Validate OpenBao snapshot evidence and record assurance closure gates
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
parent
a867ec269a
commit
31386c8e63
7 changed files with 115 additions and 3 deletions
|
|
@ -129,3 +129,11 @@ overwrite bug. The restore tool explicitly accepts both forms, with verified
|
|||
hash/decryption flags. Existing historical receipts are unchanged. These producer
|
||||
fixes enable future dated archive evidence; automatic archive adapters, fresh
|
||||
end-to-end receipts and recurring execution are still pending.
|
||||
|
||||
The OpenBao snapshot adapter also accepts the reviewed, hash-pinned receipt in
|
||||
`reviews/`. It requires the expected source cluster identity, encrypted off-host
|
||||
custody, verified hashes and creation time. That time is a conservative age
|
||||
anchor for snapshot creation, not proof of a later restore or renewed custody.
|
||||
The August 22 receipt evaluates stale under the 36-hour budget. Updating the
|
||||
index or reading the file cannot renew it; an isolated OpenBao restore remains
|
||||
a separate obligation.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue