Closes the RISK-F-0003 exposure. All 14 ungraded lanes now carry an explicit risk grade with its justification in the entry: 17 high, 10 standard, 0 ungraded. The agent read-boundary now fires (exit 7) on lanes that were silently outside it. Graded on merit rather than defensively. A first pass marked two ordinary internal workload secrets high; test_high_risk_lanes_classified asserted the opposite and was right, so both were regraded down. high means disclosure into a logged context is damaging beyond what rotation recovers. inter-hub-bootstrap-ssh is high conservatively, with the reason in the entry so it is regraded with evidence rather than assumed down. ADR-0007 records the rule the grading rests on: build-stage permissiveness applies to controls that gate work, not to controls that prevent credential disclosure. The test is friction, not severity — the read-boundary blocks nobody, since --out/--exec/--wrap remain available, so relaxing it buys nothing. A blocked operation is recovered by retrying; a credential in a logged transcript is not recovered by rotation. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
57 lines
2.7 KiB
Markdown
57 lines
2.7 KiB
Markdown
## Architecture
|
|
|
|
### Our rules are ADRs — `docs/adr/`
|
|
|
|
The decisions that govern this repo live in `docs/adr/` as addressable records,
|
|
not in wiki prose. Read `docs/adr/README.md` first; it explains the one
|
|
distinction that matters here.
|
|
|
|
| ADR | Rule |
|
|
| --- | --- |
|
|
| `ADR-0001` | The routing catalog is a pointer layer, never a second copy of an owner's procedure |
|
|
| `ADR-0002` | ops-warden is a transparent conduit, never a secret broker |
|
|
| `ADR-0003` | Cover gaps, but never silently own them |
|
|
| `ADR-0004` | High-risk lanes refuse raw value streaming to agent sessions |
|
|
| `ADR-0005` | Implement one lane narrowly, route everything else |
|
|
| `ADR-0006` | Enforcement is zone-scoped, never a global flag |
|
|
| `ADR-0007` | Build-stage permissiveness stops at credential disclosure; every lane carries an explicit `risk` grade |
|
|
|
|
### Owned versus inherited — check `owner:` before changing anything
|
|
|
|
Every ADR carries `owner:` in its frontmatter, and it decides what you are allowed
|
|
to do with the rule:
|
|
|
|
- **`owner: ops-warden`** — ours. We are bound by it *and* we may change it. Changing
|
|
one means writing a superseding ADR, not editing the decision in place.
|
|
- **any other owner** — inherited. We follow it; we do not own it. Dispute it through
|
|
that owner's process; never amend it here.
|
|
|
|
Everything in `docs/adr/` today is `owner: ops-warden`. Rules we merely follow —
|
|
NetKingdom canon, the IAM profile, the credential-management standard — are cited,
|
|
never copied in. Copying them would recreate the second-source-of-truth failure
|
|
`ADR-0001` exists to prevent.
|
|
|
|
**Naming collision, worth knowing.** `ADR-001` (three digits) in
|
|
`workplan-convention.md` and `session-protocol.md` is **the-custodian's** ADR
|
|
establishing the workplan convention across the whole estate. It is inherited and
|
|
not ours to change. Our records are four-digit — `ADR-0001` … `ADR-0005` — and live
|
|
in this repo. When writing, say "the-custodian's ADR-001" if that is what you mean.
|
|
|
|
### Precedence
|
|
|
|
If a wiki page, playbook, or `.claude/rules/` file disagrees with an ADR, **the ADR
|
|
is right and the other file is a defect** — fix it rather than working around it.
|
|
The rule files are agent-facing operational instructions derived from these
|
|
decisions; they should cite an ADR rather than restate its reasoning.
|
|
|
|
### Publication
|
|
|
|
These ADRs are publishable through `policy-nexus` at `policy.coulomb.social`, which
|
|
requires `title`, `status` and `owner`, renders owner in the page header and in the
|
|
index, and records source repo, path and revision digest in its manifest. Ownership
|
|
survives the repo boundary. `policy-nexus` publishes and never writes back: the file
|
|
here is the source of truth.
|
|
|
|
## Quick Reference
|
|
|
|
`~/state-hub/mcp_server/TOOLS.md` — MCP tool reference
|