Complete security zone model and canon draft
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a0291a-1e87-7151-9934-fcbfe3f65eb1
This commit is contained in:
parent
14f789d080
commit
b7095bbabd
5 changed files with 346 additions and 25 deletions
18
SCOPE.md
18
SCOPE.md
|
|
@ -130,15 +130,17 @@ Their answers are binding on this repo and are recorded in the workplan.
|
|||
|
||||
## Current state (2026-08-22)
|
||||
|
||||
`ZONE-WP-0001` is active. T01 confirmed ownership, T02 partitioned the estate,
|
||||
and T04 selected reviewed declarations with enforcement-time expiry: **no
|
||||
zone-engine runtime is warranted**. The exception lifecycle is recorded in
|
||||
`docs/exception-lifecycle-2026-08-22.md`.
|
||||
`ZONE-WP-0001` is active. T01–T05 are complete: ownership is confirmed, the
|
||||
estate is partitioned, stance and failure mode are modelled, the exception
|
||||
lifecycle requires **no zone-engine runtime**, and the declaration/compiler
|
||||
contract is drafted. The integrated owner draft is
|
||||
`docs/security-zones_v0.1.md`.
|
||||
|
||||
T03 is waiting on a declaration-boundary ruling from `repo-manager` and
|
||||
`net-kingdom`. The current evidence has nine declared rapp workloads, but only
|
||||
one of ops-warden's 27 lanes can be joined to one; unknown membership is kept
|
||||
unknown rather than inferred. No API, storage, or wire schema has been shipped.
|
||||
Net-kingdom Decisions 5.6.1 and 5.6.2 settle the workload boundary. Operational
|
||||
execution units declare authoritative workload identity directly in
|
||||
`tenancy.yaml`; absence resolves to `unknown`, never inference. T06 is offering
|
||||
the draft for canon publication and T07 remains adoption. No API, storage, or
|
||||
wire schema has been shipped.
|
||||
|
||||
---
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue