2026-08-22 11:46:58 +02:00
{
"engagement_id" : "WH-ENG-20260822-AUDIT-E2-01" ,
2026-08-22 20:20:38 +02:00
"status" : "expired" ,
"expired_at" : "2026-08-22T18:15:00Z" ,
"expiry_reason" : "Approved window ended with no projection-ready notice from railiance-platform and zero target requests. Do not reuse this identifier." ,
2026-08-22 11:46:58 +02:00
"proposal_at" : "2026-08-22T09:44:00Z" ,
2026-08-22 11:54:09 +02:00
"proposal_reason" : "Fresh live-e2 proposal after foundational plane apply. Do not reuse WH-ENG-20260821-AUDIT-E2." ,
"authorization_id" : "operator-session-2026-08-22-e2-approval" ,
"authorizer" : "repository operator and infrastructure owner" ,
"approved_at" : "2026-08-22T09:52:55Z" ,
2026-08-22 11:46:58 +02:00
"expires_at" : "2026-08-22T18:15:00Z" ,
"target" : "http://audit-core.audit-core.svc.cluster.local:8080" ,
"target_id" : "audit-core" ,
"target_owner" : "audit-core / infrastructure operator" ,
2026-08-22 12:05:40 +02:00
"target_owner_acknowledged_at" : "2026-08-22T10:04:56Z" ,
"target_owner_acknowledgement_status" : "audit-core accepted the bounded routes, declared fixtures, two expiring tenant-scoped identities, target revision, window, abort thresholds, and cleanup obligation after review at whitehat-security 1418dac and audit-core abd22fa/fa6665f" ,
2026-08-22 11:46:58 +02:00
"environment" : "production" ,
2026-08-22 11:54:09 +02:00
"production_approval" : "Explicit operator approval of WH-ENG-20260822-AUDIT-E2-01 in the coordinating session on 2026-08-22" ,
2026-08-22 11:46:58 +02:00
"approval_class" : "live-e2" ,
"plane_namespace" : "whitehat" ,
2026-08-22 12:04:50 +02:00
"runner_image_digest" : "sha256:c2fe39a0185b99be3fc0cb14d2de69772b8e66e20490097c9d11d90cc39719a6" ,
2026-08-22 11:46:58 +02:00
"namespace" : "whitehat" ,
"source" : "dedicated pod whitehat/whitehat-e2-audit, labels whitehat.security/plane=true, whitehat.security/target=audit-core, whitehat.security/engagement=WH-ENG-20260822-AUDIT-E2-01, serviceAccount whitehat-runner, automountServiceAccountToken=false" ,
2026-08-22 12:04:50 +02:00
"source_image" : "forgejo.coulomb.social/coulomb/audit-core@sha256:c2fe39a0185b99be3fc0cb14d2de69772b8e66e20490097c9d11d90cc39719a6" ,
2026-08-22 11:46:58 +02:00
"control_plane_scope" : [
"GET apps/v1 deployment audit-core/audit-core for target revision only" ,
"GET v1 service audit-core/audit-core for target identity only" ,
"CREATE/GET/EXEC/DELETE v1 pod whitehat/whitehat-e2-audit only; EXEC may stream runners/audit_core_e2.py to python3 stdin and invoke no other program" ,
"mount but never GET v1 secret whitehat/whitehat-e2-audit-credentials provisioned by the custody owner" ,
"GET pod log whitehat/whitehat-e2-audit only"
] ,
"routes" : [
"GET /readyz" ,
"POST /v1/events" ,
"GET /v1/events/{event_id}" ,
"GET /v1/events?correlation_id={correlation_id}"
] ,
"fixture_ids" : [
"tenant:trial:whitehat-a-20260822" , "tenant:trial:whitehat-b-20260822" ,
"whitehat-e2-event-a-20260822" , "whitehat-e2-event-b-20260822" ,
2026-08-22 12:04:50 +02:00
"whitehat-e2-absent-20260822" , "whitehat-e2-forged-b-20260822" ,
"whitehat-e2-correlation-20260822"
2026-08-22 11:46:58 +02:00
] ,
"credential_lane" : "audit-core sender registry through its sanctioned custody owner; no credential value retained" ,
"credential_role" : "two temporary ordinary tenant-scoped may_read/may_write fixture senders bound to source=whitehat-security" ,
"credential_max_ttl_seconds" : 900 ,
"techniques" : [ "e2-differential" ] ,
"prohibited_techniques" : [
"discovery" , "direct-database-access" , "saturation" , "large-payload" ,
"real-data-collection" , "adjacent-service-follow-up" ,
"any control-plane operation outside control_plane_scope"
] ,
"rate_limit_per_minute" : 10 ,
"max_concurrency" : 1 ,
"maximum_requests" : 30 ,
"window_start" : "2026-08-22T18:00:00Z" ,
"window_end" : "2026-08-22T18:15:00Z" ,
"operator_contact" : "repository operator in coordinating session" ,
"abort_contact" : "repository operator in coordinating session" ,
"abort_thresholds" : {
"p95_latency_ms" : 500 ,
"probe_attributable_5xx" : 1 ,
"unexpected_or_non_fixture_data" : 1 ,
"missing_attribution" : 1
} ,
"posture_claim" : "implemented E2; currently evidenced E1" ,
"attacker_model" : "E2-authenticated-tenant-a" ,
"finding_destination" : "risk-nexus" ,
"plane_bundle_digest" : "9636f48f0b994118ff60a8c014e0099486945d66a2b3d3582dc57a09862b2035" ,
"target_ingress" : "audit-core-whitehat-ingress at audit-core 5b5196e; namespace=whitehat AND whitehat.security/plane=true AND whitehat.security/target=audit-core"
}