ops-warden/wiki/playbooks
tegwick c3eb59ea04
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
WARDEN-WP-0026 T06: rotation guidance registry + warden rotate-guide
- routing model: RotationGuide (method rotate|re-establish, steps, owner,
  automatable), RouteEntry.rotation + has_rotation + vends_secret.
- catalog parser: validate rotation block; secret-material screen gains a
  prose-safe mode (high-entropy detector only) so authored steps aren't tripped
  by substrings like "s."/"exists.".
- CLI: `warden rotate-guide <id>` (human + --json); route show --json now
  carries has_rotation + rotation.
- scorecard: catalog_rotation_coverage — every active secret-vending lane must
  carry a rotation block (SSH/login/pointer lanes exempt). Promotion checklist
  criterion 9.
- data: rotation blocks for all 7 active vending lanes + the draft
  railiance-backup lane (re-establish: age keypair regen + re-encrypt).
- fix pre-existing collision: bare `npm` keyword on forgejo-admin -> forgejo-npm
  so "npm token" routes to the generic lane (restores test_access expectations).
- tests: rotation parse/coverage/prose-screen/CLI in tests/test_routing.py;
  scorecard count 6 -> 7.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 14:40:30 +02:00
..
activity-core-issue-sink.md Add activity-core-issue-sink routing playbook and catalog entry 2026-06-18 22:34:59 +02:00
catalog-lane-promotion.md WARDEN-WP-0026 T06: rotation guidance registry + warden rotate-guide 2026-07-16 14:40:30 +02:00
database-dynamic-credentials.md Complete WARDEN-WP-0012 routing scenario playbooks 2026-06-25 10:27:23 +02:00
forgejo-admin-api-token.md WARDEN-WP-0026 T01: capabilities-safe lane verification + incident note 2026-07-16 14:26:05 +02:00
issue-core-ingestion-api-key.md Promote issue-core-ingestion-api-key and openrouter-llm-connect lanes to active 2026-07-02 20:48:39 +02:00
object-storage-sts.md Complete WARDEN-WP-0012 routing scenario playbooks 2026-06-25 10:27:23 +02:00
openrouter-llm-connect.md Promote issue-core-ingestion-api-key and openrouter-llm-connect lanes to active 2026-07-02 20:48:39 +02:00
operator-openbao-token-hygiene.md Add ops-warden-warden-sign-token routing lane for RAILIANCE-WP-0005 T08 2026-07-01 23:16:38 +02:00
ops-bridge-tunnel-cert.md Implement WP-0022 audit trail and WP-0023 INTENT–SCOPE closeout 2026-07-01 23:32:38 +02:00
ops-warden-warden-sign-token.md Add ops-warden-warden-sign-token routing lane for RAILIANCE-WP-0005 T08 2026-07-01 23:16:38 +02:00
railiance-backup-offsite-lane.md WARDEN-WP-0026 T01: capabilities-safe lane verification + incident note 2026-07-16 14:26:05 +02:00
reuse-surface-hub-write-token.md Link reuse-surface playbook to rotation runbook (T04) 2026-07-08 00:01:22 +02:00
scheduled-worker.md feat(WARDEN-WP-0021): T3-T5 — visibility, approve loop, runbook (scheduled worker complete) 2026-06-30 15:24:10 +02:00
whynot-design-npm-publish.md feat(WARDEN-WP-0019): route secret-exec lanes to secrets-engine (route-primary, proxy fallback) 2026-06-29 17:41:49 +02:00