Complete KG-WP-0004-T05 and finish the architecture vocabulary sweep
Layer note is v0.7 Staff: propose containment, memory is not a state plane. §6 audit lists every decision-shaped object; none is a Staff allow/deny. Document version 0.2.0. KG-IN-0002 residual is closed. Assistant: grok Assistant-Session: 01a05ef1-9e5a-70f2-b0ff-0b05d6b38ae9
This commit is contained in:
parent
ac3aa1287e
commit
824fb1b966
6 changed files with 97 additions and 19 deletions
|
|
@ -1,32 +1,41 @@
|
|||
---
|
||||
title: NetKingdom Immune Architecture
|
||||
document_id: KG-ARCH-IMMUNE
|
||||
version: 0.1.0
|
||||
version: 0.2.0
|
||||
status: Draft
|
||||
date: 2026-07-23
|
||||
date: 2026-09-02
|
||||
repo: kings-guard
|
||||
brand: Kings Guard Security
|
||||
ecosystem: NetKingdom
|
||||
owners:
|
||||
- Kings Guard Security Architecture
|
||||
classification: Public
|
||||
layer_sweep: KG-WP-0004
|
||||
standard: net-kingdom/canon/standards/security-layer-model_v0.7.md
|
||||
---
|
||||
|
||||
# NetKingdom Immune Architecture
|
||||
|
||||
> **Layer note (2026-08-28).** kings-guard is a **Staff**-layer repository
|
||||
> under the NetKingdom Security Layer Model v0.6 (assented in
|
||||
> `decisions/decisions.md` KG-DEC-2026-001). Where this document uses "control
|
||||
> plane", read it as naming an **estate-wide, Engine-layer** arrangement of
|
||||
> deterministic authorities — never as a self-description of `kings-guard`,
|
||||
> which publishes posture and requests bounded response through engine APIs.
|
||||
> The parts of this architecture that render decisions or hold state belong to
|
||||
> engines; kings-guard owns observation, judgment, and the request. A full
|
||||
> vocabulary sweep of this document is tracked as intake KG-IN-0002.
|
||||
> **Layer note (2026-09-02, KG-WP-0004).** kings-guard is a **Staff**-layer
|
||||
> repository under the NetKingdom Security Layer Model
|
||||
> `net-kingdom/canon/standards/security-layer-model_v0.7.md` (**accepted**;
|
||||
> assented in `decisions/decisions.md` KG-DEC-2026-001 against v0.1). Catalog
|
||||
> (v0.7 §4): adaptive defence and judgment; observation of Staff-reachable
|
||||
> sources — identity and secret observation **pending**; **proposes**
|
||||
> containment, which it does not own (§9.2). It **publishes** posture;
|
||||
> `gate-house` defines authority meaning; `access-engine` renders it. Posture
|
||||
> is not a privilege source. Immune memory is not a state plane (§3.4 rule 3).
|
||||
> Remaining "control plane" wording in this file names a Kubernetes or
|
||||
> platform API plane, never this repository. The vocabulary sweep that was
|
||||
> `KG-IN-0002` is complete.
|
||||
|
||||
## 1. Purpose
|
||||
|
||||
This document defines the reference architecture for **Kings Guard Security**, implemented in the `kings-guard` repository and positioned within the wider **NetKingdom** ecosystem.
|
||||
This document is the **estate map** for NetKingdom immune security. The
|
||||
`kings-guard` repository implements the **Staff** slice: observation,
|
||||
judgment, posture publication, bounded proposals, and governed memory.
|
||||
Identity issuance, the authorization decision, secret custody, and
|
||||
actuation belong to other layers — actuation is unowned and held at zero.
|
||||
|
||||
The architecture applies principles observed in biological immune systems to the design of a secure, resilient, multi-tenant and multi-purpose cloud platform. The biological analogy is used as an architectural reasoning model, not as a literal implementation prescription.
|
||||
|
||||
|
|
@ -2403,6 +2412,11 @@ Implementations may change without changing the stable Kings Guard capability mo
|
|||
10. How should business continuity requirements influence defensive posture?
|
||||
11. How should the architecture integrate with the wider NetKingdom identity and policy canon?
|
||||
12. Which components belong in `kings-guard`, and which should remain independent reusable repositories?
|
||||
**Answered 2026-09-02 (KG-WP-0004-T05):** `kings-guard` owns observation,
|
||||
judgment, posture publication, bounded proposals, and governed memory
|
||||
that is not a state plane. Identity issuance (`key-cape` / `user-engine`),
|
||||
the PDP (`access-engine`), secret custody (`secrets-engine` / OpenBao),
|
||||
and actuation (unowned Engine/PEP surface) do not belong here.
|
||||
|
||||
---
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue