|
D-137 ruling 4 EXECUTED: SEC-009 demoted to a pointer, policy moves to D-137
Ruling 4 was already RULED and its stated trigger (tier 2 built) had passed, so this is execution, not a decision. The standing consolidation rule moved from docs/security-ledger.md into D-137, restated as six numbered points and updated to D-137's own mechanisms (matrix is the register; manifests are DERIVED; discovery bounded by vm-secret-locations; one identity one principal; enforcement is blocking P5). The ledger keeps a pointer and returns to being purely an exposure/rotation register -- which is what lets a gate cite a D-number instead of a SEC row. Kept as history: SEC-009's founding addendum (the NetBox token that lived only on the VM and went un-consolidated until needed). That miss established the convention, and history is what the register is for. Carried forward WITH CORRECTIONS: the moved text's "11 entries", "7/7", and its description of manifests as hand-declared were all stale and are not reproduced. Callers repointed in the same commit, because a demotion that leaves callers citing the moved text is not done: - dc-dc-phase3-maas-enlist-deploy.md:491 is the ONLY credential DoD in any runbook and it told operators to hand-edit creds-manifests/$DC.manifest -- a GENERATED artifact under sub-ruling 2. The live runbook was teaching the anti-pattern. It now directs a matrix row plus a locations row, and its close-out requires both creds-audit CLEAN and no new creds-matrix finding class for that DC. - docs/vr1-office1-as-built.md restated the convention; now a pointer. Gauntlet ALL GREEN (80), repo-lint 0-fail. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf |
|---|
|
|
| docs/CURRENT-STATE.md |
|---|
| docs/changelog-20260726-d137-tier1.md |
|---|
| docs/design-decisions.md |
|---|
| docs/security-ledger.md |
|---|
| docs/vr1-office1-as-built.md |
|---|
| runbooks/dc-dc-phase3-maas-enlist-deploy.md |
|---|