2026-05-17 14:17:55 +02:00
|
|
|
---
|
|
|
|
|
id: NK-WP-0009
|
|
|
|
|
type: workplan
|
|
|
|
|
title: NetKingdom Security Pattern Tutorials
|
2026-06-22 23:16:27 +02:00
|
|
|
domain: infotech
|
2026-05-17 14:17:55 +02:00
|
|
|
repo: net-kingdom
|
2026-09-28 23:16:51 +02:00
|
|
|
status: active
|
2026-09-14 15:50:43 +02:00
|
|
|
flavor: implementation
|
2026-05-17 14:17:55 +02:00
|
|
|
owner: codex
|
|
|
|
|
topic_slug: netkingdom
|
|
|
|
|
planning_priority: medium
|
|
|
|
|
planning_order: 9
|
|
|
|
|
created: 2026-05-17
|
2026-09-28 12:40:03 +02:00
|
|
|
updated: "2026-09-28"
|
2026-05-17 14:17:55 +02:00
|
|
|
depends_on:
|
|
|
|
|
- NK-WP-0008
|
2026-08-31 19:08:31 +02:00
|
|
|
state_hub_workstream_id: "d4d02dbf-3974-502d-8b87-b776fc63e17e"
|
2026-05-17 14:17:55 +02:00
|
|
|
---
|
|
|
|
|
|
|
|
|
|
# NK-WP-0009 - NetKingdom Security Pattern Tutorials
|
|
|
|
|
|
|
|
|
|
## Goal
|
|
|
|
|
|
|
|
|
|
Build practical tutorials that show operators and developers how to
|
|
|
|
|
implement canonical NetKingdom security architecture patterns in
|
|
|
|
|
NetKingdom-enabled IT infrastructures.
|
|
|
|
|
|
|
|
|
|
Where NK-WP-0008 is the pattern library, this workplan is the hands-on
|
|
|
|
|
path: runnable examples, checklists, commands, manifests, verification
|
|
|
|
|
steps, and failure-mode exercises.
|
|
|
|
|
|
|
|
|
|
## Context
|
|
|
|
|
|
|
|
|
|
The platform needs more than architecture statements. A new deployment
|
|
|
|
|
should be able to answer:
|
|
|
|
|
|
|
|
|
|
- How do I issue identity tokens in lightweight mode versus expanded
|
|
|
|
|
mode?
|
|
|
|
|
- How do I ask flex-auth for a resource decision?
|
|
|
|
|
- How do I vend temporary object-storage credentials?
|
|
|
|
|
- How do I deploy OpenBao and avoid secret zero traps?
|
|
|
|
|
- How do I use short-lived SSH certificates for agents and automations?
|
|
|
|
|
- How do I verify audit records and break-glass behavior?
|
|
|
|
|
|
|
|
|
|
Tutorials turn canonical patterns into repeatable implementation
|
|
|
|
|
practice without forcing every application repo to rediscover the same
|
|
|
|
|
steps.
|
|
|
|
|
|
|
|
|
|
## Scope
|
|
|
|
|
|
|
|
|
|
In scope:
|
|
|
|
|
|
|
|
|
|
- tutorial structure and style guide
|
|
|
|
|
- runnable or copy-pasteable examples
|
|
|
|
|
- local/dev and production variants where appropriate
|
|
|
|
|
- verification and rollback steps
|
|
|
|
|
- integration references to key-cape, flex-auth, ops-warden,
|
|
|
|
|
ops-bridge, railiance-platform, and artifact-store
|
|
|
|
|
|
|
|
|
|
Out of scope:
|
|
|
|
|
|
|
|
|
|
- deploying live services directly from this repo
|
|
|
|
|
- replacing repo-specific operator runbooks
|
|
|
|
|
- hiding provider-specific security differences behind one generic
|
|
|
|
|
command
|
|
|
|
|
|
2026-09-28 12:40:03 +02:00
|
|
|
## Create the tutorial template
|
2026-05-17 14:17:55 +02:00
|
|
|
|
|
|
|
|
```task
|
2026-08-21 23:51:36 +02:00
|
|
|
id: NK-WP-0009-T01
|
2026-09-28 23:31:48 +02:00
|
|
|
status: done
|
2026-05-17 14:17:55 +02:00
|
|
|
priority: high
|
2026-08-31 19:08:31 +02:00
|
|
|
state_hub_task_id: "3c6824a0-39e6-51f5-b46f-5861a9375439"
|
2026-05-17 14:17:55 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Create a tutorial template with prerequisites, architecture context,
|
|
|
|
|
commands, manifests, verification, rollback, threat checks, and
|
|
|
|
|
cross-repo ownership notes.
|
|
|
|
|
|
2026-09-28 12:40:03 +02:00
|
|
|
## Demonstrate temporary object credentials
|
|
|
|
|
|
2026-05-17 14:17:55 +02:00
|
|
|
```task
|
2026-08-21 23:51:36 +02:00
|
|
|
id: NK-WP-0009-T02
|
2026-05-17 14:17:55 +02:00
|
|
|
status: todo
|
|
|
|
|
priority: high
|
2026-08-31 19:08:31 +02:00
|
|
|
state_hub_task_id: "d13760fd-2527-5a39-acb1-11c8091d65a1"
|
2026-05-17 14:17:55 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Write the first tutorial: "Vend temporary S3 credentials from a
|
|
|
|
|
NetKingdom identity token", covering key-cape/Keycloak identity,
|
|
|
|
|
flex-auth authorization, object-store STS exchange, and SDK consumer
|
|
|
|
|
configuration.
|
|
|
|
|
|
2026-09-28 12:40:03 +02:00
|
|
|
## Document the existing OpenBao operating path
|
|
|
|
|
|
2026-05-17 14:17:55 +02:00
|
|
|
```task
|
2026-08-21 23:51:36 +02:00
|
|
|
id: NK-WP-0009-T03
|
2026-09-28 23:31:48 +02:00
|
|
|
status: progress
|
2026-05-17 14:17:55 +02:00
|
|
|
priority: high
|
2026-08-31 19:08:31 +02:00
|
|
|
state_hub_task_id: "16cf51a4-0763-59e9-9b4c-d486f5bde908"
|
2026-05-17 14:17:55 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Write "Deploy OpenBao as the canonical secrets manager for a
|
|
|
|
|
NetKingdom-enabled Railiance platform", linking to the Railiance
|
|
|
|
|
Platform workplan and covering auth methods, secret engines, CSI/ESO
|
|
|
|
|
integration, leases, unseal, backup, and break-glass.
|
|
|
|
|
|
2026-09-28 12:40:03 +02:00
|
|
|
## Document SSH certificates and tunnels
|
|
|
|
|
|
2026-05-17 14:17:55 +02:00
|
|
|
```task
|
2026-08-21 23:51:36 +02:00
|
|
|
id: NK-WP-0009-T04
|
2026-09-28 23:31:48 +02:00
|
|
|
status: progress
|
2026-05-17 14:17:55 +02:00
|
|
|
priority: medium
|
2026-08-31 19:08:31 +02:00
|
|
|
state_hub_task_id: "1d28e3f1-fb39-5d0e-a7ee-ce2e9bc16ed5"
|
2026-05-17 14:17:55 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Write "Use short-lived SSH credentials for admins, agents, and
|
|
|
|
|
automations", using ops-warden and ops-bridge as the reference
|
|
|
|
|
implementation.
|
|
|
|
|
|
2026-09-28 12:40:03 +02:00
|
|
|
## Integrate a protected flex-auth consumer
|
|
|
|
|
|
2026-05-17 14:17:55 +02:00
|
|
|
```task
|
2026-08-21 23:51:36 +02:00
|
|
|
id: NK-WP-0009-T05
|
2026-05-17 14:17:55 +02:00
|
|
|
status: todo
|
|
|
|
|
priority: medium
|
2026-08-31 19:08:31 +02:00
|
|
|
state_hub_task_id: "c380ef19-4bc2-5ade-b127-baf18c64bf35"
|
2026-05-17 14:17:55 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Write "Add a protected system to flex-auth", covering resource
|
|
|
|
|
manifests, action vocabulary, claim envelopes, policy packages,
|
|
|
|
|
decision envelopes, and delegated PDP options.
|
|
|
|
|
|
2026-09-28 12:40:03 +02:00
|
|
|
## Verify the tutorial outcomes
|
|
|
|
|
|
2026-05-17 14:17:55 +02:00
|
|
|
```task
|
2026-08-21 23:51:36 +02:00
|
|
|
id: NK-WP-0009-T06
|
2026-09-28 23:31:48 +02:00
|
|
|
status: done
|
2026-05-17 14:17:55 +02:00
|
|
|
priority: medium
|
2026-08-31 19:08:31 +02:00
|
|
|
state_hub_task_id: "5b6a1670-a283-56e9-892e-ef8b91194a7b"
|
2026-05-17 14:17:55 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Add tutorial verification fixtures or checklists so each tutorial has a
|
|
|
|
|
clear "done when" outcome and does not become prose-only guidance.
|
|
|
|
|
|
|
|
|
|
## Acceptance Criteria
|
|
|
|
|
|
|
|
|
|
- Tutorials are grouped under a stable docs path with a repeatable
|
|
|
|
|
format.
|
|
|
|
|
- Each tutorial maps back to one or more NK-WP-0008 patterns.
|
|
|
|
|
- Tutorials name the owning repo for every concrete implementation
|
|
|
|
|
step.
|
|
|
|
|
- Tutorials include verification and rollback guidance, not just happy
|
|
|
|
|
path commands.
|
2026-09-28 12:40:03 +02:00
|
|
|
|
|
|
|
|
## Infrastructure review — 2026-09-28
|
|
|
|
|
|
|
|
|
|
Keep this plan in backlog, with the first implementation slice T01 + T03 +
|
|
|
|
|
T04 + T06: document the paths already operated and capture safe verification
|
|
|
|
|
and recovery outcomes. OpenBao is already deployed and private; T03 should
|
|
|
|
|
teach consumption, attended access and recovery, with greenfield deployment
|
|
|
|
|
kept as an isolated lab exercise. Use the named `openbao-ui-railiance01`
|
|
|
|
|
tunnel and owner runbooks, not a public Bao URL or copied runtime manifest.
|
|
|
|
|
|
|
|
|
|
T02 is conditional on an owner-backed object-store STS issuer and refusal/lease
|
|
|
|
|
proof; ADR-0008 is architecture, not evidence that the endpoint is live. T05
|
|
|
|
|
must include projected caller identity, audience, binding and unauthorized
|
|
|
|
|
caller rejection: all six live consumers now enforce caller authentication.
|
|
|
|
|
Use accepted IAM v0.3 and owner package declarations under ADR-0015. T06
|
|
|
|
|
requires executable safe fixtures or repeatable outcome checks; never teach
|
|
|
|
|
operators to apply the stale tenant-engine reference YAML.
|
|
|
|
|
|
|
|
|
|
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).
|