Updated by fix-consistency on 2026-09-28: - update .custodian-brief.md for ops-warden Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e6ef-4273-7fc2-8741-dc96b3e5fe0d
2.7 KiB
2.7 KiB
Custodian Brief — ops-warden
Domain: infotech
Last synced: 2026-09-28 07:45 UTC
State Hub: http://127.0.0.1:8000 (adjust if running on a remote machine)
Active Workstreams
Adopt unknown -> fail_closed behind signing-target classification coverage
Progress: 1/4 done | workplan_id: c8ee441e-1be1-5219-910c-e79ff23cc9ec
Open tasks:
- ! Tasks
611f0901(wait: Await authoritative owner declaration of the actual continuity actor/target and z2-continuity resolution. adm-example is not an admitted repair actor.) - ! Tasks
54ad4864(wait: Coverage refreshed: 0 resolved, 3 unknown, 1 not-applicable signing targets. Owner routing/declaration follow-up remains for ops-bridge-tunnel, codex-interhub-bootstrap and backup-daily.) - ! Tasks
93eaf1f2(wait: Await classified continuity path (T01) and acceptance of security-layer-model v0.8 or successor; local authoritative v0.8 remains proposed.)
Layer model v0.7 conformance — state the deadline, bind the agent boundary, steward the estate's newest rule
Progress: 5/6 done | workplan_id: ae3ff76f-883d-5e2f-b6aa-144d61e8fdef
Open tasks:
- ! Tasks
7d1b3c82(wait: Await ops-mason stance-map answer and railiance-infra KRL-versus-TTL answer. Flex-auth decision-lifetime answer already recorded.)
Tamper-resistant credential governance + mass rotation/lockdown (Strand B)
Progress: 2/3 done | workplan_id: 21528e8d-a049-523d-9ae1-da7a27cb8bbf
Open tasks:
- ! Task: Graded lockdown / break-glass with explicit trust-root
cae498ee(wait: Await fresh platform-owned attended emergency seal/unseal scenario, current platform/infra/master receipts and new founder GO. Prior NO-GO consumed the August scenario.)
Repoint the whynot-design npm lane to Forgejo
Progress: 2/3 done | workplan_id: 42a097db-1c24-558e-a724-030bb2b4443e
Open tasks:
- ! Prove routing and publication
a8b1b855
Preserve explicit policy caller refusals before credential and CA effects
Progress: 2/3 done | workplan_id: ae44a935-6fca-514c-a385-4550dd2b1fe8
Open tasks:
- ! Resolve the credential proxy's admitted policy binding
8ca28b63(wait: The configured ops-warden caller represents ops-warden; credential requests name their owner as resource.system. Need the flex-auth/credential-owner contract for that exact delegated read, without broadening caller bindings or relabelling resource ownership.)
MCP Orientation (when available)
If the state-hub MCP server is reachable, call:
get_domain_summary("infotech")
This provides richer cross-domain context.
If the MCP call fails, use this file as your orientation source.