Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a0291a-1e87-7151-9934-fcbfe3f65eb1
1.8 KiB
1.8 KiB
Ops-warden security-zone admission evidence — 2026-08-22
This record supports the z1-operational membership declared in
tenancy.yaml. It does not claim the M2 gates that ops-warden has not met.
Identity and scope
- Workload id:
ops-warden. - Runtime binding: Kubernetes ServiceAccount
system:serviceaccount:ops-warden:ops-warden, issued by railiance01 and verified against the enforcing flex-auth pin on 2026-08-19. - Responsible party:
team:platform-securityin this repository. - Scope: attended issuance of short-lived SSH certificates plus a pointer-only credential catalog. Secret values are not stored in the catalog or audit.
M1 evidence
- Owned front door:
warden signis the sole certificate-issuance interface; actor inventory, principal allow-list, and TTL ceilings are enforced before the CA backend. - Basic service objective: production signing is bounded by the actor TTL
policy (
adm48h,agt24h,atm8h);warden statusand the production verification records expose backend readiness. - Data handling:
ADR-0002makes ops-warden a transparent conduit andADR-0004/ADR-0007prevent raw agent reads and fail safe on ungraded lanes. - Policy path:
history/2026-08-19-flex-auth-caller-identity-evidence.mdproves the authenticated caller path and anonymous rejection. At adoption, the migrated real operator config reran the check successfully through the existing tunnel: HTTP 200, effectallow, decisiondecision:f3f7c88f9585582a.
Why not z2
Ops-warden has security review artifacts, but not the complete M2 promotion
set: there is no SLO history, on-call rotation, or exercised signing-path
incident/recovery runbook. Its tenancy posture therefore remains V0 and its
accurate zone membership remains z1-operational.