permissions: 12 read-only allow rules for the per-DC MAAS/PKI checkers
Scanned 50 recent transcripts. Most high-frequency read-only commands were
already covered (repo-lint, ledger-scan, run-tests-all, tests/*, preflight,
opentofu-validate, tofu validate/state list). These twelve were not.

Every rule is pinned to a read-only SUBCOMMAND -- check/verify/assert/plan/
--list -- so apply, reserve, reissue and --run stay gated. Nothing that mutates
the cloud was added, and no interpreter or ssh wildcard.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
1 parent d870d76 commit 6f6b97bea949f3ee73950667453a950d04d50978
@JANeumatrix JANeumatrix authored 18 hours ago
Showing 1 changed file
View
.claude/settings.json