D-137 ruling 4 EXECUTED: SEC-009 demoted to a pointer, policy moves to D-137
Ruling 4 was already RULED and its stated trigger (tier 2 built) had passed,
so this is execution, not a decision.

The standing consolidation rule moved from docs/security-ledger.md into
D-137, restated as six numbered points and updated to D-137's own mechanisms
(matrix is the register; manifests are DERIVED; discovery bounded by
vm-secret-locations; one identity one principal; enforcement is blocking P5).
The ledger keeps a pointer and returns to being purely an exposure/rotation
register -- which is what lets a gate cite a D-number instead of a SEC row.

Kept as history: SEC-009's founding addendum (the NetBox token that lived
only on the VM and went un-consolidated until needed). That miss established
the convention, and history is what the register is for.

Carried forward WITH CORRECTIONS: the moved text's "11 entries", "7/7", and
its description of manifests as hand-declared were all stale and are not
reproduced.

Callers repointed in the same commit, because a demotion that leaves callers
citing the moved text is not done:
- dc-dc-phase3-maas-enlist-deploy.md:491 is the ONLY credential DoD in any
  runbook and it told operators to hand-edit creds-manifests/$DC.manifest --
  a GENERATED artifact under sub-ruling 2. The live runbook was teaching the
  anti-pattern. It now directs a matrix row plus a locations row, and its
  close-out requires both creds-audit CLEAN and no new creds-matrix finding
  class for that DC.
- docs/vr1-office1-as-built.md restated the convention; now a pointer.

Gauntlet ALL GREEN (80), repo-lint 0-fail.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
1 parent 71e0551 commit f0289e694c83a9d0b0533a3ec17ffeb550443a70
@JANeumatrix JANeumatrix authored 31 minutes ago
Showing 6 changed files
View
docs/CURRENT-STATE.md
View
docs/changelog-20260726-d137-tier1.md
View
docs/design-decisions.md
View
docs/security-ledger.md
View
docs/vr1-office1-as-built.md
View
runbooks/dc-dc-phase3-maas-enlist-deploy.md