Block CUST-WP-0071 and CUST-WP-0073 pending cross-repo requirements
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 7s

Remaining tasks wait on GLAS-WP-0012, RAPPS-WP-0014-T03 and platform/infra/warden
owners; requirement tables added to both workplans.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
codex 2026-09-28 20:25:41 +02:00
parent 807bed6bba
commit 693f7f1962
3 changed files with 49 additions and 12 deletions

View file

@ -4,7 +4,7 @@ type: workplan
title: "Separate agent credentials and establish supervised privileged execution"
domain: infotech
repo: the-custodian
status: active
status: blocked
owner: the-custodian
topic_slug: custodian
flavor: implementation
@ -84,8 +84,9 @@ limits or authorization of a live cutover. Existing human-only lanes still apply
```task
id: CUST-WP-0073-T02
status: progress
status: wait
priority: high
blocking_reason: "Await GLAS-WP-0012 (glas-harness) production acceptance of the local supervised profile; then railiance-platform RBAC, railiance-enablement k3s config, railiance-infra principal mapping and ops-warden certificate issuance."
state_hub_task_id: "4b88b0b7-dc7e-5612-aa5d-1a08f0530c35"
```
@ -146,8 +147,9 @@ drill Secret was deleted with its UID precondition; absence verified and the
```task
id: CUST-WP-0073-T04
status: progress
status: wait
priority: medium
blocking_reason: "Await CUST-WP-0073-T02: the verified agent identity and execution path must exist before it can be documented; Codex/Grok read-denial guard needs glas-harness or harness-owner delivery."
state_hub_task_id: "90725511-4e31-549f-b567-47feff1a9ca4"
```
@ -239,3 +241,21 @@ There is no eligible acceptance-rate sample or autopilot grant yet.
T05 remains the founder's trigger-based rotation deferral, not cancelled or done.
Neither workplan completion nor live credential separation is claimed.
## Blocked — requirements on other repos (2026-09-28)
Nothing further is implementable in this repository; T01 and T03 are done and
T04's local guidance is complete. Workplan set to `blocked`. Requirements:
| Owner | Requirement | Gates |
|-------|-------------|-------|
| glas-harness (GLAS-WP-0012, blocked; T03 progress, T02/T04/T05 wait) | End-to-end production acceptance receipt for the local supervised profile, usable for an interactive agent | T02 |
| railiance-platform | ServiceAccount/cert, ClusterRole and binding in git; no `secrets`/`pods/exec` | T02 |
| railiance-enablement | k3s `write-kubeconfig-mode: 600` in install config | T02 |
| railiance-infra | Host principal mapping; remove unrestricted sudo/admin kubeconfig from the agent account | T02 |
| ops-warden | Certificate issuance for the agent identity | T02 |
| harness owners (Codex/Grok) | Read-denial guard equivalent to the Claude hook, or a recorded statement that none exists | T04 |
Resume when GLAS-WP-0012 records production acceptance: then T02 proof
(`auth can-i`, whoami, approved/unapproved action, admin-path denial) and T04
documentation of the verified path. T05 stays trigger-based.