feat: add fail-closed Hub access profile foundation
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 3s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 11:44:50 +02:00
parent df39fd5f43
commit 3e386147fd
35 changed files with 2009 additions and 195 deletions

View file

@ -1,12 +1,16 @@
# Hub Core and extension access through NetKingdom
Status: proposed implementation blueprint, 2026-09-28. Owner: `hub-core`.
Status: reviewed source blueprint; owner/live acceptance pending, 2026-09-28. Owner: `hub-core`.
Execution record: [HUB-WP-0012](../workplans/HUB-WP-0012-netkingdom-platform-root-access.md).
Requested outcome: the person signing in as `platform-root` can access and
administer the whole platform, including Hub Core, its extensions, and Railiance.
Other human users are denied initially. Public exposure follows proven access
enforcement. Fine-grained delegation is a later phase of the same workplan.
The [access profile candidate](access-profile-v1.md) records the subsequent source
implementation and remaining integration gates. The table below is the original
pre-implementation baseline, not a claim that the new enforcement is deployed.
## Findings and evidence boundary
This is a source/configuration review plus read-only runtime observation, not