Skip to content

docs(gaps): GT-588 criterion 1 — the wire was complete, the switch was missing - #386

Merged
beyondnetPeru merged 1 commit into
developfrom
docs/gt-588-operable
Aug 2, 2026
Merged

docs(gaps): GT-588 criterion 1 — the wire was complete, the switch was missing#386
beyondnetPeru merged 1 commit into
developfrom
docs/gt-588-operable

Conversation

@beyondnetPeru

Copy link
Copy Markdown
Contributor

Records what evolith_tracker#111 changed, and what it deliberately did not.

The wire had shipped: a decorator over IAuditEntryRepository, Merkle, COSE_Sign1, an Ed25519 signer, a JSONL ledger, cross-language interop in CI. And nothing was signed anywhere, for a reason that was not in the code — Transparency appeared in no values.yaml, no configmap and no deployment. An operator holding real keys could only invent a --set over a key that does not exist, which Helm accepts in silence and which enables nothing.

It is now declared and off, with both Ed25519 seeds read from an existing Secret, the ledger on a PVC whose absence fails the render, and the operator procedure written down.

Criterion 1 stays unticked. No environment enables it, and doing so needs two distinct seeds in a secret store plus a persistent volume — key custody is an owner decision, not a code change. This went from impossible without touching code to a deployment decision, which is progress worth recording and not a closure.

🤖 Generated with Claude Code

…s missing

Measured again today. The Tracker side had shipped: a decorator over
IAuditEntryRepository, Merkle, COSE_Sign1, an Ed25519 signer, a JSONL ledger and
cross-language interop in CI. And nothing was signed anywhere, for a reason that
was not in the code — Transparency appeared in no values.yaml, no configmap and
no deployment, so an operator holding real keys could only invent a --set over a
key that does not exist, which Helm accepts in silence and which enables nothing.

tracker#111 makes it operable: declared and OFF, both seeds from an existing
Secret, the ledger on a PVC whose absence fails the render, and an operator
procedure in the chart README.

The criterion stays UNTICKED on purpose. No environment enables it, and doing so
needs key custody, which is an owner decision. The honest state is that this went
from impossible without touching code to a deployment decision — progress worth
recording, not a closure.
@beyondnetPeru
beyondnetPeru requested a review from a team as a code owner August 2, 2026 14:51
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown

📊 Bilingual Coverage Impact

PR Changes

  • Paired EN/ES files modified: 4
  • New EN files needing ES translation: 0

Repository Coverage

Metric Value
Total EN files 526
Total ES files 500
Paired files 0
Coverage 0%

Good: All EN changes have ES counterparts.


Generated by GitHub Actions

@beyondnetPeru
beyondnetPeru merged commit 45cd66f into develop Aug 2, 2026
32 checks passed
@beyondnetPeru
beyondnetPeru deleted the docs/gt-588-operable branch August 2, 2026 14:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant