Owner acknowledgement remains pending. Offline admission stays fail-closed. No credentials requested and no packets sent. Assistant: grok Assistant-Session: 01a02670-3345-76f2-a014-70fde8e2a2bb
1.5 KiB
Plane provision request — not an engagement
Status: foundational plane applied by ops-mason 2026-08-22 (c26a6e5).
This repository still applies nothing. WH-ENG-20260822-AUDIT-E2-01 is
operator-approved and awaits target-owner acknowledgement. Do not apply a
runner or credential until that acknowledgement exists.
WHITEHAT-WP-0001-T08 encoded the governed test plane as a contract. Live E2
still needs the cluster objects. This note asks ops-mason to provision the
namespace, default-deny network policy, and runner service account from
plane/. It does not authorize:
- applying the runner pod
- projecting credentials
- sending packets
- reusing
WH-ENG-20260821-AUDIT-E2orWH-ENG-20260821-TENANT-E2
Requested objects
| Object | File | Notes |
|---|---|---|
Namespace whitehat |
plane/namespace.yaml |
restricted PSS |
| Default-deny NetworkPolicy | plane/network-policy.yaml |
audit-core egress is documented, not a standing allow for other targets |
ServiceAccount whitehat-runner |
plane/service-account.yaml |
automountServiceAccountToken: false |
Do not create a credential secret. The live custody broker is still unconnected; whitehat will fail closed until a later engagement ID exists.
Next engagement (not this request)
After the namespace exists, a new audit-core E2 ID can be drafted. It will
need two ordinary tenant-scoped may_read/may_write fixture senders, TTL
≤ 900s, projected into the runner mount without exposing values to the agent.
That is a separate request and uses a new ID.