feat(web): add IwoooS host evidence readiness
This commit is contained in:
@@ -43,6 +43,7 @@ IwoooS 首版只讀取或對齊以下已提交 evidence:
|
||||
11. 7 個 owner evidence readiness items。
|
||||
12. 3 個只讀主機覆蓋 items:Kali 112、開發主機 168、開發主機 111。
|
||||
13. 6 個主機動作 gate items:active scan、credentialed scan、Kali `/execute`、SSH / host change、Kali update、runtime blocking control。
|
||||
14. 7 個主機 evidence readiness items:scope boundary、owner decision、credential handling、maintenance window、rollback plan、validation metrics、redacted ingestion。
|
||||
|
||||
## 3.1 既有前端資安頁面整合
|
||||
|
||||
@@ -140,6 +141,22 @@ S2.15 將主機相關高風險動作拆成只讀 gate matrix,避免「主機
|
||||
|
||||
每個 item 都固定 `display_mode=gate_only`,且 `active_scan_authorized=false`、`credentialed_scan_authorized=false`、`ssh_change_authorized=false`、`host_update_authorized=false`、`runtime_execution_authorized=false`、`action_buttons_allowed=false`、`not_authorization=true`。
|
||||
|
||||
## 3.7 主機 Evidence Readiness
|
||||
|
||||
S2.16 將主機動作解鎖前需要的 evidence 顯示成只讀 readiness board。這一層只回答「要進下一步前缺什麼」,不代表任何 evidence 已收到或已接受。
|
||||
|
||||
| 順序 | Evidence item | 目前狀態 | 影響範圍 |
|
||||
|------|---------------|----------|----------|
|
||||
| 1 | Scope boundary | waiting redacted scope approval;received=0、accepted=0 | 112、168、111 的目標、排除範圍、深度與速率 |
|
||||
| 2 | Owner decision record | waiting human decision record;received=0、accepted=0 | 人控決策,不可由可見狀態替代 |
|
||||
| 3 | Credential handling | credential material collection forbidden;received=0、accepted=0 | credentialed scan 前的憑證來源、保存邊界、遮蔽與拒收規則 |
|
||||
| 4 | Maintenance window | waiting maintenance window;received=0、accepted=0 | Kali update、SSH / host change 與主機調校窗口 |
|
||||
| 5 | Rollback plan | waiting rollback plan;received=0、accepted=0 | 套件、設定、服務、工具鏈版本回復 |
|
||||
| 6 | Validation metrics | waiting post-check metrics;received=0、accepted=0 | 掃描器、監控、服務與使用者流程 post-check |
|
||||
| 7 | Redacted ingestion | waiting redacted payload acceptance;received=0、accepted=0 | finding / scan result 只能以脫敏摘要進 mirror |
|
||||
|
||||
每個 item 都固定 `display_mode=evidence_readiness_only`,且 `active_scan_authorized=false`、`credentialed_scan_authorized=false`、`ssh_change_authorized=false`、`host_update_authorized=false`、`runtime_execution_authorized=false`、`action_buttons_allowed=false`、`not_authorization=true`。
|
||||
|
||||
## 4. 仍禁止
|
||||
|
||||
IwoooS 不得提供下列輸出:
|
||||
@@ -151,7 +168,8 @@ IwoooS 不得提供下列輸出:
|
||||
5. production deploy 或 runtime enforcement。
|
||||
6. SSH 到主機、開 SSH session、更新 Kali、package upgrade、credentialed scan 或 active scan。
|
||||
7. 套用 runtime blocking control。
|
||||
8. 把 58% progress、contract count、mirror readiness 或前端可見狀態當成授權。
|
||||
8. 將主機 evidence 標記為 received / accepted,或匯入 raw host evidence。
|
||||
9. 把 58% progress、contract count、mirror readiness 或前端可見狀態當成授權。
|
||||
|
||||
## 5. 驗證
|
||||
|
||||
|
||||
@@ -35,7 +35,7 @@
|
||||
| Owner response validation | S4.13 已建立;四包 owner response 目前 received/accepted 皆為 0;4 條 missing response lanes、4 步 collection order、next collection candidate、6 條 evidence routing rules、8 個 display sections、7 條 state transition rules、9 個 reviewer checklist items、7 條 reviewer outcome lanes、4 個 reviewer audit event templates、5 個 reviewer audit display sections、6 個 reviewer audit collection checks、5 個 reviewer audit redaction examples、5 條 reviewer audit retention rules、6 個 reviewer audit retention checks、6 個 reviewer audit handoff packets、6 個 reviewer audit handoff checks、6 個 parallel session sync checks、6 條 parallel session conflict lanes、6 個 parallel session recovery checks 與 7 條 parallel session recovery outcome lanes 可供 AwoooP 直接顯示;下一個建議收件為 S4.9 Gitea owner attestation;latest local validation 為 `SOURCE_CONTROL_OWNER_RESPONSE_GUARD_OK`,reviewer audit emitted 仍為 0,不代表 owner response 已收到或任何執行授權 |
|
||||
| Low-friction rollout policy | S1.3 已補 7 條 non-blocking escalation lanes;LOW / MEDIUM、缺 owner response、partial mirror、source-control drift、Kali observe finding、workflow / secret name gap 與 headline holding 初期只能 observe / warn;`owner_review_required_before_blocking=true`、`runtime_blocking_allowed=false` |
|
||||
| IwoooS frontend posture | S2.8 已新增 `/iwooos` read-only Information Security 入口;顯示 Security Posture / Exposure、source-control supply chain、Kali 112 Mesh、approval boundary、non-blocking lanes 與 evidence refs;不新增執行按鈕 |
|
||||
| IwoooS posture projection | S2.9 已新增 `iwooos_posture_projection_v1`;S2.10 已把 10 個既有前端資安相關頁面納入 projection;S2.11 已補 4 個 coverage groups 與 5 個 conflict controls;S2.12 已補 6 個只讀 operator journey steps;S2.13 已補 7 個 owner evidence readiness items;S2.14 已補 3 個 host coverage items:Kali 112、開發主機 168、開發主機 111;S2.15 已補 6 個 host action gate items;仍不新增 action button |
|
||||
| IwoooS posture projection | S2.9 已新增 `iwooos_posture_projection_v1`;S2.10 已把 10 個既有前端資安相關頁面納入 projection;S2.11 已補 4 個 coverage groups 與 5 個 conflict controls;S2.12 已補 6 個只讀 operator journey steps;S2.13 已補 7 個 owner evidence readiness items;S2.14 已補 3 個 host coverage items:Kali 112、開發主機 168、開發主機 111;S2.15 已補 6 個 host action gate items;S2.16 已補 7 個 host evidence readiness items;仍不新增 action button |
|
||||
| Dry-run | `contract_defined_not_executed`;已納入 `CHECK_PROGRESS_GUARD` 與 `CHECK_OWNER_RESPONSE_GUARD`,latest local validation 為 `repo_snapshot_guard_pass`,仍不代表 production ingestion |
|
||||
| Runtime actions | `false` |
|
||||
| Payload ingestion | `false` |
|
||||
@@ -99,6 +99,7 @@
|
||||
| S2.13 IwoooS owner evidence readiness board | framework detail | 0 | 只顯示 headline 進度下一步需要的 owner evidence / approval gate,received / accepted 仍為 0,不代表 owner response received、approval、runtime gate、Kali scan 或 GitHub primary 授權 |
|
||||
| S2.14 IwoooS host coverage view | framework detail | 0 | 只顯示 Kali 112 與 168 / 111 開發主機已納入 observe-only 資安視野,不代表 active scan、SSH 變更、主機更新、credentialed scan、runtime gate 或 Kali `/execute` 授權 |
|
||||
| S2.15 IwoooS host action gate matrix | framework detail | 0 | 只把 active scan、credentialed scan、Kali `/execute`、SSH / host change、Kali update 與 runtime blocking control 拆成只讀 gate,不代表任何主機動作或 runtime enforcement 已批准 |
|
||||
| S2.16 IwoooS host evidence readiness board | framework detail | 0 | 只顯示主機動作前仍缺 scope、owner decision、credential handling、maintenance window、rollback、validation metrics 與 redacted ingestion evidence;received / accepted 仍為 0,不代表任何主機動作已批准 |
|
||||
|
||||
headline 進度要再往上,至少需要下列任一高層 gate 有實質 evidence:
|
||||
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
|------|------|
|
||||
| 日期 | 2026-05-17 |
|
||||
| 狀態 | S0/S1 read-only evidence 建置中 |
|
||||
| 本階段完成 | 資安供應鏈 contract manifest + Source Control Approval Board + Draft Reconcile Plan + Ref Detail Diff + Ref Truth Classification + Source Control Ref Truth Owner Response 收件包 + GitHub Primary Readiness Gate + GitHub Primary Rollback ADR + GitHub Target Owner Decision Response 收件包 + Gitea 認證清冊匯出請求 + Gitea 認證清冊匯入驗收契約 + Gitea 清冊覆蓋 Owner Attestation + Gitea Owner Attestation Approval Lane 對齊 + Gitea Owner Attestation Response 收件包 + Workflow / Secret Name Inventory + Workflow / Secret Name Local Evidence + Workflow / Secret Name Redacted Export Request + Workflow / Secret Name Owner Response 收件包 + Source Control Owner Response Validation Rollup + Kali 112 live integration status + Security Finding contract + Kali scan scope approval package + Security Approval Queue + S3 人工批准 Gate + S3 人工決策紀錄 + S3 人工審查封包 + S3 人工決策狀態轉移 + S3 後續 runtime gate 準備契約 + 鏡像 readiness index + 鏡像接收計畫 + 鏡像事件信封 + 鏡像路由矩陣 + 鏡像驗收契約 + 鏡像隔離契約 + 鏡像 dry-run 報告契約 + 鏡像狀態彙整契約 + IwoooS 前端態勢入口 + IwoooS posture projection contract + IwoooS 既有前端資安頁面整合 + IwoooS 覆蓋與邊界矩陣 + IwoooS 只讀資安處理旅程 + IwoooS owner evidence readiness board + IwoooS host coverage view + IwoooS host action gate matrix |
|
||||
| 本階段完成 | 資安供應鏈 contract manifest + Source Control Approval Board + Draft Reconcile Plan + Ref Detail Diff + Ref Truth Classification + Source Control Ref Truth Owner Response 收件包 + GitHub Primary Readiness Gate + GitHub Primary Rollback ADR + GitHub Target Owner Decision Response 收件包 + Gitea 認證清冊匯出請求 + Gitea 認證清冊匯入驗收契約 + Gitea 清冊覆蓋 Owner Attestation + Gitea Owner Attestation Approval Lane 對齊 + Gitea Owner Attestation Response 收件包 + Workflow / Secret Name Inventory + Workflow / Secret Name Local Evidence + Workflow / Secret Name Redacted Export Request + Workflow / Secret Name Owner Response 收件包 + Source Control Owner Response Validation Rollup + Kali 112 live integration status + Security Finding contract + Kali scan scope approval package + Security Approval Queue + S3 人工批准 Gate + S3 人工決策紀錄 + S3 人工審查封包 + S3 人工決策狀態轉移 + S3 後續 runtime gate 準備契約 + 鏡像 readiness index + 鏡像接收計畫 + 鏡像事件信封 + 鏡像路由矩陣 + 鏡像驗收契約 + 鏡像隔離契約 + 鏡像 dry-run 報告契約 + 鏡像狀態彙整契約 + IwoooS 前端態勢入口 + IwoooS posture projection contract + IwoooS 既有前端資安頁面整合 + IwoooS 覆蓋與邊界矩陣 + IwoooS 只讀資安處理旅程 + IwoooS owner evidence readiness board + IwoooS host coverage view + IwoooS host action gate matrix + IwoooS host evidence readiness board |
|
||||
| 原則 | 低摩擦分階段;文件、schema、read-only evidence 優先;不做 runtime enforcement、不切 primary |
|
||||
|
||||
## 0. 本階段完成後整體進度
|
||||
@@ -75,6 +75,7 @@ python3 scripts/security/security-mirror-progress-guard.py
|
||||
| S2.13 IwoooS owner evidence readiness board | 已完成草案,將 S4.9 / S4.10 / S4.11 / S4.12 owner response、redacted finding ingestion、Kali scan scope、follow-up runtime gate 固定為 7 個只讀 readiness items | 0 |
|
||||
| S2.14 IwoooS host coverage view | 已完成草案,將 Kali 112、開發主機 168、開發主機 111 固定為 3 個只讀 host coverage items;active scan、SSH 變更、主機更新、credentialed scan 與 runtime control 仍未批准 | 0 |
|
||||
| S2.15 IwoooS host action gate matrix | 已完成草案,將 active scan、credentialed scan、Kali `/execute`、SSH / host change、Kali update、runtime blocking control 固定為 6 個只讀 gate items | 0 |
|
||||
| S2.16 IwoooS host evidence readiness board | 已完成草案,將 scope boundary、owner decision、credential handling、maintenance window、rollback plan、validation metrics、redacted ingestion 固定為 7 個只讀 readiness items | 0 |
|
||||
|
||||
headline 要再往上,需要 S4.9 / S4.10 / S4.11 / S4.12 任一 owner response 收到並通過脫敏驗收,或人工批准後出現 active runtime gate、redacted payload ingestion、GitHub primary readiness 這類落地 evidence。
|
||||
|
||||
@@ -109,6 +110,7 @@ headline 要再往上,需要 S4.9 / S4.10 / S4.11 / S4.12 任一 owner respons
|
||||
| S2.13 IwoooS Owner Evidence Readiness | 完成草案 | `/iwooos` 新增 owner evidence readiness board,顯示下一步真正影響 headline progress 的 7 個 evidence / gate 缺口 | 使用者能理解為什麼 58% 不應灌水提高;全部 received / accepted 仍為 0,不新增執行控制 |
|
||||
| S2.14 IwoooS Host Coverage View | 完成草案 | `/iwooos` 新增主機覆蓋視圖,明確顯示 Kali 112 與 168 / 111 兩台開發主機已納入 observe-only 資安視野 | 使用者能看到指定主機已納管到資安架構視圖;仍不新增 SSH、scan、update、execute、credentialed scan 或 blocking control |
|
||||
| S2.15 IwoooS Host Action Gate Matrix | 完成草案 | `/iwooos` 新增主機動作 gate 矩陣,將 active scan、credentialed scan、Kali `/execute`、SSH / host change、Kali update 與 runtime blocking control 拆成只讀 gate | 使用者能看懂主機動作為什麼仍需人工批准;仍不新增任何主機操作或 runtime enforcement |
|
||||
| S2.16 IwoooS Host Evidence Readiness | 完成草案 | `/iwooos` 新增主機 evidence readiness board,顯示主機動作前仍缺 scope、owner decision、credential handling、maintenance window、rollback、validation metrics 與 redacted ingestion evidence | 使用者能看懂主機行動前置證據,不會把規劃誤認為已批准;仍不新增任何主機操作 |
|
||||
| S3 approval gate | 進行中 | `security_approval_gate_v1` 已建立 8 個人工 gate items:7 pending、1 block candidate、0 approved | 不得繞過人工批准;批准後仍需 follow-up runtime gate |
|
||||
| S3.0 人工批准 Gate 契約 | 完成草案 | 定義批准範圍、決策選項、required reviewers、still forbidden 與 follow-up runtime gate | AwoooP 可記錄決策,不可執行 gate item |
|
||||
| S3.1 人工決策紀錄契約 | 完成草案 | `security_approval_decision_record_v1` 已建立;目前 0 筆 decision records、0 個 runtime action 授權 | AwoooP 可稽核決策,不可把決策當執行 |
|
||||
|
||||
@@ -41,7 +41,8 @@
|
||||
"operator_journey_step_count": 6,
|
||||
"owner_evidence_readiness_item_count": 7,
|
||||
"host_coverage_item_count": 3,
|
||||
"host_action_gate_item_count": 6
|
||||
"host_action_gate_item_count": 6,
|
||||
"host_evidence_readiness_item_count": 7
|
||||
},
|
||||
"progress": {
|
||||
"overall_percent": 58,
|
||||
@@ -117,6 +118,7 @@
|
||||
"display_owner_evidence_readiness_board",
|
||||
"display_host_coverage_view",
|
||||
"display_host_action_gate_matrix",
|
||||
"display_host_evidence_readiness_board",
|
||||
"display_evidence_refs",
|
||||
"display_next_gate",
|
||||
"display_forbidden_actions"
|
||||
@@ -140,6 +142,9 @@
|
||||
"auto_update_host",
|
||||
"run_host_package_upgrade",
|
||||
"apply_runtime_blocking_control",
|
||||
"mark_host_evidence_received",
|
||||
"mark_host_evidence_accepted",
|
||||
"ingest_raw_host_evidence",
|
||||
"production_deploy",
|
||||
"treat_progress_as_authorization"
|
||||
],
|
||||
@@ -766,5 +771,154 @@
|
||||
"action_buttons_allowed": false,
|
||||
"not_authorization": true
|
||||
}
|
||||
],
|
||||
"host_evidence_readiness_items": [
|
||||
{
|
||||
"item_id": "host_scope_boundary_evidence",
|
||||
"display_order": 1,
|
||||
"related_hosts": [
|
||||
"192.168.0.112",
|
||||
"192.168.0.168",
|
||||
"192.168.0.111"
|
||||
],
|
||||
"required_gate": "kali_scan_scope_approval_v1",
|
||||
"evidence_state": "waiting_redacted_scope_approval",
|
||||
"received_count": 0,
|
||||
"accepted_count": 0,
|
||||
"display_mode": "evidence_readiness_only",
|
||||
"active_scan_authorized": false,
|
||||
"credentialed_scan_authorized": false,
|
||||
"ssh_change_authorized": false,
|
||||
"host_update_authorized": false,
|
||||
"runtime_execution_authorized": false,
|
||||
"action_buttons_allowed": false,
|
||||
"not_authorization": true
|
||||
},
|
||||
{
|
||||
"item_id": "host_owner_decision_record_evidence",
|
||||
"display_order": 2,
|
||||
"related_hosts": [
|
||||
"192.168.0.112",
|
||||
"192.168.0.168",
|
||||
"192.168.0.111"
|
||||
],
|
||||
"required_gate": "security_approval_decision_record_v1",
|
||||
"evidence_state": "waiting_human_decision_record",
|
||||
"received_count": 0,
|
||||
"accepted_count": 0,
|
||||
"display_mode": "evidence_readiness_only",
|
||||
"active_scan_authorized": false,
|
||||
"credentialed_scan_authorized": false,
|
||||
"ssh_change_authorized": false,
|
||||
"host_update_authorized": false,
|
||||
"runtime_execution_authorized": false,
|
||||
"action_buttons_allowed": false,
|
||||
"not_authorization": true
|
||||
},
|
||||
{
|
||||
"item_id": "host_credential_handling_evidence",
|
||||
"display_order": 3,
|
||||
"related_hosts": [
|
||||
"192.168.0.112",
|
||||
"192.168.0.168",
|
||||
"192.168.0.111"
|
||||
],
|
||||
"required_gate": "credential_handling_review_before_credentialed_scan",
|
||||
"evidence_state": "credential_material_collection_forbidden_waiting_policy",
|
||||
"received_count": 0,
|
||||
"accepted_count": 0,
|
||||
"display_mode": "evidence_readiness_only",
|
||||
"active_scan_authorized": false,
|
||||
"credentialed_scan_authorized": false,
|
||||
"ssh_change_authorized": false,
|
||||
"host_update_authorized": false,
|
||||
"runtime_execution_authorized": false,
|
||||
"action_buttons_allowed": false,
|
||||
"not_authorization": true
|
||||
},
|
||||
{
|
||||
"item_id": "host_maintenance_window_evidence",
|
||||
"display_order": 4,
|
||||
"related_hosts": [
|
||||
"192.168.0.112",
|
||||
"192.168.0.168",
|
||||
"192.168.0.111"
|
||||
],
|
||||
"required_gate": "security_approval_gate_v1_with_maintenance_window",
|
||||
"evidence_state": "waiting_maintenance_window",
|
||||
"received_count": 0,
|
||||
"accepted_count": 0,
|
||||
"display_mode": "evidence_readiness_only",
|
||||
"active_scan_authorized": false,
|
||||
"credentialed_scan_authorized": false,
|
||||
"ssh_change_authorized": false,
|
||||
"host_update_authorized": false,
|
||||
"runtime_execution_authorized": false,
|
||||
"action_buttons_allowed": false,
|
||||
"not_authorization": true
|
||||
},
|
||||
{
|
||||
"item_id": "host_rollback_plan_evidence",
|
||||
"display_order": 5,
|
||||
"related_hosts": [
|
||||
"192.168.0.112",
|
||||
"192.168.0.168",
|
||||
"192.168.0.111"
|
||||
],
|
||||
"required_gate": "security_approval_gate_v1_with_change_plan_and_rollback_evidence",
|
||||
"evidence_state": "waiting_rollback_plan",
|
||||
"received_count": 0,
|
||||
"accepted_count": 0,
|
||||
"display_mode": "evidence_readiness_only",
|
||||
"active_scan_authorized": false,
|
||||
"credentialed_scan_authorized": false,
|
||||
"ssh_change_authorized": false,
|
||||
"host_update_authorized": false,
|
||||
"runtime_execution_authorized": false,
|
||||
"action_buttons_allowed": false,
|
||||
"not_authorization": true
|
||||
},
|
||||
{
|
||||
"item_id": "host_validation_metrics_evidence",
|
||||
"display_order": 6,
|
||||
"related_hosts": [
|
||||
"192.168.0.112",
|
||||
"192.168.0.168",
|
||||
"192.168.0.111"
|
||||
],
|
||||
"required_gate": "security_followup_runtime_gate_v1_post_check",
|
||||
"evidence_state": "waiting_post_check_metrics",
|
||||
"received_count": 0,
|
||||
"accepted_count": 0,
|
||||
"display_mode": "evidence_readiness_only",
|
||||
"active_scan_authorized": false,
|
||||
"credentialed_scan_authorized": false,
|
||||
"ssh_change_authorized": false,
|
||||
"host_update_authorized": false,
|
||||
"runtime_execution_authorized": false,
|
||||
"action_buttons_allowed": false,
|
||||
"not_authorization": true
|
||||
},
|
||||
{
|
||||
"item_id": "host_redacted_ingestion_evidence",
|
||||
"display_order": 7,
|
||||
"related_hosts": [
|
||||
"192.168.0.112",
|
||||
"192.168.0.168",
|
||||
"192.168.0.111"
|
||||
],
|
||||
"required_gate": "security_finding_v1_redacted_payload_acceptance",
|
||||
"evidence_state": "waiting_redacted_payload_acceptance_payloads_ingested_false",
|
||||
"received_count": 0,
|
||||
"accepted_count": 0,
|
||||
"display_mode": "evidence_readiness_only",
|
||||
"active_scan_authorized": false,
|
||||
"credentialed_scan_authorized": false,
|
||||
"ssh_change_authorized": false,
|
||||
"host_update_authorized": false,
|
||||
"runtime_execution_authorized": false,
|
||||
"action_buttons_allowed": false,
|
||||
"not_authorization": true
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -696,6 +696,18 @@
|
||||
"runtime_delta": false,
|
||||
"execution_authorized": false,
|
||||
"not_authorization": true
|
||||
},
|
||||
{
|
||||
"delta_id": "s2_16_iwooos_host_evidence_readiness_board",
|
||||
"display_order": 45,
|
||||
"completed_stage": "S2.16 IwoooS host evidence readiness board",
|
||||
"progress_axis": "framework_detail",
|
||||
"headline_percent_delta": 0,
|
||||
"framework_delta_visible": true,
|
||||
"why_headline_unchanged": "IwoooS host evidence readiness board 只顯示主機掃描、SSH/host change、Kali update 與 runtime blocking 前仍缺 scope、owner decision、credential handling、maintenance window、rollback、validation metrics 與 redacted ingestion evidence;received / accepted 仍為 0,所有主機動作授權仍為 false。",
|
||||
"runtime_delta": false,
|
||||
"execution_authorized": false,
|
||||
"not_authorization": true
|
||||
}
|
||||
],
|
||||
"next_safe_actions": [
|
||||
|
||||
Reference in New Issue
Block a user