Validate OpenBao snapshot evidence and record assurance closure gates
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
codex 2026-09-06 15:24:58 +02:00
parent a867ec269a
commit 31386c8e63
7 changed files with 115 additions and 3 deletions

View file

@ -129,3 +129,11 @@ overwrite bug. The restore tool explicitly accepts both forms, with verified
hash/decryption flags. Existing historical receipts are unchanged. These producer
fixes enable future dated archive evidence; automatic archive adapters, fresh
end-to-end receipts and recurring execution are still pending.
The OpenBao snapshot adapter also accepts the reviewed, hash-pinned receipt in
`reviews/`. It requires the expected source cluster identity, encrypted off-host
custody, verified hashes and creation time. That time is a conservative age
anchor for snapshot creation, not proof of a later restore or renewed custody.
The August 22 receipt evaluates stale under the 36-hour budget. Updating the
index or reading the file cannot renew it; an isolated OpenBao restore remains
a separate obligation.