Add governed test plane and close T04/T08
Encode fail-closed admission, target registrations, and a credential broker that never returns secret values. Calibrate audit-core shaped probes in-process. Send no packets and request no live credentials. Assistant: grok Assistant-Session: 01a02670-3345-76f2-a014-70fde8e2a2bb
This commit is contained in:
parent
0aab0cb4c6
commit
95129d7a35
35 changed files with 1599 additions and 103 deletions
48
docs/test-plane.md
Normal file
48
docs/test-plane.md
Normal file
|
|
@ -0,0 +1,48 @@
|
|||
# Governed test plane
|
||||
|
||||
This is the missing control from the 2026-08-22 cutoff. It is a fail-closed
|
||||
admission path, not a standing authorization to probe.
|
||||
|
||||
## What the plane is
|
||||
|
||||
A live E2 run is admitted only when every item below is true:
|
||||
|
||||
1. The target is registered in `targets/` with `applicability: applicable`.
|
||||
2. Known-bad calibration for that target has already failed in-process.
|
||||
3. The engagement is complete, in window, owner-acknowledged, and not a
|
||||
retired ID.
|
||||
4. `approval_class` is `live-e2` (or `fixture-e2` for in-process only).
|
||||
5. The runner namespace is `whitehat`, the image digest is pinned, and
|
||||
engagement labels are present.
|
||||
6. The custody broker projected exactly two identity *handles* (owner and
|
||||
attacker). Credential values are not returned to the operator or agent.
|
||||
7. The kill switch is clear.
|
||||
8. The rate watcher is attached. Cleanup revokes the lease.
|
||||
|
||||
If any item is false, `whitehat admit-plane` exits 2 and no identity is
|
||||
requested.
|
||||
|
||||
## What the plane is not
|
||||
|
||||
- Not authorization. Rules of engagement §1 still apply.
|
||||
- Not a packet. Manifests in `plane/` are a contract for `ops-mason`.
|
||||
- Not a secret broker. `UnconnectedCustodyBroker` is the default for every
|
||||
non-fixture environment and raises before any custody call.
|
||||
- Not a way to finish tenant-engine E2. That target is `not_applicable`.
|
||||
|
||||
## Operator commands
|
||||
|
||||
```sh
|
||||
PYTHONPATH=src python3 -m whitehat_security.cli validate-targets targets
|
||||
PYTHONPATH=src python3 -m whitehat_security.cli admit-plane engagements/<record>.json targets/<target>.json
|
||||
PYTHONPATH=src python3 -m whitehat_security.cli kill-switch
|
||||
PYTHONPATH=src python3 -m whitehat_security.cli deliver evidence/<run>.json --outbox outbox
|
||||
```
|
||||
|
||||
Create `plane/KILL` to abort independently of the runner process.
|
||||
|
||||
## Retired identifiers
|
||||
|
||||
`WH-ENG-20260821-AUDIT-E2` and `WH-ENG-20260821-TENANT-E2` are terminal. A new
|
||||
live run needs a new ID after the cluster plane exists and the custody broker
|
||||
can project identities without exposing values.
|
||||
Loading…
Add table
Add a link
Reference in a new issue