Record the Kubernetes change gate in Mode of Authority terms; drop bare 'operator'.

Option C: the gate on ADMINISTER @ realm:kubernetes is tiered by ADR-0006
readiness state. Below production-approved, activation=APPROVED by founder
plan approval; at production-approved, CONSTRUCT via ArgoCD for
external-audited evidence, direct apply only as activation=BREAK_GLASS.
rapp-policy-nexus gets a dated transition to 2026-12-21.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
codex 2026-09-21 14:07:30 +02:00
parent 4e58927dac
commit e3d0d13253
3 changed files with 80 additions and 12 deletions

View file

@ -218,7 +218,7 @@ names the defect generally. The custodian's contribution that survived is the
- **secrets-engine** established that its exec reads the ungoverned legacy path
`secret/coulomb/whynot-design/npm/publish` (field `npm_token`), while ops-warden's
runbook rotates the governed path (field `NPM_AUTH_TOKEN`). A rotation per the
runbook would not reach the live publish path. Held for the operator.
runbook would not reach the live publish path. Held by the founder.
Ten repositories still carry the pre-ruling sidecar form.
@ -242,7 +242,7 @@ disk. The repositories' own reports had suggested a 33 split on the versioned
v3 is not rolled out.
- **tenant-engine** is admitted as an audit-core sender but cannot deliver:
the egress NetworkPolicy, the URL, and the token projection are missing from
its deploy manifests. TEN-IN-0005; this needs an operator credential path.
its deploy manifests. TEN-IN-0005; this needs a credential path from custody (OpenBao, railiance-platform).
- **secrets-engine** surfaced a question: the service JWT design names
`tenant:coulomb`, but the approval chain resolved to `tenant:platform`.
@ -288,7 +288,7 @@ Still open: A11 r2 and A12 r3 assent, INFD-IN-0007 (the §3 cut, outside the §1
## Follow-ups, 2026-09-21
The operator approved A11 r2 and A12 r3. The approval was relayed to gate-house under GH-WP-0004-T09 as the return for the four round members that deferred to the operator: audit-core, access-engine, ops-warden and net-kingdom. It does not stand in for approval-engine, kings-guard, informed-decision or railiance-master.
The founder approved A11 r2 and A12 r3, exercising `GOVERN`. The approval was relayed to gate-house under GH-WP-0004-T09 as the return for the four round members that deferred to the founder: audit-core, access-engine, ops-warden and net-kingdom. It does not stand in for approval-engine, kings-guard, informed-decision or railiance-master.
GH-DEC-2026-021's immediate changes are applied:
@ -296,3 +296,9 @@ GH-DEC-2026-021's immediate changes are applied:
- **ops-warden** (`3979152`): the playbook is now titled as the estate reference detector. Prose citations are recorded as not reached, with a note of what widens if A12 r3 is rejected. `intent_version` is named as a key that must not be flagged.
The reference detector flags a versioned path to any document, not only one naming the standard. GH-DEC-2026-021 §3 accepts that. No declaration carries such a path today.
## Terminology, 2026-09-21
This record and the custodian's messages today used bare "operator" for the founder's decisions. SecurityCanon's disambiguation rule forbids that: `Operator` is a CARING lifecycle role, and `OPERATE` is an Auth Mode. The founder's decisions today were authority over authority, which is `GOVERN`. The records are corrected. Messages already sent are not; later messages use the canon's terms.
The Kubernetes change gate is recorded in `docs/kubernetes-change-gate-decision.md` in Mode of Authority terms.