Replace the gate-house review note with this repository's own declaration:
INTENT.md frontmatter, layer.yaml, and a published PEP stance map. SCOPE.md
and agent boundary docs now match that layer. The review under history/
identifies the implementation remainder; SECRETS-WP-0008 is the follow-on
workplan. SECRETS-IN-0001 is closed.
The layer is not contested. Catalog "custody" is a finding: OpenBao owns
custody, this engine owns the lifecycle API over it. SSH-CA signing is
accepted as a proposed engine API and declined as a Staff lane.
Assistant: grok
Assistant-Session: 01a04cea-cb33-7c63-bad7-c1b0f9f0076b
`ADHOC-YYYY-MM-DD` is unique per date but not per repository, so any two repos
opening an ad-hoc on the same day collide. The 2026-08-26 fleet projection
reset refused 9 records for exactly this reason.
Canon (work-record-types_v0.1, CUST-WP-0066) settled the form as
`{PREFIX}-WP-ADHOC-YYYY-MM-DD`, filename unchanged, and grandfathered existing
ids on the condition they are never *silently* re-derived. This is the explicit
migration that clause allows for.
The hub id is derived from the record id, so a changed id is a different
record: stale state_hub_*_id fields are dropped and fix-consistency re-derives.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
Apply, provision, and verify the prod lane on live OpenBao, publish
@whynot/design@0.4.1 through native secrets-engine exec, and teach the
OpenBao client to tolerate stage-role mount/approle probes when sys/mounts
and sys/auth are denied.
Add the warden-sign auth-capability lane, AppRole handoff, verification guards, docs, and tests.
Point the whynot-design pilot at the canonical decision and add the real publish closeout preflight/runbook.
- SECRETS-WP-0004: scoped warden-sign OpenBao token lane for ops-warden, to
unblock FLEX-WP-0007 T4 joint smoke. First auth-capability (non-KV) lane and
first lane touching production OpenBao (bao.coulomb.social).
- SCOPE.md: add the standard sections flagged by the repo scope review (Relevant
When, Not Relevant When, How It Fits, Terminology, Related / Overlapping,
Provided Capabilities with fenced capability blocks); refresh Current State to
reflect the delivered MVP.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
SECRETS-WP-0003 scopes the real pilot close-out: canonical State Hub decision,
dedicated Gitea bot account for an enforced repo-scope, real token provisioning,
a real @whynot/design publish through secrets-engine exec, and the ops-warden
routing handoff. Does not change the dormant netkingdom publication-scope gate.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- repo-identity.md / repo-boundary.md: replace leftover repo-seed template text
with secrets-engine identity and boundary (T01)
- mark SECRETS-WP-0001 T01–T03 done (T02 dev-workflow commands and T03 first real
workplan were completed during the MVP build); workplan status -> finished
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Implements SECRETS-WP-0002 end to end as a uv-managed Python package:
- catalog: non-secret lane registry + strict validator (build/test/prod)
- stage roles + OpenBao ACL policies; guards refuse wildcards, sys/, identity/,
admin names, and cross-stage paths before any backend call
- plan/apply: dry-run-first, idempotent policy + approle apply, decision-gated
- decisions: State Hub lookup with local-fixture fallback; non-secret evidence
to JSONL + hub progress, scrubbed of any value
- provision/verify: mode-0600 file import + generated test values; positive/
negative checks that never print the value
- exec delivery: `exec --catalog ... -- npm publish` injects the token via a
temp .npmrc for the child only, cleaned up on exit/failure/interrupt
- ops-warden routing contract + hardening backlog docs
- 34 tests incl. live OpenBao integration; scripts/demo-e2e.sh runs the full
chain against a throwaway bao dev server
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>