> **Terminology note:** Historical text in this archived workplan may use the legacy term "workstream". The fleet term is **workplan** (`canon/standards/workplan-terminology-fleet_v0.1.md`).
**2026-06-03:** 0019 polish (dry-run orchestrator, console subcommands/make targets/claims/validators/runbook) and the user-engine/net-kingdom assessment (see T04) are cross-cutting enablers. See per-task notes (T02–T09) for specifics; 0019 advances T06/T07/T08 for lifecycle automation; assessment fulfills UE boundary review portion of T04. Related: NET-WP-0019, docs/user-engine-netkingdom-integration-assessment.md.
**2026-06-03:** Started T02. Using pragmatic tracking (this note + will POST /progress/ with task). Gathering deployed components from existing docs, code, and configs to produce specific-as-deployed doc (not idealized). Will cover all listed items + pragmatic audit paths, dry-run 0019 additions, UE integration points/gaps per assessment.
**2026-06-03:** T02 complete. Created docs/NetkingdomRuntimeArchitecture.md (comprehensive sections on planes model, identity stores/MFA/OIDC flows (lightweight key-cape: LLDAP at lldap.coulomb.social + Authelia + privacyIDEA + KeyCape issuer https://kc.coulomb.social with bootstrap clients), Authelia handoff, OpenBao OIDC admin + secrets/credential path (SOPS/age bootstrap -> runtime with K8s auth, ESO, leases), bootstrap console/UI state (S6 Reopen, full gates incl. audit_core_posture, 0019 dry-run orchestrator/console subcmds/make targets/evidence/validators/runbook entry), State Hub relation (progress/decisions for tracking), k8s/DNS/routes/ingress/trust boundaries (sso/openbao ns, recursive rule, concrete hosts), operational assumptions + rebuild notes. Explicitly includes current pragmatic audit paths (local-identity/audit.py TSV, OpenBao PVC+mock, State Hub/console evidence) and UE integration points + 7 gaps (from assessment + contract refs). Specific as-deployed for rebuild guidance. This doc now feeds T03 retrospective, T05 guide, T09 risk, and T02/T08 validation targets.
**2026-06-03:** Started T03 (after T02 arch doc complete). Using pragmatic (progress + file notes). Compiling bumps from 0015-0017/0019 history + T02 doc + console/metadata/evidence examples. Will produce docs/security-bootstrap-retrospective.md + gap matrix (state persistence, privacyIDEA repair, KeyCape delivery, OIDC callbacks, OpenBao claims, token revocation, **audit**, escrow, rebuild verification + new: 0019 dry-run hygiene/automation, console evidence, UE gaps). What is now automated vs. remaining manual/fragile.
**2026-06-03:** T03 initial substantial progress. Created docs/security-bootstrap-retrospective.md (exec summary, 9 detailed bumps with "now automated?" status, full gap matrix table covering audit + UE + 0019 items, recommendations for T05/T07/T08/T09, references to T02 doc + pragmatic records + evidence). Uses 0019 dry-run/evidence as model. Still in_progress (expand with any new from later T0x).
**2026-06-03:** T03 complete. Finalized retrospective draft with comprehensive bumps analysis, gap matrix (explicitly including audit, UE integration, 0019 polish as enablers), and actionable recs. No further expansion needed at this stage (will reference in later tasks). Used pragmatic tracking throughout (progress events with task_id, workplan notes, git). The doc + T02 now provide strong foundation for T05 (guide), T07/T08 (tests/validations), T09 (risk). Marked done in file and will sync via fix.
**2026-06-03:** T04 complete (no dedicated review session needed). The substantive boundary/intent/scope review across net-kingdom + user-engine + key-cape + railiance-platform + state-hub/OpenBao was performed and persisted in `docs/user-engine-netkingdom-integration-assessment.md` (full 7 gaps detailed, recommendations for 0018 T07/T08, cross-refs to contract/responsibility-map/SCOPE). This was explicitly noted in T04's 2026-06-03 entry at creation time. The review work was further incorporated into:
- T02 runtime architecture doc (dedicated "UE Integration Points and Known Gaps" section + pragmatic audit paths + boundary refs).
- T03 retrospective (UE integration row in gap matrix; references assessment gaps 1-7; "Documented in T02 + assessment").
- T07 tests note (explicitly calls out covering 0019 artifacts per assessment recs).
- Multiple cross-refs in SCOPE.md, workplan Related sections, etc.
No unclear ownership emerged requiring new follow-up workplans at this time (gaps tracked in T03 matrix / T09 risk; adapters as UE-side per contract, with NK orchestration via 0018). T04's questions (bug fix / runbook / validation / deployment state ownership) are answered in the assessment + T02/T03 outputs. Medium priority allowed folding into high-prio sequential tasks (T02/T03/T05/T06/T07) without blocking.
**2026-06-03:** Started T05 (after T03 complete). Per retrospective recs (T05 high priority now that T02 arch + T03 retrospective exist). Using pragmatic tracking. Will consolidate piecemeal materials (T02, T03 retrospective, console lifecycle-guide + 0019 extensions, security-bootstrap-operator-journey.md, user-lifecycle.md, other *-ux.md, evidence templates/validators from console/0019) into a single operator guide with clear sequence, prerequisites, evidence per step (links to validate-*, 0019 dry-run, etc.), and "next safe action" / blocked gates model from the UX contract. Update console guide section as needed. Produce docs/smooth-bootstrap-guide.md or update main journey doc.
**2026-06-03:** T05 complete. Created docs/smooth-bootstrap-guide.md (the consolidated NET-WP-0018 smooth bootstrap guide): covers full sequence from prereqs to reopen + user lifecycle (using 0019 polish), per-step evidence + validator/make links, blocked conditions, next safe action / blocked gates from UX contracts (operator-journey + user-lifecycle), references to T02 arch, T03 retrospective, console, 0019 artifacts. Also notes to update console lifecycle-guide for 0019 polish. Pragmatic tracking used (progress, file notes). This fulfills T05 + feeds T06 alignment.
**2026-06-03:** Started T06 (after T05 guide complete). Per T05 recs and plan. Review console/make against new smooth-bootstrap-guide.md + T02/T03. Will refresh console lifecycle_guide T06 DRY-RUN to prefer 0019 orchestrator/make (deprecate old manual secret path); ensure status/actions reference the new guide; leverage existing 0019 validators for "replace passive with validators"; make wrong-order hard via next-safe/blocked in guide + console. Use pragmatic. Small targeted updates to console.py (print_lifecycle_guide) and perhaps Makefile/docs refs.
**2026-06-03:** T06 complete. Aligned control surface to T05 smooth-bootstrap-guide.md:
- Refreshed print_lifecycle_guide T06 DRY-RUN section in console.py to use 0019 orchestrator + make + script + new guide (no more old manual secret steps).
- Enhanced print_status: added "Follow the NET-WP-0018 Smooth Bootstrap Guide" section with doc ref + entrypoint (lifecycle-guide / make); updated available actions list to note guide for #9.
- Updated workplan T06 description note and added completion. Status done.
- UI now explicitly guides to the sequence in the doc and makes the path clear (status points to guide for full flows; blocked/evidence from prior + 0019 validators help wrong-order).
- Uses pragmatic throughout.
This fulfills "UI guides same sequence as the bootstrap guide and makes wrong-order visibly hard" for the current control surface (console + make + runbooks + evidence). Further (T07 tests, T08 more validators) will strengthen.
**Note (NET-WP-0019 polish):** Include tests for the user-lifecycle dry-run (T06 from 0017/0019): the orchestrator script, onboarding-dry-run console command, claims verification (T05), cleanup helper, and evidence validators. See NET-WP-0019 workplan and sso-mfa/k8s/lldap/dry-run-nonroot-user.sh . This cross-links the T06-adjacent polish into 0018's automation goals.
See also `docs/user-engine-netkingdom-integration-assessment.md` for the broader intent/scope fit, gaps (esp. adapters), and recommendations. (The 0019 artifacts -- script, console subcmds, make targets, runbook entry, templates/validators -- are now the concrete implementation to cover with the layered tests in T07.)
**2026-06-03:** Started T07. Using pragmatic tracking. Adding layered tests per spec: Python pytest for console (templates, runbooks incl. dry-run T06, posture validators), shell syntax for scripts, fixture-style for evidence validators. Will create tests/ dir + Makefile target. Include 0019 items as noted.
**2026-06-03:** T07 complete. Added:
- tools/security-bootstrap-console/tests/test_security_bootstrap_console.py (pytest, 8 tests: templates have fields esp. 0019 dry-run, runbook_payloads has T06 entry, audit_core_posture_ready with samples, etc.)
- Makefile: security-bootstrap-console-test (pytest), security-bootstrap-scripts-syntax (bash -n for dry-run, create-user, etc.), added to .PHONY and lists.
- Tests cover console logic for UI sections, runbooks, validators per T07 spec + 0019 note.
- Ran: pytest passes.
- Pragmatic: progress, workplan notes, commit.
This ensures tests would fail if sections disappear/wrong (e.g. no dry-run in runbooks, missing template fields).
**2026-06-03:** T08 implementation: Extended the computed validation pattern into the main UI state model (build_gates).
- Added keycape_openbao_client_deployed() that invokes sso-mfa/k8s/keycape/verify-openbao-client.sh (live check) when possible.
- Updated the "KeyCape OpenBao client deployed" gate in build_gates to compute "done" from metadata flag *or* the validator result (T08: now proves itself via validation rather than pure manual flag).
- Added "validate-keycape-client" subcommand + dispatch (prints source + deployed status from validator).
- Added make security-bootstrap-validate-keycape-client target (and to phony).
- T07 tests + console-test cover related.
- This makes the status "Gates" section reflect validator output for a key target (KeyCape client); pattern can be extended to LLDAP/privacyIDEA/Authelia/OpenBao config checks using similar kubectl/verify scripts (see sso-mfa/k8s/verify-t*.sh and keycape/verify-*.sh).
- Console status now shows more "proof" from validations. Updated workplan note.
- See also smooth-bootstrap-guide.md for how UI validations fit the sequence.
**2026-06-04 (T09 complete):** Started T09 (last high-prio task; 8/9 in brief). Using pragmatic tracking (todo, file notes, will POST /progress/ with task_id, git, console/evidence review, T07/T08 run). Reviewed all prior: T02 NetkingdomRuntimeArchitecture.md (specific-as-deployed incl. full UE 7 gaps section + pragmatic audit + 0019 + rebuild notes), T03 retrospective.md (9 bumps + gap matrix with UE/audit/rebuild rows high for T09 + explicit rec "T09 classify UE risk + rehearsal scripted/namespace first"), T05 smooth-bootstrap-guide.md (consolidated sequence + Step 7/8 refs 0019 dry-run + "Rehearse rebuild per T09 (scripted/namespace first; use 0019 as model)"), T07 tests (8 pytest covering templates/0019 dry-run bools/runbooks/validators + syntax), T08 (keycape_openbao_client_deployed() live via verify script + or into build_gates + subcmd/make; "prove itself through same validations UI shows"), live console status (S6, T08 gate "done (computed via verify...)", action #17 validate-keycape-client, 0019 dry-run actions), .local/metadata (platform_reopened, cleanup_complete, audit_core_bootstrap_risk_accepted:true + review 2026-07-02, many oidc/openbao flags true), /tmp onboarding evidence (validated OK with 12+ exact bools: actor_class=user, no_secret_material_recorded, lldap_identity_verified, keycape_oidc_claims_verified, effective_access_summary, lock_offboard_result clean, prevents root etc.), assessment.md (full 7 gaps: #1 missing adapters biggest, bootstrap users vs UE, claims drift, membership, governance, audit correlation, etc.; no intent conflicts; recs for 0018 to classify + drive integration tests), boundary contract, creds-init skill (automated SOPS/age/k8s + --dry-run + human emergency bundle gate), 0019 orchestrator (dry-run-nonroot-user.sh: /tmp+trap, k8s-fallback, --test, claims, lock/offboard, cleanup-only, evidence populate+validate), Makefile (security-bootstrap-onboarding-dry-run + validate-* + console-test + scripts-syntax + validate-keycape-client all first-class; bootstrap target lists them), T08 verify script.
Created docs/security-bootstrap-rebuild-risk-and-rehearsal.md (exec summary with live posture from T09 exercise of validators/tests; full risk table ~12 areas classified by likelihood/impact/detection/mitigation/remaining-human/priority — UE adapters HIGH #1, scratch state loss HIGH, claims path HIGH until fixed, cluster rehearsal unexercised HIGH, audit correlation HIGH, etc.; detailed non-destructive rehearsal plan: 1. scripted local dry-run (creds-init --dry + make security-bootstrap-onboarding-dry-run + all validate-* + T07 pytest + console status prove + /tmp evidence), 2. ns-isolated/k8s-fallback (orchestrator k8s extract + scoped; isolated restore drill), 3. parallel cluster (full guide + S6 re-proof when avail), 4. live scratch only post-rehearsal + approval (non-goal); rollback via 0019 cleanup/GraphQL; prove criteria (validators 0, tests green, evidence bools, no taint, progress events); current coverage gaps documented; recs: prioritize adapters per assessment, extend T08 validators, drive future dry-run UE exercise from 0018/0019, schedule T09 drills, use as rebuild bible + 0017 handoff gate).
Updated T09 in workplan to done + this note (refs new doc + all cross + pragmatic infra used for T09 itself + that 9/9 closes 0018). No destructive actions. All review via tools + direct execution of tests/validate (passed). File-first per ADR-001.
Pragmatic: this note + will POST /progress/ (task_id a9e60fd5-... + workstream), git commit, make fix-consistency (expect brief 9/9, C-10 etc.), verify. T09 fulfills the "assess resulting + define rehearsal" + T03 rec + smooth-guide callout + assessment recs. Brief will show 9/9 once synced.