ops-warden/wiki/playbooks
tegwick a70f559d40
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Apply GH-DEC-2026-017: INTENT.md governs, the sidecar is derived, no version
Verified against gate-house's own committed files before editing, not the inbox
message: GH-DEC-2026-017 in decisions/decisions.md at gate-house@def0af2,
amendments A9-A13 in docs/amendments/v0.8-section-11-declaration-amendments.md,
and sections 3, 4 and 11 of net-kingdom's security-layer-model_v0.8.md. The
ruling and docs/layer-declaration-precedence.md's secondary account agreed.

INTENT.md's frontmatter is the declaration; layer.yaml is a derived artifact,
now marked derived: true / derived_from: INTENT.md, and it does not govern.

standard_version is removed from BOTH forms. The ruling's general form is that a
layer declaration must not carry a standard version, and INTENT.md is the
declaration, so removing it from the sidecar alone would have left the field in
the only file that actually declares. INTENT.md's version-pinned `standard:`
path is de-versioned for the same reason: a pinned path reads as a validity
condition. The version ops-warden assented at stays with the assent, ADR-0010.

NO LAYER VALUE IS CHANGED. INTENT.md still says Staff and layer.yaml still says
staff. Section 3's vocabulary is closed, four tokens, and case-insensitive: the
two forms were never in disagreement about a layer, and the ruling asked nobody
to re-spell anything. The comment marking the divergence is rewritten from
"unruled, do not touch" to "ruled, folding case is the checker's job".

check_layer_conformance.py would have rejected the conforming declaration this
ruling produces -- it listed standard_version as a required key. It now reads
INTENT.md as the governing form, ASCII-folds before comparing, validates both
values against the closed four-token vocabulary (Taxonomy included; omitting it
is the defect A9 records against the estate's other validator), requires the
derived marking, rejects a returning standard_version in either file, and
reports a post-fold disagreement between the forms as a finding rather than
resolving it away by precedence.

The test asserts the fold, not equality. An equality assertion here would be
this repository quietly performing the re-spelling the ruling declined to order;
the fold still fails on a real layer divergence.

pep-stance.yaml is untouched. A stance map is not a layer declaration, and the
sidecar schema beyond the derived marking and the version is explicitly not
ruled.

layer.yaml is the form seven repositories copied, so the adopter change set is
written out in wiki/playbooks/netkingdom-layer-declaration.md -- including the
trap that an adopter which also copied the checker turns a conforming
declaration into MALFORMED exit 2 by removing the field alone. No other
repository is edited here.

Still open: where the removed version lives. A12 says the derived conformance
record "already MUST" carry it; ops-warden has a re-runnable checker that emits
nothing durable. Asked of gate-house in message 4220413a, unanswered, and left
open rather than answered by choosing. Nothing above depends on it.

Carries WARDEN-WP-0034-T06 to done.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
2026-09-21 02:38:55 +02:00
..
activity-core-issue-sink.md Refresh the activity-core issue-sink lane; close WP-0032-T01 2026-08-21 00:43:42 +02:00
agent-harness-secrets.md WARDEN-WP-0029: implement plan front door, org posture, desk, freshness 2026-07-18 16:59:37 +02:00
agent-read-boundary.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
audit-core-senders.md Add draft routing entry audit-core-senders 2026-08-13 10:27:13 +02:00
binky-company-email-imap.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
binky-qonto-api.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
catalog-lane-promotion.md Ship WARDEN-WP-0030: delegation register for every catalog lane 2026-08-15 20:54:58 +02:00
coulomb-social-runtime-env.md Note apps-pg live and coulomb-social DB connectivity in playbook 2026-08-09 02:18:17 +02:00
database-dynamic-credentials.md Route dynamic database credentials to rapp-postgres 2026-08-10 19:37:05 +02:00
email-connect-transactional.md Route email-connect transactional SMTP and ingest token. 2026-08-12 13:32:11 +02:00
exposed-taint.md WARDEN-WP-0026 finish Strand A (T04/T05/T07) 2026-07-16 23:26:26 +02:00
flex-auth-decision-envelope-signing-key.md Draft the flex-auth envelope-signing credential route. 2026-09-14 09:59:11 +02:00
forgejo-admin-api-token.md WARDEN-WP-0029: implement plan front door, org posture, desk, freshness 2026-07-18 16:59:37 +02:00
informed-decision-sitting-requester-login.md Point sitting-create at the attended-exec wrapper. 2026-09-15 22:31:44 +02:00
issue-core-ingestion-api-key.md Promote issue-core-ingestion-api-key and openrouter-llm-connect lanes to active 2026-07-02 20:48:39 +02:00
net-kingdom-sso-bind-credentials.md Add NetKingdom SSO credential routing lanes 2026-08-23 21:43:12 +02:00
netkingdom-layer-declaration.md Apply GH-DEC-2026-017: INTENT.md governs, the sidecar is derived, no version 2026-09-21 02:38:55 +02:00
object-storage-sts.md Complete WARDEN-WP-0012 routing scenario playbooks 2026-06-25 10:27:23 +02:00
openbao-platform-admin-login.md fix: contain attended OpenBao login output 2026-08-23 01:31:05 +02:00
openbao-shamir-recovery-ceremony.md fix: route OpenBao recovery ceremonies safely 2026-08-22 20:54:45 +02:00
openrouter-llm-connect.md Retire CoulombCore references; correct the 16443 diagnosis 2026-08-19 19:31:41 +02:00
operator-openbao-token-hygiene.md Add ops-warden-warden-sign-token routing lane for RAILIANCE-WP-0005 T08 2026-07-01 23:16:38 +02:00
ops-bridge-tunnel-cert.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
ops-warden-warden-sign-token.md Add ops-warden-warden-sign-token routing lane for RAILIANCE-WP-0005 T08 2026-07-01 23:16:38 +02:00
policy-nexus-forgejo-source-read.md feat: route Policy Nexus source credential 2026-09-01 00:46:28 +02:00
railiance-backup-offsite-lane.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
rein-openweights-openrouter-approle.md Promote rein-openweights-openrouter-approle: draft -> active 2026-07-27 01:51:57 +02:00
reuse-surface-hub-write-token.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
scaleway-bootstrap.md catalog: draft scaleway-bootstrap lane 2026-08-14 17:36:17 +02:00
scheduled-worker.md feat(WARDEN-WP-0021): T3-T5 — visibility, approve loop, runbook (scheduled worker complete) 2026-06-30 15:24:10 +02:00
secrets-engine-approval-client-login.md Route attended approval-client login to scoped OpenBao reader 2026-09-14 01:46:46 +02:00
secrets-engine-requester-login.md Route attended T03 requester login to scoped owner reader 2026-09-14 02:47:32 +02:00
state-hub-forge-derivation-read.md Register the State Hub Forgejo derivation-read routing lane. 2026-09-14 04:57:55 +02:00
tenant-secret-onboarding.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
whynot-design-npm-publish.md Revert the npm field, re-measure coverage, and hold the layer divergence 2026-09-21 02:16:33 +02:00