Operational guardrails for ethics policies, verify-gate, and observability.
dist/opa/mandala-ethics-bundle.tar.gz (+ .sha256, .asc)ETHICS_POLICY_SIGNATURE_REQUIRED=1, VERIFY_GATE_REQUIRE_POLICY_SIGNATURE=1)/policy/status, /readyz (fail-closed on missing/invalid signature)pnpm opa:cover (threshold via OPA_MIN_COVERAGE, default 0.85)grafana/dashboards/panels/opa-coverage-stat.jsonhttp|https, preflight every hopX-Verify-Degraded: 1 → fail-closedVERIFY_GATE_JWT_SECRETS map + VERIFY_GATE_JWT_ACTIVE_KIDdocs/runbooks/verify-gate-jwt-rotation.mdpnpm opa:test, pnpm opa:coverpnpm chaos:verify-dns-rebind, pnpm chaos:verify-redirect-loop