diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index a9e8dae..09e89a9 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -804,9 +804,14 @@ "D-137 is the authority"** -- D-137 becomes the credential-lifecycle policy authority and the SEC-009 convention block demotes to a pointer (its founding history stays in the ledger as history); gates may then cite a D-number instead of an exposure register. - Sub-ruling 5 remains OPEN and the - entry stays PROPOSED until all five are ruled; nothing is built before that. - Research capture: `docs/audit/creds-creation-points-20260725.md`. + **SUB-RULING 5 RULED 2026-07-26: "Fold in as a D-137 invariant"** -- the invariant is + ONE IDENTITY SERVES ONE PRINCIPAL TYPE, enforced by the matrix `principal` column, so + the SEC-020 conflation becomes machine-detectable and needs no separate D-number. + **ALL FIVE SUB-RULINGS RULED -> D-137 is ADOPTED 2026-07-26 and implementation is + UNBLOCKED** (Status line in design-decisions.md is the authority). Expect the first + run to be RED by design: `admin` serves both a human and a service row, which is the + defect the invariant names. Research capture: + `docs/audit/creds-creation-points-20260725.md`. ## 9. Additional defect found while authoring (FIXED in sweep Batch 0.3, 2026-07-19 -- wrap-aware exclusion, GA-F15; history below) diff --git a/docs/changelog-20260725-maas-admin-recovery.md b/docs/changelog-20260725-maas-admin-recovery.md index e009043..28a3cd4 100644 --- a/docs/changelog-20260725-maas-admin-recovery.md +++ b/docs/changelog-20260725-maas-admin-recovery.md @@ -210,3 +210,33 @@ must consolidate `~/admin-openrc` BY HAND at mint time). **Revert:** delete the three rows, restore the G14 evidence cell, re-seed the ledger block to 16. + +## Item 11 -- D-137 ADOPTED: all five sub-rulings ruled (GA-R5), implementation unblocked + +**What:** the operator's follow-up ask ("better best practices method ... and a durable +rule so credentials aren't misplaced or lost") was designed, committee-reviewed, and +ruled. D-137 moves PROPOSED -> **ADOPTED 2026-07-26**. Five sub-rulings, each its own +operator exchange, each committed+pushed BEFORE the next was asked (GA-R5), verbatim +selections quoted in the Status block: (1) enforcement = "Blocking in preflight"; +(2) derivation = "Derive manifests from matrix"; (3) remote scope = "Declared locations +only"; (4) policy home = "D-137 is the authority"; (5) identity = "Fold in as a D-137 +invariant". Commits `a3a2d46`, `df8fa21`, `aa67634`, `db85531`, and this one. +**Why the design changed:** the operator identified the flaw in D-137-as-first-proposed -- +a discovery sweep can never detect a credential that was NEVER MINTED, because absence is +invisible to discovery. The known creation points support a forward EXPECTED-state +register, which is the only instrument that catches a missed mint. Research (3 read-only +agents) then produced four measured findings that validated it and one that qualified the +premise: `ssh-keygen` returns ZERO hits repo-wide, so **12 declared secrets have no mint +command anywhere** -- recorded in `docs/audit/creds-creation-points-20260725.md`, and the +reason `mint-ref` must admit an `operator-terminal` provenance kind. +**Committee (5 lenses)** produced three amendments now folded into the ruled design: +cardinality + host-role as first-class columns; manifests DERIVED not dual-maintained +(the GA-F06 mitigation); and a VALIDITY tier distinct from existence -- prompted by +finding that `creds-audit` parses provenance and NEVER verifies it, so the SEC-020 stale +trap is unchecked today. +**NOT done:** nothing built. No matrix file, no checker, no `--render`, no preflight `Pn`, +no SEC-009 demotion. Implementation is unblocked but unstarted. Note the first run of the +identity invariant is expected RED by design (`admin` serves both a human and a service +row -- that IS the defect). +**Revert:** flip the D-137 Status line back to PROPOSED and drop the five sub-ruling +blocks; restore CURRENT-STATE item 9 and the ledger open-decision count to 5. diff --git a/docs/design-decisions.md b/docs/design-decisions.md index 15e0858..3366e1c 100644 --- a/docs/design-decisions.md +++ b/docs/design-decisions.md @@ -4998,16 +4998,23 @@ `docs/audit/committee-20260724-track2-bundle-render.md`. -## D-137: PROPOSED -- credential mint-and-consolidate pipeline: make consolidation STRUCTURAL, not remembered [ARCH] +## D-137: ADOPTED -- credential mint-and-consolidate pipeline: make consolidation STRUCTURAL, not remembered [ARCH] -**Status:** PROPOSED 2026-07-25 (this session, repo HEAD `1155729`; operator asked for +**Status:** ADOPTED 2026-07-26 -- all five sub-rulings RULED individually (GA-R5), each +committed and pushed before the next was asked; implementation UNBLOCKED. Sub-ruling +selections, verbatim: (1) enforcement = "Blocking in preflight"; (2) derivation = "Derive +manifests from matrix (Recommended)"; (3) remote scope = "Declared locations only +(Recommended)"; (4) policy home = "D-137 is the authority (Recommended)"; (5) identity = +"Fold in as a D-137 invariant (Recommended)". Full question texts and consequences are in +the sub-ruling blocks below. Originally PROPOSED 2026-07-25 (repo HEAD `1155729`; operator asked for "a better best practices method for minting and saving these credentials going forward" and "a durable rule to make sure when accounts are created there is a consolidation that happens every time so credentials aren't misplaced or lost"). Supersedes nothing. Would make the SEC-009 standing convention a D-governed policy with a Roosevelt-transferable home. -**PARTIALLY RULED -- sub-rulings recorded individually (GA-R5, one exchange each). -The entry stays PROPOSED until all five forks are ruled; NOTHING is built before that.** +**ADOPTED 2026-07-26 -- all five sub-rulings RULED individually (GA-R5, one exchange +each), each committed and pushed before the next was asked. Implementation is UNBLOCKED. +The five sub-rulings and their verbatim operator selections are recorded below.** **Sub-ruling 1 (ENFORCEMENT STRENGTH) -- RULED 2026-07-25.** Question as presented: "D-137 ruling 1 of 5 -- enforcement strength. This decides whether the rule binds or @@ -5081,7 +5088,25 @@ control) and the enforcement description; that history stays in the ledger as history, while the RULE moves to D-137. -**Sub-ruling 5 OPEN** (whether the SEC-020 human/service identity conflation folds in). Design record, committee review and the measured findings +**Sub-ruling 5 (IDENTITY FOLD-IN) -- RULED 2026-07-26.** Question as presented: "D-137 +ruling 5 of 5 -- identity fold-in. SEC-020 found that `admin` is both the human GUI login +and the automation identity (its API key drives 19 call sites in 4 scripts). I split that +off to avoid batching rulings, but the matrix has a `principal` column, which would make +the conflation machine-detectable. Fold it in, or keep it separate?" Options presented: +fold in as a D-137 invariant / keep separate as its own D / fold in with detection +deferred. Operator selection, exact: **"Fold in as a D-137 invariant (Recommended)"**. +CONSEQUENCE: D-137 gains the invariant **one identity serves one principal type**, and the +matrix's `principal` column ENFORCES it -- a credential serving both `human` and `service` +is a FAIL, not an observation. The SEC-020 conflation is therefore machine-detectable, and +NO separate D-number is needed (the identity question that SEC-020 left "proposable but +unassigned" is hereby absorbed here). The `operator`/`admin` split performed 2026-07-25 is +the reference fix pattern. Note the invariant will FAIL on today's tree by design: `admin` +serves a human GUI row and a service API row simultaneously, which is the defect, and +`juju-vr1-dc0`/`-dc1` are superusers with unstored passwords (service-only by ruling) -- +those rows encode the intended end state, so the first run is expected to be red. + +**ALL FIVE SUB-RULINGS ARE NOW RULED. This entry moves from PROPOSED to ADOPTED and +implementation is unblocked** -- see the Status line above. Design record, committee review and the measured findings that shaped them: plan `whimsical-wandering-spindle`, capture `docs/audit/creds-creation-points-20260725.md`, rows SEC-021/-022/-023. diff --git a/docs/session-ledger.md b/docs/session-ledger.md index 4e65266..4875ce9 100644 --- a/docs/session-ledger.md +++ b/docs/session-ledger.md @@ -33,16 +33,15 @@ _Re-seeded from a 2026-07-25 scan (SEC-020 session; the prior seeding was the 2026-07-23 close and had gone stale on every line -- counts and next-free both). Re-run `bash scripts/ledger-scan.sh` to refresh._ -- **PROPOSED / OPEN decisions (5):** D-137 (credential mint-and-consolidate pipeline [ARCH] -- - PROPOSED 2026-07-25, operator-requested; 3 forks unruled: enforcement strength, --remote - discovery scope, policy home. NOT implemented), D-068 (Vault substrate hardening, Roosevelt -- sole remainder +- **PROPOSED / OPEN decisions (4):** D-068 (Vault substrate hardening, Roosevelt -- sole remainder is Q2 path selection at Roosevelt Vault design time), D-131 (node-facing DNS strategy for rack-only controllers [ARCH] -- PARTIALLY RULED: sub-1 ruled + delivered 2026-07-21, sub-2 ruled 2026-07-21 (metal-admin only), sub-3 resolved 2026-07-21 (no defect), sub-4 open + pinned DNS architectural review), D-132 (Roosevelt per-DC MAAS topology [ARCH] -- PROPOSED 2026-07-21, operator-pinned to the next deployment), D-136 (NetBox-coupled per-DC render pipeline for bundle overlays and tfvars [ARCH] -- PROPOSED 2026-07-25 in Chat, non-gating for the dc1 deploy). - D-071 and D-129 previously listed here are ADOPTED/RESOLVED and correctly drop off the scan. + D-071, D-129 and now D-137 (ADOPTED 2026-07-26, all five sub-rulings ruled) are + ADOPTED/RESOLVED and correctly drop off the scan. Status lines in `docs/design-decisions.md` are the only ruling authority. - **OPEN security rows:** 19 open per `bash scripts/ledger-scan.sh` (re-seeded 2026-07-25). Since the last seeding this went 12 -> 19: SEC-017 (caveman plugin supply-chain re-verify), SEC-018/-019 @@ -388,3 +387,25 @@ [ARCH]; 3 /root secrets unmoved. **GA-R4 F1: ledger 370 lines at OPEN vs 300 cap -- rotation OWED.** - Gauntlet 79 GREEN, repo-lint 0-fail, b2b0c80 pushed. Bookend EARLY (07-21 precedent); further work appends a POST-CLOSE ADDENDUM. Details: docs/changelog-20260725-maas-admin-recovery.md. + +## POST-CLOSE ADDENDUM 2026-07-26 -- D-137 ADOPTED (GA-R4; 07-18/07-21 addendum precedent) +- The 2026-07-25 close bookend landed early by design; this addendum records the work that + followed it rather than re-opening the entry. +- Operator asked for a better mint/save method + "a durable rule ... so credentials aren't + misplaced or lost". Committee review (5 lenses) run; the operator's own insight drove the + design: a discovery sweep can NEVER detect a credential that was never minted -- absence + is invisible to discovery -- so an expected-state credential MATRIX is the missing half. +- **D-137 ADOPTED 2026-07-26**, all five sub-rulings RULED individually (GA-R5, each pushed + before the next was asked): enforcement = blocking in preflight; manifests DERIVED from + the matrix; --remote bounded to declared locations; D-137 is the policy authority + (SEC-009 demotes to a pointer); identity conflation FOLDED IN as the one-identity-one- + principal invariant. Implementation UNBLOCKED, not started. +- Research: 3 read-only agents. Capture `docs/audit/creds-creation-points-20260725.md` -- + 55 MINT sites, and **12 declared secrets have NO mint command anywhere** (`ssh-keygen` + = ZERO hits repo-wide), plus three credential dirs outside the SEC-009 convention. +- **SEC-021/-022/-023 OPENED** (rows 16 -> 19): a consolidated dc0 credential ABSENT from + its recorded location; two UNAUDITED shadow *-creds/ stores on the headend; sprawl-glob + blind spots incl. a PREDICTED Stage-5 admin-openrc exposure. All logged-not-actioned. +- NEXT: build per the approved plan (matrix + checker + --render + preflight Pn + SEC-009 + demotion), first run expected RED by design. Plan: whimsical-wandering-spindle. +- Status ONLY in CURRENT-STATE.md. Detail: docs/changelog-20260725-maas-admin-recovery.md.