Five owner replies worked through: one fix closed, two grades corrected, one control retired
RISK-F-0006 fixed and public — railiance-platform's restore evidence was read, not taken: 56s restore, all 13 coulomb_social row counts matching, plus the BestEffort QoS this register had graded on, plus a failed first WAL attempt recorded alongside the successful one. RISK-F-0004 high -> medium. tenant-engine corrected in both directions: payloads are returned (worse than graded) but there is no HTTP event-read route, so the live network-reachable read this register wrote down does not exist. L3 was a reachability claim inherited from a summary and never tested. RISK-F-0002: reading (c) confirmed — nothing blocks policy.enabled, it is off by decision. ADR-0006 retires it in favour of zone-scoped enforcement. Ruled: the framing is superseded, the risk is not. A control retired before its replacement exists is still an absent control. The successor's blocker is 26 of 27 lanes having no identifiable workload, which is RISK-N-0004 with a number on it. RISK-F-0009: uncovered count 8 -> 6, corrected by the reporter against themselves; the token was never expired; and the deployed policy differs from the file, which moves 'a file is not a safe proxy for the server' from suspicion to evidence and amends verification.md — including the admission that fix_tracker.py reads records, and a record can be stale. RISK-V-0001 reconciled: ops-warden reaches the pin from the node through a tunnel, so a podSelector ingress rule does not constrain it. The observation was right and the inference was not. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
59e3e0a23a
commit
e482423523
8 changed files with 280 additions and 58 deletions
|
|
@ -34,10 +34,10 @@ accepted_by: the-custodian
|
|||
accepted_on: "2026-08-19"
|
||||
accepted_until: "production transition (hard expiry, not a date)"
|
||||
decision: "pragmatic default before production — carried unverified; verification of a named consumer boundary on request"
|
||||
last_checked: "2026-08-20T10:02:41Z"
|
||||
next_check: "2026-08-20T10:02:41Z"
|
||||
cadence: instant
|
||||
clean_streak: 0
|
||||
last_checked: "2026-08-21T07:32:10Z"
|
||||
next_check: "2026-08-21T08:32:10Z"
|
||||
cadence: 1h
|
||||
clean_streak: 1
|
||||
waiting_on:
|
||||
- who: user-engine
|
||||
what: "does anything verify that a caller for tenant A cannot reach tenant B (RISK-V-0002)"
|
||||
|
|
@ -47,6 +47,7 @@ waiting_on:
|
|||
default_at: "2026-09-03"
|
||||
graded_by: risk-nexus
|
||||
ruling: RISK-RULING-2026-08-19-B
|
||||
checked_by: "risk-nexus"
|
||||
---
|
||||
|
||||
# RISK-F-0007 — nothing checks that tenants stay apart
|
||||
|
|
@ -182,3 +183,4 @@ assumption that asking works.
|
|||
|
||||
Grade unchanged. Nothing about the boundary itself has moved.
|
||||
- **2026-08-20** — not clean: On-request verification walked for the first time: RISK-V-0002 asks user-engine. Cadence instant → instant; checked again immediately.
|
||||
- **2026-08-21** — clean check: no answer yet from user-engine; nothing about the boundary moved. Cadence instant → 1h (1 clean in a row); next check 2026-08-21 08:32Z.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue