Make S1 handoff read-only by default
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02994-7685-7940-bf34-3555b8256018
This commit is contained in:
parent
24b799ec59
commit
40e295e3bd
16 changed files with 637 additions and 46 deletions
|
|
@ -179,9 +179,12 @@ interpreting an expected-red exception.
|
|||
`make s1-handoff` validate source contracts, require a clean revision, run each
|
||||
host separately, fail the aggregate on any non-zero result, require TAP hashes
|
||||
for a pass, and record a freshness boundary. Dry-run output is forcibly
|
||||
`not-run`. The attended all-host run waits for an environment with Ansible and
|
||||
reviewed permission to refresh the on-host Goss surface; this workstation has
|
||||
no `ansible-playbook`. No host was contacted.
|
||||
`not-run`. The live playbook is now remotely read-only: a static contract
|
||||
rejects mutating modules and arbitrary commands, it requires the installed
|
||||
Goss surface to match the locally rendered profile digest, and it writes only
|
||||
controller-side evidence. Refresh is a separate exact-approval interface. The
|
||||
attended all-host run now waits only for Ansible plus short-lived SSH access;
|
||||
no host was contacted.
|
||||
|
||||
## T06 — Repair and enforce the secret-source contract
|
||||
|
||||
|
|
@ -286,10 +289,14 @@ decryption receipt or recipient change was attempted.
|
|||
|
||||
Current evidence (2026-08-23):
|
||||
|
||||
- Python unit suite: 25 tests pass.
|
||||
- Python unit suite: 30 tests pass, including rejection of a remote template,
|
||||
arbitrary remote command, non-delegated controller write, and unreviewed
|
||||
Goss command surface in the handoff path.
|
||||
- Terraform 1.9.8 mock-provider tests: 2 pass.
|
||||
- Ansible 2.17.13 syntax checks: bootstrap, verify, and firewall pass in a
|
||||
disposable environment.
|
||||
- Ansible 2.17.13 syntax checks: bootstrap, read-only verify, explicit
|
||||
verify-refresh, and firewall pass in a disposable environment. A disposable
|
||||
render comparison also proves the template lookup digest matches the bytes
|
||||
produced by Ansible's deployment template action.
|
||||
- Both profile-specific Goss templates render and parse as YAML.
|
||||
- Inventory, baseline, secret metadata, receipt, shell syntax, Python compile,
|
||||
and whitespace checks pass.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue