# Completed Tasks - TYR - **Phase 1.1: Deploy step-ca** - Status: **Complete** - Notes: `step ca init` was successful and the `step-ca` systemd service is active. - **Phase 1.2: Bootstrap SPIRE** - Status: **Complete** - Notes: `install_spire.sh` executed and daemons are running. - **Phase 1.4: Binary Authorization** - Status: **Complete** - Notes: KMS key, attestor, and policy are created and active. - **Task 2.1: Establish VPC-SC Perimeter** - Status: **Complete** - Notes: Created `tyr_perimeter` to restrict Cloud Run and Artifact Registry. - **Task 2.2: Enable Private Google Access** - Status: **Complete** - Notes: Enabled Private Google Access on the default subnet in `us-central1`. - **Task 2.3: Deploy Cloud Armor WAF** - Status: **Complete** - Notes: Created `tyr-armor-policy` with XSS, rate-limiting, and default-deny rules. - **Task 2.4: Harden Ingress** - Status: **Complete** - Notes: Replaced default SSH rule with IAP-only rule and set Cloud Run ingress to internal. - **Task 3.1: Draft Gatekeeper Policy** - Status: **Complete** - Notes: Wrote `container_security.yaml` with policies to disallow root and require resource limits. - **Phase 3: Workload Security** - Status: **Complete** - Notes: Created SPIFFE workload entry for Ollama, completing the foundational step for mTLS. - **Task 4.1: Create Auto-Rotating Secret** - Status: **Staged** - Notes: Secret `tyr-api-credentials` created, but auto-rotation could not be configured via gcloud.