net-kingdom/history/2026-08-23-key-cape-c1-c2b-composition.md

34 lines
1.4 KiB
Markdown
Raw Permalink Normal View History

# KeyCape C1 and C2b composition evidence
Date: 2026-08-23
Workplan: NK-WP-0030
Mode: plan-only
KeyCape published provider-owned Playbook Capability Contract v0.1
declarations for `key-cape.lightweight-sso` and
`key-cape.privacyidea-token-authority`. The implementation content originates
at KeyCape revision `efce3e9`; its file-first workplan and State Hub identifiers
were reconciled by revision `34fadae`. NetKingdom received the handoff in State
Hub message `1d5f5f15-d137-4c11-8386-c8cc58c17bb8`.
Both owner declarations passed NetKingdom's canonical playbook capability
validator. The reference request in
`examples/security-scenarios/c1-c2b-key-cape.yaml` then composed successfully
with:
- initial trust: `cluster_trust`, `runtime_secret_trust`;
- step 1: `key-cape.lightweight-sso` provides C1 and establishes
`runtime_identity_trust`;
- step 2: `key-cape.privacyidea-token-authority` provides C2b after consuming
that identity trust;
- final trust: `cluster_trust`, `runtime_secret_trust`, and
`runtime_identity_trust`; and
- composition digest:
`sha256:cd7aeba3c83c83e2de7bc9a64d2dd9922f4f39a4de81c41760f9f9a431a820a6`.
The plan retains KeyCape, railiance-platform, and privacyIDEA ownership exactly
as declared. It sets `execution.mode: plan-only` and
`execution.permitted: false`; no provider entry point was invoked. C2a built-in
factors are not part of the scenario, and neither NetKingdom nor KeyCape claims
them through this composition.