180 lines
13 KiB
Markdown
180 lines
13 KiB
Markdown
|
|
# Open workplans versus infrastructure — 2026-09-28
|
||
|
|
|
||
|
|
Reviewed all ten nonterminal root workplans (eight blocked, two backlog).
|
||
|
|
Initial review result: one finished, one active, six blocked, two backlog.
|
||
|
|
The follow-through section below records subsequent implementation and statuses.
|
||
|
|
Existing task IDs
|
||
|
|
and State Hub UUIDs are preserved. This is a planning reconciliation; no
|
||
|
|
runtime, credential, policy, DNS or destructive change was performed.
|
||
|
|
|
||
|
|
## Evidence boundary
|
||
|
|
|
||
|
|
Read-only `kubectl` checks against context `default` found one Ready node at
|
||
|
|
92.205.62.239, Kubernetes v1.35.1+k3s1. KeyCape, Authelia, LLDAP,
|
||
|
|
privacyIDEA, user-engine, tenant-engine and audit-core each had one ready
|
||
|
|
Deployment replica. All six flex-auth consumer Deployments were ready and
|
||
|
|
contained `--caller-auth-mode enforce`. This is configuration/readiness
|
||
|
|
proof, not fresh user login, negative authorization or recovery testing.
|
||
|
|
|
||
|
|
All eight CNPG clusters reported one instance and one ready instance:
|
||
|
|
apps-pg, forgejo-db, net-kingdom-pg, platform-pg, platform-pg-2, state-hub-db,
|
||
|
|
target-revenue-pg and user-engine-pg. A healthy single-node cluster does not
|
||
|
|
prove HA or off-host recovery. No Keycloak Deployment was present.
|
||
|
|
|
||
|
|
OpenBao StatefulSet and UI gateway were ready; gateway/API Services were
|
||
|
|
ClusterIP and the namespace had no Ingress. CoulombCore, retained backup
|
||
|
|
contents, public DNS withdrawal and browser sessions were not reverified.
|
||
|
|
Owner receipts below support historical completion, not a fresh execution.
|
||
|
|
Sibling repositories were inspected as available local checkouts; their state
|
||
|
|
was not assumed to be a newly fetched remote head.
|
||
|
|
|
||
|
|
The State Hub inbox supplied flex-auth's September 27 approval of its reference
|
||
|
|
cleanup (`77b26d1e-550b-4926-9610-44fc3a566273`); it was marked read. The
|
||
|
|
human-needed task query returned no NK-/NET-prefixed records. This does not
|
||
|
|
remove the explicit approval gate written in NK-WP-0022. Topic-wide active
|
||
|
|
workplans include other repositories and are not the NetKingdom plan inventory.
|
||
|
|
|
||
|
|
## Plan dispositions at the initial review
|
||
|
|
|
||
|
|
| Plan | Updated state and next acceptance gate |
|
||
|
|
| --- | --- |
|
||
|
|
| [0009 tutorials](../workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md) | Backlog. Start with existing private OpenBao and SSH paths, caller-auth refusal checks and executable verification. STS tutorial needs an actual owner-backed service. |
|
||
|
|
| [0011 federation](../workplans/NK-WP-0011-enterprise-federation-saml.md) | Backlog. Correct issuer to kc.coulomb.social, accepted IAM to v0.3, database admission and managed-package ownership. Require a named enterprise demand before broker implementation. |
|
||
|
|
| [0022 retirement](../workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md) | Blocked. Cutover was completed in July; August 29 retention minimum has elapsed. T08 still needs retained-resource inventory, identity recovery evidence and explicit deletion approval. |
|
||
|
|
| [0027 reef/posture](../workplans/NK-WP-0027-reef-placement-reconciliation.md) | Blocked. Carrier agreement still absent. Include railiance-infra as substrate owner. Public classification exists upstream; maturity mapping versus synthetic provenance remains unresolved. |
|
||
|
|
| [0031 freshness](../workplans/NK-WP-0031-deterministic-posture-feedback.md) | Blocked. Audit Core still lacks structured owner/freshness fields; September V1 recovery evidence does not replace August E2 boundary evidence. |
|
||
|
|
| [0032 Bao callback](../workplans/NK-WP-0032-openbao-operator-loopback-callback.md) | Finished. T03/T04 closed from September 15 callback/login receipts and September 22 platform handoff. Public callback rollback text is historical. |
|
||
|
|
| [0035 cadence](../workplans/NK-WP-0035-emission-cadence-security-profile.md) | Blocked. Update upstream version/pin metadata; migrate source envelopes and obtain real observer evidence. Include local-identity's known profile incompatibility. |
|
||
|
|
| [0039 rename/reference](../workplans/NK-WP-0039-flex-auth-access-engine-coordinate-intake.md) | Active. T04 now has an actionable flex-auth reference-cleanup portion. Tenant-engine agreement and T03 rename notification remain separate gates. |
|
||
|
|
| [0040 execution receipt](../workplans/NK-WP-0040-execution-attribution-receipt.md) | Blocked. Agree emitter/custodian/schema; require an actual run-to-audit receipt proof, preserving unknown attribution and clock bounds. |
|
||
|
|
| [0042 step-up](../workplans/NK-WP-0042-workload-mfa-step-up.md) | Blocked. Reuse delivered P06 enrollment and scoped optional policies; agree and accept one workload's step-up/recovery journey. |
|
||
|
|
|
||
|
|
The two oldest plans now have one task per second-level section, conforming to
|
||
|
|
the file-backed workplan format. Completed implementation tasks were not
|
||
|
|
reopened merely because their historical validation dates are old.
|
||
|
|
|
||
|
|
## Necessary changes and conflicts
|
||
|
|
|
||
|
|
1. **Stale deployment copies can remove a live security control.**
|
||
|
|
`sso-mfa/k8s/tenant-engine/runtime.yaml` lacks live caller enforcement and
|
||
|
|
other owner changes. Keep DO-NOT-APPLY. Flex-auth approved pointers to its
|
||
|
|
`values/<consumer>.yaml`; tenant-engine's portion remains separately owned.
|
||
|
|
Repository rename does not rename the runtime, token audience or OCI package.
|
||
|
|
Source: [FLEX-WP-0020](../../flex-auth/workplans/FLEX-WP-0020-repository-identity-migration.md)
|
||
|
|
(locate by workplan ID if the owner filename changes), inbox receipt above.
|
||
|
|
2. **Recovery claims must follow the actual failure domain.** Reef declarations
|
||
|
|
still omit provider ceilings; one node and single-instance databases cannot
|
||
|
|
establish independent failover. Proposed V0/V1 carrier semantics require
|
||
|
|
owner agreement and workload evidence. A platform database drill does not
|
||
|
|
satisfy full identity restoration for destructive retirement.
|
||
|
|
Sources: [reef declaration](../../reef-railiance/declarations/reef.yaml),
|
||
|
|
[provider proposal](../docs/reef-posture-provider-contract.md).
|
||
|
|
3. **Declared evidence remains behind runtime improvements.** Audit Core's
|
||
|
|
tenancy file still describes flex-auth as unauthenticated A0, despite the
|
||
|
|
observed enforcement flags. Its E2 review metadata is unstructured and old.
|
||
|
|
Have the owner reconcile this; do not infer A/E upgrades from flags or tests.
|
||
|
|
Source: [audit tenancy](../../audit-core/tenancy.yaml).
|
||
|
|
4. **Generic cadence validity is not profile compliance or observation.**
|
||
|
|
Approval Engine and Qonto still fail the owner schema. Local-identity passes
|
||
|
|
that schema but fails the rare-class heartbeat obligation when its source
|
||
|
|
inventory is explicitly supplied. Audit Core holds no local-identity feed.
|
||
|
|
Upstream corrected its candidate bundle digest; profile and declaration
|
||
|
|
metadata need reconciliation without changing historical findings.
|
||
|
|
Sources: [local findings](../local-identity/emission-cadence-findings.md),
|
||
|
|
[upstream review](../../info-tech-canon/feedback/2026-09-21-net-kingdom-emission-cadence-declaration.md).
|
||
|
|
5. **Existing MFA work and proposed generic step-up are different scopes.**
|
||
|
|
P06 already delivered optional policies for two clients, enrollment checks
|
||
|
|
and privileged guards. IAM v0.4 remains proposed; it is not evidence of
|
||
|
|
arbitrary workload step-up support. Reuse the implementation and close the
|
||
|
|
pilot UX/interop gap. Sources: USER-WP-0033, KEY-WP-0035 and
|
||
|
|
[P06 evidence](../../user-engine/docs/evidence/2026-09-13-p06-authentication-policy.md).
|
||
|
|
6. **Public Bao is retired.** September 24 removed public role callbacks;
|
||
|
|
current client source rejects their return. Do not repeat completed login
|
||
|
|
admission or preserve public URLs as a future default. DNS withdrawal is a
|
||
|
|
railiance-infra residual. Sources:
|
||
|
|
[callback receipt](../../railiance-platform/docs/evidence/2026-09-15-openbao-loopback-callback-already-present.json),
|
||
|
|
[login/retraction receipt](../../railiance-platform/docs/evidence/2026-09-15-openbao-public-listener-retract.json),
|
||
|
|
[callback pruning](../../railiance-platform/docs/evidence/2026-09-24-platform-admin-callback-prune.json),
|
||
|
|
[platform closure](../../railiance-platform/workplans/RPF-WP-0025-openbao-operator-only-access.md).
|
||
|
|
7. **Accepted canon and proposals must stay distinct.** IAM v0.3, Playbook
|
||
|
|
Capability v0.1 and security layer v0.7 remain the accepted baselines;
|
||
|
|
proposed amendments do not authorize runtime implementation or replace
|
||
|
|
owner agreement. New federation work must follow ADR-0015 packaging and
|
||
|
|
current tenant identity contracts, not the original greenfield assumptions.
|
||
|
|
|
||
|
|
## Most valuable future implementation
|
||
|
|
|
||
|
|
Recommended order; this is prioritization, not approval of deployment or deletion.
|
||
|
|
|
||
|
|
1. **Remove stale reference authority (0039).** Small, locally actionable work
|
||
|
|
that prevents a caller-auth regression. Replace the approved flex-auth
|
||
|
|
objects with exact owner pointers; finish tenant-engine's portion after its
|
||
|
|
answer. No rollout is needed.
|
||
|
|
2. **Close one real workload MFA journey (0042).** High user value with existing
|
||
|
|
provider work available. Pick a pilot with its owner, demonstrate enrollment,
|
||
|
|
return to action, recovery and denial with stale/insufficient assurance.
|
||
|
|
Coordinate existing actual-user gates rather than create another onboarding
|
||
|
|
implementation.
|
||
|
|
3. **Make evidence freshness and emission operational (0031 + 0035).** Add
|
||
|
|
authoritative metadata first, then migrate a source already sending to
|
||
|
|
Audit Core and prove heartbeat/reconciliation through its observer. This
|
||
|
|
makes missing or stale security evidence detectable. Resolve local-identity
|
||
|
|
activity-scope incompatibility explicitly; do not force a bootstrap tool
|
||
|
|
into a permanent service just to pass the profile.
|
||
|
|
4. **Bind a real execution to evidence (0040).** Agree the receipt and implement
|
||
|
|
one Railiance emitter/receiver integration with actor, artifact, decision,
|
||
|
|
approval and bounded time. This unblocks clock attribution and gives more
|
||
|
|
value than a schema-only finish.
|
||
|
|
5. **Mechanize recovery ceilings and finish retirement safely (0027 + 0022).**
|
||
|
|
Agree reef provider declarations, implement the three-valued join, and use
|
||
|
|
measured recovery evidence. Prepare the exact old identity deletion package
|
||
|
|
only after its recovery gate passes; approval remains a separate final step.
|
||
|
|
|
||
|
|
Tutorials should capture these proven paths incrementally. Enterprise
|
||
|
|
federation is lower priority until a concrete tenant/IdP demand justifies its
|
||
|
|
additional issuer, trust mapping, database and recovery burden.
|
||
|
|
|
||
|
|
## Validation
|
||
|
|
|
||
|
|
- Current read-only node, Deployment, CNPG and OpenBao resource inventories.
|
||
|
|
- Existing cadence checker against the current owner schema: Approval Engine
|
||
|
|
fails with three generic findings; Qonto fails with five. Local-identity is
|
||
|
|
generic-valid; supplying both documented load-bearing/rare classes yields
|
||
|
|
two `rare-heartbeat-missing` failures. Omitting inventory flags checks no
|
||
|
|
rare-class obligations and must not be used to claim adoption.
|
||
|
|
- Existing posture evaluator at explicit `2026-09-28T12:00:00Z` confirms
|
||
|
|
unknown owner/freshness and overdue review for audit-core. This is a chosen
|
||
|
|
reproducible evaluation instant, not the observation timestamp.
|
||
|
|
- Workplan frontmatter, task-ID preservation, task statuses and local Markdown
|
||
|
|
links checked; authored files pass `git diff --check`. The generated brief
|
||
|
|
retains its generator's Markdown hard-break whitespace. No application code changed.
|
||
|
|
|
||
|
|
State Hub lifecycle reconciliation classifies partially completed 0039 with an
|
||
|
|
actionable task as `active`; its file follows that convention. Existing
|
||
|
|
NK-WP/NET-WP prefix warnings are retained rather than renumbering historical
|
||
|
|
work records. At the initial review, repository instructions contained conflicting prefix
|
||
|
|
conventions. NK-WP-0043 subsequently standardized new plans on NK-WP while
|
||
|
|
preserving historical IDs.
|
||
|
|
|
||
|
|
## Follow-through — 2026-09-28
|
||
|
|
|
||
|
|
After the user requested implementation, the approved part of NK-WP-0039-T04
|
||
|
|
was completed: seven obsolete flex-auth objects were removed from the combined
|
||
|
|
reference manifest and replaced with owner links in
|
||
|
|
[sso-mfa/k8s/tenant-engine/README.md](../sso-mfa/k8s/tenant-engine/README.md).
|
||
|
|
Parsed before/after YAML confirms all five tenant-engine objects are unchanged.
|
||
|
|
No repository apply path consumes the combined manifest; the user-engine
|
||
|
|
verifier uses its own file. Owner values enforce caller authentication and
|
||
|
|
bind each consumer to its own ServiceAccount. The remaining YAML stays
|
||
|
|
DO-NOT-APPLY. T04 now waits only for tenant-engine's disposition; T03 still
|
||
|
|
waits for the rename. This returns 0039 to blocked: the current disposition
|
||
|
|
of the original ten is one finished, seven blocked and two backlog.
|
||
|
|
|
||
|
|
The locally owned portion of NK-WP-0035-T04 also advanced: corrected the
|
||
|
|
profile's imported document maturity/version/revision and the local-identity
|
||
|
|
candidate bundle pin. The old pin and its correction remain in historical
|
||
|
|
findings. Schema SHA-256 is unchanged. All 15 focused checker tests pass;
|
||
|
|
explicit rare-class revalidation remains generic-valid with exactly two
|
||
|
|
missing-heartbeat failures. The profile stays proposed and source/observer
|
||
|
|
adoption remains open. No runtime or external-owner source was changed.
|