Make S1 handoff read-only by default
All checks were successful
CI Smoke / source-contract (push) Successful in 8s
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02994-7685-7940-bf34-3555b8256018
This commit is contained in:
codex 2026-08-23 12:41:23 +02:00
parent 24b799ec59
commit 40e295e3bd
16 changed files with 637 additions and 46 deletions

View file

@ -112,7 +112,8 @@ maintenance, evidence collection, and drift checks are ongoing S1 work.
has not been migrated safely to this repo's UFW model
- Verification: the executable baseline now resolves `ufw-managed` and
`external-firewall` profiles into both Ansible and Goss. The fail-closed
handoff command and receipt format exist; a fresh attended all-host receipt
handoff command is remotely read-only, refuses a stale installed Goss
surface, and emits metadata-only receipts; a fresh attended all-host receipt
is still pending
- Provisioning: adopted and provider-managed records now have a validated
schema. Terraform selects only provider-managed Hetzner records, with mock