whitehat-security/engagements/2026-08-22-plane-provision.md
tegwick 7e83a66573 Admit E3 and capacity on the test plane
Register in-process E3 and capacity fixtures, keep live database and
substrate targets pending, and ask ops-mason for namespace-only provision.
No packets, no credentials, no cancelled engagement IDs.

Assistant: grok
Assistant-Session: 01a02670-3345-76f2-a014-70fde8e2a2bb
2026-08-22 09:40:27 +02:00

1.3 KiB

Plane provision request — not an engagement

Status: coordination only; apply nothing from this repository

WHITEHAT-WP-0001-T08 encoded the governed test plane as a contract. Live E2 still needs the cluster objects. This note asks ops-mason to provision the namespace, default-deny network policy, and runner service account from plane/. It does not authorize:

  • applying the runner pod
  • projecting credentials
  • sending packets
  • reusing WH-ENG-20260821-AUDIT-E2 or WH-ENG-20260821-TENANT-E2

Requested objects

Object File Notes
Namespace whitehat plane/namespace.yaml restricted PSS
Default-deny NetworkPolicy plane/network-policy.yaml audit-core egress is documented, not a standing allow for other targets
ServiceAccount whitehat-runner plane/service-account.yaml automountServiceAccountToken: false

Do not create a credential secret. The live custody broker is still unconnected; whitehat will fail closed until a later engagement ID exists.

Next engagement (not this request)

After the namespace exists, a new audit-core E2 ID can be drafted. It will need two ordinary tenant-scoped may_read/may_write fixture senders, TTL ≤ 900s, projected into the runner mount without exposing values to the agent. That is a separate request and uses a new ID.