Admit E3 and capacity on the test plane
Register in-process E3 and capacity fixtures, keep live database and substrate targets pending, and ask ops-mason for namespace-only provision. No packets, no credentials, no cancelled engagement IDs. Assistant: grok Assistant-Session: 01a02670-3345-76f2-a014-70fde8e2a2bb
This commit is contained in:
parent
4882c2d47a
commit
7e83a66573
22 changed files with 501 additions and 74 deletions
|
|
@ -215,12 +215,13 @@ notices. This repo is that something.
|
|||
control the interval between runs *is* the exposure window, and ADR-0003 leaves
|
||||
the number to this repo. Set it, and state the resulting window in the record.
|
||||
|
||||
Implementation progress, 2026-08-21: the cadence is fixed at 24 hours plus run
|
||||
Implementation progress, 2026-08-22: the cadence is fixed at 24 hours plus run
|
||||
and reporting latency, with event-triggered pre-promotion runs after schema,
|
||||
role, RLS or security-definer changes. `src/whitehat_security/e3.py` encodes the
|
||||
seven expected outcomes and keeps the SQL-compromise GUC reset labeled as E3's
|
||||
documented limit. A live database run still requires its separate authorized
|
||||
target and window.
|
||||
seven expected outcomes, keeps the SQL-compromise GUC reset labeled as E3's
|
||||
documented limit, and calibrates known-good/known-bad in-process. `platform-pg`
|
||||
is registered `pending`. A live database run still requires its separate
|
||||
authorized target, named database, ordinary runtime role, and window.
|
||||
|
||||
### T06 — Noisy-neighbour characterisation (the P1/P2 artifact)
|
||||
|
||||
|
|
@ -244,11 +245,12 @@ acceptable.
|
|||
Runs inside a declared window per T01 — on a single-node rail with a six-
|
||||
consumer connection ceiling, a saturation probe is an outage if run carelessly.
|
||||
|
||||
Implementation progress, 2026-08-21: `src/whitehat_security/capacity.py`
|
||||
Implementation progress, 2026-08-22: `src/whitehat_security/capacity.py`
|
||||
records baseline/loaded latency, errors and throughput per consumer, governor
|
||||
binding, aggressor peak/ceiling and neighbour degradation. No live load has
|
||||
been generated; the required operator-approved substrate window and ceilings
|
||||
do not yet exist.
|
||||
binding, aggressor peak/ceiling and neighbour degradation. The in-process
|
||||
fixture is registered as `fixture-capacity`. `shared-substrate` is `pending`.
|
||||
No live load has been generated; the required operator-approved substrate
|
||||
window and aggressor ceiling do not yet exist.
|
||||
|
||||
### T07 — Reporting into risk-nexus
|
||||
|
||||
|
|
@ -297,9 +299,10 @@ Completed 2026-08-22 as a repository contract, not a cluster provision:
|
|||
- Rate watcher, lease cleanup, default-deny plane manifests, runner identity.
|
||||
- Automatic outbox delivery of target reports only.
|
||||
|
||||
`ops-mason` still has to provision namespace, network policy and a real
|
||||
custody projection after a new engagement ID exists. That provision is not
|
||||
this task, and this task does not authorize it.
|
||||
`ops-mason` was asked on 2026-08-22 to provision only the namespace, default
|
||||
deny policy and runner service account from `plane/`. That message does not
|
||||
authorize a pod, a credential, or traffic. A real custody projection still
|
||||
waits on a new engagement ID.
|
||||
|
||||
## Sequencing
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue