Register in-process E3 and capacity fixtures, keep live database and substrate targets pending, and ask ops-mason for namespace-only provision. No packets, no credentials, no cancelled engagement IDs. Assistant: grok Assistant-Session: 01a02670-3345-76f2-a014-70fde8e2a2bb
1.3 KiB
1.3 KiB
Plane provision request — not an engagement
Status: coordination only; apply nothing from this repository
WHITEHAT-WP-0001-T08 encoded the governed test plane as a contract. Live E2
still needs the cluster objects. This note asks ops-mason to provision the
namespace, default-deny network policy, and runner service account from
plane/. It does not authorize:
- applying the runner pod
- projecting credentials
- sending packets
- reusing
WH-ENG-20260821-AUDIT-E2orWH-ENG-20260821-TENANT-E2
Requested objects
| Object | File | Notes |
|---|---|---|
Namespace whitehat |
plane/namespace.yaml |
restricted PSS |
| Default-deny NetworkPolicy | plane/network-policy.yaml |
audit-core egress is documented, not a standing allow for other targets |
ServiceAccount whitehat-runner |
plane/service-account.yaml |
automountServiceAccountToken: false |
Do not create a credential secret. The live custody broker is still unconnected; whitehat will fail closed until a later engagement ID exists.
Next engagement (not this request)
After the namespace exists, a new audit-core E2 ID can be drafted. It will
need two ordinary tenant-scoped may_read/may_write fixture senders, TTL
≤ 900s, projected into the runner mount without exposing values to the agent.
That is a separate request and uses a new ID.