whitehat-security/engagements/2026-08-22-audit-core-e2.md
tegwick 5082f86c61 Propose WH-ENG-20260822-AUDIT-E2-01 without authorizing traffic
Align plane ordering with Mason's apply, record the fresh audit-core
engagement as proposed, and keep offline admission fail-closed until
operator approval and owner acknowledgement exist.

Assistant: grok
Assistant-Session: 01a02670-3345-76f2-a014-70fde8e2a2bb
2026-08-22 11:46:58 +02:00

28 lines
1.5 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# WH-ENG-20260822-AUDIT-E2-01 — proposal
Status: **proposed**. This is not operator approval, not target-owner
acknowledgement, and not authorization to send a packet.
Reserved by audit-core in `c45151e1-df1a-4306-a70a-83be7875f01c` after Mason
applied the foundational plane (`c26a6e5`). The cancelled ID
`WH-ENG-20260821-AUDIT-E2` remains terminal.
| Field | Proposed value |
| --- | --- |
| Target | `audit-core.audit-core.svc.cluster.local:8080` |
| Registration | `targets/audit-core-e2.json` (`applicable`, `live-e2`) |
| Source | pod `whitehat/whitehat-e2-audit` with plane and target labels, SA `whitehat-runner`, no token |
| Image pin | `forgejo.coulomb.social/coulomb/audit-core@sha256:7febc28e8a828dbc245144a38e5728e0fbf496b594dd7591170b450a1265fb10` |
| Identities | two ordinary tenant-scoped `may_read`/`may_write` senders, `source=whitehat-security`, TTL ≤ 900s, mount-only |
| Routes | `GET /readyz`, `POST /v1/events`, `GET /v1/events/{event_id}`, `GET /v1/events?correlation_id=` |
| Ceiling | concurrency 1; 10/min; at most 30 requests |
| Window | 2026-08-22T18:00:00Z18:15:00Z (refresh at approval if stale) |
| Cleanup | revoke both leases; delete only named synthetic fixtures; prove cleanup |
| Reporting | `risk-nexus`, no severity |
Offline preflight (`validate-engagement`, `admit-plane`) must fail closed while
`status` is `proposed` and the live custody broker is unconnected. That
failure is the expected result, not a pass.
Do not apply `plane/runner-pod.yaml` against this ID until approval,
acknowledgement, and projected identities exist.