Review blocked platform obligations and archive completed ESO recovery
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
codex 2026-09-05 21:16:53 +02:00
parent b2c2848e49
commit 34e78e8937
10 changed files with 302 additions and 10 deletions

View file

@ -8,10 +8,10 @@ plans is not a count of missing implementations or independent incidents.
| Workplan | Purpose and next gate | S3 boundary |
| --- | --- | --- |
| [RPF-WP-0027](RPF-WP-0027-keycape-live-secret-exposure-recovery.md) | Incident custody and final evidence; accept NetKingdom's residual disposition and publish exact custody handoff | The bundle was already rotated. Provider/MFA reconciliation belongs to NetKingdom. |
| [RPF-WP-0029](RPF-WP-0029-backup-credential-default-removal.md) | Backup credential exposure; attended provider invalidation and replacement recovery receipts | S3 retains custody acceptance; S1 and forge own their backup execution. |
| [RPF-WP-0029](RPF-WP-0029-backup-credential-default-removal.md) | Backup account cutover complete; old share invalidation and full offsite application restore remain | S3 retains custody acceptance; S1 and forge own their backup execution. |
| [RPF-WP-0025](RPF-WP-0025-openbao-operator-only-access.md) | Private OpenBao access; fresh attended callback/login then guarded retraction | Coordinate package, issuer, tunnel and DNS owners; keep the window separate. |
| [RPF-WP-0015](RPF-WP-0015-audit-core-custody-and-recovery-coordination.md) | Two prepared recovery exercises; fresh synthetic-load/outage approvals and custody readiness | S3 contributes lease/ESO and snapshot/unseal proof; S1/S2 and audit-core execute their parts. |
| [RPF-WP-0035](RPF-WP-0035-credential-lane-implementation.md) | One implementation queue for secrets-engine JWT, Fluid operator KV and preflight signing | Three independent task gates; no new approval inherited from the completed designs. |
| [RPF-WP-0015](RPF-WP-0015-audit-core-custody-and-recovery-coordination.md) | Two prepared recovery exercises; registered load driver exists; fresh sender/window/abort approvals and custody readiness remain | S3 contributes lease/ESO and snapshot/unseal proof; S1/S2 and audit-core execute their parts. |
| [RPF-WP-0035](RPF-WP-0035-credential-lane-implementation.md) | Two remaining lanes: secrets-engine JWT and Fluid operator KV | Signing T04 is complete; JWT and Fluid retain separate issuer/consumer gates. |
| [RPF-WP-0036](RPF-WP-0036-platform-service-assurance.md) | Implemented local assurance/admission; waits for recurring restore evidence, Q2 reception and owner handoff | Run the assurance commands; live acceptance and external ownership remain gated. |
RPF-WP-0036-T02/T05/T07 are complete; T03/T04/T06 retain the remaining
@ -23,3 +23,11 @@ and [generated current record index](../WORK-RECORDS.md).
Do not recreate completed workplans because an old Hub alias or generated brief
still shows them active. Use source IDs, and follow AGENTS.md for verified sync.
## Latest closure review
[2026-09-05 blocker review](../history/2026-09-05-blocked-workplan-closure-review.md):
12 unfinished tasks across six genuine blocked plans. All terminal plans have
only done/cancel tasks. Completed ESO recovery RPF-WP-0037 is archived.
Three retired Hub aliases still appear open; they are a derived-view defect,
not three more workplans. Use this file before the dated generated brief.

View file

@ -336,3 +336,14 @@ containment defect; the next attempt still needs current acceptance evidence.
Do not create another platform-owned whole-host drill or duplicate these live
tasks in RPF-WP-0036; that plan owns recurring service assurance.
## Blocker recheck — 2026-09-05
AUDIT-WP-0008-T07 already records the synthetic-load driver at `8c8bcf4`,
candidate receipt `7879bf65-06b7-4d0c-bbd1-873b6d20b7fc` and SHA-256
`941ba251f638869626b06e9cbf430c70188c0bdf4715e3eff9c7610366f68662`.
It also records a local accepted/duplicate HTTP round trip. Driver construction
is no longer missing. T02 waits on its separately approved sender identity,
fresh bounded window, abort operator and live recovery receipt. Local driver
success does not prove lease revocation/ESO recovery. T03 remains a separate
outage exercise; no historical window or terminal NO-GO may be reused.

View file

@ -229,3 +229,16 @@ negative checks and repeated refresh passed, obsolete invalid delivery tokens
were removed, and all 27 ExternalSecrets now report Ready. The earlier dated
assurance snapshot is retained as historical evidence. T04 still waits on the
accepted Q2 receiver and controlled failure/absence transport proof.
## Blocker closure review — 2026-09-05
Fresh metadata capture verified all 15 collected signals healthy; seven recovery
signals remain absent from the evaluator. RPF-WP-0037 is archived. The completed
Backup account fixture proof remains separate from a full backup/restore receipt.
T03/T04 remain waiting on recovery evidence/cadence and Q2 delivery respectively.
T06's source inventory hashes were refreshed; its dated retention decision is
unchanged. A repo-filtered Hub read confirms three retired aliases still appear
open. The installed generator would reproduce them; exact UUID mapping and
remaining owner requirements are persisted in
`history/2026-09-05-blocked-workplan-closure-review.md`. No duplicate recovery,
monitoring or owner-transfer workplan was created.