2026-09-29 00:25:18 +02:00
|
|
|
---
|
|
|
|
|
id: NK-WP-0044
|
|
|
|
|
type: workplan
|
|
|
|
|
title: "Provide NetKingdom runbook packs for the runbook-tutorials engine"
|
|
|
|
|
domain: infotech
|
|
|
|
|
repo: net-kingdom
|
|
|
|
|
status: active
|
|
|
|
|
flavor: implementation
|
|
|
|
|
owner: claude
|
|
|
|
|
topic_slug: netkingdom
|
|
|
|
|
created: "2026-09-29"
|
|
|
|
|
updated: "2026-09-29"
|
|
|
|
|
related: [NK-WP-0009]
|
2026-09-29 00:26:35 +02:00
|
|
|
state_hub_workstream_id: "82414324-e9cf-5581-af9e-b0122411d7bf"
|
2026-09-29 00:25:18 +02:00
|
|
|
---
|
|
|
|
|
|
|
|
|
|
The guided console invented here (NET-WP-0016) now has a home: the
|
|
|
|
|
`runbook-tutorials` repository (workplans `RBT-WP-0002` to `RBT-WP-0006`). This
|
|
|
|
|
workplan is net-kingdom's side: keep the existing console working, and offer
|
|
|
|
|
NetKingdom runbooks as packs in `runbooks/`, following `runbook-pack/v0.1`.
|
|
|
|
|
|
|
|
|
|
## Wrap the existing console as a legacy pack
|
|
|
|
|
|
|
|
|
|
```task
|
|
|
|
|
id: NK-WP-0044-T01
|
|
|
|
|
status: done
|
|
|
|
|
priority: high
|
2026-09-29 00:26:35 +02:00
|
|
|
state_hub_task_id: "44a2d9a7-c0bc-5099-89fb-f6a3fa0c2e50"
|
2026-09-29 00:25:18 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
`runbooks/security-bootstrap-console/pack.yaml`, engine `legacy-command`. Verified
|
|
|
|
|
end to end: `rtut launch` starts `make security-bootstrap-ui`, port 8876
|
|
|
|
|
answers, and the process stops on exit. The console itself is unchanged.
|
|
|
|
|
|
|
|
|
|
## Convert the SSH certificate tutorial to a native pack
|
|
|
|
|
|
|
|
|
|
```task
|
|
|
|
|
id: NK-WP-0044-T02
|
|
|
|
|
status: done
|
|
|
|
|
priority: high
|
2026-09-29 00:26:35 +02:00
|
|
|
state_hub_task_id: "ea4b5cb2-cb7d-5349-9057-bf2657690c79"
|
2026-09-29 00:25:18 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
`runbooks/ssh-certificates/pack.yaml` (parameters actor, pubkey, tunnel; owner-tagged
|
|
|
|
|
steps; verify and rollback). It validates; it is `unexercised`.
|
|
|
|
|
|
|
|
|
|
## Convert the OpenBao and flex-auth tutorials
|
|
|
|
|
|
|
|
|
|
```task
|
|
|
|
|
id: NK-WP-0044-T03
|
2026-09-29 08:34:34 +02:00
|
|
|
status: done
|
2026-09-29 00:25:18 +02:00
|
|
|
priority: high
|
2026-09-29 00:26:35 +02:00
|
|
|
state_hub_task_id: "ba1a41a7-b40d-5312-851e-93c613ac9b27"
|
2026-09-29 00:25:18 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
`docs/tutorials/openbao-operating-path.md` and `protected-system-flex-auth.md` become
|
|
|
|
|
native packs. The flex-auth pack's live part uses the informed-decision pin and the
|
2026-09-29 08:34:34 +02:00
|
|
|
negative tests N1-N3 as parameterized steps. N4 (expired token) is not in the pack:
|
|
|
|
|
it needs a ten-minute wait and a held token, so it stays a documented manual check in
|
|
|
|
|
the markdown tutorial. The markdown stays until the packs are exercised. Verified
|
|
|
|
|
without a run record: the ten offline and read-only verify commands were executed
|
|
|
|
|
and passed; the cluster-touching steps (port-forward and token calls) have not been run.
|
2026-09-29 00:25:18 +02:00
|
|
|
|
|
|
|
|
## Validate packs in this repository
|
|
|
|
|
|
|
|
|
|
```task
|
|
|
|
|
id: NK-WP-0044-T04
|
|
|
|
|
status: done
|
|
|
|
|
priority: medium
|
2026-09-29 00:26:35 +02:00
|
|
|
state_hub_task_id: "1423d9d7-ce11-5fd3-9905-3566f947b0a9"
|
2026-09-29 00:25:18 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
`make runbooks-validate` runs the `rtut` validator from the runbook-tutorials
|
|
|
|
|
checkout (`RTUT_HOME`, default `~/runbook-tutorials`).
|
|
|
|
|
|
|
|
|
|
## Exercise the packs through the UI
|
|
|
|
|
|
|
|
|
|
```task
|
|
|
|
|
id: NK-WP-0044-T05
|
|
|
|
|
status: wait
|
|
|
|
|
priority: high
|
2026-09-29 00:26:35 +02:00
|
|
|
state_hub_task_id: "2d99180e-25ff-51db-8208-b0320c8ec7e3"
|
2026-09-29 00:25:18 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Blocked on `RBT-WP-0004` (UI). Bernd runs the SSH, OpenBao and flex-auth packs in the
|
|
|
|
|
UI; the engine records outcomes, and NK-WP-0009 T03-T05 close on those receipts.
|
|
|
|
|
|
|
|
|
|
## Retire the markdown verifier
|
|
|
|
|
|
|
|
|
|
```task
|
|
|
|
|
id: NK-WP-0044-T06
|
|
|
|
|
status: wait
|
|
|
|
|
priority: low
|
2026-09-29 00:26:35 +02:00
|
|
|
state_hub_task_id: "1b747058-d4df-5f5c-bd63-e85d46dd094e"
|
2026-09-29 00:25:18 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Once the tutorials are packs, `tools/tutorial-verify` and `make tutorials-verify` are
|
|
|
|
|
replaced by `runbooks-validate`, and `docs/tutorials/` becomes a pointer.
|
|
|
|
|
|
|
|
|
|
## Acceptance Criteria
|
|
|
|
|
|
|
|
|
|
- The console still works and is launched by the engine without changes to it.
|
|
|
|
|
- Every NetKingdom pack validates; each is honestly labelled exercised or unexercised.
|