blumeops/docs/changelog.d
Erich Blume 4b85e8ca73 Add compensating controls framework with review tooling
Introduce compensating-controls.yaml to track named controls that
justify suppressed security findings. Each control has a description,
verification notes, and last-reviewed date.

Update all Prowler mutelist descriptions to reference controls via
"CC: <id>" prefix instead of restating findings. Nine controls cover:
single-user-cluster, tailscale-network-isolation, local-registry,
sso-gated-admin-tools, operator-managed-pods, ephemeral-privileged-jobs,
trusted-ci-only, init-container-isolation, observability-stack-audit.

Add mise task (review-compensating-controls) that surfaces the most
stale control with all codebase references, and how-to doc
([[review-compensating-controls]]) explaining the review process.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-30 17:35:48 -07:00
..
+ansible-doc-review.doc.md Review Ansible reference doc: add missing roles, clarify IaC positioning 2026-03-30 16:10:24 -07:00
+borgmatic-photos-hardening.infra.md Harden borgmatic photos backup: restrict dirs, add keepalives + checkpoints 2026-03-30 10:30:28 -07:00
+forgejo-runner-12.7.3.infra.md Upgrade forgejo-runner 12.7.0 → 12.7.3, add service card 2026-03-30 16:31:06 -07:00
+kingfisher-docs.doc.md Document Kingfisher secret scanner service 2026-03-28 21:47:37 -07:00
+kingfisher-prek.feature.md Add Kingfisher secret scanner to prek hooks 2026-03-28 21:07:07 -07:00
+spork-strategy.feature.md Add spork strategy: tooling and documentation 2026-03-28 22:58:10 -07:00
.gitkeep Add towncrier changelog system (#86) 2026-02-03 11:48:13 -08:00
compensating-controls.infra.md Add compensating controls framework with review tooling 2026-03-30 17:35:48 -07:00
feature-kingfisher-container.feature.md Build custom Kingfisher container from sporked deploy branch (#318) 2026-03-30 06:34:49 -07:00
feature-kingfisher-cronjob.feature.md Add Kingfisher secret scanner CronJob (#317) 2026-03-28 21:39:55 -07:00
prowler-mutelist.infra.md Add Prowler mutelist and fix kube-state-metrics seccomp (#319) 2026-03-30 17:22:31 -07:00