Sweep risk inbox and reconcile findings

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
This commit is contained in:
tegwick 2026-09-01 02:41:32 +02:00
parent d65aaf7484
commit 7f1424dbcf
12 changed files with 363 additions and 96 deletions

View file

@ -2,7 +2,8 @@
id: RISK-F-0002
type: finding
title: "ops-warden signs SSH certificates with no authorization decision, and its unblock is now unsafe"
status: open
status: fixed
owner: risk-nexus
reported_by: ops-warden
reported_via: ops-warden
routed_by: ops-warden
@ -10,7 +11,7 @@ date_reported: "2026-08-18"
system: ops-warden
environment: production
fix_owner: ops-warden
fix_tracking: ZONE-WP-0001 / WARDEN-WP-0032 (successor; the original framing is superseded)
fix_tracking: ZONE-WP-0001 / WARDEN-WP-0032-T02 (finished 2026-08-22)
fix_tracking_superseded: "WARDEN-WP-0007 (archived 2026-07-08) / FLEX-WP-0007 (finished 2026-06-29)"
related: [RISK-F-0001]
# Graded by risk-nexus 2026-08-19 — docs/rulings/2026-08-19-first-grading.md
@ -23,20 +24,27 @@ production_rescore: false
constraint_on: RISK-F-0001
constraint_severity: lifted
constraint: "LIFTED 2026-08-19 — flex-auth /v1/check now authenticates callers (RISK-F-0001 fixed). Enabling policy.enabled is now an availability question for ops-warden, no longer an attestation hazard."
disclosure: embargoed
embargo_condition: "FLEX-WP-0015-T02 shipped and ops-warden policy.enabled true in production"
embargo_since: "2026-08-19"
embargo_review: "2026-11-17"
disclosure: public
publication: pending-handover
publication_id: risk-f-0002-ops-warden-signing-authorization-gap
publication_path: "findings/ops-warden-signing-authorization-gap/v1/index.html"
publication_subtitle: "Production SSH signing once had no per-request authorization decision; the retired global switch is now replaced by an enforced zone-aware gate."
revision: "fixed-1"
last_reviewed: "2026-09-01"
review_interval: 6m
embargo_lifted: "2026-08-22 — zone-aware authorization replaced the retired global gate and passed the live authenticated-caller check"
embargo_was_since: "2026-08-19"
escalation: withdrawn
escalation_trigger: 6
escalation_status: withdrawn-hazard-window-closed
last_checked: "2026-08-21T07:32:09Z"
next_check: "2026-08-21T07:32:09Z"
date_fixed: "2026-08-22"
last_checked: "2026-09-01T00:32:44Z"
next_check: "2026-09-01T00:32:44Z"
cadence: instant
clean_streak: 0
graded_by: risk-nexus
ruling: RISK-RULING-2026-08-19
checked_by: "risk-nexus"
checked_by: "codex/risk-nexus"
---
# RISK-F-0002 — the SSH signing gate is off, and turning it on is now the more dangerous move
@ -381,3 +389,19 @@ whatever staleness convention this register settles rather than inventing a
second one. That is worth answering properly and is recorded as an open item
for the next round.
- **2026-08-21** — not clean: owner replied; see the dated check section Cadence instant → instant; checked again immediately.
## Closure — 2026-09-01: the successor control is live
`WARDEN-WP-0032-T02` is done. The production configuration rejects the retired
global `policy.enabled` and `policy.fail_closed` switches; the signing PEP now
uses compiled security-zone membership, the stance returned by `flex-auth`, and
a local per-zone failure mode. The owner re-ran the authenticated caller path
against the migrated operator configuration and received a live allow decision
with decision id `decision:f3f7c88f9585582a`.
Risk Nexus also ran the current policy, configuration, routing, and read-boundary
regressions: **137 passed**. The defect this finding carried—production signing
proceeding with no per-request authorization decision—is gone. The finding is
`fixed`; the embargo lifts and publication is handed over.
- **2026-09-01** — not clean: the zone-aware successor is implemented and live-verified; status fixed and embargo lifted. Cadence instant → instant; checked again immediately.