secrets-engine/workplans
tegwick b9058c96b2
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
docs: answer the GLAS-WP-0015 tenant question and record the DNS hazard
Probing the handed-over Service DNS name from the workstation found that
every *.svc.cluster.local name resolves here to one unrelated public
address via the ad.binect.de search suffix -- including names of services
that do not exist, which proves it is suffix expansion and not a record.

Pointing SECRETS_ENGINE_PDP_URL at the Service name would send the
CheckRequest body (subject, tenant, lane ids, stage, field names, purpose)
and the static Bearer token to that host. Decision envelopes are
structurally validated but not signed, so a responder knowing the package
and version can return a well-formed allow; the fail-closed posture
assumes the PDP is the PDP.

Not mitigated here: choosing the transport control is the owners' call,
not this consumer's. Recommended to FLEX-WP-0021-T05 that the handover be
a trailing-dot FQDN or explicit address, with the response channel's
authentication stated. Our pin stays unset, so the hazard is theoretical.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E4tNMAYcSQmZWUE4wqP4ij

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 715726@bnt-lap001
Assistant-Session: 80a42b32-cba6-4b23-8be0-68819b1a6092
2026-09-06 22:34:20 +02:00
..
archived CUST-WP-0055 T07: add archive workplan terminology grandfather note 2026-07-08 20:26:38 +02:00
ADHOC-2026-08-21.md repo.work.assign_missing_identifiers 2026-09-04 00:03:13 +02:00
ADHOC-2026-08-23.md repo.work.assign_missing_identifiers 2026-09-04 00:03:13 +02:00
SECRETS-WP-0001-statehub-bootstrap.md chore(wp-0001): close State Hub bootstrap workplan; de-template repo identity 2026-06-29 12:14:00 +02:00
SECRETS-WP-0002-bootstrap.md feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
SECRETS-WP-0004-warden-sign-token-lane.md Close warden-sign token lane 2026-06-30 01:01:55 +02:00
SECRETS-WP-0005-scope-intent-value-gaps.md Document scope alignment and warden-sign readiness 2026-06-30 00:52:05 +02:00
SECRETS-WP-0006-catalog-lane-adoption.md docs: record whynot-design lane pointer discrepancy from ops-warden 2026-09-06 00:46:02 +02:00
SECRETS-WP-0007-production-lifecycle-hardening.md feat: bind the destroy gate to approval_binding_digest and pdp_path 2026-09-06 20:39:59 +02:00
SECRETS-WP-0008-layer-model-lifecycle-conformance.md feat: implement the PIP claim + validate authorization join 2026-09-06 01:01:55 +02:00
SECRETS-WP-0009-glas-claude-native-delivery.md docs: answer the GLAS-WP-0015 tenant question and record the DNS hazard 2026-09-06 22:34:20 +02:00