docs: block HUB-WP-0012 pending external owner action
All remaining tasks (T01-T07) require owner-reviewed contracts, delivered credentials, or live infrastructure outside hub-core (NetKingdom/KeyCape login, User/Tenant Engine authenticated readers, flex-auth PDP deployment, Railiance attended receipts, rapp-core-hub exposure approval). No further source-only progress is possible from this repo alone, so each task moves to wait with an explicit blocked_on reason and the workplan status moves to blocked. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: sonnet Assistant-Process: 227000@bnt-lap001 Assistant-Session: 5b6507f6-feaf-4716-a581-e9d3f520b20c
This commit is contained in:
parent
709848a9b1
commit
f6c800baad
1 changed files with 34 additions and 8 deletions
|
|
@ -4,10 +4,11 @@ type: workplan
|
|||
title: "NetKingdom identity and tenant integration: platform-root first"
|
||||
domain: infotech
|
||||
repo: hub-core
|
||||
status: active
|
||||
status: blocked
|
||||
flavor: implementation
|
||||
owner: codex
|
||||
topic_slug: infotech
|
||||
status_reason: "All open tasks require owner-reviewed contracts, credentials, or live infrastructure outside hub-core; no further source progress is possible from this repo alone."
|
||||
created: "2026-09-28"
|
||||
updated: "2026-09-28"
|
||||
related:
|
||||
|
|
@ -53,9 +54,10 @@ per-task sequencing, not a blanket wait for every related workplan to finish.
|
|||
|
||||
```task
|
||||
id: HUB-WP-0012-T01
|
||||
status: progress
|
||||
status: wait
|
||||
priority: high
|
||||
state_hub_task_id: "204f4fb0-e240-5558-8790-5985517b85e0"
|
||||
blocked_on: "Contract reviewers' (NetKingdom, user-engine, tenant-engine, flex-auth) sign-off on the inventory and disputed rows"
|
||||
```
|
||||
|
||||
Owner: hub-core; contract reviewers: NetKingdom, user-engine, tenant-engine,
|
||||
|
|
@ -85,9 +87,10 @@ platform-root login or enforcement test is claimed by inventory validation.
|
|||
|
||||
```task
|
||||
id: HUB-WP-0012-T02
|
||||
status: progress
|
||||
status: wait
|
||||
priority: high
|
||||
state_hub_task_id: "9a955fbf-f289-51b7-9682-bbe471694595"
|
||||
blocked_on: "NetKingdom/KeyCape live root login, AAL2 enrollment acceptance, and User/Tenant Engine authenticated HTTP readers (contract published in docs/owner-facts-contract.md, no owner endpoint admitted yet)"
|
||||
```
|
||||
|
||||
Live admission depends on T01; independently testable source may proceed. Owners: NetKingdom/KeyCape, user-engine and tenant-engine;
|
||||
|
|
@ -110,9 +113,10 @@ step-up implementation is actually required.
|
|||
|
||||
```task
|
||||
id: HUB-WP-0012-T03
|
||||
status: progress
|
||||
status: wait
|
||||
priority: high
|
||||
state_hub_task_id: "feea8f20-aad4-583b-958a-a8efeb9c133c"
|
||||
blocked_on: "flex-auth production PDP deployment and signing-key delivery from platform owners (audit-core-senders routing entry to ops-mason/OpenBao is unresolved; no Hub sender credential minted)"
|
||||
```
|
||||
|
||||
Depends on T01; live acceptance also needs T02. flex-auth owns the protected
|
||||
|
|
@ -134,9 +138,10 @@ substituted for evidence of production custody and delivery.
|
|||
|
||||
```task
|
||||
id: HUB-WP-0012-T04
|
||||
status: progress
|
||||
status: wait
|
||||
priority: high
|
||||
state_hub_task_id: "15bc3cae-4575-56c9-afd2-e1e348109ca9"
|
||||
blocked_on: "T02/T03 live admission; private full-root browser/API/MCP journeys need a real root login and PDP, which do not exist yet"
|
||||
```
|
||||
|
||||
Live admission depends on T02/T03; the default-deny source seam may proceed. Add the reusable verified actor/tenant context and local
|
||||
|
|
@ -157,9 +162,10 @@ bounded migration/rollback paths without a public bypass.
|
|||
|
||||
```task
|
||||
id: HUB-WP-0012-T05
|
||||
status: todo
|
||||
status: wait
|
||||
priority: high
|
||||
state_hub_task_id: "6d29854e-e894-5340-9e13-8866e80246f4"
|
||||
blocked_on: "T04 live admission"
|
||||
```
|
||||
|
||||
Depends on T04. Publish the versioned extension security profile and harness.
|
||||
|
|
@ -179,9 +185,10 @@ parity, retention and zero-traffic gates. This task does not claim retirement.
|
|||
|
||||
```task
|
||||
id: HUB-WP-0012-T06
|
||||
status: todo
|
||||
status: wait
|
||||
priority: high
|
||||
state_hub_task_id: "97b0b242-e9a7-53cd-941f-a1822fcf93a5"
|
||||
blocked_on: "T04/T05 live admission and Railiance/platform owners' attended receipts"
|
||||
```
|
||||
|
||||
Depends on T04/T05 and the external owners for each T01 row. Integrate the same
|
||||
|
|
@ -201,9 +208,10 @@ another service. Any missing backend integration keeps M1 open.
|
|||
|
||||
```task
|
||||
id: HUB-WP-0012-T07
|
||||
status: todo
|
||||
status: wait
|
||||
priority: high
|
||||
state_hub_task_id: "0c15cb82-7c59-5a44-8bf0-857ea4438642"
|
||||
blocked_on: "M1 acceptance; owner: rapp-core-hub via RAPPCOREHUB-WP-0002-T05"
|
||||
```
|
||||
|
||||
Depends on M1. Owner: rapp-core-hub through existing RAPPCOREHUB-WP-0002-T05,
|
||||
|
|
@ -513,6 +521,24 @@ T03 tracks authenticated workload HTTP exposure and private acceptance. Hub's
|
|||
without treating it as a connected HTTP adapter. T01/T02 here remain `progress`.
|
||||
No Tenant Engine source, live credential/grant or deployment was changed.
|
||||
|
||||
## Blocked pending owner action — 2026-09-28
|
||||
|
||||
Reviewed every remaining task against hub-core's own tree for further source-only
|
||||
implementation. `hub_core/security/facts.py` already exposes a typed
|
||||
`AccountReader`/`TenantReader` protocol; wiring a real reader for User Engine's
|
||||
new `lookup_account_authority` or Tenant Engine's role endpoint needs the actual
|
||||
endpoint contract, base URL and workload-auth scheme, none of which are visible
|
||||
from this repo and which `docs/owner-facts-contract.md` records as still awaiting
|
||||
owner disposition. No further movement is possible without another team's review,
|
||||
a delivered credential, or live infrastructure access this repo does not have.
|
||||
|
||||
T01–T07 are set to `wait` with an explicit `blocked_on` reason each; T08 was
|
||||
already correctly deferred. The workplan status moves to `blocked`. This is a
|
||||
sequencing state, not an abandonment — the moment an owner delivers a reviewed
|
||||
contract, credential, or acceptance receipt for any task, that task resumes from
|
||||
its recorded state. No source, test or documentation regresses as part of this
|
||||
change.
|
||||
|
||||
## Acceptance checkpoints
|
||||
|
||||
- [x] Architecture/source/runtime review captured; new implementation owner is hub-core
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue