secrets-engine/workplans
tegwick 8a48cb05df Apply GH-DEC-2026-017: INTENT.md governs, layer.yaml is derived, no version
Verified against gate-house's committed ruling (decisions/decisions.md,
GH-DEC-2026-017) and amendments A9-A13, then ops-warden's reference change set
(a70f559, wiki/playbooks/netkingdom-layer-declaration.md). They agree.

layer.yaml: standard_version removed; derived: true and derived_from:
INTENT.md added; declared_by kept. INTENT.md frontmatter never carried
standard_version, but its standard: value was a version-pinned path; it is
de-versioned as the reference instance did. No layer value is re-spelled:
INTENT.md still says Engine and layer.yaml still says engine.

The checker changes in the same commit because it listed standard_version as
a required key: removing the field alone would have made a conforming
declaration exit 2 MALFORMED. It now reads INTENT.md as the governing form,
requires the derived marking, rejects a returning standard_version in either
form, checks both layer values against the closed four-token vocabulary
(Taxonomy included) after an ASCII fold, and reports a post-fold disagreement
between the forms as a finding rather than resolving it by precedence.

Tests assert the fold, not per-file spelling, and cover fold agreement, a
real disagreement, the closed vocabulary and a returning version. Full suite
430 passed.

role:, pep-stance.yaml and schema_version are untouched (not ruled). Still
open: where the removed version lives in a derived conformance record; asked
of gate-house by ops-warden (4220413a), followed rather than chosen here.

Closes the SECRETS-WP-0008 note that waited on the reference form.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
2026-09-21 07:37:53 +02:00
..
archived CUST-WP-0055 T07: add archive workplan terminology grandfather note 2026-07-08 20:26:38 +02:00
ADHOC-2026-08-21.md repo.work.assign_missing_identifiers 2026-09-04 00:03:13 +02:00
ADHOC-2026-08-23.md repo.work.assign_missing_identifiers 2026-09-04 00:03:13 +02:00
SECRETS-WP-0001-statehub-bootstrap.md chore(wp-0001): close State Hub bootstrap workplan; de-template repo identity 2026-06-29 12:14:00 +02:00
SECRETS-WP-0002-bootstrap.md feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
SECRETS-WP-0004-warden-sign-token-lane.md Close warden-sign token lane 2026-06-30 01:01:55 +02:00
SECRETS-WP-0005-scope-intent-value-gaps.md Document scope alignment and warden-sign readiness 2026-06-30 00:52:05 +02:00
SECRETS-WP-0006-catalog-lane-adoption.md Answer the exec-path question: the front door reads the ungoverned duplicate. 2026-09-21 02:36:31 +02:00
SECRETS-WP-0007-production-lifecycle-hardening.md Complete T03 with native OpenRouter authentication evidence 2026-09-16 02:12:45 +02:00
SECRETS-WP-0008-layer-model-lifecycle-conformance.md Apply GH-DEC-2026-017: INTENT.md governs, layer.yaml is derived, no version 2026-09-21 07:37:53 +02:00
SECRETS-WP-0009-glas-claude-native-delivery.md Classify open workplans with flavor (CUST-WP-0072). 2026-09-14 15:50:49 +02:00
SECRETS-WP-0010-openrouter-native-access.md Complete T03 with native OpenRouter authentication evidence 2026-09-16 02:12:45 +02:00