whitehat-security/plane/README.md
tegwick 95129d7a35 Add governed test plane and close T04/T08
Encode fail-closed admission, target registrations, and a credential
broker that never returns secret values. Calibrate audit-core shaped
probes in-process. Send no packets and request no live credentials.

Assistant: grok
Assistant-Session: 01a02670-3345-76f2-a014-70fde8e2a2bb
2026-08-22 00:44:21 +02:00

1.2 KiB

Governed test plane

Contract only. This repository does not apply cluster objects, request credentials, or send packets. ops-mason provisions from these files after a new, unretired engagement ID exists. Cancelled IDs WH-ENG-20260821-AUDIT-E2 and WH-ENG-20260821-TENANT-E2 are terminal.

Controls

  1. Namespace whitehat, default-deny networking, explicit target egress.
  2. Immutable runner identity with required engagement labels and no standing service-account token.
  3. Custody broker projects two short-lived tenant-scoped identities into the runner mount and revokes them. Values never enter Git, chat, evidence or State Hub.
  4. Pinned runner image digest on the engagement.
  5. Independently usable kill switch: create plane/KILL or set WHITEHAT_KILL_SWITCH=1. Admission fails closed while it is engaged.
  6. Rate watcher and automatic lease cleanup in whitehat_security.plane.

Standing versus live

fixture-e2 is the in-process class already permitted by the rules of engagement. live-e2 still needs a dated engagement, target-owner acknowledgement, plane namespace, pinned digest and a connected custody broker. e3 and capacity are separate approval classes and will not be admitted by the E2 plane.