diff --git a/.custodian-brief.md b/.custodian-brief.md index a814658..7bf1138 100644 --- a/.custodian-brief.md +++ b/.custodian-brief.md @@ -2,7 +2,7 @@ # Custodian Brief — secrets-engine **Domain:** infotech -**Last synced:** 2026-09-28 08:44 UTC +**Last synced:** 2026-09-28 21:33 UTC **State Hub:** http://127.0.0.1:8000 *(adjust if running on a remote machine)* ## Active Workstreams @@ -14,6 +14,20 @@ Progress: 2/3 done | workplan_id: `40ccc3b4-d046-5a58-8649-e7935f45c974` - ! Activate the approved native lane and verify real owner delivery `f8069c8a` *(wait: Native apply/verify and credential delivery/revocation completed; owner attempt failed on runtime launchers. Await corrected artifact admission/pins, owner reconciliation of the held EUR 10 reservation and unknown billing, and separate retry authority under REINAH-WP-0003-T05/T06.)* +### Evolve the Lifecycle engine to the accepted security layer model +Progress: 5/6 done | workplan_id: `9c9e5164-b2f5-5ea2-a557-5368d65e9fe0` + +**Open tasks:** +- ! No standing engine credential `d7bc8bdc` + *(wait: RPF-WP-0035-T02 awaits coordinated platform-tenant live registration, credential custody and scoped attended JWT role provisioning with native login/negative/revocation proof. The historical env-auth acceptance is not service-JWT adoption.)* + +### Production-safe provisioning, authorization, and lifecycle hardening +Progress: 6/7 done | workplan_id: `68a39be1-bd9c-5133-ad64-e7bca892aaf3` + +**Open tasks:** +- ! Resume native production lane adoption `a0a1dd92` + *(wait: Engine approval hardening is complete. Remaining per-lane cutover includes native routing/proxy retirement with ops-warden under SECRETS-WP-0006-T05/T06; the exact OpenRouter key-check receipt does not establish broader recipient readiness.)* + ### Adopt concrete OpenBao credential lanes from ops-warden Progress: 4/6 done | workplan_id: `31f7f8ea-7f73-516c-8877-f03a13f1db82` @@ -23,20 +37,6 @@ Progress: 4/6 done | workplan_id: `31f7f8ea-7f73-516c-8877-f03a13f1db82` - ! Reconcile routing ownership and retire interim proxies `1431edae` *(wait: Needs owner-agreed routing/proxy retirement for each verified lane and custody disposition of the legacy npm pointer; a single approved OpenRouter key-check does not authorize broader routing cutover.)* -### Production-safe provisioning, authorization, and lifecycle hardening -Progress: 6/7 done | workplan_id: `68a39be1-bd9c-5133-ad64-e7bca892aaf3` - -**Open tasks:** -- ! Resume native production lane adoption `a0a1dd92` - *(wait: Engine approval hardening is complete. Remaining per-lane cutover includes native routing/proxy retirement with ops-warden under SECRETS-WP-0006-T05/T06; the exact OpenRouter key-check receipt does not establish broader recipient readiness.)* - -### Evolve the Lifecycle engine to the accepted security layer model -Progress: 5/6 done | workplan_id: `9c9e5164-b2f5-5ea2-a557-5368d65e9fe0` - -**Open tasks:** -- ! No standing engine credential `d7bc8bdc` - *(wait: RPF-WP-0035-T02 awaits coordinated platform-tenant live registration, credential custody and scoped attended JWT role provisioning with native login/negative/revocation proof. The historical env-auth acceptance is not service-JWT adoption.)* - --- ## MCP Orientation (when available)