|
D-137 sub-ruling 3 RULED (GA-R5): remote discovery = declared locations only
Question as presented: "D-137 ruling 3 of 5 -- remote discovery scope ... The tension is tenant isolation on a commercial multi-tenant cloud." Operator selection, exact: "Declared locations only (Recommended)". Dated 2026-07-26 -- this session crossed the date boundary; sub-rulings 1-2 were pushed 2026-07-25. A declared list (creds-manifests/vm-secret-locations, <host-role> <path>) bounds --remote absolutely; it never walks outside the list. No tenant surface touched, D-069 custody boundary and hard-isolation posture preserved, fast on a live region. Records a faithful-implementation note (NOT an override): the list must be populated with everything already known to hold credential material or the ruling leaves measured defects uncovered -- per-site creds folders on the headend as well as the jumphost (SEC-022 shadow stores), the region secrets dir (SEC-020), and the three directories outside the SEC-009 convention found by the creation-point inventory. Accepted residual: a secret minted at an undeclared location stays invisible, so adding a row is part of DoD for any new mint site. D-137 stays PROPOSED; sub-rulings 4-5 OPEN; nothing built until all five. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf |
|---|
|
|
| docs/CURRENT-STATE.md |
|---|
| docs/design-decisions.md |
|---|