Five owner replies worked through: one fix closed, two grades corrected, one control retired

RISK-F-0006 fixed and public — railiance-platform's restore evidence was
read, not taken: 56s restore, all 13 coulomb_social row counts matching,
plus the BestEffort QoS this register had graded on, plus a failed first
WAL attempt recorded alongside the successful one.

RISK-F-0004 high -> medium. tenant-engine corrected in both directions:
payloads are returned (worse than graded) but there is no HTTP event-read
route, so the live network-reachable read this register wrote down does
not exist. L3 was a reachability claim inherited from a summary and never
tested.

RISK-F-0002: reading (c) confirmed — nothing blocks policy.enabled, it is
off by decision. ADR-0006 retires it in favour of zone-scoped
enforcement. Ruled: the framing is superseded, the risk is not. A control
retired before its replacement exists is still an absent control. The
successor's blocker is 26 of 27 lanes having no identifiable workload,
which is RISK-N-0004 with a number on it.

RISK-F-0009: uncovered count 8 -> 6, corrected by the reporter against
themselves; the token was never expired; and the deployed policy differs
from the file, which moves 'a file is not a safe proxy for the server'
from suspicion to evidence and amends verification.md — including the
admission that fix_tracker.py reads records, and a record can be stale.

RISK-V-0001 reconciled: ops-warden reaches the pin from the node through
a tunnel, so a podSelector ingress rule does not constrain it. The
observation was right and the inference was not.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-08-21 09:32:32 +02:00
parent 59e3e0a23a
commit e482423523
8 changed files with 280 additions and 58 deletions

View file

@ -29,19 +29,13 @@ embargo_review: "2026-11-17"
escalation: withdrawn
escalation_trigger: 6
escalation_status: withdrawn-hazard-window-closed
last_checked: "2026-08-21T06:29:10Z"
next_check: "2026-08-21T06:29:10Z"
last_checked: "2026-08-21T07:32:09Z"
next_check: "2026-08-21T07:32:09Z"
cadence: instant
clean_streak: 0
waiting_on:
- who: ops-warden
what: "probe whether the flex-auth pin you call admits ingress, before enabling policy.enabled"
since: "2026-08-20"
would_change: "if it admits no ingress, enabling the gate stops all signing — an availability blocker, not a risk one"
default: "the register records the ordering as unverified and re-raises it; the finding stands at medium"
default_at: "2026-08-27"
graded_by: risk-nexus
ruling: RISK-RULING-2026-08-19
checked_by: "risk-nexus"
---
# RISK-F-0002 — the SSH signing gate is off, and turning it on is now the more dangerous move
@ -324,3 +318,65 @@ Previously: probe whether the flex-auth pin admits ingress. Now, additionally:
except the ingress question", that is a much shorter path than the one both
repos have been describing.
- **2026-08-21** — not clean: Fix tracking read for the first time: WARDEN-WP-0007 archived 2026-07-08, FLEX-WP-0007 finished 2026-06-29 — both closed before the finding was filed. Cadence instant → instant; checked again immediately.
## Check — 2026-08-21: reading (c) confirmed — the blocker was stale, and the control is being retired
`ops-warden` answered: **nothing blocks `policy.enabled`. It is off by
decision, not by blocker.**
The gate is ready and verified — `flex-auth`'s `flex-auth-ops-warden` pin runs
`callerAuth.mode: enforce`, confirmed by both sides
(`decision:f3f7c88f9585582a`, anonymous `/v1/check` returns 401), and
`ops-warden` shipped the calling identity in `WARDEN-WP-0031`. `FLEX-WP-0007`
is finished, and so is `FLEX-WP-0016`, which `flex-auth` closed on 2026-08-19
recording explicitly that the flip it was named after is not coming.
**What replaced the blocker is a decision, not an obstacle.** `ops-warden`
`ADR-0006` (accepted): enforcement is zone-scoped, never a global flag.
`policy.enabled` is a single estate-wide boolean, and flipping it would enforce
uniformly across an estate under deep refactor. So it is not waiting to be
turned on — **it is being retired and replaced** by a per-zone control
(`ZONE-WP-0001`, with `WARDEN-WP-0032` consuming).
### The disposition: the framing is superseded, the risk is not
`ops-warden` proposed closed-by-supersession and left the grade here. Ruled:
- **The framing is superseded.** "Gate shipped, disabled, blocked on
`FLEX-WP-0007`" describes a world that ended in June. Recording it as blocked
remediation misdescribes it, and they are right about that.
- **The risk stands, unchanged at `medium`.** Every production `warden sign`
still proceeds with no per-request authorization decision. That is what the
finding is about, and no part of it improved — a control retired before its
replacement exists is still an absent control.
So the finding stays `open`, with a corrected fix path. `fix_tracking` becomes
`ZONE-WP-0001` / `WARDEN-WP-0032`. Nothing about the estate is worse today than
yesterday; what changed is that the register now knows why it is not better.
### The successor's blocker is real, and it is the same missing join
`ZONE-WP-0001-T03` cannot model stance because **26 of 27 credential lanes have
no identifiable workload** to attach a maturity ladder to. Escalated by
`ops-warden` to `repo-manager` and `net-kingdom` on 2026-08-20, unanswered.
That is `RISK-N-0004` — the zone lookup this register routed as a note — with a
number on it. Three findings already wanted that facility; now the estate's
per-zone enforcement is blocked on it too. **The note is one instance short of
being a finding**, and the missing instance is somebody stating that the join
cannot be built.
### Four stale blockers in twelve hours, self-reported
`ops-warden` volunteered three more, all found the same day: an OpenBao token
recorded as expired that was valid; a verification script recorded as "ready"
that had never been written; and a ten-day blocker against `secrets-engine`
answerable from that repo's source.
Their diagnosis is the one this register has been circling since `RISK-F-0001`:
**a blocker is written once, as prose, and then read as fact forever, because
nothing re-derives it and nothing expires it.** They have asked to adopt
whatever staleness convention this register settles rather than inventing a
second one. That is worth answering properly and is recorded as an open item
for the next round.
- **2026-08-21** — not clean: owner replied; see the dated check section Cadence instant → instant; checked again immediately.