Make S1 handoff read-only by default
All checks were successful
CI Smoke / source-contract (push) Successful in 8s
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02994-7685-7940-bf34-3555b8256018
This commit is contained in:
codex 2026-08-23 12:41:23 +02:00
parent 24b799ec59
commit 40e295e3bd
16 changed files with 637 additions and 46 deletions

View file

@ -179,9 +179,12 @@ interpreting an expected-red exception.
`make s1-handoff` validate source contracts, require a clean revision, run each
host separately, fail the aggregate on any non-zero result, require TAP hashes
for a pass, and record a freshness boundary. Dry-run output is forcibly
`not-run`. The attended all-host run waits for an environment with Ansible and
reviewed permission to refresh the on-host Goss surface; this workstation has
no `ansible-playbook`. No host was contacted.
`not-run`. The live playbook is now remotely read-only: a static contract
rejects mutating modules and arbitrary commands, it requires the installed
Goss surface to match the locally rendered profile digest, and it writes only
controller-side evidence. Refresh is a separate exact-approval interface. The
attended all-host run now waits only for Ansible plus short-lived SSH access;
no host was contacted.
## T06 — Repair and enforce the secret-source contract
@ -286,10 +289,14 @@ decryption receipt or recipient change was attempted.
Current evidence (2026-08-23):
- Python unit suite: 25 tests pass.
- Python unit suite: 30 tests pass, including rejection of a remote template,
arbitrary remote command, non-delegated controller write, and unreviewed
Goss command surface in the handoff path.
- Terraform 1.9.8 mock-provider tests: 2 pass.
- Ansible 2.17.13 syntax checks: bootstrap, verify, and firewall pass in a
disposable environment.
- Ansible 2.17.13 syntax checks: bootstrap, read-only verify, explicit
verify-refresh, and firewall pass in a disposable environment. A disposable
render comparison also proves the template lookup digest matches the bytes
produced by Ansible's deployment template action.
- Both profile-specific Goss templates render and parse as YAML.
- Inventory, baseline, secret metadata, receipt, shell syntax, Python compile,
and whitespace checks pass.