railiance-platform/credential-change-requests
codex b7aef386d5
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Stabilize credential-change test suite (RAILIANCE-WP-0014)
Five failures in full credential test discovery, none of them broker
regressions:

- CCR-2026-0009 referenced a policy file that was never added, and used a
  schema-invalid access_frontdoor.readiness value. Add the least-privilege
  workload-kv-read-qonto-assistant.hcl (read-only on tenants/binky/qonto-api)
  and set readiness to pending-review. The lane stays proposed and
  non-resolvable.

- Three refusal tests used the live CCR-2026-0002 file as their "unapproved
  CCR" fixture. That lane is now approved, applied and active, so the gates
  correctly permitted it and the tests failed; applier-apply then walked into
  its interactive confirmation prompt and raised EOFError under a
  non-interactive runner. Add an unapproved_ccr() helper that materializes a
  normalized temp copy so approval state is no longer read off a mutable
  production artifact.

- The approve/unconfirmed-claim test demoted an active CCR to approved while
  leaving resolvable=true, tripping a correct validation rule. Build it from
  the same helper.

No gate, blocker, validation rule, or grant semantic was changed. Verified:
credential discovery 52/52 and full discovery 61/61 pass non-interactively,
make credential-change-validate passes all nine CCRs, the grant catalog
validates, and both audit-core openbao-database-credential grants retain
exec-env-only delivery and revoke-on-exec-exit.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 10:28:10 +02:00
..
CCR-2026-0001-whynot-design-npm-publish.yaml Close delegated prod applier pilot 2026-07-01 23:34:13 +02:00
CCR-2026-0002-issue-core-ingestion-api-key.yaml RAILIANCE-WP-0009/0010 finished: front doors active; WP-0005 T10 done 2026-07-02 20:54:29 +02:00
CCR-2026-0003-llm-connect-openrouter-api-key.yaml RAILIANCE-WP-0009/0010 finished: front doors active; WP-0005 T10 done 2026-07-02 20:54:29 +02:00
CCR-2026-0004-railiance-backup-offsite-lane.yaml CCR-2026-0004: capabilities-safe verify + agent high-risk boundary 2026-07-16 23:26:28 +02:00
CCR-2026-0005-reuse-surface-runtime-secrets-lane.yaml Complete RAILIANCE-WP-0011-T03 catalog migration for CCR-2026-0005 2026-07-07 22:38:45 +02:00
CCR-2026-0006-forgejo-admin-api-token-lane.yaml Apply CCR-2026-0006 Forgejo admin PAT lane metadata 2026-07-12 16:07:32 +02:00
CCR-2026-0007-binky-company-email-imap.yaml CCR-2026-0007: activate binky IMAP lane after founder provision 2026-07-17 00:33:20 +02:00
CCR-2026-0008-binky-qonto-api.yaml CCR-2026-0008 active: tenants/binky/qonto-api lane live 2026-07-21 21:42:10 +02:00
CCR-2026-0009-qonto-assistant-workload-kv-read.yaml Stabilize credential-change test suite (RAILIANCE-WP-0014) 2026-08-11 10:28:10 +02:00