risk-nexus/docs/method
tegwick 97fcc56a4d RISK-WP-0004-T05: establish what this register can verify, by trying it
Cluster reads work from this host; OpenBao returns 403, the same wall
ops-warden hit. So the register can check what the cluster admits and
cannot check what the secret store permits, and every grade touching an
OpenBao policy is a grade on a document. That asymmetry is recorded
rather than closed: a risk register holding production secret-store
access would have traded a verification problem for a worse one.

RISK-V-0001 is the first verification. It confirms RISK-F-0001's ingress
claim against the live cluster — the first grade here standing on
evidence this repo gathered — contradicts the 'egress: []' claim, which
live shows as 443/6443 to anywhere, and surfaces a third policy created
the day of the fix whose Ingress policyType carries no rules, which bears
on whether enabling ops-warden's gate would fail closed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 08:46:06 +02:00
..
disclosure.md RISK-WP-0001 T01-T06,T08: the four instruments, the index, and the first grading 2026-08-19 23:29:39 +02:00
escalation.md Adaptive check cadence: the interval is earned, not assigned 2026-08-20 07:43:51 +02:00
review.md Adaptive check cadence: the interval is earned, not assigned 2026-08-20 07:43:51 +02:00
severity.md RISK-WP-0001-T07: rule on what was waiting outside the register 2026-08-19 23:33:08 +02:00
verification.md RISK-WP-0004-T05: establish what this register can verify, by trying it 2026-08-20 08:46:06 +02:00