Add governed test plane and close T04/T08

Encode fail-closed admission, target registrations, and a credential
broker that never returns secret values. Calibrate audit-core shaped
probes in-process. Send no packets and request no live credentials.

Assistant: grok
Assistant-Session: 01a02670-3345-76f2-a014-70fde8e2a2bb
This commit is contained in:
tegwick 2026-08-22 00:44:21 +02:00
parent 0aab0cb4c6
commit 95129d7a35
35 changed files with 1599 additions and 103 deletions

48
docs/test-plane.md Normal file
View file

@ -0,0 +1,48 @@
# Governed test plane
This is the missing control from the 2026-08-22 cutoff. It is a fail-closed
admission path, not a standing authorization to probe.
## What the plane is
A live E2 run is admitted only when every item below is true:
1. The target is registered in `targets/` with `applicability: applicable`.
2. Known-bad calibration for that target has already failed in-process.
3. The engagement is complete, in window, owner-acknowledged, and not a
retired ID.
4. `approval_class` is `live-e2` (or `fixture-e2` for in-process only).
5. The runner namespace is `whitehat`, the image digest is pinned, and
engagement labels are present.
6. The custody broker projected exactly two identity *handles* (owner and
attacker). Credential values are not returned to the operator or agent.
7. The kill switch is clear.
8. The rate watcher is attached. Cleanup revokes the lease.
If any item is false, `whitehat admit-plane` exits 2 and no identity is
requested.
## What the plane is not
- Not authorization. Rules of engagement §1 still apply.
- Not a packet. Manifests in `plane/` are a contract for `ops-mason`.
- Not a secret broker. `UnconnectedCustodyBroker` is the default for every
non-fixture environment and raises before any custody call.
- Not a way to finish tenant-engine E2. That target is `not_applicable`.
## Operator commands
```sh
PYTHONPATH=src python3 -m whitehat_security.cli validate-targets targets
PYTHONPATH=src python3 -m whitehat_security.cli admit-plane engagements/<record>.json targets/<target>.json
PYTHONPATH=src python3 -m whitehat_security.cli kill-switch
PYTHONPATH=src python3 -m whitehat_security.cli deliver evidence/<run>.json --outbox outbox
```
Create `plane/KILL` to abort independently of the runner process.
## Retired identifiers
`WH-ENG-20260821-AUDIT-E2` and `WH-ENG-20260821-TENANT-E2` are terminal. A new
live run needs a new ID after the cluster plane exists and the custody broker
can project identities without exposing values.