# Plane provision request — not an engagement Status: **foundational plane applied by ops-mason 2026-08-22** (`c26a6e5`). This repository still applies nothing. `WH-ENG-20260822-AUDIT-E2-01` is operator-approved and awaits target-owner acknowledgement. Do not apply a runner or credential until that acknowledgement exists. `WHITEHAT-WP-0001-T08` encoded the governed test plane as a contract. Live E2 still needs the cluster objects. This note asks `ops-mason` to provision the **namespace, default-deny network policy, and runner service account** from `plane/`. It does **not** authorize: - applying the runner pod - projecting credentials - sending packets - reusing `WH-ENG-20260821-AUDIT-E2` or `WH-ENG-20260821-TENANT-E2` ## Requested objects | Object | File | Notes | | --- | --- | --- | | Namespace `whitehat` | `plane/namespace.yaml` | restricted PSS | | Default-deny NetworkPolicy | `plane/network-policy.yaml` | audit-core egress is documented, not a standing allow for other targets | | ServiceAccount `whitehat-runner` | `plane/service-account.yaml` | `automountServiceAccountToken: false` | Do not create a credential secret. The live custody broker is still unconnected; whitehat will fail closed until a later engagement ID exists. ## Next engagement (not this request) After the namespace exists, a **new** audit-core E2 ID can be drafted. It will need two ordinary tenant-scoped `may_read`/`may_write` fixture senders, TTL ≤ 900s, projected into the runner mount without exposing values to the agent. That is a separate request and uses a new ID.