Make S1 handoff read-only by default
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02994-7685-7940-bf34-3555b8256018
This commit is contained in:
parent
24b799ec59
commit
40e295e3bd
16 changed files with 637 additions and 46 deletions
3
SCOPE.md
3
SCOPE.md
|
|
@ -112,7 +112,8 @@ maintenance, evidence collection, and drift checks are ongoing S1 work.
|
|||
has not been migrated safely to this repo's UFW model
|
||||
- Verification: the executable baseline now resolves `ufw-managed` and
|
||||
`external-firewall` profiles into both Ansible and Goss. The fail-closed
|
||||
handoff command and receipt format exist; a fresh attended all-host receipt
|
||||
handoff command is remotely read-only, refuses a stale installed Goss
|
||||
surface, and emits metadata-only receipts; a fresh attended all-host receipt
|
||||
is still pending
|
||||
- Provisioning: adopted and provider-managed records now have a validated
|
||||
schema. Terraform selects only provider-managed Hetzner records, with mock
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue