Record live receiver gate and isolate readiness from attestation jobs
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
codex 2026-09-11 07:26:16 +02:00
parent 5cc325b744
commit 290e2b51fd
4 changed files with 211 additions and 3 deletions

View file

@ -0,0 +1,172 @@
{
"schema": "hfact.factory-audit-receiver-live.v1",
"observed_at": "2026-09-11",
"release": {
"image": "forgejo.coulomb.social/coulomb/audit-core@sha256:c82e0442de0fd181342916ae9cd5d6de41d859e1efda637bd93936c67873afa5",
"source_commit": "cb23dc82fd5dbadfdfb84e99581068bd0aa667c0"
},
"native_contract": {
"schema": "platform.factory-audit-custody.v1",
"status": "receiver_contract_supported",
"credential_values_emitted": false,
"started_at": "2026-09-11T04:50:27.072575+00:00",
"lanes": [
{
"ccr": "CCR-2026-0021",
"name": "approval-engine",
"kv": "platform/data/workloads/approval-engine/audit-sender",
"store": "openbao-approval-engine-audit",
"secret": "approval-engine-audit",
"secret_key": "audit-token",
"source_sha256": "ba69ecc8227c5bf887c2cd0ac4c50518c019bebfdfb6d49628edee1ce570da7d"
},
{
"ccr": "CCR-2026-0022",
"name": "informed-decision",
"kv": "platform/data/workloads/informed-decision/audit-sender",
"store": "openbao-informed-decision-audit",
"secret": "informed-decision-audit",
"secret_key": "token",
"source_sha256": "2f7f7f214d1e21fd79275197edd03ee7e154ef451d62a182017926250515a6aa"
}
],
"receiver": {
"image": "forgejo.coulomb.social/coulomb/audit-core@sha256:c82e0442de0fd181342916ae9cd5d6de41d859e1efda637bd93936c67873afa5",
"deployment_uid": "b85fe3d0-75c9-4e0d-8c34-c6f1df0881bb",
"deployment_resource_version": "59740687",
"pod_uid": "6642c414-a942-4b11-b048-267423e12da8",
"capabilities": {
"load_bearing": true,
"redact": true,
"write_only": true,
"source_exact": true,
"tenant_exact": true
},
"synthetic_probe_only": true,
"credential_reads": 0
}
},
"native_before": {
"ready": {
"status": "ok",
"custody_class": "operational",
"durable": true,
"tamper_evidence": true,
"recoverable_days": 30,
"recoverable_source": "resource-control/data/capability/platform-audit-storage.json#provisions[capability=data.backup]",
"recoverable_basis": "measured"
},
"chain": {
"intact": true,
"events": 32,
"head": "9fc0b4f25c562cec037a5077f00ee63380db8b5c4e85b6016fc40b301431e4fd",
"head_event_id": "whitehat-e2-event-b-20260822-03",
"head_accepted_at": "2026-08-22T22:09:37+00:00",
"first_break": null,
"attestation_match": null
},
"image": "forgejo.coulomb.social/coulomb/audit-core@sha256:c2fe39a0185b99be3fc0cb14d2de69772b8e66e20490097c9d11d90cc39719a6",
"generation": 15,
"deployment_uid": "b85fe3d0-75c9-4e0d-8c34-c6f1df0881bb"
},
"native_after": {
"ready": {
"status": "ok",
"custody_class": "operational",
"durable": true,
"tamper_evidence": false,
"recoverable_days": 30,
"recoverable_source": "resource-control/data/capability/platform-audit-storage.json#provisions[capability=data.backup]",
"recoverable_basis": "measured"
},
"chain": {
"intact": true,
"events": 32,
"head": "9fc0b4f25c562cec037a5077f00ee63380db8b5c4e85b6016fc40b301431e4fd",
"head_event_id": "whitehat-e2-event-b-20260822-03",
"head_accepted_at": "2026-08-22T22:09:37+00:00",
"first_break": null,
"attestation_match": null
}
},
"release_container": {
"image": "forgejo.coulomb.social/coulomb/audit-core:cb23dc82fd5dbadfdfb84e99581068bd0aa667c0",
"native_credentials_used": false,
"checks": {
"operational_ready": true,
"nonroot_readonly": true,
"approval-engine": {
"accepted": 202,
"duplicate": 200,
"wrong_source": 400,
"wrong_tenant": 400,
"read_routes_denied": 7,
"independent_read": 200,
"redacted": true,
"stored_once": true
},
"informed-decision": {
"accepted": 202,
"duplicate": 200,
"wrong_source": 400,
"wrong_tenant": 400,
"read_routes_denied": 7,
"independent_read": 200,
"redacted": true,
"stored_once": true
},
"sigterm": {
"exit_code": 0,
"inflight_committed_once": true,
"restart_retry_duplicate": true,
"chain_intact": true
}
},
"started_at": "2026-09-11T04:47:21.436615+00:00",
"status": "passed",
"own_fixture_cleanup": true
},
"approvals": [
{
"ccr": "CCR-2026-0021",
"decision_id": "2c9fe9f0-034a-41d7-9d49-b99df488fdc8",
"status": "resolved",
"decided_by": "user (platform-operator, audit-core-owner, approval-engine-owner)",
"decided_at": "2026-09-11T04:36:46.312720Z"
},
{
"ccr": "CCR-2026-0022",
"decision_id": "ee4ff001-256a-4406-9cb8-51be2cd5d31b",
"status": "resolved",
"decided_by": "user (platform-operator, audit-core-owner, informed-decision-owner)",
"decided_at": "2026-09-11T04:36:46.480026Z"
}
],
"approval_engine_namespace": "created from owner manifest; no workload deployed",
"sender_ingress": "two exact source-declared namespace AND workload-label peers applied",
"sender_custody": {
"status": "attended_login_failed_before_command_handoff",
"credential_command_started": false,
"custody_receipt_exists": false,
"remote_session_revocation": "not_confirmed_by_warden",
"operator_browser_feedback": "requested"
},
"receiver_tests": {
"passed": 229,
"migration_exclusion": "AUDIT-IN-0004: five existing PostgreSQL failures in historical SQLite importer"
},
"platform_tests": {
"passed": 18
},
"schema_migration_executed": false,
"attestation_residual": "AUDIT-WP-0009-T12",
"factory_attempts": 0,
"paid_model_calls": 0,
"release_scan": {
"vulnerabilities": 0,
"sha256": "f2e6be3514040766bd29a4f8a5265989e8fab6802c935b86bad19aa3ae6c4824",
"scanner": "aquasec/trivy@sha256:62b1e65e8869bc4b4c6aa4fa2b21595256c7c2f6018a9d9ad61caf87187c1969",
"warning": "Alpine 3.24 not in scanner OS lifecycle list"
},
"receiver_selector": "app.kubernetes.io/name=audit-core,app.kubernetes.io/component=receiver"
}

View file

@ -89,7 +89,7 @@ def receiver_check(kube, expected_image):
and dep['status'].get('observedGeneration',0) >= dep['metadata']['generation'], 'receiver_not_ready') and dep['status'].get('observedGeneration',0) >= dep['metadata']['generation'], 'receiver_not_ready')
containers = dep['spec']['template']['spec']['containers'] containers = dep['spec']['template']['spec']['containers']
require(len(containers) == 1 and containers[0]['image'] == expected_image, 'receiver_image_mismatch') require(len(containers) == 1 and containers[0]['image'] == expected_image, 'receiver_image_mismatch')
pods = data(command(kube + ['-n','audit-core','get','pods','-l','app.kubernetes.io/name=audit-core','-o','json']))['items'] pods = data(command(kube + ['-n','audit-core','get','pods','-l','app.kubernetes.io/name=audit-core,app.kubernetes.io/component=receiver','-o','json']))['items']
require(len(pods) == 1 and not pods[0]['metadata'].get('deletionTimestamp'), 'receiver_rollout_in_progress') require(len(pods) == 1 and not pods[0]['metadata'].get('deletionTimestamp'), 'receiver_rollout_in_progress')
pod = pods[0] pod = pods[0]
require(pod['spec']['containers'][0]['image'] == expected_image require(pod['spec']['containers'][0]['image'] == expected_image

View file

@ -77,6 +77,25 @@ class Contracts(unittest.TestCase):
lane.receiver_check(['kubectl'],dep['spec']['template']['spec']['containers'][0]['image']) lane.receiver_check(['kubectl'],dep['spec']['template']['spec']['containers'][0]['image'])
def test_completed_attestation_pods_do_not_block_the_receiver(self):
image='forgejo.coulomb.social/coulomb/audit-core@sha256:'+'a'*64
dep={'metadata':{'uid':'d','generation':1,'resourceVersion':'1'},'spec':{'replicas':1,'template':{'spec':{'containers':[{'name':'audit-core','image':image}]}}},'status':{'observedGeneration':1,'readyReplicas':1}}
receiver={'metadata':{'name':'receiver','uid':'p','labels':{'app.kubernetes.io/name':'audit-core','app.kubernetes.io/component':'receiver'}},'spec':dep['spec']['template']['spec'],'status':{'containerStatuses':[{'ready':True}]}}
attest={'metadata':{'name':'attestation-completed','labels':{'app.kubernetes.io/name':'audit-core','app.kubernetes.io/component':'attest'}},'status':{'phase':'Succeeded'}}
def kube(argv):
if 'deployment' in argv: result=dep
elif 'pods' in argv:
selector=argv[argv.index('-l')+1]
terms=[pair.split('=',1) for pair in selector.split(',')]
result={'items':[p for p in [receiver,attest] if all(p['metadata']['labels'].get(k)==v for k,v in terms)]}
else:
self.assertIn('receiver',argv)
result={k:True for k in ['load_bearing','redact','write_only','source_exact','tenant_exact']}
return subprocess.CompletedProcess(argv,0,json.dumps(result).encode(),b'')
with patch.object(lane,'assert_cluster'),patch.object(lane,'command',side_effect=kube),patch.object(lane,'bao',side_effect=AssertionError('no credentials')):
self.assertEqual(lane.receiver_check(['kubectl'],image)['pod_uid'],'p')
class OpenBaoExercise(unittest.TestCase): class OpenBaoExercise(unittest.TestCase):
@classmethod @classmethod
def setUpClass(cls): def setUpClass(cls):

View file

@ -397,11 +397,11 @@ into this client-identity grant.
```task ```task
id: RPF-WP-0035-T08 id: RPF-WP-0035-T08
status: progress status: wait
priority: high priority: high
assignee: railiance-platform assignee: railiance-platform
needs_human: true needs_human: true
intervention_note: "CCR-2026-0021/0022 need named platform-operator, audit-core-owner and producer-owner reviews. Receiver upgrade and namespace readiness remain separate preconditions; approval alone does not admit factory execution." intervention_note: "All named CCR-2026-0021/0022 reviews are approved. Compatible receiver and namespaces are ready. Attended OIDC failed before owner-command handoff; Warden could not confirm remote session revocation. Await operator browser/MFA feedback and login/session resolution before custody retry. Do not repeat sender approval."
state_hub_task_id: "0ef52c26-2669-5cd1-8149-b1f6fcdda6cb" state_hub_task_id: "0ef52c26-2669-5cd1-8149-b1f6fcdda6cb"
``` ```
@ -481,3 +481,20 @@ platform-operator, audit-core-owner and both producer owners. Both exact request
are approved; their existing State Hub decisions are resolved. This clears the are approved; their existing State Hub decisions are resolved. This clears the
review request only. Receiver rollout, namespace readiness, attended custody and review request only. Receiver rollout, namespace readiness, attended custody and
positive/negative native evidence remain the execution gates. positive/negative native evidence remain the execution gates.
### Native receiver and attended execution return — 2026-09-11
Audit Core c82e0442de0f is deployed and passes the native synthetic contract.
Its existing 32-event chain/head is unchanged. The owner Approval Engine
namespace now exists and all four ESO objects pass strict server dry-run.
The two exact ingress rules are applied; sender custody/ESO application is not.
Warden selected founder_required/oidc_login and attempted the reviewed silent
seed command through the contained wrapper. Login failed before command
handoff; no custody receipt was created. Warden could not confirm remote
session revocation. Await operator browser/MFA feedback and login/session
resolution. Approvals remain valid; T08 waits for the identity act, not review.
The receiver check now selects component=receiver, so retained attestation-job
pods cannot falsely block a stable receiver. Eighteen custody tests pass.
[Native return](../docs/evidence/2026-09-11-factory-receiver-live.json).