0020-ops-warden-worker.md",
|
|
"uuid": "6e7ae317-7f8b-468a-bb5c-b08093ed43a0",
|
|
"parent_id": "WARDEN-WP-0020",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0021",
|
|
"status": "finished",
|
|
"title": "Enable the scheduled worker tick \u2014 conservative inbox triage, unattended",
|
|
"source_path": "workplans/WARDEN-WP-0021-enable-scheduled-worker-tick.md",
|
|
"uuid": "8c487014-b630-4016-a4f0-31b971a473d2",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0021-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Scheduler install + enablement + kill switch",
|
|
"source_path": "workplans/WARDEN-WP-0021-enable-scheduled-worker-tick.md",
|
|
"uuid": "10451fe6-7fab-4ae0-8494-e6cfdfbcf8cf",
|
|
"parent_id": "WARDEN-WP-0021",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0021-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Scheduled-run robustness (graceful degradation)",
|
|
"source_path": "workplans/WARDEN-WP-0021-enable-scheduled-worker-tick.md",
|
|
"uuid": "1f35f816-1af5-46ff-b48c-1715f3ae5784",
|
|
"parent_id": "WARDEN-WP-0021",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0021-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 Operator visibility (see new drafts)",
|
|
"source_path": "workplans/WARDEN-WP-0021-enable-scheduled-worker-tick.md",
|
|
"uuid": "3c7f6423-8db0-4bc6-b67d-078d9d929c6d",
|
|
"parent_id": "WARDEN-WP-0021",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0021-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Review\u2192send loop (`warden worker approve`)",
|
|
"source_path": "workplans/WARDEN-WP-0021-enable-scheduled-worker-tick.md",
|
|
"uuid": "dabc9fc0-abb1-4e9d-b87e-5f0c5950693c",
|
|
"parent_id": "WARDEN-WP-0021",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0021-T05",
|
|
"status": "done",
|
|
"title": "T5 \u2014 Runbook + SCOPE",
|
|
"source_path": "workplans/WARDEN-WP-0021-enable-scheduled-worker-tick.md",
|
|
"uuid": "9915da96-1b33-4d0f-b752-408ea8d43333",
|
|
"parent_id": "WARDEN-WP-0021",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0022",
|
|
"status": "finished",
|
|
"title": "Audit trail + `warden activity` \u2014 one place to see what ops-warden did",
|
|
"source_path": "workplans/WARDEN-WP-0022-audit-trail-and-activity.md",
|
|
"uuid": "fc8afa28-68a7-4250-a19e-9754829f0cd5",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0022-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Unified audit event log",
|
|
"source_path": "workplans/WARDEN-WP-0022-audit-trail-and-activity.md",
|
|
"uuid": "7f8f768a-4c62-4096-bad8-912cea0f35a7",
|
|
"parent_id": "WARDEN-WP-0022",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0022-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Instrument the actions",
|
|
"source_path": "workplans/WARDEN-WP-0022-audit-trail-and-activity.md",
|
|
"uuid": "e7ae4037-ca79-4557-81f0-bfb8478ff647",
|
|
"parent_id": "WARDEN-WP-0022",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0022-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 `warden activity` command",
|
|
"source_path": "workplans/WARDEN-WP-0022-audit-trail-and-activity.md",
|
|
"uuid": "4439bdd8-1461-47df-8b0b-048df7384a68",
|
|
"parent_id": "WARDEN-WP-0022",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0022-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Tests, runbook, SCOPE",
|
|
"source_path": "workplans/WARDEN-WP-0022-audit-trail-and-activity.md",
|
|
"uuid": "bdfb8703-7a79-43e7-913b-19d61722f164",
|
|
"parent_id": "WARDEN-WP-0022",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0023",
|
|
"status": "finished",
|
|
"title": "INTENT\u2013SCOPE Alignment Closeout",
|
|
"source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md",
|
|
"uuid": "7bad1ec4-a7c2-4980-b8f9-49a7f5408574",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0023-T01",
|
|
"status": "done",
|
|
"title": "T01 \u2014 Persist gap analysis",
|
|
"source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md",
|
|
"uuid": "52485c90-87fe-40b1-9db5-a51ebb957dd5",
|
|
"parent_id": "WARDEN-WP-0023",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0023-T02",
|
|
"status": "done",
|
|
"title": "T02 \u2014 Refresh INTENT.md",
|
|
"source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md",
|
|
"uuid": "9a9b3631-8948-45af-ace1-c19ee74ace4d",
|
|
"parent_id": "WARDEN-WP-0023",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0023-T03",
|
|
"status": "done",
|
|
"title": "T03 \u2014 Production integration coordination pack",
|
|
"source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md",
|
|
"uuid": "26f23798-494b-45fc-baa8-af27bdffa038",
|
|
"parent_id": "WARDEN-WP-0023",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0023-T04",
|
|
"status": "done",
|
|
"title": "T04 \u2014 `warden sign` broker hint when `VAULT_TOKEN` unset",
|
|
"source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md",
|
|
"uuid": "85e324f9-273d-4740-a202-9c4e8fb122ae",
|
|
"parent_id": "WARDEN-WP-0023",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0023-T05",
|
|
"status": "done",
|
|
"title": "T05 \u2014 Catalog draft-lane promotion checklist",
|
|
"source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md",
|
|
"uuid": "82608692-2845-41e1-a498-90ed53780748",
|
|
"parent_id": "WARDEN-WP-0023",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0023-T06",
|
|
"status": "done",
|
|
"title": "T06 \u2014 SCOPE and workplan consistency",
|
|
"source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md",
|
|
"uuid": "79ca7b9a-554e-4952-9393-a29b100f6190",
|
|
"parent_id": "WARDEN-WP-0023",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0023-T07",
|
|
"status": "done",
|
|
"title": "T07 \u2014 Sequence WP-0022 audit implementation",
|
|
"source_path": "workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md",
|
|
"uuid": "1f3b3b33-974e-49bf-be4a-9d50b702c2a4",
|
|
"parent_id": "WARDEN-WP-0023",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0024",
|
|
"status": "finished",
|
|
"title": "Experiential Memory Across Worker, Agent Sessions, And OpenRouter",
|
|
"source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md",
|
|
"uuid": "5d9fafb3-f9b6-43bf-b259-5f5301daa2e9",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0024-T01",
|
|
"status": "done",
|
|
"title": "T01 - Canonical memory store and discovery",
|
|
"source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md",
|
|
"uuid": "6305f1bc-c016-4298-adc2-a07d52b6aca5",
|
|
"parent_id": "WARDEN-WP-0024",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0024-T02",
|
|
"status": "done",
|
|
"title": "T02 - Session recording hooks in CLI commands",
|
|
"source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md",
|
|
"uuid": "242a4d9a-5375-4df8-8d43-063b0491d202",
|
|
"parent_id": "WARDEN-WP-0024",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0024-T03",
|
|
"status": "done",
|
|
"title": "T03 - Memory-aware worker tick",
|
|
"source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md",
|
|
"uuid": "176fcae1-e4e5-481f-9a83-e9a7000fac1a",
|
|
"parent_id": "WARDEN-WP-0024",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0024-T04",
|
|
"status": "done",
|
|
"title": "T04 - Agent session activation helper",
|
|
"source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md",
|
|
"uuid": "16501557-6cde-44ea-bc6f-1726cb7ec070",
|
|
"parent_id": "WARDEN-WP-0024",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0024-T05",
|
|
"status": "done",
|
|
"title": "T05 - Cross-runtime continuity",
|
|
"source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md",
|
|
"uuid": "55ae679c-c08f-4afd-8646-9f5f3019f86e",
|
|
"parent_id": "WARDEN-WP-0024",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0024-T06",
|
|
"status": "done",
|
|
"title": "T06 - OpenRouter efficiency layer",
|
|
"source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md",
|
|
"uuid": "fc2dffcf-7184-4f3d-8653-d26dc18a9afc",
|
|
"parent_id": "WARDEN-WP-0024",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0024-T07",
|
|
"status": "done",
|
|
"title": "T07 - Operator and agent documentation",
|
|
"source_path": "workplans/WARDEN-WP-0024-experiential-memory-and-agent-sessions.md",
|
|
"uuid": "ca2aaf23-833f-49a6-a49b-a0b659208f5f",
|
|
"parent_id": "WARDEN-WP-0024",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0025",
|
|
"status": "finished",
|
|
"title": "Forgejo admin PAT OpenBao lane (CCR-2026-0006)",
|
|
"source_path": "workplans/WARDEN-WP-0025-forgejo-admin-api-token-lane.md",
|
|
"uuid": "70c11222-d8e7-5936-99f7-7d626a4a5deb",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0025-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Draft CCR + policy metadata",
|
|
"source_path": "workplans/WARDEN-WP-0025-forgejo-admin-api-token-lane.md",
|
|
"uuid": "2c288bf0-b39c-5f5b-ad25-eed3da826dc3",
|
|
"parent_id": "WARDEN-WP-0025",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0025-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 ops-warden catalog + playbook",
|
|
"source_path": "workplans/WARDEN-WP-0025-forgejo-admin-api-token-lane.md",
|
|
"uuid": "01b81595-f9e5-5746-b0dd-2075189cb00e",
|
|
"parent_id": "WARDEN-WP-0025",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0025-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 Platform-operator approval + metadata apply",
|
|
"source_path": "workplans/WARDEN-WP-0025-forgejo-admin-api-token-lane.md",
|
|
"uuid": "279b74d7-3240-5ca0-897d-b1ddffd23c4e",
|
|
"parent_id": "WARDEN-WP-0025",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0025-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Attended PAT provision + verification",
|
|
"source_path": "workplans/WARDEN-WP-0025-forgejo-admin-api-token-lane.md",
|
|
"uuid": "4e21232c-62a1-5115-acce-edfbcfa84e48",
|
|
"parent_id": "WARDEN-WP-0025",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0025-T05",
|
|
"status": "done",
|
|
"title": "T5 \u2014 Notify downstream consumers",
|
|
"source_path": "workplans/WARDEN-WP-0025-forgejo-admin-api-token-lane.md",
|
|
"uuid": "f8c7c70b-b9b6-5980-a25b-7f11033b81a2",
|
|
"parent_id": "WARDEN-WP-0025",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0026",
|
|
"status": "finished",
|
|
"title": "Credential disclosure hygiene + rotation guidance (Strand A)",
|
|
"source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md",
|
|
"uuid": "331c7620-bd34-5acd-9135-591985b568e5",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0026-T01",
|
|
"status": "done",
|
|
"title": "Task: Capabilities-based lane verification",
|
|
"source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md",
|
|
"uuid": "1cb22a40-b7c6-560a-a805-7766a5786dcc",
|
|
"parent_id": "WARDEN-WP-0026",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0026-T02",
|
|
"status": "done",
|
|
"title": "Task: Safe access transport (no stdout values)",
|
|
"source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md",
|
|
"uuid": "bcb7da96-0a28-5484-bf3e-06e97acf5873",
|
|
"parent_id": "WARDEN-WP-0026",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0026-T03",
|
|
"status": "done",
|
|
"title": "Task: Masking display filter (defense-in-depth)",
|
|
"source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md",
|
|
"uuid": "d90b0628-fa1d-527d-99c3-28a7ed933e52",
|
|
"parent_id": "WARDEN-WP-0026",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0026-T04",
|
|
"status": "done",
|
|
"title": "Task: Agent read-boundary on high-risk lanes",
|
|
"source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md",
|
|
"uuid": "827fa67d-5f69-5fac-bdce-9903b1b909fb",
|
|
"parent_id": "WARDEN-WP-0026",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0026-T05",
|
|
"status": "done",
|
|
"title": "Task: EXPOSED taint convention",
|
|
"source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md",
|
|
"uuid": "09ef8727-31da-59ac-aac7-2d47924569fe",
|
|
"parent_id": "WARDEN-WP-0026",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0026-T06",
|
|
"status": "done",
|
|
"title": "Task: Rotation / re-establishment guidance registry",
|
|
"source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md",
|
|
"uuid": "a2e1544e-e501-57eb-a40e-9a2147cef12a",
|
|
"parent_id": "WARDEN-WP-0026",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0026-T07",
|
|
"status": "done",
|
|
"title": "Task: Incident lessons + first worked lane (CCR-2026-0004)",
|
|
"source_path": "workplans/WARDEN-WP-0026-credential-disclosure-hygiene.md",
|
|
"uuid": "62d8286f-7954-52a8-bce6-6a16072e5246",
|
|
"parent_id": "WARDEN-WP-0026",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0027",
|
|
"status": "active",
|
|
"title": "Tamper-resistant credential governance + mass rotation/lockdown (Strand B)",
|
|
"source_path": "workplans/WARDEN-WP-0027-credential-governance-lockdown.md",
|
|
"uuid": "21528e8d-a049-523d-9ae1-da7a27cb8bbf",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0027-T01",
|
|
"status": "cancel",
|
|
"title": "Task: Executable mass rotation driver",
|
|
"source_path": "workplans/WARDEN-WP-0027-credential-governance-lockdown.md",
|
|
"uuid": "b5691939-9d84-5115-9618-0f8839010d14",
|
|
"parent_id": "WARDEN-WP-0027",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0027-T02",
|
|
"status": "progress",
|
|
"title": "Task: Graded lockdown / break-glass with explicit trust-root",
|
|
"source_path": "workplans/WARDEN-WP-0027-credential-governance-lockdown.md",
|
|
"uuid": "cae498ee-6307-5d32-9f1b-a471cfcc2536",
|
|
"parent_id": "WARDEN-WP-0027",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0027-T03",
|
|
"status": "cancel",
|
|
"title": "Task: Tamper-evident policy governance + reconcile",
|
|
"source_path": "workplans/WARDEN-WP-0027-credential-governance-lockdown.md",
|
|
"uuid": "7dbedcdc-dd5a-551c-bff1-0702fea0a9cf",
|
|
"parent_id": "WARDEN-WP-0027",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0028",
|
|
"status": "finished",
|
|
"title": "Tenant secret custody \u2014 NetKingdom pattern for client/tenant secrets",
|
|
"source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md",
|
|
"uuid": "6b66228a-199a-5b85-b5e2-a7afeaab903b",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0028-T01",
|
|
"status": "done",
|
|
"title": "T01 \u2014 Canon note: tenant secret path + ownership",
|
|
"source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md",
|
|
"uuid": "9982a884-7a50-593e-861e-cc8d2343a0ba",
|
|
"parent_id": "WARDEN-WP-0028",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0028-T02",
|
|
"status": "done",
|
|
"title": "T02 \u2014 Align binky-control integration plan to production path",
|
|
"source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md",
|
|
"uuid": "d7d7ee9d-2ecf-5492-8a13-0b747d899456",
|
|
"parent_id": "WARDEN-WP-0028",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0028-T03",
|
|
"status": "done",
|
|
"title": "T03 \u2014 Enable `tenants` mount + extend CCR tooling + policy/role",
|
|
"source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md",
|
|
"uuid": "e0b675ef-9c08-5f89-8f13-ef4249ca2364",
|
|
"parent_id": "WARDEN-WP-0028",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0028-T04",
|
|
"status": "done",
|
|
"title": "T04 \u2014 ops-warden catalog + playbook + rotation",
|
|
"source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md",
|
|
"uuid": "9405b13d-4045-519b-8e3f-79a891323397",
|
|
"parent_id": "WARDEN-WP-0028",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0028-T05",
|
|
"status": "done",
|
|
"title": "T05 \u2014 Founder provision (Red) + first scan evidence",
|
|
"source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md",
|
|
"uuid": "f17bba95-bc53-5c2a-8b44-7df9e42b2341",
|
|
"parent_id": "WARDEN-WP-0028",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0028-T06",
|
|
"status": "done",
|
|
"title": "T06 \u2014 Generalize \"tenant secret onboarding\" playbook",
|
|
"source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md",
|
|
"uuid": "76bd01a0-1d03-5ff9-8f59-a1b44763979d",
|
|
"parent_id": "WARDEN-WP-0028",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0028-T07",
|
|
"status": "done",
|
|
"title": "T07 \u2014 secrets-engine alignment decision (record only)",
|
|
"source_path": "workplans/WARDEN-WP-0028-tenant-secret-custody.md",
|
|
"uuid": "46c8f8a9-3bbe-568f-8a45-07b690874273",
|
|
"parent_id": "WARDEN-WP-0028",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0029",
|
|
"status": "finished",
|
|
"title": "Policy front door: posture-aware access planning + founder interaction surface",
|
|
"source_path": "workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md",
|
|
"uuid": "bbb3d9ec-d88d-5088-b4c0-55bfba0a10cf",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0029-T02",
|
|
"status": "done",
|
|
"title": "T02 \u2014 Declared organization posture (build phase)",
|
|
"source_path": "workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md",
|
|
"uuid": "6c213024-6601-5116-b52f-d6711dc0587d",
|
|
"parent_id": "WARDEN-WP-0029",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0029-T05",
|
|
"status": "done",
|
|
"title": "T05 \u2014 Catalog freshness + agent guidance",
|
|
"source_path": "workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md",
|
|
"uuid": "c82d8745-4af4-5b89-ab49-06d8a902e592",
|
|
"parent_id": "WARDEN-WP-0029",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0029-T01",
|
|
"status": "done",
|
|
"title": "T01 \u2014 `warden plan` decision front door",
|
|
"source_path": "workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md",
|
|
"uuid": "34db38fa-cb99-5ced-9a12-85176a7f2b44",
|
|
"parent_id": "WARDEN-WP-0029",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0029-T04",
|
|
"status": "done",
|
|
"title": "T04 \u2014 Retire file-drop patterns from playbooks",
|
|
"source_path": "workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md",
|
|
"uuid": "717f57da-fbc4-5a4d-9f8c-c1c3fa75e0ee",
|
|
"parent_id": "WARDEN-WP-0029",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0029-T03",
|
|
"status": "done",
|
|
"title": "T03 \u2014 Founder interaction surface (local web approval page)",
|
|
"source_path": "workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md",
|
|
"uuid": "47c781d2-768b-5777-b971-b5227fe41f5c",
|
|
"parent_id": "WARDEN-WP-0029",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0030",
|
|
"status": "finished",
|
|
"title": "Delegation register \u2014 make gap-covering interim, visible, and retirable",
|
|
"source_path": "workplans/WARDEN-WP-0030-delegation-register.md",
|
|
"uuid": "da3367d5-890c-52c6-aa54-1bdd0f277342",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0030-T01",
|
|
"status": "done",
|
|
"title": "T01 \u2014 Interim custodianship doctrine",
|
|
"source_path": "workplans/WARDEN-WP-0030-delegation-register.md",
|
|
"uuid": "6f88876e-434c-5718-9c8d-ec6bf64ae4aa",
|
|
"parent_id": "WARDEN-WP-0030",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0030-T02",
|
|
"status": "done",
|
|
"title": "T02 \u2014 `delegation:` metadata + backfill",
|
|
"source_path": "workplans/WARDEN-WP-0030-delegation-register.md",
|
|
"uuid": "b02e8da6-57ca-5f9f-9405-9b0624498e3a",
|
|
"parent_id": "WARDEN-WP-0030",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0030-T03",
|
|
"status": "done",
|
|
"title": "T03 \u2014 `warden route gaps` + conformance test",
|
|
"source_path": "workplans/WARDEN-WP-0030-delegation-register.md",
|
|
"uuid": "f5e0f5af-45d8-5c82-9de2-d640d7d0a1f7",
|
|
"parent_id": "WARDEN-WP-0030",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0030-T04",
|
|
"status": "done",
|
|
"title": "T04 \u2014 Promotion gate",
|
|
"source_path": "workplans/WARDEN-WP-0030-delegation-register.md",
|
|
"uuid": "b808a749-e1d7-5708-aabf-91732dd76abd",
|
|
"parent_id": "WARDEN-WP-0030",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0030-T05",
|
|
"status": "done",
|
|
"title": "T05 \u2014 Publish the register to the owners",
|
|
"source_path": "workplans/WARDEN-WP-0030-delegation-register.md",
|
|
"uuid": "b0188ec4-4860-57c8-8030-45904a132190",
|
|
"parent_id": "WARDEN-WP-0030",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0031",
|
|
"status": "finished",
|
|
"title": "Calling-side identity for flex-auth, so policy.enabled can flip",
|
|
"source_path": "workplans/WARDEN-WP-0031-policy-caller-identity.md",
|
|
"uuid": "739bad25-2345-5f4f-aaa3-cc4cd8c71f6c",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0031-T01",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0031-policy-caller-identity.md",
|
|
"uuid": "d3b7c701-bcdd-53f9-aa72-6f289bf5909b",
|
|
"parent_id": "WARDEN-WP-0031",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0031-T02",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0031-policy-caller-identity.md",
|
|
"uuid": "b77b3c80-a168-564a-9b7f-3063aefc3c2e",
|
|
"parent_id": "WARDEN-WP-0031",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0031-T03",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0031-policy-caller-identity.md",
|
|
"uuid": "4245155e-6c71-5425-b574-11f61e1d4461",
|
|
"parent_id": "WARDEN-WP-0031",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0031-T04",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0031-policy-caller-identity.md",
|
|
"uuid": "f3834af7-2a08-51dd-bf31-8ce8550de699",
|
|
"parent_id": "WARDEN-WP-0031",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0031-T05",
|
|
"status": "cancel",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0031-policy-caller-identity.md",
|
|
"uuid": "3f6dc609-89db-52eb-a6f9-d2fd271be821",
|
|
"parent_id": "WARDEN-WP-0031",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0032",
|
|
"status": "finished",
|
|
"title": "Adopt security zones as a consumer \u2014 retire the global policy.enabled",
|
|
"source_path": "workplans/WARDEN-WP-0032-security-zones.md",
|
|
"uuid": "38c6a5f3-fb0d-5230-be85-f9e3ffc850f6",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0032-T01",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0032-security-zones.md",
|
|
"uuid": "b03a5caa-0bb5-5cdd-bb99-32c694b0da29",
|
|
"parent_id": "WARDEN-WP-0032",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0032-T02",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0032-security-zones.md",
|
|
"uuid": "b3f41c85-a293-58ad-ac27-9f8110c51266",
|
|
"parent_id": "WARDEN-WP-0032",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0032-T03",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0032-security-zones.md",
|
|
"uuid": "d04a737b-ecdf-5747-ba25-20dadd99d3bc",
|
|
"parent_id": "WARDEN-WP-0032",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0032-T04",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0032-security-zones.md",
|
|
"uuid": "c7879127-3dba-55c0-853c-a10775736873",
|
|
"parent_id": "WARDEN-WP-0032",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0032-T05",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0032-security-zones.md",
|
|
"uuid": "1d968627-83f4-59cd-84ca-0f9f35e435ff",
|
|
"parent_id": "WARDEN-WP-0032",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0032-T06",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0032-security-zones.md",
|
|
"uuid": "4294084c-bf3f-5aa6-b84d-5173121882ff",
|
|
"parent_id": "WARDEN-WP-0032",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0032-T07",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0032-security-zones.md",
|
|
"uuid": "6b4bbbed-2864-5fe9-82be-22ff9543f6f4",
|
|
"parent_id": "WARDEN-WP-0032",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0033",
|
|
"status": "active",
|
|
"title": "Native lane handoff \u2014 review secrets-engine's catalog admission, and fix what it exposed",
|
|
"source_path": "workplans/WARDEN-WP-0033-native-lane-handoff.md",
|
|
"uuid": "4627d89b-4b00-562a-81e9-76e96f90fa7e",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0033-T01",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0033-native-lane-handoff.md",
|
|
"uuid": "154f2f03-387d-5fe6-a0f5-1929c46a2bd8",
|
|
"parent_id": "WARDEN-WP-0033",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0033-T02",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0033-native-lane-handoff.md",
|
|
"uuid": "6996d07f-63bb-5708-a171-68c4b1bbddde",
|
|
"parent_id": "WARDEN-WP-0033",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0033-T03",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0033-native-lane-handoff.md",
|
|
"uuid": "a736f983-94da-5a4a-aaf9-5114485518a6",
|
|
"parent_id": "WARDEN-WP-0033",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0033-T04",
|
|
"status": "wait",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0033-native-lane-handoff.md",
|
|
"uuid": "5acac140-a586-5db3-b231-bbf236710786",
|
|
"parent_id": "WARDEN-WP-0033",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0033-T05",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0033-native-lane-handoff.md",
|
|
"uuid": "75051d17-399b-5129-860b-ae00dae91c47",
|
|
"parent_id": "WARDEN-WP-0033",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0033-T06",
|
|
"status": "done",
|
|
"title": "Tasks",
|
|
"source_path": "workplans/WARDEN-WP-0033-native-lane-handoff.md",
|
|
"uuid": "94f77f5a-f919-5328-832c-ba1d24c6431b",
|
|
"parent_id": "WARDEN-WP-0033",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0001",
|
|
"status": "archived",
|
|
"title": "OpsWarden Initial Implementation",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"uuid": "c3118cc6-adfb-428c-a9c6-edd0ee152ae6",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0001-T1",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Repository bootstrap",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"uuid": "6d643e9d-5e97-4224-9d82-87267b5ba6bc",
|
|
"parent_id": "WARDEN-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0001-T2",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Models and config",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"uuid": "c66fc65a-0b16-4ba2-9e70-a83d875572ec",
|
|
"parent_id": "WARDEN-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0001-T3",
|
|
"status": "done",
|
|
"title": "T3 \u2014 LocalCA backend",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"uuid": "a5a41e58-1c6d-42a9-9b11-2088f17c29b5",
|
|
"parent_id": "WARDEN-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0001-T4",
|
|
"status": "done",
|
|
"title": "T4 \u2014 VaultCA backend",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"uuid": "b2067ee6-c9ce-423b-9d60-0d28069fb304",
|
|
"parent_id": "WARDEN-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0001-T5",
|
|
"status": "done",
|
|
"title": "T5 \u2014 Principals inventory",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"uuid": "6d13f8cd-1850-44c9-b769-b21250348319",
|
|
"parent_id": "WARDEN-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0001-T6",
|
|
"status": "done",
|
|
"title": "T6 \u2014 CLI commands",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"uuid": "656a4615-92bb-4b5d-9406-e86d24fa15d0",
|
|
"parent_id": "WARDEN-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0001-T7",
|
|
"status": "done",
|
|
"title": "T7 \u2014 Scorecard runner",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"uuid": "7818bcc5-f40e-4793-b117-d36f653ffeed",
|
|
"parent_id": "WARDEN-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0001-T8",
|
|
"status": "done",
|
|
"title": "T8 \u2014 ops-ssh-wrapper script",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"uuid": "e9c28152-5785-4995-83a5-439985ed3db9",
|
|
"parent_id": "WARDEN-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0001-T9",
|
|
"status": "done",
|
|
"title": "T9 \u2014 Tests",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"uuid": "950139ab-cc17-4f1d-9a17-d5744e402ddf",
|
|
"parent_id": "WARDEN-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0001-T10",
|
|
"status": "done",
|
|
"title": "T10 \u2014 Documentation",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0001-initial-implementation.md",
|
|
"uuid": "271d6759-e359-41ce-80e4-76c574634a87",
|
|
"parent_id": "WARDEN-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0002",
|
|
"status": "archived",
|
|
"title": "OpsWarden Correctness and Operational Completeness",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0002-correctness-and-completeness.md",
|
|
"uuid": "5a9fba2c-6161-49a4-a231-e750fa4ab572",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0002-T1",
|
|
"status": "done",
|
|
"title": "T1 \u2014 TTL max enforcement per ActorType",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0002-correctness-and-completeness.md",
|
|
"uuid": "b0d0b5f7-a181-4590-be26-c48ae28cd964",
|
|
"parent_id": "WARDEN-WP-0002",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0002-T2",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Stale cert cleanup command",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0002-correctness-and-completeness.md",
|
|
"uuid": "aeeefbad-c0bd-4ae8-a3fe-9f72321b4caa",
|
|
"parent_id": "WARDEN-WP-0002",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0002-T3",
|
|
"status": "done",
|
|
"title": "T3 \u2014 Outgoing signatures log",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0002-correctness-and-completeness.md",
|
|
"uuid": "0194d24f-a8fe-4f6d-88e6-addea3542c0e",
|
|
"parent_id": "WARDEN-WP-0002",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0003",
|
|
"status": "archived",
|
|
"title": "OpsWarden Test Coverage and Code Quality",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md",
|
|
"uuid": "cb2bbf3c-848a-4af6-ba64-8361e64cd4d7",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0003-T1",
|
|
"status": "done",
|
|
"title": "T1 \u2014 VaultCA tests",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md",
|
|
"uuid": "eff074ce-c027-4df5-8006-0990296592ac",
|
|
"parent_id": "WARDEN-WP-0003",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0003-T2",
|
|
"status": "done",
|
|
"title": "T2 \u2014 LocalCA.generate_keypair tests",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md",
|
|
"uuid": "ddfe5331-0a3b-4783-bdf4-f5ebcdf7965c",
|
|
"parent_id": "WARDEN-WP-0003",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0003-T3",
|
|
"status": "done",
|
|
"title": "T3 \u2014 CLI tests",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md",
|
|
"uuid": "040ce3a1-0efb-4816-a2d9-357162dd1612",
|
|
"parent_id": "WARDEN-WP-0003",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0003-T4",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Real ssh-keygen integration test",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md",
|
|
"uuid": "434fb008-103f-410c-85fd-e77b33e61fe4",
|
|
"parent_id": "WARDEN-WP-0003",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0003-T5",
|
|
"status": "done",
|
|
"title": "T5 \u2014 File permissions enforcement (mode 600)",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md",
|
|
"uuid": "ac146fe6-d1fd-4186-91bd-6f098de72449",
|
|
"parent_id": "WARDEN-WP-0003",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0003-T6",
|
|
"status": "done",
|
|
"title": "T6 \u2014 warden status --state-dir override",
|
|
"source_path": "workplans/archived/260515-WARDEN-WP-0003-test-coverage-and-quality.md",
|
|
"uuid": "1c9f1987-7b11-43c1-a5e3-c2fd8d1c1589",
|
|
"parent_id": "WARDEN-WP-0003",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0004",
|
|
"status": "archived",
|
|
"title": "OpsWarden Repo Hygiene and Hub Sync",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0004-repo-hygiene-and-hub-sync.md",
|
|
"uuid": "3c4b6e68-550a-4fc6-a804-95f1f68936c3",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0004-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Update orientation docs",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0004-repo-hygiene-and-hub-sync.md",
|
|
"uuid": "f9d3926c-8637-411c-a477-2960b754704c",
|
|
"parent_id": "WARDEN-WP-0004",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0004-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Fill agent rules",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0004-repo-hygiene-and-hub-sync.md",
|
|
"uuid": "86c764a5-62fc-45fe-a8d2-332d6554a976",
|
|
"parent_id": "WARDEN-WP-0004",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0004-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 Archive finished workplans",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0004-repo-hygiene-and-hub-sync.md",
|
|
"uuid": "d3e54e63-ce98-4632-bc08-0e2667f19f12",
|
|
"parent_id": "WARDEN-WP-0004",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0004-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Sync State Hub",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0004-repo-hygiene-and-hub-sync.md",
|
|
"uuid": "51729695-262f-4fe4-9c38-f99ee046d32a",
|
|
"parent_id": "WARDEN-WP-0004",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0005",
|
|
"status": "archived",
|
|
"title": "OpsWarden OpenBao-First Documentation Alignment",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0005-openbao-doc-alignment.md",
|
|
"uuid": "57f6ebf8-0ef3-4686-9a73-3f9d38288be9",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0005-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 OpsWardenConfig.md",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0005-openbao-doc-alignment.md",
|
|
"uuid": "bbbc4dda-9634-4c04-86e5-94b96c021b43",
|
|
"parent_id": "WARDEN-WP-0005",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0005-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Cross-reference updates",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0005-openbao-doc-alignment.md",
|
|
"uuid": "6391cb82-896e-405a-a59b-36640e6480ba",
|
|
"parent_id": "WARDEN-WP-0005",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0006",
|
|
"status": "archived",
|
|
"title": "NetKingdom Alignment and Operational Access Stewardship",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md",
|
|
"uuid": "a5c9f24b-1ad4-46da-bc8e-b99897f8e302",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0006-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Credential routing runbook",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md",
|
|
"uuid": "ffc6a0c2-4312-4584-be7a-c8411cb01899",
|
|
"parent_id": "WARDEN-WP-0006",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0006-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Actor inventory patterns",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md",
|
|
"uuid": "3816463d-7dfd-469d-9324-fd7880b50608",
|
|
"parent_id": "WARDEN-WP-0006",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0006-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 NetKingdom cross-links (ops-warden side)",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md",
|
|
"uuid": "f158366a-5746-48b8-acce-472dce8f925e",
|
|
"parent_id": "WARDEN-WP-0006",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0006-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 NetKingdom canon patch (coordination)",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md",
|
|
"uuid": "e40e4395-8f01-4f79-a539-d0de8e427321",
|
|
"parent_id": "WARDEN-WP-0006",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0006-T05",
|
|
"status": "done",
|
|
"title": "T5 \u2014 OpenBao SSH engine operational checklist",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md",
|
|
"uuid": "a94e20a2-970b-4a0c-bd23-8510b841b938",
|
|
"parent_id": "WARDEN-WP-0006",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0006-T06",
|
|
"status": "done",
|
|
"title": "T6 \u2014 Policy-gated signing design (design only)",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md",
|
|
"uuid": "b10a4b4d-bfa1-4f49-b6a5-f339f1e6a2e1",
|
|
"parent_id": "WARDEN-WP-0006",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0006-T07",
|
|
"status": "done",
|
|
"title": "T7 \u2014 Re-assess INTENT \u2194 SCOPE",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0006-netkingdom-alignment-and-access-stewardship.md",
|
|
"uuid": "ef8b5c57-2343-4cfc-9fee-48db1e56f69a",
|
|
"parent_id": "WARDEN-WP-0006",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0007",
|
|
"status": "archived",
|
|
"title": "Policy Gate and Production OpenBao Verification",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0007-policy-gate-and-production-verify.md",
|
|
"uuid": "3718ac07-2fa2-47d0-a02a-c9a7b83a5ba9",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0007-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Production OpenBao verification evidence",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0007-policy-gate-and-production-verify.md",
|
|
"uuid": "344540ad-5912-4118-b406-450b96e13c40",
|
|
"parent_id": "WARDEN-WP-0007",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0007-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Policy config and flex-auth client",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0007-policy-gate-and-production-verify.md",
|
|
"uuid": "05424ddf-5fe9-43a1-a2f8-c47235a012c8",
|
|
"parent_id": "WARDEN-WP-0007",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0007-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 Wire policy gate into sign/issue",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0007-policy-gate-and-production-verify.md",
|
|
"uuid": "f5ae8e6e-8cce-4526-b18c-0452a135af49",
|
|
"parent_id": "WARDEN-WP-0007",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0007-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Tests and docs",
|
|
"source_path": "workplans/archived/260617-WARDEN-WP-0007-policy-gate-and-production-verify.md",
|
|
"uuid": "ea921d56-033b-4619-8032-61af7992e610",
|
|
"parent_id": "WARDEN-WP-0007",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0008",
|
|
"status": "finished",
|
|
"title": "Production SSH Path and Stewardship Closeout",
|
|
"source_path": "workplans/archived/260618-WARDEN-WP-0008-production-ssh-path-and-stewardship-closeout.md",
|
|
"uuid": "a174963a-4ff1-4565-b19f-896cd4ff14a0",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0008-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Post-WP-0007 INTENT/SCOPE reassessment",
|
|
"source_path": "workplans/archived/260618-WARDEN-WP-0008-production-ssh-path-and-stewardship-closeout.md",
|
|
"uuid": "05379da4-79d0-4742-8638-9e9565cccf72",
|
|
"parent_id": "WARDEN-WP-0008",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0008-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Production OpenBao end-to-end sign verification",
|
|
"source_path": "workplans/archived/260618-WARDEN-WP-0008-production-ssh-path-and-stewardship-closeout.md",
|
|
"uuid": "b1a1831d-b2b3-4204-95f6-04dc7f29f67c",
|
|
"parent_id": "WARDEN-WP-0008",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0008-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 State Hub task status canon migration",
|
|
"source_path": "workplans/archived/260618-WARDEN-WP-0008-production-ssh-path-and-stewardship-closeout.md",
|
|
"uuid": "876827c4-4a86-4e58-9a1f-ac87045dc903",
|
|
"parent_id": "WARDEN-WP-0008",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0008-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Production config example and archive hygiene",
|
|
"source_path": "workplans/archived/260618-WARDEN-WP-0008-production-ssh-path-and-stewardship-closeout.md",
|
|
"uuid": "75b9f366-3d7a-419d-98ad-bc10ab90a697",
|
|
"parent_id": "WARDEN-WP-0008",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0008-T05",
|
|
"status": "cancel",
|
|
"title": "T5 \u2014 flex-auth policy gate production readiness (coordination)",
|
|
"source_path": "workplans/archived/260618-WARDEN-WP-0008-production-ssh-path-and-stewardship-closeout.md",
|
|
"uuid": "03b412a5-5b99-42df-a154-733dd4156000",
|
|
"parent_id": "WARDEN-WP-0008",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0009",
|
|
"status": "archived",
|
|
"title": "flex-auth Policy Gate Production Readiness",
|
|
"source_path": "workplans/archived/260623-WARDEN-WP-0009-flex-auth-policy-gate-production.md",
|
|
"uuid": "9213b262-e2f5-480e-a5bc-56635d5eb4c9",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0009-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 flex-auth policy package confirmation",
|
|
"source_path": "workplans/archived/260623-WARDEN-WP-0009-flex-auth-policy-gate-production.md",
|
|
"uuid": "f988ed2e-0f63-4e89-abc4-183a7f23ddc2",
|
|
"parent_id": "WARDEN-WP-0009",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0009-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Production enablement and smoke",
|
|
"source_path": "workplans/archived/260623-WARDEN-WP-0009-flex-auth-policy-gate-production.md",
|
|
"uuid": "9d0fabc2-10ef-426d-a3d2-d4970d377029",
|
|
"parent_id": "WARDEN-WP-0009",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0010",
|
|
"status": "archived",
|
|
"title": "Access Routing \u2014 Charter and Pointer Catalog",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0010-access-routing-charter.md",
|
|
"uuid": "e93de9fd-0192-4d02-bb7c-5e859fb76b9b",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0010-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 INTENT wording",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0010-access-routing-charter.md",
|
|
"uuid": "589081a6-d1f5-47b4-bec0-e82d9c3444f4",
|
|
"parent_id": "WARDEN-WP-0010",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0010-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Routing-role wiki page",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0010-access-routing-charter.md",
|
|
"uuid": "9ac333f7-5fc4-4fa2-82f3-d5ece8ff0d92",
|
|
"parent_id": "WARDEN-WP-0010",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0010-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 Pointer catalog schema + seed",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0010-access-routing-charter.md",
|
|
"uuid": "59e0f480-694a-482a-b35e-b7bc4930aa41",
|
|
"parent_id": "WARDEN-WP-0010",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0010-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Routing index in CredentialRouting.md",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0010-access-routing-charter.md",
|
|
"uuid": "aabd28c0-db2d-4267-be98-95be272c687d",
|
|
"parent_id": "WARDEN-WP-0010",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0010-T05",
|
|
"status": "done",
|
|
"title": "T5 \u2014 Registry and repo-boundary alignment",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0010-access-routing-charter.md",
|
|
"uuid": "3335a689-922c-4319-98d0-4263ab13790b",
|
|
"parent_id": "WARDEN-WP-0010",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0011",
|
|
"status": "archived",
|
|
"title": "Routing Lookup CLI",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0011-routing-guide-cli.md",
|
|
"uuid": "0a520f8e-01b4-48f1-9af3-2f3f69fd0672",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0011-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Catalog loader and models",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0011-routing-guide-cli.md",
|
|
"uuid": "55b8422c-ad3c-4084-9e00-acaa4c360906",
|
|
"parent_id": "WARDEN-WP-0011",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0011-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 `warden route list` and `show`",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0011-routing-guide-cli.md",
|
|
"uuid": "60b679c5-79bd-4186-b5a6-ac576931f06c",
|
|
"parent_id": "WARDEN-WP-0011",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0011-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 `warden route find`",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0011-routing-guide-cli.md",
|
|
"uuid": "d307701f-0117-44f0-80fd-ca6f7ae06f42",
|
|
"parent_id": "WARDEN-WP-0011",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0011-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Tests",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0011-routing-guide-cli.md",
|
|
"uuid": "00a76e0f-8ab6-4f9a-ac6a-00eae633342c",
|
|
"parent_id": "WARDEN-WP-0011",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0011-T05",
|
|
"status": "done",
|
|
"title": "T5 \u2014 Doc consistency + drift guard",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0011-routing-guide-cli.md",
|
|
"uuid": "bf848375-eca7-4116-bb1d-fb7df6395c70",
|
|
"parent_id": "WARDEN-WP-0011",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0013",
|
|
"status": "archived",
|
|
"title": "Production Integration & Stewardship Closeout",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md",
|
|
"uuid": "4678c41a-c1d0-48cd-9988-4ea0380e8258",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0013-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Post-gap reassessment and SCOPE refresh",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md",
|
|
"uuid": "de46f9a2-bf11-4651-a23c-430c63f396c8",
|
|
"parent_id": "WARDEN-WP-0013",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0013-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Archive hygiene (WP-0010, WP-0011)",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md",
|
|
"uuid": "1b35321d-63ad-40da-a1aa-0b66190a0733",
|
|
"parent_id": "WARDEN-WP-0013",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0013-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 ops-bridge cert_command migration playbook",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md",
|
|
"uuid": "ad8588b2-9ae9-4f94-bd77-8025851a38f5",
|
|
"parent_id": "WARDEN-WP-0013",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0013-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Operator OpenBao token hygiene runbook",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md",
|
|
"uuid": "5cb35829-32eb-4d59-97a1-f4d92ce8e239",
|
|
"parent_id": "WARDEN-WP-0013",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0013-T05",
|
|
"status": "done",
|
|
"title": "T5 \u2014 Principals inventory drift check",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md",
|
|
"uuid": "4025cd32-89f8-42c3-b1e8-eaf78497d91f",
|
|
"parent_id": "WARDEN-WP-0013",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0013-T06",
|
|
"status": "done",
|
|
"title": "T6 \u2014 Policy gate production enablement checklist",
|
|
"source_path": "workplans/archived/260624-WARDEN-WP-0013-production-integration-and-stewardship-closeout.md",
|
|
"uuid": "51663f65-79cb-4108-87c8-9721f9476259",
|
|
"parent_id": "WARDEN-WP-0013",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0012",
|
|
"status": "finished",
|
|
"title": "Routing Scenario Playbooks",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0012-routing-scenario-playbooks.md",
|
|
"uuid": "a7e712a0-02f8-4f83-944e-6b207e77bc4c",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0012-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 issue-core ingestion key playbook",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0012-routing-scenario-playbooks.md",
|
|
"uuid": "830bb512-0288-4dba-9dd4-ccfd28a4921f",
|
|
"parent_id": "WARDEN-WP-0012",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0012-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Inter-Hub and bootstrap lanes",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0012-routing-scenario-playbooks.md",
|
|
"uuid": "7726a703-6e00-4e49-9380-ed3fb3268827",
|
|
"parent_id": "WARDEN-WP-0012",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0012-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 ops-bridge tunnel migration",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0012-routing-scenario-playbooks.md",
|
|
"uuid": "9fb397f0-0abb-48f5-bb62-7e77edae93bb",
|
|
"parent_id": "WARDEN-WP-0012",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0012-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Platform secret scenarios (LLM, STS, DB)",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0012-routing-scenario-playbooks.md",
|
|
"uuid": "edcf4ed7-f18d-4a92-a42d-8cc7ca0ab792",
|
|
"parent_id": "WARDEN-WP-0012",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0012-T05",
|
|
"status": "done",
|
|
"title": "T5 \u2014 Drift review cadence",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0012-routing-scenario-playbooks.md",
|
|
"uuid": "db98d655-8551-487b-9413-41bf97fc06e1",
|
|
"parent_id": "WARDEN-WP-0012",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0014",
|
|
"status": "finished",
|
|
"title": "Operator Access Assist \u2014 warden access front door",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0014-operator-access-assist.md",
|
|
"uuid": "3c30b2ed-6ede-4b95-a438-fde6da6f6633",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0014-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Catalog schema: structured handoff fields",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0014-operator-access-assist.md",
|
|
"uuid": "abb0e722-6524-4224-8638-6ee1573ed3e0",
|
|
"parent_id": "WARDEN-WP-0014",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0014-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 `warden access` advisory surface",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0014-operator-access-assist.md",
|
|
"uuid": "c1497263-7124-459f-b63a-d0c0c7005c86",
|
|
"parent_id": "WARDEN-WP-0014",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0014-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 OpenBao proxy lane (`--fetch` / `--exec`)",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0014-operator-access-assist.md",
|
|
"uuid": "6d3eb0e4-309c-4065-893e-6c4053fb0db2",
|
|
"parent_id": "WARDEN-WP-0014",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0014-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 key-cape / login orchestration lane",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0014-operator-access-assist.md",
|
|
"uuid": "481997e4-193d-4724-84a6-61cbc2940153",
|
|
"parent_id": "WARDEN-WP-0014",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0014-T05",
|
|
"status": "done",
|
|
"title": "T5 \u2014 Docs, security model, and INTENT/SCOPE alignment",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0014-operator-access-assist.md",
|
|
"uuid": "a5eb616e-4edf-42db-a4fb-bf296cdb92bc",
|
|
"parent_id": "WARDEN-WP-0014",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-0015",
|
|
"status": "finished",
|
|
"title": "Workload Security Posture \u2014 env posture \u00d7 maturity + conformance",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0015-secret-lifecycle-tiering.md",
|
|
"uuid": "99f4a0e1-853c-456f-8aa7-8ff0f318ea65",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0015-T01",
|
|
"status": "done",
|
|
"title": "T1 \u2014 Author the two-axis Workload Security Posture standard (canon-bound)",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0015-secret-lifecycle-tiering.md",
|
|
"uuid": "85aeb676-a593-4056-986a-db14d4c5209f",
|
|
"parent_id": "WARDEN-WP-0015",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0015-T02",
|
|
"status": "done",
|
|
"title": "T2 \u2014 Machine-readable posture descriptors (both axes)",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0015-secret-lifecycle-tiering.md",
|
|
"uuid": "011fb0af-154d-40f4-a03e-3172c325321a",
|
|
"parent_id": "WARDEN-WP-0015",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0015-T03",
|
|
"status": "done",
|
|
"title": "T3 \u2014 Conformance checker (incl. secret-flow lattice)",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0015-secret-lifecycle-tiering.md",
|
|
"uuid": "c1a0e987-19d0-478e-ac08-2dbe98e64e09",
|
|
"parent_id": "WARDEN-WP-0015",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0015-T04",
|
|
"status": "done",
|
|
"title": "T4 \u2014 Dev-tier contract-double fixture library",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0015-secret-lifecycle-tiering.md",
|
|
"uuid": "e556fd2e-4e39-4c7d-bd94-b4330e4bef45",
|
|
"parent_id": "WARDEN-WP-0015",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-0015-T05",
|
|
"status": "done",
|
|
"title": "T5 \u2014 INTENT/SCOPE alignment + canon contributions",
|
|
"source_path": "workplans/archived/260627-WARDEN-WP-0015-secret-lifecycle-tiering.md",
|
|
"uuid": "298c9b09-4a5a-41bf-a3bd-6c572385236b",
|
|
"parent_id": "WARDEN-WP-0015",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "WARDEN-WP-ADHOC-2026-07-07",
|
|
"status": "finished",
|
|
"title": "Ad Hoc Tasks \u2014 2026-07-07",
|
|
"source_path": "workplans/archived/260707-ADHOC-2026-07-07.md",
|
|
"uuid": null,
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "WARDEN-WP-ADHOC-2026-07-07-T01",
|
|
"status": "done",
|
|
"title": "T01 \u2014 Roll out proxy pipe fix (be3b4a2)",
|
|
"source_path": "workplans/archived/260707-ADHOC-2026-07-07.md",
|
|
"uuid": null,
|
|
"parent_id": "WARDEN-WP-ADHOC-2026-07-07",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "intake",
|
|
"id": "WARDEN-IN-0001",
|
|
"status": "open",
|
|
"title": "Assent requested: Staff layer, doctrine vs runbook, and the access lane/rule demarcation",
|
|
"source_path": "intakes/intakes.md",
|
|
"uuid": null,
|
|
"parent_id": null,
|
|
"extra": {
|
|
"record": {
|
|
"id": "WARDEN-IN-0001",
|
|
"kind": "intake",
|
|
"title": "Assent requested: Staff layer, doctrine vs runbook, and the access lane/rule demarcation",
|
|
"status": "open",
|
|
"origin": "cross-repo",
|
|
"origin_ref": "gate-house GH-DEC-2026-001",
|
|
"priority": "medium",
|
|
"owner": "ops-warden",
|
|
"requested_by": "gate-house",
|
|
"standard": "net-kingdom/canon/standards/security-layer-model_v0.1.md",
|
|
"description": "gate-house asks ops-warden to assent to three boundary items. (1) ops-warden is Staff, bound by the rule that Staff acts only through Engine APIs and never touches Tooling directly (standard section 5). (2) Doctrine versus runbook: the NetKingdom Security Literacy section in ops-warden INTENT is evidence the security curriculum had no owner; it now has one in gate-house. Proposal is that doctrine and curriculum move to gate-house and that section becomes lane-specific runbooks referencing gate-house doctrine rather than restating it. ops-warden keeps the lanes it stewards and everything operational about them. (3) The access lane/rule demarcation, normative in standard section 8: ops-warden and ops-mason own access lanes \u2014 how a worker reaches a host; access-engine owns access rules \u2014 whether they may. This demarcation is the condition attached to renaming flex-auth to access-engine, so ops-warden effectively holds a veto on that name. Also requested: add gate-house to the Security Literacy and routing tables \u2014 currently every plane is listed and gate-house appears nowhere \u2014 routing doctrine and authority-model questions there while continuing to route policy decisions to access-engine. If moving the curriculum out leaves ops-warden unable to instruct its own workers, say so; the boundary is wrong if it does.",
|
|
"created": "2026-08-28T19:30:28.087109Z",
|
|
"updated": "2026-08-28T19:30:28.087109Z"
|
|
}
|
|
}
|
|
}
|
|
],
|
|
"events": [
|
|
{
|
|
"type": "repo.command.applied",
|
|
"command": "repo.work.create_intake",
|
|
"operation": "create",
|
|
"correlation_id": "65d40cdd-5894-440e-9c95-c6bcfe259b66",
|
|
"kind": "intake",
|
|
"id": "WARDEN-IN-0001",
|
|
"git_sha": "467635e84b99757336ee49d7f0dbf107607d0560",
|
|
"files_touched": [
|
|
"intakes/intakes.md"
|
|
],
|
|
"source": "repo-manager",
|
|
"emitted_at": "2026-08-28T19:30:29.829125Z"
|
|
}
|
|
]
|
|
}
|