Record operator approval of the two factory audit sender lanes
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
parent
0adc5b0e49
commit
5cc325b744
6 changed files with 155 additions and 106 deletions
|
|
@ -3,29 +3,38 @@ kind: credential-change-request
|
||||||
schema_version: 1
|
schema_version: 1
|
||||||
request_type: workload-kv-read
|
request_type: workload-kv-read
|
||||||
title: approval-engine load-bearing audit sender custody and delivery
|
title: approval-engine load-bearing audit sender custody and delivery
|
||||||
status: proposed
|
status: approved
|
||||||
created: '2026-09-11'
|
created: '2026-09-11'
|
||||||
updated: '2026-09-11'
|
updated: '2026-09-11'
|
||||||
requester:
|
requester:
|
||||||
agent: codex
|
agent: codex
|
||||||
reason: AUDIT-WP-0009-T09 and HFACT-WP-0001-T03 require the existing exact sender declaration. This
|
reason: AUDIT-WP-0009-T09 and HFACT-WP-0001-T03 require the existing exact sender
|
||||||
request supplies the missing platform custody and ESO delivery; receiver compatibility and service
|
declaration. This request supplies the missing platform custody and ESO delivery;
|
||||||
rollout remain explicit gates.
|
receiver compatibility and service rollout remain explicit gates.
|
||||||
review:
|
review:
|
||||||
required: true
|
required: true
|
||||||
required_approvers:
|
required_approvers:
|
||||||
- platform-operator
|
- platform-operator
|
||||||
- audit-core-owner
|
- audit-core-owner
|
||||||
- approval-engine-owner
|
- approval-engine-owner
|
||||||
comments: []
|
comments:
|
||||||
|
- at: '2026-09-11T04:36:46+00:00'
|
||||||
|
reviewer: user (platform-operator, audit-core-owner, approval-engine-owner)
|
||||||
|
decision: approved
|
||||||
|
comment: User replied "good, go on" on 2026-09-11 to the explicit approval question
|
||||||
|
for CCR-2026-0021 and CCR-2026-0022 as platform operator and owner of Audit
|
||||||
|
Core, Approval Engine, and Informed Decision. Record this as approval of the
|
||||||
|
reviewed exact sender lane. Compatible receiver, namespace readiness, attended
|
||||||
|
custody and native verification remain prerequisites; no factory execution or
|
||||||
|
broader grant is admitted.
|
||||||
target:
|
target:
|
||||||
domain: financials
|
domain: financials
|
||||||
tenant: platform
|
tenant: platform
|
||||||
workload: approval-engine
|
workload: approval-engine
|
||||||
environment: production
|
environment: production
|
||||||
purpose: Provide only the approval-engine sender with source=approval-engine, tenants=[tenant:platform],
|
purpose: Provide only the approval-engine sender with source=approval-engine, tenants=[tenant:platform],
|
||||||
may_write=true, may_read=false, evidence_kind=load-bearing, secret_policy=redact. Preserve the
|
may_write=true, may_read=false, evidence_kind=load-bearing, secret_policy=redact.
|
||||||
existing receiver registry and every other sender.
|
Preserve the existing receiver registry and every other sender.
|
||||||
openbao:
|
openbao:
|
||||||
mount: platform
|
mount: platform
|
||||||
kv_path: platform/workloads/approval-engine/audit-sender
|
kv_path: platform/workloads/approval-engine/audit-sender
|
||||||
|
|
@ -55,56 +64,64 @@ access_frontdoor:
|
||||||
resolvable: false
|
resolvable: false
|
||||||
delivery:
|
delivery:
|
||||||
surface: external-secrets
|
surface: external-secrets
|
||||||
target: 'ClusterSecretStore openbao-approval-engine-audit restricted to namespace approval-engine;
|
target: 'ClusterSecretStore openbao-approval-engine-audit restricted to namespace
|
||||||
ExternalSecret and Secret approval-engine/approval-engine-audit, key audit-token. Source: manifests/factory-audit-senders.yaml.
|
approval-engine; ExternalSecret and Secret approval-engine/approval-engine-audit,
|
||||||
A missing namespace stays a workload-owner prerequisite; this packet creates none.'
|
key audit-token. Source: manifests/factory-audit-senders.yaml. A missing namespace
|
||||||
|
stays a workload-owner prerequisite; this packet creates none.'
|
||||||
risk:
|
risk:
|
||||||
classification: high
|
classification: high
|
||||||
notes:
|
notes:
|
||||||
- A bearer permits append for its exact sender and tenant, never reading or changing stored evidence.
|
- A bearer permits append for its exact sender and tenant, never reading or changing
|
||||||
- The registry update reads existing sender credentials inside the attended platform process only.
|
stored evidence.
|
||||||
No registry is delivered to a producer.
|
- The registry update reads existing sender credentials inside the attended platform
|
||||||
- OpenBao login TTL limits the ESO reader session, not the audit bearer. Revocation must remove
|
process only. No registry is delivered to a producer.
|
||||||
the sender token from the receiver registry and prove refusal.
|
- OpenBao login TTL limits the ESO reader session, not the audit bearer. Revocation
|
||||||
- New paths extend the existing coding-agent deny boundary. No existing high-risk grant is widened.
|
must remove the sender token from the receiver registry and prove refusal.
|
||||||
|
- New paths extend the existing coding-agent deny boundary. No existing high-risk
|
||||||
|
grant is widened.
|
||||||
verification:
|
verification:
|
||||||
positive:
|
positive:
|
||||||
- Independent CAS=0 token creation and exact sender merge with registry-version compare-and-set;
|
- Independent CAS=0 token creation and exact sender merge with registry-version
|
||||||
repeated runs preserve both tokens and other registry fields.
|
compare-and-set; repeated runs preserve both tokens and other registry fields.
|
||||||
- ESO delivers only AUDIT_TOKEN into approval-engine/approval-engine-audit:audit-token; source and
|
- ESO delivers only AUDIT_TOKEN into approval-engine/approval-engine-audit:audit-token;
|
||||||
receiver copies agree without displaying values.
|
source and receiver copies agree without displaying values.
|
||||||
- Compatible deployed receiver accepts and deduplicates a declared synthetic event for the exact
|
- Compatible deployed receiver accepts and deduplicates a declared synthetic event
|
||||||
sender and tenant, retaining load-bearing/redact declarations.
|
for the exact sender and tenant, retaining load-bearing/redact declarations.
|
||||||
negative:
|
negative:
|
||||||
- Sibling sender path, full registry and parent listing are denied to each workload reader. Wrong
|
- Sibling sender path, full registry and parent listing are denied to each workload
|
||||||
service account/namespace and disallowed store namespace fail.
|
reader. Wrong service account/namespace and disallowed store namespace fail.
|
||||||
- Receiver denies sibling source, wrong tenant, every read route and revoked token. No existing
|
- Receiver denies sibling source, wrong tenant, every read route and revoked token.
|
||||||
sender is removed or re-scoped.
|
No existing sender is removed or re-scoped.
|
||||||
- Proposed or altered CCR, legacy receiver, malformed/duplicate registry identity, token collision,
|
- Proposed or altered CCR, legacy receiver, malformed/duplicate registry identity,
|
||||||
stale registry version or partial/conflicting custody refuses without overwriting.
|
token collision, stale registry version or partial/conflicting custody refuses
|
||||||
|
without overwriting.
|
||||||
activation_conditions:
|
activation_conditions:
|
||||||
- All three named owner reviews are approved before any native credential mutation.
|
- All three named owner reviews are approved before any native credential mutation.
|
||||||
- A current image supporting evidence_kind is published/admitted by audit-core and deployed with
|
- A current image supporting evidence_kind is published/admitted by audit-core and
|
||||||
its source scope and network policy; current c2fe39a image fails compatibility.
|
deployed with its source scope and network policy; current c2fe39a image fails
|
||||||
- Use the Warden attended platform-admin login envelope; preserve independent receipt and revoke
|
compatibility.
|
||||||
the session on exit.
|
- Use the Warden attended platform-admin login envelope; preserve independent receipt
|
||||||
- Apply reviewed policy/auth metadata and ESO projection only after receiver compatibility and namespace
|
and revoke the session on exit.
|
||||||
readiness. An interrupted seed resumes from durable KV values, never blindly rotates or deletes.
|
- Apply reviewed policy/auth metadata and ESO projection only after receiver compatibility
|
||||||
- Record native positive/negative evidence before declaring verified or active. Custody alone does
|
and namespace readiness. An interrupted seed resumes from durable KV values, never
|
||||||
not admit UI, human approval or factory execution.
|
blindly rotates or deletes.
|
||||||
|
- Record native positive/negative evidence before declaring verified or active.
|
||||||
|
Custody alone does not admit UI, human approval or factory execution.
|
||||||
lifecycle:
|
lifecycle:
|
||||||
deactivate: Stop the exact producer; remove only its admitted token from the registry using CAS
|
deactivate: Stop the exact producer; remove only its admitted token from the registry
|
||||||
and reload/verify receiver refusal. Then detach its reader policy and remove its ExternalSecret/projection,
|
using CAS and reload/verify receiver refusal. Then detach its reader policy and
|
||||||
retaining KV versions for investigation. Do not delete audit events or other sender entries.
|
remove its ExternalSecret/projection, retaining KV versions for investigation.
|
||||||
rotate: 'Reviewed overlap-first rotation: append a replacement to this sender only, deliver it,
|
Do not delete audit events or other sender entries.
|
||||||
prove acceptance, then remove the predecessor and prove refusal. The first-provision helper refuses
|
rotate: 'Reviewed overlap-first rotation: append a replacement to this sender only,
|
||||||
rotation and unexpected existing values.'
|
deliver it, prove acceptance, then remove the predecessor and prove refusal. The
|
||||||
compromised: Stop affected producer and revoke the exact receiver token first; inspect affected
|
first-provision helper refuses rotation and unexpected existing values.'
|
||||||
source/tenant events, rotate through a separate reviewed action, and preserve the independent
|
compromised: Stop affected producer and revoke the exact receiver token first; inspect
|
||||||
audit trail.
|
affected source/tenant events, rotate through a separate reviewed action, and
|
||||||
|
preserve the independent audit trail.
|
||||||
state_hub:
|
state_hub:
|
||||||
workplan_id: RPF-WP-0035
|
workplan_id: RPF-WP-0035
|
||||||
task_id: RPF-WP-0035-T08
|
task_id: RPF-WP-0035-T08
|
||||||
related_workplan: AUDIT-WP-0009-T09
|
related_workplan: AUDIT-WP-0009-T09
|
||||||
decision_id: 2c9fe9f0-034a-41d7-9d49-b99df488fdc8
|
decision_id: 2c9fe9f0-034a-41d7-9d49-b99df488fdc8
|
||||||
decision_api_url: http://127.0.0.1:8000/decisions/2c9fe9f0-034a-41d7-9d49-b99df488fdc8
|
decision_api_url: http://127.0.0.1:8000/decisions/2c9fe9f0-034a-41d7-9d49-b99df488fdc8
|
||||||
|
decision_resolved_at: '2026-09-11T04:36:46.312720Z'
|
||||||
|
|
|
||||||
|
|
@ -3,29 +3,39 @@ kind: credential-change-request
|
||||||
schema_version: 1
|
schema_version: 1
|
||||||
request_type: workload-kv-read
|
request_type: workload-kv-read
|
||||||
title: informed-decision load-bearing audit sender custody and delivery
|
title: informed-decision load-bearing audit sender custody and delivery
|
||||||
status: proposed
|
status: approved
|
||||||
created: '2026-09-11'
|
created: '2026-09-11'
|
||||||
updated: '2026-09-11'
|
updated: '2026-09-11'
|
||||||
requester:
|
requester:
|
||||||
agent: codex
|
agent: codex
|
||||||
reason: AUDIT-WP-0009-T11 and HFACT-WP-0001-T03 require the existing exact sender declaration. This
|
reason: AUDIT-WP-0009-T11 and HFACT-WP-0001-T03 require the existing exact sender
|
||||||
request supplies the missing platform custody and ESO delivery; receiver compatibility and service
|
declaration. This request supplies the missing platform custody and ESO delivery;
|
||||||
rollout remain explicit gates.
|
receiver compatibility and service rollout remain explicit gates.
|
||||||
review:
|
review:
|
||||||
required: true
|
required: true
|
||||||
required_approvers:
|
required_approvers:
|
||||||
- platform-operator
|
- platform-operator
|
||||||
- audit-core-owner
|
- audit-core-owner
|
||||||
- informed-decision-owner
|
- informed-decision-owner
|
||||||
comments: []
|
comments:
|
||||||
|
- at: '2026-09-11T04:36:46+00:00'
|
||||||
|
reviewer: user (platform-operator, audit-core-owner, informed-decision-owner)
|
||||||
|
decision: approved
|
||||||
|
comment: User replied "good, go on" on 2026-09-11 to the explicit approval question
|
||||||
|
for CCR-2026-0021 and CCR-2026-0022 as platform operator and owner of Audit
|
||||||
|
Core, Approval Engine, and Informed Decision. Record this as approval of the
|
||||||
|
reviewed exact sender lane. Compatible receiver, namespace readiness, attended
|
||||||
|
custody and native verification remain prerequisites; no factory execution or
|
||||||
|
broader grant is admitted.
|
||||||
target:
|
target:
|
||||||
domain: financials
|
domain: financials
|
||||||
tenant: platform
|
tenant: platform
|
||||||
workload: informed-decision
|
workload: informed-decision
|
||||||
environment: production
|
environment: production
|
||||||
purpose: Provide only the informed-decision sender with source=informed-decision, tenants=[tenant:platform],
|
purpose: Provide only the informed-decision sender with source=informed-decision,
|
||||||
may_write=true, may_read=false, evidence_kind=load-bearing, secret_policy=redact. Preserve the
|
tenants=[tenant:platform], may_write=true, may_read=false, evidence_kind=load-bearing,
|
||||||
existing receiver registry and every other sender.
|
secret_policy=redact. Preserve the existing receiver registry and every other
|
||||||
|
sender.
|
||||||
openbao:
|
openbao:
|
||||||
mount: platform
|
mount: platform
|
||||||
kv_path: platform/workloads/informed-decision/audit-sender
|
kv_path: platform/workloads/informed-decision/audit-sender
|
||||||
|
|
@ -55,56 +65,64 @@ access_frontdoor:
|
||||||
resolvable: false
|
resolvable: false
|
||||||
delivery:
|
delivery:
|
||||||
surface: external-secrets
|
surface: external-secrets
|
||||||
target: 'ClusterSecretStore openbao-informed-decision-audit restricted to namespace informed-decision;
|
target: 'ClusterSecretStore openbao-informed-decision-audit restricted to namespace
|
||||||
ExternalSecret and Secret informed-decision/informed-decision-audit, key token. Source: manifests/factory-audit-senders.yaml.
|
informed-decision; ExternalSecret and Secret informed-decision/informed-decision-audit,
|
||||||
A missing namespace stays a workload-owner prerequisite; this packet creates none.'
|
key token. Source: manifests/factory-audit-senders.yaml. A missing namespace stays
|
||||||
|
a workload-owner prerequisite; this packet creates none.'
|
||||||
risk:
|
risk:
|
||||||
classification: high
|
classification: high
|
||||||
notes:
|
notes:
|
||||||
- A bearer permits append for its exact sender and tenant, never reading or changing stored evidence.
|
- A bearer permits append for its exact sender and tenant, never reading or changing
|
||||||
- The registry update reads existing sender credentials inside the attended platform process only.
|
stored evidence.
|
||||||
No registry is delivered to a producer.
|
- The registry update reads existing sender credentials inside the attended platform
|
||||||
- OpenBao login TTL limits the ESO reader session, not the audit bearer. Revocation must remove
|
process only. No registry is delivered to a producer.
|
||||||
the sender token from the receiver registry and prove refusal.
|
- OpenBao login TTL limits the ESO reader session, not the audit bearer. Revocation
|
||||||
- New paths extend the existing coding-agent deny boundary. No existing high-risk grant is widened.
|
must remove the sender token from the receiver registry and prove refusal.
|
||||||
|
- New paths extend the existing coding-agent deny boundary. No existing high-risk
|
||||||
|
grant is widened.
|
||||||
verification:
|
verification:
|
||||||
positive:
|
positive:
|
||||||
- Independent CAS=0 token creation and exact sender merge with registry-version compare-and-set;
|
- Independent CAS=0 token creation and exact sender merge with registry-version
|
||||||
repeated runs preserve both tokens and other registry fields.
|
compare-and-set; repeated runs preserve both tokens and other registry fields.
|
||||||
- ESO delivers only AUDIT_TOKEN into informed-decision/informed-decision-audit:token; source and
|
- ESO delivers only AUDIT_TOKEN into informed-decision/informed-decision-audit:token;
|
||||||
receiver copies agree without displaying values.
|
source and receiver copies agree without displaying values.
|
||||||
- Compatible deployed receiver accepts and deduplicates a declared synthetic event for the exact
|
- Compatible deployed receiver accepts and deduplicates a declared synthetic event
|
||||||
sender and tenant, retaining load-bearing/redact declarations.
|
for the exact sender and tenant, retaining load-bearing/redact declarations.
|
||||||
negative:
|
negative:
|
||||||
- Sibling sender path, full registry and parent listing are denied to each workload reader. Wrong
|
- Sibling sender path, full registry and parent listing are denied to each workload
|
||||||
service account/namespace and disallowed store namespace fail.
|
reader. Wrong service account/namespace and disallowed store namespace fail.
|
||||||
- Receiver denies sibling source, wrong tenant, every read route and revoked token. No existing
|
- Receiver denies sibling source, wrong tenant, every read route and revoked token.
|
||||||
sender is removed or re-scoped.
|
No existing sender is removed or re-scoped.
|
||||||
- Proposed or altered CCR, legacy receiver, malformed/duplicate registry identity, token collision,
|
- Proposed or altered CCR, legacy receiver, malformed/duplicate registry identity,
|
||||||
stale registry version or partial/conflicting custody refuses without overwriting.
|
token collision, stale registry version or partial/conflicting custody refuses
|
||||||
|
without overwriting.
|
||||||
activation_conditions:
|
activation_conditions:
|
||||||
- All three named owner reviews are approved before any native credential mutation.
|
- All three named owner reviews are approved before any native credential mutation.
|
||||||
- A current image supporting evidence_kind is published/admitted by audit-core and deployed with
|
- A current image supporting evidence_kind is published/admitted by audit-core and
|
||||||
its source scope and network policy; current c2fe39a image fails compatibility.
|
deployed with its source scope and network policy; current c2fe39a image fails
|
||||||
- Use the Warden attended platform-admin login envelope; preserve independent receipt and revoke
|
compatibility.
|
||||||
the session on exit.
|
- Use the Warden attended platform-admin login envelope; preserve independent receipt
|
||||||
- Apply reviewed policy/auth metadata and ESO projection only after receiver compatibility and namespace
|
and revoke the session on exit.
|
||||||
readiness. An interrupted seed resumes from durable KV values, never blindly rotates or deletes.
|
- Apply reviewed policy/auth metadata and ESO projection only after receiver compatibility
|
||||||
- Record native positive/negative evidence before declaring verified or active. Custody alone does
|
and namespace readiness. An interrupted seed resumes from durable KV values, never
|
||||||
not admit UI, human approval or factory execution.
|
blindly rotates or deletes.
|
||||||
|
- Record native positive/negative evidence before declaring verified or active.
|
||||||
|
Custody alone does not admit UI, human approval or factory execution.
|
||||||
lifecycle:
|
lifecycle:
|
||||||
deactivate: Stop the exact producer; remove only its admitted token from the registry using CAS
|
deactivate: Stop the exact producer; remove only its admitted token from the registry
|
||||||
and reload/verify receiver refusal. Then detach its reader policy and remove its ExternalSecret/projection,
|
using CAS and reload/verify receiver refusal. Then detach its reader policy and
|
||||||
retaining KV versions for investigation. Do not delete audit events or other sender entries.
|
remove its ExternalSecret/projection, retaining KV versions for investigation.
|
||||||
rotate: 'Reviewed overlap-first rotation: append a replacement to this sender only, deliver it,
|
Do not delete audit events or other sender entries.
|
||||||
prove acceptance, then remove the predecessor and prove refusal. The first-provision helper refuses
|
rotate: 'Reviewed overlap-first rotation: append a replacement to this sender only,
|
||||||
rotation and unexpected existing values.'
|
deliver it, prove acceptance, then remove the predecessor and prove refusal. The
|
||||||
compromised: Stop affected producer and revoke the exact receiver token first; inspect affected
|
first-provision helper refuses rotation and unexpected existing values.'
|
||||||
source/tenant events, rotate through a separate reviewed action, and preserve the independent
|
compromised: Stop affected producer and revoke the exact receiver token first; inspect
|
||||||
audit trail.
|
affected source/tenant events, rotate through a separate reviewed action, and
|
||||||
|
preserve the independent audit trail.
|
||||||
state_hub:
|
state_hub:
|
||||||
workplan_id: RPF-WP-0035
|
workplan_id: RPF-WP-0035
|
||||||
task_id: RPF-WP-0035-T08
|
task_id: RPF-WP-0035-T08
|
||||||
related_workplan: AUDIT-WP-0009-T11
|
related_workplan: AUDIT-WP-0009-T11
|
||||||
decision_id: ee4ff001-256a-4406-9cb8-51be2cd5d31b
|
decision_id: ee4ff001-256a-4406-9cb8-51be2cd5d31b
|
||||||
decision_api_url: http://127.0.0.1:8000/decisions/ee4ff001-256a-4406-9cb8-51be2cd5d31b
|
decision_api_url: http://127.0.0.1:8000/decisions/ee4ff001-256a-4406-9cb8-51be2cd5d31b
|
||||||
|
decision_resolved_at: '2026-09-11T04:36:46.480026Z'
|
||||||
|
|
|
||||||
|
|
@ -1,11 +1,13 @@
|
||||||
# Factory audit senders: concrete custody review
|
# Factory audit senders: concrete custody review
|
||||||
|
|
||||||
CCR-2026-0021 and CCR-2026-0022 are **proposed**. RPF-WP-0035-T08 owns the
|
CCR-2026-0021 and CCR-2026-0022 are **approved** by the user on 2026-09-11,
|
||||||
platform work; AUDIT-WP-0009-T09/T11 retain receiver admission. This packet
|
replying "good, go on" to the explicit question naming the platform operator,
|
||||||
requires the named platform operator, Audit Core owner and each producer owner
|
Audit Core owner, and each producer owner. The source review comments and the
|
||||||
to approve its request before native credential mutation.
|
two existing State Hub decisions record that approval. RPF-WP-0035-T08 owns
|
||||||
|
platform execution; AUDIT-WP-0009-T09/T11 retain receiver admission. Approval
|
||||||
|
alone does not mark custody delivered or either producer admitted.
|
||||||
|
|
||||||
## Scope to approve
|
## Approved scope
|
||||||
|
|
||||||
| Request | Producer / exact source | OpenBao path | Producer Secret / key |
|
| Request | Producer / exact source | OpenBao path | Producer Secret / key |
|
||||||
| --- | --- | --- | --- |
|
| --- | --- | --- | --- |
|
||||||
|
|
@ -24,7 +26,7 @@ log in to the reader role (15-minute session). Neither producer can read the
|
||||||
full sender registry or its sibling's token. The coding-agent boundary gains
|
full sender registry or its sibling's token. The coding-agent boundary gains
|
||||||
exact denies on the two new data/metadata paths; existing rules are preserved.
|
exact denies on the two new data/metadata paths; existing rules are preserved.
|
||||||
|
|
||||||
The approved first-provision operation would generate two independent values
|
The approved first-provision operation generates two independent values
|
||||||
in the attended platform process, store them with CAS=0, and append the exact
|
in the attended platform process, store them with CAS=0, and append the exact
|
||||||
identities to `platform/workloads/audit-core/senders` with compare-and-set on
|
identities to `platform/workloads/audit-core/senders` with compare-and-set on
|
||||||
its observed KV version. That process necessarily reads the existing registry
|
its observed KV version. That process necessarily reads the existing registry
|
||||||
|
|
|
||||||
|
|
@ -1,11 +1,11 @@
|
||||||
# CCR-2026-0021/0022. Review only; no credentials or namespaces.
|
# CCR-2026-0021/0022 approved 2026-09-11; no credentials or namespaces.
|
||||||
apiVersion: external-secrets.io/v1
|
apiVersion: external-secrets.io/v1
|
||||||
kind: ClusterSecretStore
|
kind: ClusterSecretStore
|
||||||
metadata:
|
metadata:
|
||||||
name: openbao-approval-engine-audit
|
name: openbao-approval-engine-audit
|
||||||
annotations:
|
annotations:
|
||||||
railiance.io/credential-change: CCR-2026-0021
|
railiance.io/credential-change: CCR-2026-0021
|
||||||
railiance.io/admission: proposed
|
railiance.io/admission: approved
|
||||||
spec:
|
spec:
|
||||||
provider:
|
provider:
|
||||||
vault:
|
vault:
|
||||||
|
|
@ -30,7 +30,7 @@ metadata:
|
||||||
namespace: approval-engine
|
namespace: approval-engine
|
||||||
annotations:
|
annotations:
|
||||||
railiance.io/credential-change: CCR-2026-0021
|
railiance.io/credential-change: CCR-2026-0021
|
||||||
railiance.io/admission: proposed
|
railiance.io/admission: approved
|
||||||
spec:
|
spec:
|
||||||
refreshInterval: 5m
|
refreshInterval: 5m
|
||||||
secretStoreRef:
|
secretStoreRef:
|
||||||
|
|
@ -52,7 +52,7 @@ metadata:
|
||||||
name: openbao-informed-decision-audit
|
name: openbao-informed-decision-audit
|
||||||
annotations:
|
annotations:
|
||||||
railiance.io/credential-change: CCR-2026-0022
|
railiance.io/credential-change: CCR-2026-0022
|
||||||
railiance.io/admission: proposed
|
railiance.io/admission: approved
|
||||||
spec:
|
spec:
|
||||||
provider:
|
provider:
|
||||||
vault:
|
vault:
|
||||||
|
|
@ -77,7 +77,7 @@ metadata:
|
||||||
namespace: informed-decision
|
namespace: informed-decision
|
||||||
annotations:
|
annotations:
|
||||||
railiance.io/credential-change: CCR-2026-0022
|
railiance.io/credential-change: CCR-2026-0022
|
||||||
railiance.io/admission: proposed
|
railiance.io/admission: approved
|
||||||
spec:
|
spec:
|
||||||
refreshInterval: 5m
|
refreshInterval: 5m
|
||||||
secretStoreRef:
|
secretStoreRef:
|
||||||
|
|
|
||||||
|
|
@ -22,7 +22,11 @@ import factory_audit_custody as lane
|
||||||
class Contracts(unittest.TestCase):
|
class Contracts(unittest.TestCase):
|
||||||
def test_proposed_requests_cannot_seed(self):
|
def test_proposed_requests_cannot_seed(self):
|
||||||
self.assertEqual(len(lane.contracts()),2)
|
self.assertEqual(len(lane.contracts()),2)
|
||||||
with patch.object(lane,'bao',side_effect=AssertionError('must not contact Bao')):
|
module=lane.credential_module(); original=module.validate_ccr
|
||||||
|
def proposed(path):
|
||||||
|
c,errors,warnings=original(path); c=copy.deepcopy(c); c['status']='proposed'
|
||||||
|
return c,errors,warnings
|
||||||
|
with patch.object(module,'validate_ccr',side_effect=proposed), patch.object(lane,'credential_module',return_value=module), patch.object(lane,'bao',side_effect=AssertionError('must not contact Bao')):
|
||||||
with self.assertRaisesRegex(lane.LaneError,'approved_ccrs_required'):
|
with self.assertRaisesRegex(lane.LaneError,'approved_ccrs_required'):
|
||||||
lane.contracts(approved=True)
|
lane.contracts(approved=True)
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -407,11 +407,11 @@ state_hub_task_id: "0ef52c26-2669-5cd1-8149-b1f6fcdda6cb"
|
||||||
|
|
||||||
Consume AUDIT-WP-0009-T09/T11's exact declarations for approval-engine and
|
Consume AUDIT-WP-0009-T09/T11's exact declarations for approval-engine and
|
||||||
informed-decision: tenant:platform, write-only, load-bearing, redact. Source
|
informed-decision: tenant:platform, write-only, load-bearing, redact. Source
|
||||||
preparation supplies two proposed CCRs, independent exact-path policies/ESO
|
preparation supplies two approved CCRs, independent exact-path policies/ESO
|
||||||
projections, and the attended `factory_audit_custody.py` first-provision helper.
|
projections, and the attended `factory_audit_custody.py` first-provision helper.
|
||||||
Its CAS and request-provenance checks preserve unrelated senders and recover
|
Its CAS and request-provenance checks preserve unrelated senders and recover
|
||||||
interrupted writes without generating replacements. Native reviews and
|
interrupted writes without generating replacements. The user approved all named review roles on 2026-09-11. Native
|
||||||
provision/delivery/receiver-ingestion acceptance remain open.
|
provision/delivery/receiver-ingestion acceptance remains open.
|
||||||
|
|
||||||
The 2026-09-11 native read-only check found an additional deployment dependency:
|
The 2026-09-11 native read-only check found an additional deployment dependency:
|
||||||
receiver image c2fe39a is 1/1 Ready but does not support evidence_kind. The
|
receiver image c2fe39a is 1/1 Ready but does not support evidence_kind. The
|
||||||
|
|
@ -473,3 +473,11 @@ T05 remains wait: both CCRs are still proposed, the actual upstream ID-token
|
||||||
issuer precondition remains open, and no verifier-side credential is provisioned.
|
issuer precondition remains open, and no verifier-side credential is provisioned.
|
||||||
Client-side retrieval and audit-sender custody are still separate owner returns.
|
Client-side retrieval and audit-sender custody are still separate owner returns.
|
||||||
The capability receipt is not a review approval or service readiness proof.
|
The capability receipt is not a review approval or service readiness proof.
|
||||||
|
|
||||||
|
### Sender approval recorded — 2026-09-11
|
||||||
|
|
||||||
|
The user replied "good, go on" to the explicit CCR-2026-0021/0022 question naming
|
||||||
|
platform-operator, audit-core-owner and both producer owners. Both exact requests
|
||||||
|
are approved; their existing State Hub decisions are resolved. This clears the
|
||||||
|
review request only. Receiver rollout, namespace readiness, attended custody and
|
||||||
|
positive/negative native evidence remain the execution gates.
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue