94 lines
2.5 KiB
Markdown
94 lines
2.5 KiB
Markdown
|
|
---
|
||
|
|
id: NK-WP-0044
|
||
|
|
type: workplan
|
||
|
|
title: "Provide NetKingdom runbook packs for the runbook-tutorials engine"
|
||
|
|
domain: infotech
|
||
|
|
repo: net-kingdom
|
||
|
|
status: active
|
||
|
|
flavor: implementation
|
||
|
|
owner: claude
|
||
|
|
topic_slug: netkingdom
|
||
|
|
created: "2026-09-29"
|
||
|
|
updated: "2026-09-29"
|
||
|
|
related: [NK-WP-0009]
|
||
|
|
---
|
||
|
|
|
||
|
|
The guided console invented here (NET-WP-0016) now has a home: the
|
||
|
|
`runbook-tutorials` repository (workplans `RBT-WP-0002` to `RBT-WP-0006`). This
|
||
|
|
workplan is net-kingdom's side: keep the existing console working, and offer
|
||
|
|
NetKingdom runbooks as packs in `runbooks/`, following `runbook-pack/v0.1`.
|
||
|
|
|
||
|
|
## Wrap the existing console as a legacy pack
|
||
|
|
|
||
|
|
```task
|
||
|
|
id: NK-WP-0044-T01
|
||
|
|
status: done
|
||
|
|
priority: high
|
||
|
|
```
|
||
|
|
|
||
|
|
`runbooks/security-bootstrap-console/pack.yaml`, engine `legacy-command`. Verified
|
||
|
|
end to end: `rtut launch` starts `make security-bootstrap-ui`, port 8876
|
||
|
|
answers, and the process stops on exit. The console itself is unchanged.
|
||
|
|
|
||
|
|
## Convert the SSH certificate tutorial to a native pack
|
||
|
|
|
||
|
|
```task
|
||
|
|
id: NK-WP-0044-T02
|
||
|
|
status: done
|
||
|
|
priority: high
|
||
|
|
```
|
||
|
|
|
||
|
|
`runbooks/ssh-certificates/pack.yaml` (parameters actor, pubkey, tunnel; owner-tagged
|
||
|
|
steps; verify and rollback). It validates; it is `unexercised`.
|
||
|
|
|
||
|
|
## Convert the OpenBao and flex-auth tutorials
|
||
|
|
|
||
|
|
```task
|
||
|
|
id: NK-WP-0044-T03
|
||
|
|
status: todo
|
||
|
|
priority: high
|
||
|
|
```
|
||
|
|
|
||
|
|
`docs/tutorials/openbao-operating-path.md` and `protected-system-flex-auth.md` become
|
||
|
|
native packs. The flex-auth pack's live part uses the informed-decision pin and the
|
||
|
|
four negative tests as parameterized steps. Keep the markdown until the packs are
|
||
|
|
exercised.
|
||
|
|
|
||
|
|
## Validate packs in this repository
|
||
|
|
|
||
|
|
```task
|
||
|
|
id: NK-WP-0044-T04
|
||
|
|
status: done
|
||
|
|
priority: medium
|
||
|
|
```
|
||
|
|
|
||
|
|
`make runbooks-validate` runs the `rtut` validator from the runbook-tutorials
|
||
|
|
checkout (`RTUT_HOME`, default `~/runbook-tutorials`).
|
||
|
|
|
||
|
|
## Exercise the packs through the UI
|
||
|
|
|
||
|
|
```task
|
||
|
|
id: NK-WP-0044-T05
|
||
|
|
status: wait
|
||
|
|
priority: high
|
||
|
|
```
|
||
|
|
|
||
|
|
Blocked on `RBT-WP-0004` (UI). Bernd runs the SSH, OpenBao and flex-auth packs in the
|
||
|
|
UI; the engine records outcomes, and NK-WP-0009 T03-T05 close on those receipts.
|
||
|
|
|
||
|
|
## Retire the markdown verifier
|
||
|
|
|
||
|
|
```task
|
||
|
|
id: NK-WP-0044-T06
|
||
|
|
status: wait
|
||
|
|
priority: low
|
||
|
|
```
|
||
|
|
|
||
|
|
Once the tutorials are packs, `tools/tutorial-verify` and `make tutorials-verify` are
|
||
|
|
replaced by `runbooks-validate`, and `docs/tutorials/` becomes a pointer.
|
||
|
|
|
||
|
|
## Acceptance Criteria
|
||
|
|
|
||
|
|
- The console still works and is launched by the engine without changes to it.
|
||
|
|
- Every NetKingdom pack validates; each is honestly labelled exercised or unexercised.
|