Harden backup credentials and add durable image inventory publication
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
parent
62423fd092
commit
0349a08e1b
13 changed files with 365 additions and 23 deletions
44
docs/evidence/repo-review-2026-09-05.md
Normal file
44
docs/evidence/repo-review-2026-09-05.md
Normal file
|
|
@ -0,0 +1,44 @@
|
|||
# Repository review — 2026-09-05
|
||||
|
||||
Reviewed the working tree, fetched origin, scanned all local workplan statuses,
|
||||
and read/acknowledged the State Hub inbox. Existing WORK-RECORDS.md changes
|
||||
correct renumbered plans 0025–0027 and are retained.
|
||||
|
||||
Open plans 0015, 0025 and 0027 retain their attended gates: approved exercise
|
||||
windows/abort operators, operator listener cutover, and exact recovery/custody
|
||||
receipts. No new qualifying receipts were in the unread inbox.
|
||||
|
||||
New actionable source work is tracked by RPF-WP-0028 (durable image inventory)
|
||||
and RPF-WP-0029 (backup credential fallback). Their live completion gates remain
|
||||
explicit. No prune, reboot, lease revocation, or provider rotation was run.
|
||||
|
||||
Other inbox demands requiring scoped design or owner inputs remain pending:
|
||||
|
||||
- ops-mason fluid-telegram: tenant prefix and actual OIDC group claim remain
|
||||
unconfirmed. Read/write policy requires reviewed CCR schema/validator support;
|
||||
current read-only request shape must not be bypassed.
|
||||
- secrets-engine: native AppRole apply still requires serving canonical action
|
||||
authorization, exact targets, attended authority and consumer health proof.
|
||||
Its separate service JWT mount/role contract is not yet established here.
|
||||
- State Hub rename preflight: dedicated signing-secret lane remains to be
|
||||
designed and approved; the rename is outside this session's scope.
|
||||
- Policy Nexus CCR-2026-0014 request is superseded by the repository's existing
|
||||
activation commit 62423fd; no duplicate provisioning performed.
|
||||
- Activity-core OpenRouter recovery was reported complete and its intentional
|
||||
reuse decision retained in RPF-WP-0004.
|
||||
|
||||
No coordination messages were sent. Incoming requests are recorded here for
|
||||
follow-up rather than treated as permission to invent identities or credentials.
|
||||
|
||||
Validation: unittest discovery passed 158 tests; full pytest discovery passed
|
||||
164 tests, including the function-based tests omitted by unittest. Bash syntax
|
||||
and git diff whitespace checks passed. The inventory and credential tests use synthetic
|
||||
inputs and mocked custody only.
|
||||
|
||||
State Hub synchronization remains pending: `statehub fix-consistency` was
|
||||
attempted in the sandbox and once outside it. Both were interrupted after
|
||||
prolonged HTTP reads during the check phase, before a repair report was
|
||||
returned. No registrar skip was reported, so registrar authority was not
|
||||
assumed. Re-run `statehub fix-consistency` when these reads complete reliably
|
||||
to index the new workplans and refresh the generated records/brief. Progress
|
||||
was logged successfully as `7e317a96-eb7e-4b36-9d81-4efe49efa22c`.
|
||||
Loading…
Add table
Add a link
Reference in a new issue