secrets-engine/docs
tegwick 1945e16685
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Declare Engine/Lifecycle against security layer model v0.7
Replace the gate-house review note with this repository's own declaration:
INTENT.md frontmatter, layer.yaml, and a published PEP stance map. SCOPE.md
and agent boundary docs now match that layer. The review under history/
identifies the implementation remainder; SECRETS-WP-0008 is the follow-on
workplan. SECRETS-IN-0001 is closed.

The layer is not contested. Catalog "custody" is a finding: OpenBao owns
custody, this engine owns the lifecycle API over it. SSH-CA signing is
accepted as a proposed engine API and declined as a Staff lane.

Assistant: grok
Assistant-Session: 01a04cea-cb33-7c63-bad7-c1b0f9f0076b
2026-08-29 11:57:47 +02:00
..
catalog-admission.md feat: admit existing OpenBao catalog lanes 2026-08-21 08:20:33 +02:00
cli.md Harden production authorization and service auth 2026-08-23 14:15:42 +02:00
hardening-backlog.md Harden production authorization and service auth 2026-08-23 14:15:42 +02:00
netkingdom-security-infrastructure.md Declare Engine/Lifecycle against security layer model v0.7 2026-08-29 11:57:47 +02:00
openbao-stage-roles.md feat: add auth-capability lanes and pilot closeout 2026-06-29 16:58:16 +02:00
ops-warden-routing-contract.md Document scope alignment and warden-sign readiness 2026-06-30 00:52:05 +02:00
publication-scope-policy.md Migrate whynot-design npm catalog and docs to Forgejo registry 2026-07-09 11:38:15 +02:00
service-auth.md Harden production authorization and service auth 2026-08-23 14:15:42 +02:00
statehub-register.md Initial commit 2026-06-28 09:03:37 +00:00
template-validation-checklist.md Initial commit 2026-06-28 09:03:37 +00:00
warden-sign-auth-capability.md Close warden-sign token lane 2026-06-30 01:01:55 +02:00
whynot-design-real-publish-closeout.md Add value-safe verification and audit reporting 2026-08-23 12:33:38 +02:00