Activate NK-WP-0009/0011; add tutorials slice and proposed ADR-0009
- docs/tutorials: template, OpenBao and SSH tutorials (unexercised) - tools/tutorial-verify + make tutorials-verify (NK-WP-0009-T06) - ADR-0009 proposed: expanded-mode Keycloak trigger and topology Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: sonnet Assistant-Process: 295952@bnt-lap001 Assistant-Session: e93f64ad-516c-46eb-9666-aad8d300c477
This commit is contained in:
parent
5c4bc16706
commit
0d460e3c02
11 changed files with 469 additions and 8 deletions
36
docs/tutorials/README.md
Normal file
36
docs/tutorials/README.md
Normal file
|
|
@ -0,0 +1,36 @@
|
|||
# NetKingdom Security Pattern Tutorials
|
||||
|
||||
Hands-on paths for operating the canonical NetKingdom security patterns
|
||||
(NK-WP-0009). Each tutorial is a file in this directory, written from
|
||||
[`TEMPLATE.md`](TEMPLATE.md) and checked by `make tutorials-verify`.
|
||||
|
||||
## Rules
|
||||
|
||||
1. **Exercise status is mandatory.** Per
|
||||
[`docs/attended-procedure-standard.md`](../attended-procedure-standard.md), a
|
||||
tutorial header says `exercised <date> by <operator>` or `unexercised`.
|
||||
Nothing is labelled exercised until someone has run it.
|
||||
2. **Every concrete step names its owning repo.** This repo owns canon and
|
||||
reference tooling only (see `SCOPE.md`); deployment belongs to owners.
|
||||
3. **Verification and rollback are required**, not optional happy-path extras.
|
||||
4. **No secrets, ever.** Tutorials show paths and commands, never values.
|
||||
5. **Consume, don't copy.** Link owner runbooks; do not paste runtime
|
||||
manifests. Use the named `openbao-ui-railiance01` tunnel, never a public
|
||||
Bao URL (`bao.coulomb.social` is retired).
|
||||
|
||||
## Index
|
||||
|
||||
| Tutorial | Workplan task | Owners | Status |
|
||||
| --- | --- | --- | --- |
|
||||
| [OpenBao: consume, attend, recover](openbao-operating-path.md) | T03 | railiance-platform, net-kingdom | unexercised |
|
||||
| [Short-lived SSH credentials](ssh-certificates-and-tunnels.md) | T04 | ops-warden, ops-bridge | unexercised |
|
||||
|
||||
Deferred (see NK-WP-0009): T02 object-storage STS (needs an owner-backed
|
||||
issuer and refusal/lease proof — ADR-0008 is architecture, not evidence) and
|
||||
T05 flex-auth protected consumer.
|
||||
|
||||
## Pattern mapping
|
||||
|
||||
NK-WP-0008 (the pattern library) has no file in this repo, so tutorials map to
|
||||
the canonical documents directly: `docs/platform-identity-security-architecture.md`,
|
||||
`docs/responsibility-map.md`, `docs/platform-root-custody.md`.
|
||||
Loading…
Add table
Add a link
Reference in a new issue