Commit graph

3 commits

Author SHA1 Message Date
Adam Moussa
17ef4de415
feat(security-review): schedule the Plane-1 checker coordinator nightly + role-skip (#36)
- checker_coordinator.sh: add COORDINATOR_SKIP_ROLES env (comma-separated) to drop
  roles whose credentials are not provisioned from the registry entirely (never
  canaried/run/ALARMed). Fail-safe: empty/unset = run all.
- systemd: sea-haven-checkers.{service,timer} run the coordinator nightly at ~03:30
  UTC (90 min after the secrev sweep so they don't contend on $MIRROR_DIR / the
  Claude pool). The unit sets COORDINATOR_SKIP_ROLES=aws-posture,confluence-doc
  (aws-posture needs IAM Roles Anywhere; confluence-doc needs the confluence-bot
  token — both intentionally unprovisioned).

Deployed + enabled on the box (deploy-before-merge): canary 4/4 with the skip,
timer scheduled for 2026-06-23 03:35 UTC.
2026-06-22 19:05:02 -04:00
Adam Moussa
95e481890a
feat(secrev): wire full Plane-1 roster into checker coordinator + fix fixture SAM (#22)
* feat(secrev): wire full Plane-1 roster into the checker coordinator registry

Register doc-drift, aws-posture, plan-groomer, confluence-doc (weekly cadence)
alongside compliance-drift + dependency-cve (nightly). The coordinator canary
suite now runs all 6 roles' canaries (all PASS) under the one shared budget +
versioned rotation/coverage state; --squeeze-dry-run still proves defer-not-drop
+ COVERAGE alarm. Central integration after the parallel Phase-3/4 PRs landed.

* fix(secrev): valid SAM in doc-drift fixture templates (cfn-lint E0001)

The doc-drift sample-stack fixtures declared AWS::Serverless::Function with no
Properties; cfn-lint's SAM transform errored (HIGH). Added minimal valid
Properties (Handler/Runtime/InlineCode). Pre-existing on main — #19 pushed with
--no-verify (xargs overflow) and CI runs no cfn-lint, so it slipped through.
doc-drift still detects the stack (keys on template presence).
2026-06-18 16:31:03 -04:00
Adam Moussa
f09c94a821
feat(secrev): Plane-1 Phase 2 — coordinator + dependency-cve checker (#16)
* fix(agent-team): read SLACK_CHANNEL_ID, aligning code with deploy doc + systemd

run-team.py read os.environ['SLACK_CHANNEL'] while DEPLOY-R720.md and the
coordinator systemd unit both document SLACK_CHANNEL_ID; the mismatch would
silently default the live Slack transport channel to empty. Standardize on
SLACK_CHANNEL_ID (decision locked 2026-06-18).

* feat(secrev): dependency-cve Plane-1 Tier-1 checker (OSV, ALARM-only)

Read-only checker on the Phase-0 substrate: scans $MIRROR_DIR mirrors for
pinned deps (requirements/poetry/Pipfile/package-lock/yarn/csproj across
PyPI/npm/NuGet), cross-refs OSV querybatch (live) or an offline advisory
fixture (canary). Mode-600 reports, ALARM-only, --canary asserts 2 planted
vulns (jinja2 2.11.2, lodash 4.17.15). Complements Dependabot. Not provisioned.

* feat(secrev): Plane-1 checker coordinator (shared budget, rotation, dedup)

Coordinator (design §5/§6.7) orchestrating Tier-1 checkers under one shared
budget ledger + versioned rotation/coverage state (atomic write + schema/hash/
logical-consistency integrity, park-on-corrupt). Canary-suite-first
(COMPLACENCY skip), fan-out under the shared cap with defer-not-drop, COVERAGE
alarm past MAX_CYCLE_NIGHTS, cross-checker dedup/prioritize, ALARM-only routing.
--squeeze-dry-run proves deferral-not-drop + COVERAGE alarm. Not provisioned.

* fix(secrev): hide dependency-cve canary manifests from dependency-review

The canary fixtures intentionally pin known-vulnerable deps (jinja2 2.11.2,
lodash 4.17.15) so the checker has something to detect. GitHub's dependency
graph parsed those fixture manifests as real project deps, failing the
dependency-review PR gate (fail-on-severity: high). Store the manifests with a
.fixture suffix so the dependency graph ignores them; the --canary materializer
strips the suffix in its temp work area before scanning, so detection is
unchanged (still 2/2). No advisory allowlist, no change to the shared org
reusable workflow — the real gate stays strict for actual deps.
2026-06-18 15:08:58 -04:00