diff --git a/workplans/FLEX-WP-0008-tenant-engine-consumer-integration.md b/workplans/FLEX-WP-0008-tenant-engine-consumer-integration.md index e6520cc..445373f 100644 --- a/workplans/FLEX-WP-0008-tenant-engine-consumer-integration.md +++ b/workplans/FLEX-WP-0008-tenant-engine-consumer-integration.md @@ -16,7 +16,7 @@ related_workplans: - KEY-WP-0005 created: "2026-07-23" updated: "2026-07-23" -state_hub_workstream_id: "6341d238-fffc-4428-9265-0b6db5714e9b" +state_hub_workstream_id: "1358db95-967c-5a03-8b8c-4816dc106594" --- # FLEX-WP-0008: tenant-engine Consumer Integration @@ -52,7 +52,7 @@ and action vocabulary is small and doesn't need CARING descriptor mapping. id: FLEX-WP-0008-T01 status: done priority: high -state_hub_task_id: "d78361e6-eb8e-4623-bed2-917538c403ca" +state_hub_task_id: "5606408f-f94c-5d79-ba41-ed23fadac480" ``` Resource types: `tenant`, `role-grant`, `plan-assignment`. Actions: @@ -84,7 +84,7 @@ types match exactly, not just by convention. id: FLEX-WP-0008-T02 status: done priority: high -state_hub_task_id: "8a07e83b-27a2-4390-a169-51065bcf3bd6" +state_hub_task_id: "bbe1a8f4-dcd9-58bb-8d82-386ee0c11a51" ``` Policy: writes require an `aal2`+ assurance actor holding an appropriate @@ -140,7 +140,7 @@ HTTP, real Rego evaluation. `go test ./...` still green across the whole id: FLEX-WP-0008-T03 status: done priority: medium -state_hub_task_id: "20c005a4-48b7-4ac4-a345-aeaa0de06d80" +state_hub_task_id: "e27d24b3-0aef-5bd4-b7e3-81532cd7aa9c" ``` A context-enrichment adapter (mirrors `internal/adapters/{relationship,rule,topaz}`'s @@ -201,7 +201,7 @@ this task exists to guarantee, proven end-to-end across Go → Python → Go id: FLEX-WP-0008-T04 status: done priority: low -state_hub_task_id: "0c59ada6-c61b-41a3-8baa-a98e936c5690" +state_hub_task_id: "0f319a2f-e4bb-5ba8-92de-b693ae9a2aa3" ``` Confirm T01–T03 done; run flex-auth's existing test suite plus the new diff --git a/workplans/FLEX-WP-0009-user-engine-production-policy-service.md b/workplans/FLEX-WP-0009-user-engine-production-policy-service.md index dad8aca..62f4f1c 100644 --- a/workplans/FLEX-WP-0009-user-engine-production-policy-service.md +++ b/workplans/FLEX-WP-0009-user-engine-production-policy-service.md @@ -11,7 +11,7 @@ created: "2026-08-08" updated: "2026-08-16" depends_on: - NK-WP-0024 -state_hub_workstream_id: "45756b89-feba-45f5-a24a-63a1119254bf" +state_hub_workstream_id: "390da58d-3c58-5102-bd3c-7133956c810e" --- # FLEX-WP-0009 - user-engine production authorization @@ -26,7 +26,7 @@ net-kingdom/docs/user-engine-platform-expansion-contract.md. id: FLEX-WP-0009-T01 status: done priority: high -state_hub_task_id: "e940c5a3-ecb4-43d3-9554-2bfb422ec56d" +state_hub_task_id: "4607222e-3407-59c4-b388-aa7c88f7e3ef" ``` Add a user-engine protected-system manifest, resource manifests, subject @@ -48,7 +48,7 @@ self-service, cross-tenant, missing-role, and wrong-system cases. id: FLEX-WP-0009-T02 status: done priority: high -state_hub_task_id: "6e0fe708-d7ff-411f-a64d-84a1692a6e11" +state_hub_task_id: "7ae9de35-4f71-54d8-aabb-858c1202c833" ``` Implement policy-as-code for self-only mutations, tenant-admin authority @@ -68,7 +68,7 @@ the package validates under CARING 0.4.0-rc2 and the registry loads cleanly. id: FLEX-WP-0009-T03 status: done priority: high -state_hub_task_id: "f8293230-136d-4f2d-8d3f-bb9840ea7e63" +state_hub_task_id: "9a1ea146-0735-5d6f-bd75-96eb78e9bd2b" ``` Publish an immutable flex-auth image and deploy a namespaced Service at @@ -89,7 +89,7 @@ behind ingress restricted to the user-engine workload and with no egress. id: FLEX-WP-0009-T04 status: done priority: high -state_hub_task_id: "97b931e9-ac5b-46c7-a462-e23c0c18c4f4" +state_hub_task_id: "9639adbe-4392-5f6c-a924-3771f71ab94c" ``` Run live allow, deny, service-unavailable, and cross-tenant probes from the diff --git a/workplans/FLEX-WP-0010-tenant-lifecycle-policy-actions.md b/workplans/FLEX-WP-0010-tenant-lifecycle-policy-actions.md index a937903..f2843cc 100644 --- a/workplans/FLEX-WP-0010-tenant-lifecycle-policy-actions.md +++ b/workplans/FLEX-WP-0010-tenant-lifecycle-policy-actions.md @@ -16,7 +16,7 @@ related_workplans: - USER-WP-0021 created: "2026-08-10" updated: "2026-08-10" -state_hub_workstream_id: "c159fe8b-d35b-4a74-8a15-c1263f7f6392" +state_hub_workstream_id: "fdabae84-dc9e-5ccd-81df-8ae7e66b90b8" --- # FLEX-WP-0010 - Authorize tenant-engine lifecycle actions @@ -71,7 +71,7 @@ yet, and here is why". id: FLEX-WP-0010-T01 status: done priority: high -state_hub_task_id: "e92e45b9-724a-4fbd-8302-75558cf4b6c1" +state_hub_task_id: "8deb9564-658e-5eff-8ef7-94838bee05cc" ``` Add `tenant.update`, `tenant.retire`, and `tenant.reactivate` to @@ -112,7 +112,7 @@ retire a tenant, not what a *retired tenant* may do. id: FLEX-WP-0010-T02 status: done priority: medium -state_hub_task_id: "5aa9e104-a4b3-40cd-b5ad-4ff56421ce69" +state_hub_task_id: "82d13a89-a344-5797-b10f-390d17b11b73" ``` `tenant.retire` is the highest-consequence action in the set: it suspends a @@ -151,7 +151,7 @@ identity, or when a second `tenant-engine` operator subject is registered. id: FLEX-WP-0010-T03 status: done priority: high -state_hub_task_id: "59856c87-a1b4-4fce-b554-9b13181bb8fd" +state_hub_task_id: "2fbceaf5-514b-5ded-adb1-f4e63ce96160" ``` Add `allow`/`deny` fixture pairs to @@ -207,7 +207,7 @@ clean. Evidence table mirrored into `examples/tenant-engine/README.md`. id: FLEX-WP-0010-T04 status: done priority: low -state_hub_task_id: "04141e54-a250-424e-8dfd-4148875e67da" +state_hub_task_id: "eb2579cb-b54f-5834-abcc-81954ac34889" ``` Confirm T01–T03. Run `statehub fix-consistency`. Notify `tenant-engine` that diff --git a/workplans/FLEX-WP-0011-railiance-staged-promotion-overlay.md b/workplans/FLEX-WP-0011-railiance-staged-promotion-overlay.md index 926d38b..250a31b 100644 --- a/workplans/FLEX-WP-0011-railiance-staged-promotion-overlay.md +++ b/workplans/FLEX-WP-0011-railiance-staged-promotion-overlay.md @@ -15,7 +15,7 @@ related_workplans: - RAIL-BS-WP-0006 created: "2026-08-11" updated: "2026-08-16" -state_hub_workstream_id: "b17c3296-f8ae-4f61-bcf7-41ac80bacd47" +state_hub_workstream_id: "deda35b4-f41d-559e-954e-a75f29237f68" --- # FLEX-WP-0011 - Bring flex-auth under the railiance staged-promotion contract @@ -63,7 +63,7 @@ policy rollouts. id: FLEX-WP-0011-T01 status: done priority: medium -state_hub_task_id: "edc7fee5-b78d-4a5c-a773-42c5b39d0019" +state_hub_task_id: "75748946-68c0-5f33-abe1-810fcd55e93f" ``` Write `railiance/app.toml` against schema `railiance.app.v1`, using @@ -110,7 +110,7 @@ re-promote that image. id: FLEX-WP-0011-T02 status: done priority: medium -state_hub_task_id: "5283bc1f-88c3-431b-a9ea-4a900a3e5885" +state_hub_task_id: "4becc09f-2331-5487-a794-643c748dd1bd" ``` Prove `stage deploy`, `stage observe`, `stage promote`, and `stage rollback` @@ -147,7 +147,7 @@ Candidate image: `sha256:1f5290376dc5fcf456dc7a785e394d8b90949dabecd1d3e856f3855 id: FLEX-WP-0011-T03 status: done priority: low -state_hub_task_id: "bebd6ed9-9145-4fc0-bdc8-cac669643c62" +state_hub_task_id: "abb788fe-22a5-5226-9f08-a43e20a47ce9" ``` `the-custodian/docs/coulombcore-drain-placement-plan.md` row 23 lists diff --git a/workplans/FLEX-WP-0012-credential-grant-authorization-surface.md b/workplans/FLEX-WP-0012-credential-grant-authorization-surface.md index afdc383..7555db0 100644 --- a/workplans/FLEX-WP-0012-credential-grant-authorization-surface.md +++ b/workplans/FLEX-WP-0012-credential-grant-authorization-surface.md @@ -13,7 +13,7 @@ related_workplans: - RAILIANCE-WP-0005 created: "2026-08-11" updated: "2026-08-23" -state_hub_workstream_id: "89ecdb1f-ceb0-4a50-b72d-c3dfd5fa7c73" +state_hub_workstream_id: "2a6b5764-1831-5305-b46e-0991d02675df" --- # FLEX-WP-0012 - Authorize railiance-platform credential-grant requests @@ -86,7 +86,7 @@ What is *actually* missing is narrower and worth stating precisely: id: FLEX-WP-0012-T01 status: done priority: medium -state_hub_task_id: "a1c9ba0c-3413-4823-9f9e-ccee09cf5d74" +state_hub_task_id: "f8491771-be1a-5c70-a4aa-059e48536630" ``` Two honest options, and the choice is a charter question rather than a @@ -142,7 +142,7 @@ one generic flex-auth decision surface. id: FLEX-WP-0012-T02 status: done priority: medium -state_hub_task_id: "7e9c4e59-e59c-4617-a87f-99142952fe78" +state_hub_task_id: "685f3d70-7c50-5664-95ae-1e8c93b14073" ``` Add `examples/railiance-platform/` with a protected-system manifest, subject @@ -188,7 +188,7 @@ returned `credential_grant_allowed` for the registered runtime grant and id: FLEX-WP-0012-T03 status: done priority: medium -state_hub_task_id: "3335b2b7-cf1a-411d-95b3-03c4b4c35659" +state_hub_task_id: "045ec743-4411-5b42-b9e8-df25b0c07984" ``` Implement whichever shape T01 chose. If B, the adapter must reuse the @@ -240,7 +240,7 @@ over real HTTP, `go test ./...` is green, and `gofmt`/`go vet` are clean. id: FLEX-WP-0012-T04 status: done priority: low -state_hub_task_id: "40015a87-040c-4d48-b360-fd5566dbc552" +state_hub_task_id: "0dcf2e1f-baa2-5fea-9e3e-9a73795af11f" ``` Reply to capability request `893ff109` — it has been open since 2026-07-02 diff --git a/workplans/FLEX-WP-0013-restore-seven-action-tenant-engine-pin.md b/workplans/FLEX-WP-0013-restore-seven-action-tenant-engine-pin.md index e46cc75..95825d4 100644 --- a/workplans/FLEX-WP-0013-restore-seven-action-tenant-engine-pin.md +++ b/workplans/FLEX-WP-0013-restore-seven-action-tenant-engine-pin.md @@ -17,7 +17,7 @@ related_workplans: - TEN-WP-0006 created: "2026-08-16" updated: "2026-08-16" -state_hub_workstream_id: "41df7845-a144-420d-9852-adabde0949b3" +state_hub_workstream_id: "6f22ded6-a69c-531b-bfa6-2f8d5c886979" --- # FLEX-WP-0013 - Restore the seven-action tenant-engine policy pin @@ -70,7 +70,7 @@ Do not move `flex-auth-user-engine`. id: FLEX-WP-0013-T01 status: done priority: high -state_hub_task_id: "22db4198-b9c3-4ebf-975a-5c44c6a75928" +state_hub_task_id: "f84b0f20-f374-5d61-aa43-d1f886ea86c3" ``` Set the tenant-engine digest to `9320df39` in: @@ -96,7 +96,7 @@ that digest as live and `c25fc34a` as rollback. id: FLEX-WP-0013-T02 status: done priority: high -state_hub_task_id: "e5e76f15-369a-4573-8095-46ba05cd6b14" +state_hub_task_id: "a77ff4bb-8927-5317-a0eb-903cfeef0de5" ``` `kubectl apply -f deploy/flex-auth-tenant-engine.yaml` against railiance01, @@ -145,7 +145,7 @@ deploy/flex-auth-tenant-engine.yaml` reused ReplicaSet id: FLEX-WP-0013-T03 status: done priority: medium -state_hub_task_id: "df616e44-cfea-4811-a986-90ea0f72b68b" +state_hub_task_id: "832ba42f-4247-58a9-bc1b-f99648c2c188" ``` Notify `tenant-engine` that TEN-WP-0005-T05 authority is restored, naming diff --git a/workplans/FLEX-WP-0014-tenant-guardrail-policy-actions.md b/workplans/FLEX-WP-0014-tenant-guardrail-policy-actions.md index 6e4ab2d..4474eeb 100644 --- a/workplans/FLEX-WP-0014-tenant-guardrail-policy-actions.md +++ b/workplans/FLEX-WP-0014-tenant-guardrail-policy-actions.md @@ -16,7 +16,7 @@ related_workplans: - TEN-WP-0006 created: "2026-08-16" updated: "2026-08-16" -state_hub_workstream_id: "dd6d4e09-3664-4698-8c14-8cf1efc2d142" +state_hub_workstream_id: "7de17bd2-5e7c-5355-ba1d-40a051a67746" --- # FLEX-WP-0014 - Authorize tenant-engine guardrail actions @@ -60,7 +60,7 @@ is verified locally. Image + pin is a follow-on, named in T04. id: FLEX-WP-0014-T01 status: done priority: high -state_hub_task_id: "4f4e9fdb-ca21-40a9-b6af-ef0384cd230a" +state_hub_task_id: "34fb239a-7f06-5e96-9f10-a6bbb85bf4c3" ``` Add `tenant.guardrail.read` and `tenant.guardrail.set` to @@ -94,7 +94,7 @@ read-only subject. Registry snapshot rebuilt (2 subjects, 2 groups). id: FLEX-WP-0014-T02 status: done priority: medium -state_hub_task_id: "ec0d2d80-4052-48b1-8d31-ca8e8eac3066" +state_hub_task_id: "8ea87d5f-883a-5d63-89bb-33a3d0963472" ``` tenant-engine split the actions so a PDP can read ceilings without being @@ -120,7 +120,7 @@ subject. id: FLEX-WP-0014-T03 status: done priority: high -state_hub_task_id: "a744472b-59cb-45a3-b3b7-1cf734b04855" +state_hub_task_id: "1029d2ce-bb37-530e-91ef-ded86f6f5be8" ``` Add fixture pairs for: authorized `tenant-engine` read and set → allow; @@ -165,7 +165,7 @@ Live `flex-auth serve` on `127.0.0.1:9098` + real `tenant-engine` on id: FLEX-WP-0014-T04 status: done priority: low -state_hub_task_id: "3516be81-825b-4c83-ae61-89ac914efd7a" +state_hub_task_id: "b2b44215-ef08-5c50-b466-190156a88ef3" ``` Confirm T01–T03. Notify `tenant-engine` naming the policy revision. State diff --git a/workplans/FLEX-WP-0015-tenancy-posture-conformance.md b/workplans/FLEX-WP-0015-tenancy-posture-conformance.md index d6c5618..c202b03 100644 --- a/workplans/FLEX-WP-0015-tenancy-posture-conformance.md +++ b/workplans/FLEX-WP-0015-tenancy-posture-conformance.md @@ -15,7 +15,7 @@ related_workplans: - FLEX-WP-0011 created: "2026-08-17" updated: "2026-08-19" -state_hub_workstream_id: "31846b19-c2a3-428e-950b-5985bc9146eb" +state_hub_workstream_id: "43fe348c-02b9-5d5d-af37-a2d80cfc6e1d" --- # FLEX-WP-0015 - Tenancy posture declaration and inbound caller authentication @@ -57,7 +57,7 @@ per FLEX-WP-0007). id: FLEX-WP-0015-T01 status: done priority: high -state_hub_task_id: "0a32500d-511a-4bd7-972e-de4cd3e62dd9" +state_hub_task_id: "ee587988-d29c-5dd8-9417-8af73f627817" ``` **Publish posture and answer the review.** Write `tenancy.yaml` and @@ -69,7 +69,7 @@ corrections. Done 2026-08-17. id: FLEX-WP-0015-T02 status: done priority: high -state_hub_task_id: "b2e87a81-b63d-4be4-ad44-01426b7e6f74" +state_hub_task_id: "7c906ab5-0b3f-5a73-8561-b29d94f4e634" ``` **Close the A0 — authenticate callers of `/v1/check`.** Decide first, build @@ -192,7 +192,7 @@ said so was corrected to them. id: FLEX-WP-0015-T03 status: done priority: medium -state_hub_task_id: "64eb7652-3b67-4bfb-879b-8588deeec8b5" +state_hub_task_id: "4f885922-56c9-5d89-b7ab-e61c8d69d67a" ``` **Wire or delete `internal/adapters/tenantengine`.** The adapter is complete @@ -219,7 +219,7 @@ live-role policy must introduce the dependency explicitly. id: FLEX-WP-0015-T04 status: cancel priority: low -state_hub_task_id: "06432560-c28c-4de2-a672-87e74be54a6a" +state_hub_task_id: "1c05032a-bcae-5a4c-8f4a-c51b30a48807" ``` **AuthZEN evaluation endpoint (framework `A4`).** Deliberately deferred, not @@ -244,7 +244,7 @@ this task and may be worth doing first. id: FLEX-WP-0015-T05 status: done priority: medium -state_hub_task_id: "9195ba20-ab0f-4d75-b293-86978073beb1" +state_hub_task_id: "702e55bf-b87a-547d-9a2d-bc2ccfee9341" ``` **Guard the declaration.** Framework §12 requires verifying the declared diff --git a/workplans/FLEX-WP-0016-ops-warden-incluster-policy-pin.md b/workplans/FLEX-WP-0016-ops-warden-incluster-policy-pin.md index 4fac94d..6fca050 100644 --- a/workplans/FLEX-WP-0016-ops-warden-incluster-policy-pin.md +++ b/workplans/FLEX-WP-0016-ops-warden-incluster-policy-pin.md @@ -16,7 +16,7 @@ related_workplans: - WARDEN-WP-0009 created: "2026-08-19" updated: "2026-08-19" -state_hub_workstream_id: "5c0fac68-284d-4672-9824-8686a902d33f" +state_hub_workstream_id: "f29f159c-c79e-5c78-b1e8-569a5b63d231" --- # FLEX-WP-0016 - In-cluster ops-warden policy pin so policy.enabled can flip @@ -60,7 +60,7 @@ flip wait on that calling side. id: FLEX-WP-0016-T01 status: done priority: high -state_hub_task_id: "3d7fde8e-00b1-4bc3-be28-00afd37997ac" +state_hub_task_id: "b2f8052e-3686-593f-9359-dfd08d530a26" ``` **Overlay pin.** Add `values/ops-warden.yaml`: same digest as the A2 pins, @@ -77,7 +77,7 @@ warn, isolated, production registry. `tests/stage1.sh` renders it. id: FLEX-WP-0016-T02 status: done priority: high -state_hub_task_id: "9f30410f-e2b3-4b0a-9d70-6f6a12d2822e" +state_hub_task_id: "aa65f534-7401-5231-ae82-ea6e3d09b40c" ``` **Deploy warn.** `helm upgrade --install flex-auth-ops-warden` from the @@ -97,7 +97,7 @@ user-engine and tenant-engine pins were not moved. id: FLEX-WP-0016-T03 status: done priority: medium -state_hub_task_id: "65df7141-58f0-4be8-bc62-07f29cb96856" +state_hub_task_id: "351f502f-f0cf-5a70-86da-10b1fbe39dae" ``` **Handoff for the flip.** Tell ops-warden the Service DNS, digest, warn mode,