secrev/Plane-1: Phase 0 shared substrate + compliance-drift checker #14
No reviewers
Labels
No labels
app
bug
ci
compliance
content
dependencies
docs
documentation
duplicate
enhancement
github_actions
good first issue
help wanted
infra
invalid
javascript
needs-triage
python
question
tests
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/orchestrator#14
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "feature/agent-team-plane1-phase0"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What
Plane-1 foundation, built by a canary-gated workflow (extract → prove secrev unchanged → checker → review).
Phase 0 — shared sweep substrate (the foundation both planes' scheduled side reuses)
security-review/lib/sweep_substrate.sh(new): discovery / mirror / budget-ledger / rotation / Slack-ALARM+redaction / canary as sourceable bash functions.nightly_sweep.sh(415→362): now sources the substrate instead of inline copies.-xclean, offline two-tier dry-run byte-identical before/after (two scenarios), token discipline preserved (read-only PAT, REST-only, noghCLI, origin scrubbed),review.shuntouched. Revert point:73e35f3.Phase 1 — compliance-drift checker (Tier-1, read-only, ALARM-only)
security-review/checkers/compliance-drift.sh+ planted-drift fixtures..envsecrets, branch protection, merge settings. Handbook exceptions (docs-only, compliance-exempt) honored. Mode-600 reports, ALARM-only (clean = silent). Canary asserts the 6 planted drifts.Review (workflow)
2 dimensions (secrev-intact + checker-quality) → proof-or-kill verifier. No BLOCK. The secrev-intact pass was clean. 2 checker findings, both fixed (false-alarm hygiene, per
feedback_cloudwatch_alarms):404is drift; a transient/forbidden API failure is skipped with no alarm (the-f+-widiom was misreading real 404s as skips).secrets-committedfires only on secret-shaped values (secret-ish key name or ≥20-char value), not benign config likePORT=3000.Not in this PR (gated / later)
lib/+checkers/to the R720, a live org-discovery dry-run (needsGH_TOKEN), and wiringcompliance-driftinto the systemd schedule — all deploy-gated.Note
The
checkers/fixtures/intentionally contain fake secret-shaped strings (planted test data) so the checker can be smoke-tested offline; they are not real credentials.