codex
62423fd092
Activate Policy Nexus source credential lane
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-09-01 01:35:48 +02:00
codex
a6d47c51cc
Record Policy Nexus metadata apply and diagnose bootstrap
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-09-01 00:18:15 +02:00
codex
1b85a3ef3d
Add attended Policy Nexus source bootstrap
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-08-31 23:24:05 +02:00
codex
f342f9605e
Add contained Policy Nexus CCR apply wrapper
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-08-31 23:12:16 +02:00
codex
d18649fc6e
feat(RAILIANCE-WP-0027): add contained callback role update
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02b90-83bf-75c2-81c8-aa705414e4d4
2026-08-23 14:37:01 +02:00
codex
c9d02147d3
Adopt canonical flex-auth credential checks
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02e56-e4ad-71a2-b3e2-b6193e0d8093
2026-08-23 14:03:40 +02:00
codex
517f68593d
feat(RAILIANCE-WP-0027): prepare operator-only OpenBao access
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02b90-83bf-75c2-81c8-aa705414e4d4
2026-08-23 12:50:23 +02:00
codex
2a5c002aa5
Prepare canonical custody for audit E2 third attempt
...
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02991-be07-7bb3-8b6d-e9701b5621de
2026-08-22 23:23:41 +02:00
codex
30e6edc236
Add versioned ephemeral custody lifecycle
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02669-87ee-7a31-b111-edc95a16e0fa
2026-08-22 21:56:42 +02:00
codex
d239ed33c3
Harden remote kubectl argument quoting
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02991-be07-7bb3-8b6d-e9701b5621de
2026-08-22 21:25:20 +02:00
codex
f135c0af35
Bind audit E2 retry projection to new engagement
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02669-87ee-7a31-b111-edc95a16e0fa
2026-08-22 20:56:58 +02:00
codex
891d90e6c9
add attended custody for audit-core E2 retry
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02991-be07-7bb3-8b6d-e9701b5621de
2026-08-22 20:49:11 +02:00
codex
a557208a4a
Add direct WP-0024 load driver handoff
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02669-87ee-7a31-b111-edc95a16e0fa
2026-08-22 16:17:03 +02:00
codex
d8c0cd38a7
Report WP-0024 approvals by task
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02669-87ee-7a31-b111-edc95a16e0fa
2026-08-22 14:57:52 +02:00
codex
0d9cebedea
Add direct WP-0024 owner review interface
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02669-87ee-7a31-b111-edc95a16e0fa
2026-08-22 14:15:02 +02:00
codex
3f9e4535d1
Harden WP-0024 recovery execution gates
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02669-87ee-7a31-b111-edc95a16e0fa
2026-08-22 14:00:18 +02:00
codex
bd25f7fa40
Add audit recovery exercise preflights
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02669-87ee-7a31-b111-edc95a16e0fa
2026-08-22 13:16:13 +02:00
codex
864cc20b96
Add attended Whitehat E2 credential projection
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02669-87ee-7a31-b111-edc95a16e0fa
2026-08-22 12:59:38 +02:00
codex
429cc912ed
Finish coding-agent high-risk boundary coverage
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02669-87ee-7a31-b111-edc95a16e0fa
2026-08-22 10:03:54 +02:00
codex
382f04412a
Close CCR drift and high-risk policy gaps
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-21 01:29:28 +02:00
codex
34a3123799
Finish RAILIANCE-WP-0017 consumption-mode enforcement
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Read the resource-control open/restricted signal and refuse new orders
that would exceed a restricted entity's published allowance. Open and
missing signals stay unchanged. Safety paths admit with an exception.
2026-08-15 14:56:02 +02:00
codex
6033ae1aef
Finish RAILIANCE-WP-0016 apps-pg resource evidence
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Publish capacity, recovery, labor, and allocation-driver evidence for
resource:railiance:apps-pg so resource-control can forecast and allocate
without reading application data or inventing booked cost.
2026-08-14 02:05:25 +02:00
codex
dfa6373985
Close RAILIANCE-WP-0015-T06 rapp credential-lane binding
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Has been cancelled
Document the one recipe a new rapp uses to acquire runtime secrets:
standing KV secrets bind through a CCR target.rapp, leases through
grant rapp_id. Stamp the existing postgres grants and the qonto
workload CCR. Gate, delivery, and revocation are unchanged.
2026-08-14 00:47:28 +02:00
codex
ccb5972b42
Close RAILIANCE-WP-0015-T02 platform rapp schema convergence
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Has been cancelled
Converge the S3 platform-service pattern onto ADR-0007, emit the
reef-railiance live deployable inventory for the family coverage
check, and mark T02 done. Declaration edits land in rapp-openbao
and rapp-postgres.
2026-08-14 00:39:06 +02:00
codex
9f6bdffec4
Broker audit-core dynamic database credentials
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-10 19:36:30 +02:00
codex
12903e3bed
Cut forgejo package prune over to OpenBao lane
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 5s
2026-07-26 09:32:08 +02:00
ca4e1526bd
prune: merge exported live-image files into protection (multi-cluster)
...
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 3s
ACTIVITY-WP-0020-T07: the kubectl scan only sees the prune host's own
cluster. New repeatable --live-images-file merges image refs exported
from other production clusters; missing file surfaces as WARN (reduced
coverage), forgejo-registry tags protected, other registries ignored.
5/5 tests.
Evidence gathered 2026-07-18: activity-core on railiance01 runs a
locally-imported image (activity-core:railiance01-prod), not a forgejo
registry tag — the largest would_delete set has no live registry
consumer. Live forgejo tags: state-hub:main-1cf949b (railiance01),
issue-core:0.2.1 + state-hub:f2e042a + vergabe-teilnahme:064d295
(coulombcore cluster).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 13:54:13 +02:00
86209fa90c
CCR-2026-0007: binky IMAP on tenants/ mount + CCR allowlist
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Enable tenant commercial secrets: applier accepts mount tenants/, apply
policy and OIDC role for company-email IMAP (metadata only; values are
founder Red provision). Extend agent-high-risk-boundary for the path.
2026-07-17 00:09:28 +02:00
e9e631fbf4
feat(forgejo-package-prune): protect image tags running live in the cluster
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Adds collect_live_cluster_versions() — enumerates pod container images via
kubectl and protects any forgejo.coulomb.social/coulomb/<name>:<tag>. Closes the
gap where CI-deployed apps (e.g. state-hub) pin a live tag absent from Helm
values. On by default (--no-protect-live to skip); emits protection_notes +
live_protection in the JSON summary so consumers can detect reduced coverage.
Verified against production: protects state-hub/vergabe/issue-core live tags.
ACTIVITY-WP-0020 T07 (partial — see workplan note re multi-cluster coverage).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 14:44:03 +02:00
6f7ca31a6d
fix(forgejo-package-prune): correct version enumeration + network robustness
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Forgejo has no per-package /versions endpoint — the list endpoint returns one
entry per (name, version). build_delete_plans now groups list results by name
instead of calling a 404ing /versions sub-path. Removed dead list_versions/_paginate.
Added retry + longer timeout to _api_request for slow/large registry listings
(container list was timing out). Updated fixture test to the grouped model.
Dry-run now clean: 29 candidate deletions across 5 container packages, 0 errors
(was 53× HTTP 404). ACTIVITY-WP-0020 T02 fix; enable/apply still gated on
protection-coverage review (T05).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 02:46:15 +02:00
4a824d72bd
Apply CCR-2026-0006 Forgejo admin PAT lane metadata
...
Record platform-operator approval, delegated policy/OIDC role apply,
negative verification evidence, and add attended PAT provision script.
2026-07-12 16:07:32 +02:00
618641c984
fix(forgejo): accept FORGEJO_ADMIN_TOKEN and document PAT setup
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Align prune auth with railiance-apps forgejo tools and explain that
package prune needs a Forgejo PAT, not the OpenBao backup lane.
2026-07-12 11:57:35 +02:00
715631dedd
feat(forgejo): add package prune script with retention depth 3
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
List and optionally delete package versions beyond the newest three,
protecting production Helm image tags. Adds Make targets and unit tests
for ACTIVITY-WP-0020.
2026-07-12 11:35:04 +02:00
b38b8c1f7f
Send workplan_id only on State Hub progress metadata posts
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 6s
2026-07-09 00:32:54 +02:00
9cbf64ebee
CUST-WP-0055 T05: add State Hub workplan_id scope to credential broker
...
Accept --state-hub-workplan-id / STATE_HUB_WORKPLAN_ID and dual-write
workplan_id plus legacy workstream_id on progress events.
2026-07-08 20:00:35 +02:00
8321e14b46
Unblock credential broker warden-sign pilot
2026-07-01 23:10:38 +02:00
a95236d2e5
Add credential-change delegated applier flow
2026-07-01 20:07:26 +02:00
3527bc1cae
Request groups scope for whynot OIDC role
2026-06-28 13:23:14 +02:00
adf865611c
Mark whynot lane applied pending verification
2026-06-28 12:53:39 +02:00
271aa94642
Record whynot OpenBao lane apply evidence
2026-06-28 12:41:39 +02:00
53f3f4ca10
Document OpenBao Browser CLI limits
2026-06-28 09:18:36 +02:00
f630d5135e
Fix OpenBao role payload handoff
2026-06-28 02:33:42 +02:00
eb24e04b71
Correct whynot credential tenant path
2026-06-28 01:00:12 +02:00
248bc58b6a
Add credential CCR operator handoff
2026-06-28 00:21:02 +02:00
3706ff703e
Link CCR approval to State Hub decision
2026-06-28 00:00:02 +02:00
52687d8b3e
Confirm whynot credential binding
2026-06-27 23:45:31 +02:00
aee0dcefad
Add credential lane readiness proposals
2026-06-27 23:30:29 +02:00
815b124ab1
Implement credential change request review flow
2026-06-27 22:57:21 +02:00
85a4278a55
Add credential approval workflow plan
2026-06-27 22:48:24 +02:00
673ec46e25
feat: complete credential broker source flow
2026-06-27 00:29:53 +02:00