Encode fail-closed admission, target registrations, and a credential broker that never returns secret values. Calibrate audit-core shaped probes in-process. Send no packets and request no live credentials. Assistant: grok Assistant-Session: 01a02670-3345-76f2-a014-70fde8e2a2bb
1.2 KiB
1.2 KiB
Governed test plane
Contract only. This repository does not apply cluster objects, request
credentials, or send packets. ops-mason provisions from these files after a
new, unretired engagement ID exists. Cancelled IDs
WH-ENG-20260821-AUDIT-E2 and WH-ENG-20260821-TENANT-E2 are terminal.
Controls
- Namespace
whitehat, default-deny networking, explicit target egress. - Immutable runner identity with required engagement labels and no standing service-account token.
- Custody broker projects two short-lived tenant-scoped identities into the runner mount and revokes them. Values never enter Git, chat, evidence or State Hub.
- Pinned runner image digest on the engagement.
- Independently usable kill switch: create
plane/KILLor setWHITEHAT_KILL_SWITCH=1. Admission fails closed while it is engaged. - Rate watcher and automatic lease cleanup in
whitehat_security.plane.
Standing versus live
fixture-e2 is the in-process class already permitted by the rules of
engagement. live-e2 still needs a dated engagement, target-owner
acknowledgement, plane namespace, pinned digest and a connected custody
broker. e3 and capacity are separate approval classes and will not be
admitted by the E2 plane.