feat(audit): add rolling phase0 artifact retention tooling

This commit is contained in:
William Valentin
2026-02-27 10:20:14 -08:00
parent 149adb1c85
commit 134fa60af1
10 changed files with 420 additions and 5 deletions
+1
View File
@@ -1654,6 +1654,7 @@ Cadence scheduling (example: every 6 hours via host cron) with rolling timestamp
```
`audit:phase0-baseline:live*` scripts now default to the current UTC date tag when `--tag` is omitted.
Use `audit:phase0-baseline:live:refresh:drift:rolling` when you want each cadence run to keep a distinct tag (`YYYY-MM-DD-HHMMSS`) so drift checks compare against a recent prior snapshot immediately.
Use `audit:phase0-baseline:live:prune` for dry-run retention planning, and `audit:phase0-baseline:live:prune:apply` to prune older rolling-tag artifacts while keeping the newest snapshots per family.
Gateway-origin windows can be captured separately (for example when validating cancel paths):
```bash