Five owner replies worked through: one fix closed, two grades corrected, one control retired
RISK-F-0006 fixed and public — railiance-platform's restore evidence was read, not taken: 56s restore, all 13 coulomb_social row counts matching, plus the BestEffort QoS this register had graded on, plus a failed first WAL attempt recorded alongside the successful one. RISK-F-0004 high -> medium. tenant-engine corrected in both directions: payloads are returned (worse than graded) but there is no HTTP event-read route, so the live network-reachable read this register wrote down does not exist. L3 was a reachability claim inherited from a summary and never tested. RISK-F-0002: reading (c) confirmed — nothing blocks policy.enabled, it is off by decision. ADR-0006 retires it in favour of zone-scoped enforcement. Ruled: the framing is superseded, the risk is not. A control retired before its replacement exists is still an absent control. The successor's blocker is 26 of 27 lanes having no identifiable workload, which is RISK-N-0004 with a number on it. RISK-F-0009: uncovered count 8 -> 6, corrected by the reporter against themselves; the token was never expired; and the deployed policy differs from the file, which moves 'a file is not a safe proxy for the server' from suspicion to evidence and amends verification.md — including the admission that fix_tracker.py reads records, and a record can be stale. RISK-V-0001 reconciled: ops-warden reaches the pin from the node through a tunnel, so a podSelector ingress rule does not constrain it. The observation was right and the inference was not. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
59e3e0a23a
commit
e482423523
8 changed files with 280 additions and 58 deletions
|
|
@ -29,19 +29,13 @@ embargo_review: "2026-11-17"
|
|||
escalation: withdrawn
|
||||
escalation_trigger: 6
|
||||
escalation_status: withdrawn-hazard-window-closed
|
||||
last_checked: "2026-08-21T06:29:10Z"
|
||||
next_check: "2026-08-21T06:29:10Z"
|
||||
last_checked: "2026-08-21T07:32:09Z"
|
||||
next_check: "2026-08-21T07:32:09Z"
|
||||
cadence: instant
|
||||
clean_streak: 0
|
||||
waiting_on:
|
||||
- who: ops-warden
|
||||
what: "probe whether the flex-auth pin you call admits ingress, before enabling policy.enabled"
|
||||
since: "2026-08-20"
|
||||
would_change: "if it admits no ingress, enabling the gate stops all signing — an availability blocker, not a risk one"
|
||||
default: "the register records the ordering as unverified and re-raises it; the finding stands at medium"
|
||||
default_at: "2026-08-27"
|
||||
graded_by: risk-nexus
|
||||
ruling: RISK-RULING-2026-08-19
|
||||
checked_by: "risk-nexus"
|
||||
---
|
||||
|
||||
# RISK-F-0002 — the SSH signing gate is off, and turning it on is now the more dangerous move
|
||||
|
|
@ -324,3 +318,65 @@ Previously: probe whether the flex-auth pin admits ingress. Now, additionally:
|
|||
except the ingress question", that is a much shorter path than the one both
|
||||
repos have been describing.
|
||||
- **2026-08-21** — not clean: Fix tracking read for the first time: WARDEN-WP-0007 archived 2026-07-08, FLEX-WP-0007 finished 2026-06-29 — both closed before the finding was filed. Cadence instant → instant; checked again immediately.
|
||||
|
||||
## Check — 2026-08-21: reading (c) confirmed — the blocker was stale, and the control is being retired
|
||||
|
||||
`ops-warden` answered: **nothing blocks `policy.enabled`. It is off by
|
||||
decision, not by blocker.**
|
||||
|
||||
The gate is ready and verified — `flex-auth`'s `flex-auth-ops-warden` pin runs
|
||||
`callerAuth.mode: enforce`, confirmed by both sides
|
||||
(`decision:f3f7c88f9585582a`, anonymous `/v1/check` returns 401), and
|
||||
`ops-warden` shipped the calling identity in `WARDEN-WP-0031`. `FLEX-WP-0007`
|
||||
is finished, and so is `FLEX-WP-0016`, which `flex-auth` closed on 2026-08-19
|
||||
recording explicitly that the flip it was named after is not coming.
|
||||
|
||||
**What replaced the blocker is a decision, not an obstacle.** `ops-warden`
|
||||
`ADR-0006` (accepted): enforcement is zone-scoped, never a global flag.
|
||||
`policy.enabled` is a single estate-wide boolean, and flipping it would enforce
|
||||
uniformly across an estate under deep refactor. So it is not waiting to be
|
||||
turned on — **it is being retired and replaced** by a per-zone control
|
||||
(`ZONE-WP-0001`, with `WARDEN-WP-0032` consuming).
|
||||
|
||||
### The disposition: the framing is superseded, the risk is not
|
||||
|
||||
`ops-warden` proposed closed-by-supersession and left the grade here. Ruled:
|
||||
|
||||
- **The framing is superseded.** "Gate shipped, disabled, blocked on
|
||||
`FLEX-WP-0007`" describes a world that ended in June. Recording it as blocked
|
||||
remediation misdescribes it, and they are right about that.
|
||||
- **The risk stands, unchanged at `medium`.** Every production `warden sign`
|
||||
still proceeds with no per-request authorization decision. That is what the
|
||||
finding is about, and no part of it improved — a control retired before its
|
||||
replacement exists is still an absent control.
|
||||
|
||||
So the finding stays `open`, with a corrected fix path. `fix_tracking` becomes
|
||||
`ZONE-WP-0001` / `WARDEN-WP-0032`. Nothing about the estate is worse today than
|
||||
yesterday; what changed is that the register now knows why it is not better.
|
||||
|
||||
### The successor's blocker is real, and it is the same missing join
|
||||
|
||||
`ZONE-WP-0001-T03` cannot model stance because **26 of 27 credential lanes have
|
||||
no identifiable workload** to attach a maturity ladder to. Escalated by
|
||||
`ops-warden` to `repo-manager` and `net-kingdom` on 2026-08-20, unanswered.
|
||||
|
||||
That is `RISK-N-0004` — the zone lookup this register routed as a note — with a
|
||||
number on it. Three findings already wanted that facility; now the estate's
|
||||
per-zone enforcement is blocked on it too. **The note is one instance short of
|
||||
being a finding**, and the missing instance is somebody stating that the join
|
||||
cannot be built.
|
||||
|
||||
### Four stale blockers in twelve hours, self-reported
|
||||
|
||||
`ops-warden` volunteered three more, all found the same day: an OpenBao token
|
||||
recorded as expired that was valid; a verification script recorded as "ready"
|
||||
that had never been written; and a ten-day blocker against `secrets-engine`
|
||||
answerable from that repo's source.
|
||||
|
||||
Their diagnosis is the one this register has been circling since `RISK-F-0001`:
|
||||
**a blocker is written once, as prose, and then read as fact forever, because
|
||||
nothing re-derives it and nothing expires it.** They have asked to adopt
|
||||
whatever staleness convention this register settles rather than inventing a
|
||||
second one. That is worth answering properly and is recorded as an open item
|
||||
for the next round.
|
||||
- **2026-08-21** — not clean: owner replied; see the dated check section Cadence instant → instant; checked again immediately.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue