Fix rotation review evidence and reconcile blocked S1 workplans
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e3b9-b19e-7ba1-9eb4-4faea76af3ea
This commit is contained in:
parent
41f25fe42d
commit
9886567b40
10 changed files with 255 additions and 18 deletions
54
docs/evidence/2026-09-27-loose-ends.md
Normal file
54
docs/evidence/2026-09-27-loose-ends.md
Normal file
|
|
@ -0,0 +1,54 @@
|
|||
# Existing workplan closeout review — 2026-09-27
|
||||
|
||||
Reviewed all root and archived workplans. The only unfinished plans are
|
||||
RAIL-HO-WP-0011, 0012 and 0013; all now have state `blocked`, with eight
|
||||
remaining tasks in `wait`. No new task or workplan was opened. No residual task
|
||||
has been marked done without its required live acceptance evidence.
|
||||
|
||||
## Implemented under WP-0011 T06/T08
|
||||
|
||||
- Rotation dry-run output exposes the exact metadata-only review plan.
|
||||
- Approval binds each changed ciphertext's SHA-256 as well as recipients/path.
|
||||
- Applied receipts retain the original and resulting recipient/hash evidence.
|
||||
- Unrelated Make targets no longer eagerly decrypt the Hetzner token or read
|
||||
and export the local age private key.
|
||||
|
||||
Validation: 54 Python unit tests pass, including three new rotation regression
|
||||
tests. Inventory, baseline parity, read-only handoff contract, protected secret
|
||||
paths, SOPS recipient metadata and whitespace checks pass. Ansible-core 2.17.13
|
||||
host-time playbook syntax check passes in a disposable controller environment.
|
||||
No production decryption, recipient rotation or credential retrieval occurred.
|
||||
|
||||
## Read-only host verification
|
||||
|
||||
`ansible-playbook playbooks/verify.yaml`, Ansible-core 2.17.13, reached both hosts:
|
||||
|
||||
| Host | Checks completed | Blocking assertion | Changes |
|
||||
| --- | --- | --- | --- |
|
||||
| CoulombCore | Executable and baseline stat | `/usr/local/bin/goss` absent | 0 |
|
||||
| Railiance01 | Executable and baseline stat | Installed baseline digest differs from source render | 0 |
|
||||
|
||||
The initial sandboxed attempt failed writing Ansible's connection cache; the
|
||||
rerun with that access produced the host findings above. Neither attempt is a
|
||||
passing handoff. Host refresh includes installation/configuration and an hourly
|
||||
timer, so the concrete rendered diff must be reviewed before that separate
|
||||
mutation; subsequent baseline failures must also be resolved before T05 closes.
|
||||
|
||||
## Backup dependency correction
|
||||
|
||||
The exact S1 offsite contract remains pending:
|
||||
`d150eb3e6a19d658aa76c930b32fc20ef75ffa399558fc193fbde0738551ee62`.
|
||||
Warden's route reports unknown execution workload identity. Platform WP-0029's
|
||||
September 15 closure resolves the old upload-share incident, but does not accept
|
||||
this contract or prove S1 transfer/restore. Keep WP-0012 T05/T06 waiting for those
|
||||
specific owner and recovery receipts.
|
||||
|
||||
## Clock dependency check
|
||||
|
||||
The existing railiance-clock collector produced
|
||||
`2026-09-27-railiance01-clock-inventory.json`. Read-only `dpkg-query -W systemd
|
||||
systemd-timesyncd` returned `255.4-1ubuntu8.17` for both. Effective source/poll
|
||||
observations and configuration hashes are recorded in the receipt and WP-0013.
|
||||
RCLK-WP-0002 still lacks completed policy review; no disposable Ubuntu VM is
|
||||
declared here for reboot/outage/rollback testing. The already deployed authority
|
||||
does not close those gates. No clocks or services were changed.
|
||||
Loading…
Add table
Add a link
Reference in a new issue