whitehat-security/engagements/runtime/WH-ENG-20260822-AUDIT-E2-01-invocation.md
tegwick f8251c5de8 Expire WH-ENG-20260822-AUDIT-E2-01 after an unused window
The 18:00Z-18:15Z window ended with no projection-ready notice and zero
packets. Mark the identifier terminal. Record platform-pg E3 as not
applicable for an ordinary runtime conformance-view identity.

Assistant: grok
Assistant-Session: 01a02670-3345-76f2-a014-70fde8e2a2bb
2026-08-22 20:20:38 +02:00

62 lines
2.4 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# WH-ENG-20260822-AUDIT-E2-01 — invocation (no secrets)
This window elapsed at `2026-08-22T18:15:00Z` with no projection and no
packets. Do not apply the runner or mint credentials against this identifier.
Current time-gate: `validate-engagement` and `admit-plane` fail closed with
`engagement window has not started` until `2026-08-22T18:00:00Z`. After the
window opens, `admit-plane` still fails closed while the live custody broker
is unconnected.
## Custody projection (railiance-platform)
Procedure is implemented at railiance-platform `864cc20`
(`docs/audit-core-whitehat-e2-credential-projection.md`). `project` is
hard-gated to **18:00Z18:03Z**. Cleanup must finish before 18:15Z. No mint
before the gate.
| Handle | Binding |
| --- | --- |
| token-a | `source=whitehat-security`, tenant `tenant:trial:whitehat-a-20260822`, `may_read=true`, `may_write=true` |
| token-b | `source=whitehat-security`, tenant `tenant:trial:whitehat-b-20260822`, `may_read=true`, `may_write=true` |
Attended commands, from railiance-platform, after 18:00Z and no later than 18:03Z:
```bash
python3 scripts/audit-core-whitehat-e2-credentials.py preflight
python3 scripts/audit-core-whitehat-e2-credentials.py project \
--confirm WH-ENG-20260822-AUDIT-E2-01:attended
```
After that notice, apply the runner contract and the invocation below. Before
18:15Z:
```bash
python3 scripts/audit-core-whitehat-e2-credentials.py cleanup \
--confirm WH-ENG-20260822-AUDIT-E2-01:attended
```
Never return token values to whitehat, State Hub, or chat.
## Runner (inside the admitted pod, after projection)
```
python3 - \
--base-url http://audit-core.audit-core.svc.cluster.local:8080 \
--engagement-id WH-ENG-20260822-AUDIT-E2-01 \
--target-revision sha256:c2fe39a0185b99be3fc0cb14d2de69772b8e66e20490097c9d11d90cc39719a6 \
--token-a-file /var/run/secrets/whitehat/token-a \
--token-b-file /var/run/secrets/whitehat/token-b \
--tenant-a tenant:trial:whitehat-a-20260822 \
--tenant-b tenant:trial:whitehat-b-20260822 \
--event-a whitehat-e2-event-a-20260822 \
--event-b whitehat-e2-event-b-20260822 \
--absent-event whitehat-e2-absent-20260822 \
--forged-event whitehat-e2-forged-b-20260822 \
--correlation whitehat-e2-correlation-20260822 \
--occurred-at 2026-08-22T18:00:00Z \
--rate 10 --max-requests 30 --abort-p95-ms 500
```
stdin is `runners/audit_core_e2.py`. The forged event argument is mandatory
and must stay inside `fixture_ids`.