Implement SECRETS-WP-0008 unblocked layer-model obligations
Load pep-stance.yaml as the live unreachable-engine gate and record named stance fields on privileged evidence. Classify evidence, queue load-bearing records in a local outbox, and add heartbeat/drain commands that never sit on a mutation path. Publish proposed SSH-CA and secret-use evidence contracts without adding an OpenBao SSH-CA write. T02 (access-engine decision records) and T06 (no standing credential) stay wait on external endpoints. Assistant: grok Assistant-Session: 01a04cea-cb33-7c63-bad7-c1b0f9f0076b
This commit is contained in:
parent
57f6c4fa65
commit
3cd9955ac9
16 changed files with 1041 additions and 77 deletions
|
|
@ -23,6 +23,10 @@ class DecisionError(SecretsEngineError):
|
|||
|
||||
exit_code = 3
|
||||
|
||||
def __init__(self, message: str, *, stance: dict[str, object] | None = None):
|
||||
super().__init__(message)
|
||||
self.stance = dict(stance or {})
|
||||
|
||||
|
||||
class PolicyGuardError(SecretsEngineError):
|
||||
"""A plan violates a safety guard (wildcard, out-of-stage path, root, ...)."""
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue