Settle the change gate's edge cases and withdraw an unintended rail-to-layer mapping.
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run

Founder rulings: unmapped targets are production-tier until mapped;
an evidence lapse does not loosen the path; deprecated keeps its tier.
The contact is realm:kubernetes with no layer assigned (statute 20.3 stays
unset per ADR-0009 D4). ArgoCD on railiance01 is unverified; until the
production row has a working path, the transition rule covers every
production-tier target. Resolves the conflict gate-house noted between the
two founder records.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
codex 2026-09-21 14:38:58 +02:00
parent e3d0d13253
commit 9ba6e65654
2 changed files with 17 additions and 5 deletions

View file

@ -32,7 +32,7 @@ ops-mason's construction plans are drafted and self-reviewed by an agent, then a
- **Only these changes are covered.** The exception covers the phase-4 actions listed above, as ops-mason declared them in its INTENT.md frontmatter on 2026-09-21 (ops-mason@0ff263a). A new class of protected change is not covered until the founder accepts it.
- **Structure only.** ops-mason's own declared capability is "structure only, never secret values". The exception depends on that holding.
- **Review 2026-12-21.** That is the date ops-mason already set on the gaps. At review, the founder either renews the exception or asks for these writes to route through access-engine.
- **Review 2026-12-21.** That is the date ops-mason already set on the gaps. At review, the founder either renews the exception or asks for these writes to route through access-engine. That choice does not extend to `kubectl apply`: `docs/kubernetes-change-gate-decision.md` ruled it a quality gate, not an authorization decision, so it never routes through access-engine. gate-house GH-DEC-2026-022 noted the conflict between the two records, and this sentence resolves it.
- **Still declared.** The gaps stay declared, not removed, and are marked accepted rather than open. A conformance run must report them as accepted exceptions, not as conformance.
## Consequences for other records