risk-nexus/docs
tegwick 97fcc56a4d RISK-WP-0004-T05: establish what this register can verify, by trying it
Cluster reads work from this host; OpenBao returns 403, the same wall
ops-warden hit. So the register can check what the cluster admits and
cannot check what the secret store permits, and every grade touching an
OpenBao policy is a grade on a document. That asymmetry is recorded
rather than closed: a risk register holding production secret-store
access would have traded a verification problem for a worse one.

RISK-V-0001 is the first verification. It confirms RISK-F-0001's ingress
claim against the live cluster — the first grade here standing on
evidence this repo gathered — contradicts the 'egress: []' claim, which
live shows as 443/6443 to anywhere, and surfaces a third policy created
the day of the fix whose Ingress policyType carries no rules, which bears
on whether enabling ops-warden's gate would fail closed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 08:46:06 +02:00
..
method RISK-WP-0004-T05: establish what this register can verify, by trying it 2026-08-20 08:46:06 +02:00
regulatory RISK-REG-0001: write down the retention basis, and open regulatory intake 2026-08-20 07:25:42 +02:00
rulings Record the 2026-08-20 ruling: OpenBao layer, id collision, silent-drop defect 2026-08-20 07:44:21 +02:00
verifications RISK-WP-0004-T05: establish what this register can verify, by trying it 2026-08-20 08:46:06 +02:00