Admit E3 and capacity on the test plane
Register in-process E3 and capacity fixtures, keep live database and substrate targets pending, and ask ops-mason for namespace-only provision. No packets, no credentials, no cancelled engagement IDs. Assistant: grok Assistant-Session: 01a02670-3345-76f2-a014-70fde8e2a2bb
This commit is contained in:
parent
4882c2d47a
commit
7e83a66573
22 changed files with 501 additions and 74 deletions
31
engagements/2026-08-22-plane-provision.md
Normal file
31
engagements/2026-08-22-plane-provision.md
Normal file
|
|
@ -0,0 +1,31 @@
|
|||
# Plane provision request — not an engagement
|
||||
|
||||
Status: **coordination only; apply nothing from this repository**
|
||||
|
||||
`WHITEHAT-WP-0001-T08` encoded the governed test plane as a contract. Live E2
|
||||
still needs the cluster objects. This note asks `ops-mason` to provision the
|
||||
**namespace, default-deny network policy, and runner service account** from
|
||||
`plane/`. It does **not** authorize:
|
||||
|
||||
- applying the runner pod
|
||||
- projecting credentials
|
||||
- sending packets
|
||||
- reusing `WH-ENG-20260821-AUDIT-E2` or `WH-ENG-20260821-TENANT-E2`
|
||||
|
||||
## Requested objects
|
||||
|
||||
| Object | File | Notes |
|
||||
| --- | --- | --- |
|
||||
| Namespace `whitehat` | `plane/namespace.yaml` | restricted PSS |
|
||||
| Default-deny NetworkPolicy | `plane/network-policy.yaml` | audit-core egress is documented, not a standing allow for other targets |
|
||||
| ServiceAccount `whitehat-runner` | `plane/service-account.yaml` | `automountServiceAccountToken: false` |
|
||||
|
||||
Do not create a credential secret. The live custody broker is still
|
||||
unconnected; whitehat will fail closed until a later engagement ID exists.
|
||||
|
||||
## Next engagement (not this request)
|
||||
|
||||
After the namespace exists, a **new** audit-core E2 ID can be drafted. It will
|
||||
need two ordinary tenant-scoped `may_read`/`may_write` fixture senders, TTL
|
||||
≤ 900s, projected into the runner mount without exposing values to the agent.
|
||||
That is a separate request and uses a new ID.
|
||||
Loading…
Add table
Add a link
Reference in a new issue