|
close-out sweep: capture what existed only in the session transcript
Operator-requested final sweep before clearing. Two classes of content lived only in the transcript and are now durable in docs/audit/queued-findings-20260726.txt. PART A -- the secrets-storage advice. Checked FIRST what the repo already carries, and most of it was already there: OpenBao/BUSL/the fork question and auto-unseal are in docs/D-068-vault-1.8-vs-1.16-analysis.md, and creds-mint.sh is specified in detail in D-137 item 2(a). Only three items were genuinely unrecorded: Tang/Clevis as the no-HSM unseal mechanism; MAAS 3.7's Vault integration measured `status: disabled` together with the MAAS/Vault circular dependency that must be designed around on bare metal; and a Vault SSH CA to retire the static keypairs. The capture is framed so a future session does not re-propose what is already ruled -- re-proposing settled decisions is this project's measured failure mode. PART B -- ten committee findings acknowledged but deliberately not acted on. Most consequential: mint-ref line pins rot SILENTLY (S4 checks existence and EOF, never content, so every pin becomes wrong-but-passing when the runbooks are rewritten for Roosevelt), and ruling-5 remediation is indistinguishable from ruling-5 evasion to S6. cardinality (B6) needs an operator ruling. PART C -- items deferred by ruling, recorded so a later reader does not mistake them for oversights. Also repaired a dangling sentence fragment in CURRENT-STATE left by an earlier edit this session, and noted the repair rather than making it silently. Gauntlet ALL GREEN (81), repo-lint 0-fail. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf |
|---|
|
|
| docs/CURRENT-STATE.md |
|---|
| docs/audit/queued-findings-20260726.txt 0 → 100644 |
|---|