Activate ZONE-WP-0001 and decide exception lifecycle

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0291a-1e87-7151-9934-fcbfe3f65eb1
This commit is contained in:
tegwick 2026-08-22 13:01:14 +02:00
parent 6f6c893011
commit 11af8095ae
4 changed files with 174 additions and 17 deletions

View file

@ -4,12 +4,12 @@ type: workplan
title: "The security zone model — derive it from the estate, draft it as canon"
domain: infotech
repo: zone-engine
status: proposed
status: active
owner: zone-engine
topic_slug: netkingdom
planning_priority: P1
created: "2026-08-19"
updated: "2026-08-19"
updated: "2026-08-22"
state_hub_workstream_id: "a75c8c9c-c108-4831-8d72-4343cce49879"
---
@ -76,7 +76,7 @@ machinery; it does not grow a second vocabulary beside it.
```task
id: ZONE-WP-0001-T01
status: todo
status: done
priority: high
state_hub_task_id: "ea74316e-b711-4888-9b38-553ebc9ad856"
```
@ -91,6 +91,12 @@ the only PDP and consumes compiled membership.
If either disagrees, the model moves and this repo is archived rather than kept
for its own sake. Record the outcome either way.
**Done 2026-08-22.** Both required owners answered on the record below. Their
binding decisions have been carried into `GOAL.md` and `SCOPE.md`: zone-engine
owns identity, membership, and the exception lifecycle; net-kingdom publishes
the canon standard; flex-auth remains the only PDP; membership is compiled data
and stance is owned by the policy or enforcement point that renders the effect.
**flex-auth answered 2026-08-19 (amended by flex-auth).** Confirmed: zone-engine
owns zone identity, membership and exception lifecycle; flex-auth stays the only
PDP. But the invariant as written in `GOAL.md` guards the wrong property. *"Never
@ -263,7 +269,7 @@ those lanes are graded.
```task
id: ZONE-WP-0001-T03
status: todo
status: wait
priority: high
state_hub_task_id: "7f47b750-1ae4-467d-b3c4-064f4ec07dbd"
```
@ -277,6 +283,19 @@ Controls in scope at minimum: the flex-auth pre-sign gate (`policy.enabled`,
`fail_closed`), the agent read-boundary on `risk: high` lanes (ops-warden
`ADR-0004`), and the `warden plan` escalation verdicts.
**Waiting on owner rulings, 2026-08-22.** Re-running
`ops-warden/scripts/report_workload_join.py` finds **nine** declared rapp
workloads, but still only **one of 27 lanes** joins to a workload; 13 name an
undeclared candidate and 13 have no workload-shaped path. The exact residue was
sent to `repo-manager` (declaration ownership/surface) and `net-kingdom`
(whether operational control-plane consumers must acquire workload identities,
and whether unknown is a required result). This is the consultation required by
the 2026-08-20 finding below; stance modelling will not reopen the policy subject
merely to make the corpus fit. In the interim, `RISK-N-0004`'s consumer
requirements are accepted: the resolved view is workload-addressable,
authoritative, machine-readable, exposes guarantees as well as membership, and
returns unknown without inference.
**Operator direction 2026-08-19 — defaults derive from maturity, not from
nothing.** An ungraded lane must not inherit the safest-for-the-tool default; it
should inherit the default its *maturity context* implies. Early or experimental
@ -473,7 +492,7 @@ not, and a model that implies otherwise will be built and then not work.
```task
id: ZONE-WP-0001-T04
status: todo
status: done
priority: high
state_hub_task_id: "1c542ca5-2b82-4778-a3e4-c76e932423c9"
```
@ -491,6 +510,22 @@ happens at expiry — auto-revert, or block until renewed.
If T04 concludes the lifecycle can live as reviewed declarations in git, say so
plainly and drop the runtime. That is a valid and cheaper outcome.
**Done 2026-08-22.** The lifecycle and runtime decision are recorded in
`docs/exception-lifecycle-2026-08-22.md`. A grant is a reviewed,
machine-readable relaxation for named workloads, one zone, and one control;
only the control owner's designated authority may grant it, within that
control's declared maximum duration. The enforcement point applies it only for
`not_before <= now < not_after`, falls back to the base rule on any invalid or
unevaluable fact, stamps the active exception into its decision/verdict, and
caps any durable credential or session so no granted authority outlives the
exception. Expiry auto-restores the base rule; renewal is a new grant.
**No runtime is warranted.** flex-auth policy evaluates time in Rego; CLI and
PEP controls evaluate it on invocation. A central service could neither reload
flex-auth's digest-pinned artifacts nor improve deadline enforcement without
adding a synchronous availability and authority boundary. Git review plus
enforcement-time evaluation is the cheaper and stronger result.
**Hard constraint from flex-auth 2026-08-19 — the PDP has no reload path.**
`cmd/flex-auth/main.go:447` calls `registry.LoadFile` once at process start.
There is no watcher, no SIGHUP, no reload endpoint. Both the registry snapshot