From 0efa06fe5c8beb4ebf9d2be375e232b422d34f4f Mon Sep 17 00:00:00 2001 From: tegwick Date: Sat, 29 Aug 2026 02:54:25 +0200 Subject: [PATCH] =?UTF-8?q?Security=20Layer=20Model=20v0.5=20=E2=80=94=20f?= =?UTF-8?q?our=20reviews,=20nine=20changes?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit All four reviewing repositories returned findings on v0.4 and one contested a rule. Every change below came from a reviewer, not from gate-house. - §9.1 split into `pending` (no route, capability zero) and `declared-gap` (route exists under §5.3, capability works). v0.4's single mark would have forced a false "pending" onto ops-warden's production SSH issuance — the fix was worse than the defect, and the defect was in this section. - §9.3 rewritten. flex-auth contested it and was right: it collapsed "engine reachable but degraded" with "engine unreachable", and the second has no evaluator in the path to express anything. Input degradation is the engine's; unreachability is the consumer's, bounded by a declared auditable total stance — which ops-warden ADR-0009 already satisfies. v0.4 had ruled against shipped behaviour in a repository that assented to it. - §5 scoped: "Tooling-layer system" means a §4 Tooling row. Without this every Staff repository was in undeclared violation for writing progress events. - §9.4 requires the outbox to be local — no synchronous audit-core dependency inside the state-change transaction, so an audit outage cannot block a revocation. - §9.5 forbids compiling maturity levels into registry content while decision provenance carries no registry-snapshot digest. - §9.6 gained load-bearing versus attributive evidence, the mirror rule that absence is not evidence of non-occurrence, and kings-guard's finding that suppression biases posture optimistic and silently. - §11 gained a fourth state: blocked-clean, which MUST NOT rank below conforming. A repository that declined a break-glass path and left a capability at zero complied at cost; one that quietly opened a client and declared nothing did not. - §11 gained a machine-readable declaration form; ops-warden's layer.yaml is the reference implementation. - §13 gained state and owner-status columns; access-engine's decline of authentication evidence is recorded. Co-Authored-By: Claude Opus 5 Assistant: claude-code Assistant-Model: opus Assistant-Process: 2564823@bnt-lap001 Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9 --- .repo-manager/index.json | 3235 ++++++++++++++++++ README.md | 2 +- canon/standards/security-layer-model_v0.4.md | 8 +- canon/standards/security-layer-model_v0.5.md | 776 +++++ 4 files changed, 4019 insertions(+), 2 deletions(-) create mode 100644 .repo-manager/index.json create mode 100644 canon/standards/security-layer-model_v0.5.md diff --git a/.repo-manager/index.json b/.repo-manager/index.json new file mode 100644 index 0000000..90a8e97 --- /dev/null +++ b/.repo-manager/index.json @@ -0,0 +1,3235 @@ +{ + "schema": "repo_manager.index.v1", + "slug": "layer-declaration", + "repo_root": "/home/worsch/net-kingdom", + "head_sha": "f4f013279d2aae8b0612b56d97d4556589774a4a", + "observed_at": "2026-08-28T21:01:53.439626Z", + "source_fingerprint": "538358f8571fd10747c04305a59601b9542f1214c3713e132f4b1fa2171038d3", + "source_files": [ + ".repo-classification.yaml", + "DECISIONS.md", + "INTENT.md", + "docs/intakes/activity-core-ops-sso-operators.md", + "intakes/intakes.md", + "workplans/ADHOC-2026-07-02.md", + "workplans/ADHOC-2026-08-14.md", + "workplans/ADHOC-2026-08-23.md", + "workplans/NET-WP-0020-openbao-unseal-custody-and-ssh-automation.md", + "workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md", + "workplans/NK-WP-0011-enterprise-federation-saml.md", + "workplans/NK-WP-0021-activity-core-ops-sso-operators.md", + "workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md", + "workplans/NK-WP-0023-user-engine-portal-platform-integration.md", + "workplans/NK-WP-0024-user-engine-portal-integration-expansion.md", + "workplans/NK-WP-0025-public-self-registration-and-application-jit.md", + "workplans/NK-WP-0026-flex-auth-caller-identity-rollout.md", + "workplans/NK-WP-0027-reef-placement-reconciliation.md", + "workplans/NK-WP-0028-canon-publication-and-grouping-semantics.md", + "workplans/NK-WP-0029-scope-and-intent-reconciliation.md", + "workplans/NK-WP-0030-deterministic-security-scenario-composition.md", + "workplans/NK-WP-0031-deterministic-posture-feedback.md", + "workplans/NK-WP-0032-openbao-operator-loopback-callback.md", + "workplans/NK-WP-0033-keycape-secret-exposure-rotation.md", + "workplans/NK-WP-0034-verification-that-verifies.md", + "workplans/archived/260522-NK-WP-0015-user-engine-isolated-mvp.md", + "workplans/archived/260522-NK-WP-0016-user-engine-multi-tenancy.md", + "workplans/archived/260522-NK-WP-0017-user-engine-multi-application-catalogs.md", + "workplans/archived/260522-NK-WP-0018-user-engine-integrated-test-scenarios.md", + "workplans/archived/260522-NK-WP-0019-user-engine-finalization-polish.md", + "workplans/archived/260603-NET-WP-0015-platform-root-custody-and-openbao-identity-bootstrap.md", + "workplans/archived/260603-NET-WP-0016-guided-security-bootstrap-experience.md", + "workplans/archived/260603-NK-WP-0003-keycape-privacyidea-cluster-deployment.md", + "workplans/archived/260603-NK-WP-0004-credential-management-foundation.md", + "workplans/archived/260603-NK-WP-0005-agent-driven-credential-bootstrap.md", + "workplans/archived/260604-NET-WP-0018-bootstrap-automation-and-rebuild-readiness.md", + "workplans/archived/260702-ADHOC-2026-06-14.md", + "workplans/archived/260702-NET-WP-0017-it-security-readiness-for-user-onboarding.md", + "workplans/archived/260702-NET-WP-0019-t06-adjacent-user-lifecycle-dry-run-polish.md", + "workplans/archived/260702-NK-WP-0001-sso-mfa-platform.md", + "workplans/archived/260702-NK-WP-0002-local-identity.md", + "workplans/archived/260702-NK-WP-0006-recursive-platform-identity-security-architecture.md", + "workplans/archived/260702-NK-WP-0007-object-storage-sts-credential-vending.md", + "workplans/archived/260702-NK-WP-0008-it-security-architecture-patterns-infospace.md", + "workplans/archived/260702-NK-WP-0010-genesis-security-pattern-completion.md", + "workplans/archived/260702-NK-WP-0012-iam-profile-specification.md", + "workplans/archived/260702-NK-WP-0013-playbook-capability-contract.md", + "workplans/archived/260702-NK-WP-0014-user-engine-preparation-boundary-contracts.md" + ], + "work_records": [ + { + "kind": "workplan", + "id": "NK-WP-ADHOC-2026-07-02", + "status": "finished", + "title": "Ad Hoc Tasks \u2014 2026-07-02", + "source_path": "workplans/ADHOC-2026-07-02.md", + "uuid": "a9177c57-3f48-5d32-aa04-d1822fb86d47", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-ADHOC-2026-07-02-T01", + "status": "done", + "title": "Fix creds-bootstrap-agent Phase 0 dry-run on machines without the age key", + "source_path": "workplans/ADHOC-2026-07-02.md", + "uuid": null, + "parent_id": "NK-WP-ADHOC-2026-07-02", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-ADHOC-2026-07-02-T02", + "status": "done", + "title": "Fix broken check-secrets Make target (unescaped `$`)", + "source_path": "workplans/ADHOC-2026-07-02.md", + "uuid": null, + "parent_id": "NK-WP-ADHOC-2026-07-02", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-ADHOC-2026-08-14", + "status": "finished", + "title": "Close NK-WP-0025 residuals", + "source_path": "workplans/ADHOC-2026-08-14.md", + "uuid": "d9c4de99-ab79-5238-afe5-c4c77204758c", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-ADHOC-2026-08-14-T01", + "status": "done", + "title": "Reconcile Coulomb Social Case B residual records", + "source_path": "workplans/ADHOC-2026-08-14.md", + "uuid": null, + "parent_id": "NK-WP-ADHOC-2026-08-14", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-ADHOC-2026-08-14-T02", + "status": "done", + "title": "Protect the canonical LDAP-DN subject contract", + "source_path": "workplans/ADHOC-2026-08-14.md", + "uuid": null, + "parent_id": "NK-WP-ADHOC-2026-08-14", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-ADHOC-2026-08-14-T03", + "status": "done", + "title": "Persist the audit-core multi-tenant sender scope", + "source_path": "workplans/ADHOC-2026-08-14.md", + "uuid": null, + "parent_id": "NK-WP-ADHOC-2026-08-14", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-ADHOC-2026-08-23", + "status": "finished", + "title": "Ad Hoc Tasks \u2014 2026-08-23", + "source_path": "workplans/ADHOC-2026-08-23.md", + "uuid": "b3abc407-1fd0-58c4-9d8d-2c003ae6f1c9", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-ADHOC-2026-08-23-T01", + "status": "done", + "title": "Advance the canonical audit-core E level after adversarial evidence", + "source_path": "workplans/ADHOC-2026-08-23.md", + "uuid": null, + "parent_id": "NK-WP-ADHOC-2026-08-23", + "extra": {} + }, + { + "kind": "workplan", + "id": "NET-WP-0020", + "status": "finished", + "title": "OpenBao Unseal Custody Models and SSH Automation Path", + "source_path": "workplans/NET-WP-0020-openbao-unseal-custody-and-ssh-automation.md", + "uuid": "d6338ac9-797d-4009-8203-4b8dd39010af", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0020-T01", + "status": "done", + "title": "T1 \u2014 Custody model canon and console gates", + "source_path": "workplans/NET-WP-0020-openbao-unseal-custody-and-ssh-automation.md", + "uuid": "7040f347-d54a-42ba-a14f-5b0a7e691786", + "parent_id": "NET-WP-0020", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0020-T02", + "status": "done", + "title": "T2 \u2014 SOPS-held init/unseal automation hooks", + "source_path": "workplans/NET-WP-0020-openbao-unseal-custody-and-ssh-automation.md", + "uuid": "65407eb1-9d89-4158-aed5-4987badd83fc", + "parent_id": "NET-WP-0020", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0020-T03", + "status": "done", + "title": "T3 \u2014 Attended ceremony automation profile", + "source_path": "workplans/NET-WP-0020-openbao-unseal-custody-and-ssh-automation.md", + "uuid": "34f3d979-a040-49ca-bfcb-35cf17473a06", + "parent_id": "NET-WP-0020", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0020-T04", + "status": "done", + "title": "T4 \u2014 Auto-unseal transit profile", + "source_path": "workplans/NET-WP-0020-openbao-unseal-custody-and-ssh-automation.md", + "uuid": "54ab6505-c13b-4f63-8c94-07dd202de90a", + "parent_id": "NET-WP-0020", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0020-T05", + "status": "done", + "title": "T5 \u2014 SSH engine + host CA automation (cross-repo)", + "source_path": "workplans/NET-WP-0020-openbao-unseal-custody-and-ssh-automation.md", + "uuid": "399e82ca-6551-4020-8db5-c78076e75cfc", + "parent_id": "NET-WP-0020", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0009", + "status": "backlog", + "title": "NetKingdom Security Pattern Tutorials", + "source_path": "workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md", + "uuid": "66c9f1e9-6b2f-454b-a6d4-04e5fe42385a", + "parent_id": null, + "extra": { + "depends_on": [ + "NK-WP-0008" + ] + } + }, + { + "kind": "task", + "id": "NK-WP-0009-T01", + "status": "todo", + "title": "Tasks", + "source_path": "workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md", + "uuid": "79150b07-f25d-4407-a118-e08b6e588d37", + "parent_id": "NK-WP-0009", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0009-T02", + "status": "todo", + "title": "Tasks", + "source_path": "workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md", + "uuid": "07647ba6-90e1-4569-947a-ebccce7a2d5e", + "parent_id": "NK-WP-0009", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0009-T03", + "status": "todo", + "title": "Tasks", + "source_path": "workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md", + "uuid": "0f34eda3-f1f3-4c49-9eba-36167b6c5ea9", + "parent_id": "NK-WP-0009", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0009-T04", + "status": "todo", + "title": "Tasks", + "source_path": "workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md", + "uuid": "3c17d1ac-3232-43b4-b541-ea6538da2afb", + "parent_id": "NK-WP-0009", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0009-T05", + "status": "todo", + "title": "Tasks", + "source_path": "workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md", + "uuid": "aff82173-0b8e-4216-855a-887ac68b63e0", + "parent_id": "NK-WP-0009", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0009-T06", + "status": "todo", + "title": "Tasks", + "source_path": "workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md", + "uuid": "df427aa3-233f-4479-aed9-706676f8e87d", + "parent_id": "NK-WP-0009", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0011", + "status": "backlog", + "title": "Enterprise Federation & SAML \u2014 Expanded-Mode Keycloak Identity Broker", + "source_path": "workplans/NK-WP-0011-enterprise-federation-saml.md", + "uuid": "a44beef8-c18b-4ae7-b7fe-a178cc4fcdf0", + "parent_id": null, + "extra": { + "depends_on": [ + "NK-WP-0003", + "NK-WP-0004", + "NK-WP-0006" + ] + } + }, + { + "kind": "task", + "id": "NK-WP-0011-T01", + "status": "todo", + "title": "Tasks", + "source_path": "workplans/NK-WP-0011-enterprise-federation-saml.md", + "uuid": "934f9223-2b6f-4d01-b49b-406b5b98b6e4", + "parent_id": "NK-WP-0011", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0011-T02", + "status": "todo", + "title": "Tasks", + "source_path": "workplans/NK-WP-0011-enterprise-federation-saml.md", + "uuid": "7b514cda-41b3-492f-8731-5a131422059d", + "parent_id": "NK-WP-0011", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0011-T03", + "status": "todo", + "title": "Tasks", + "source_path": "workplans/NK-WP-0011-enterprise-federation-saml.md", + "uuid": "8c29602e-ab9b-446a-8fee-5e2d8fbcb100", + "parent_id": "NK-WP-0011", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0011-T04", + "status": "todo", + "title": "Tasks", + "source_path": "workplans/NK-WP-0011-enterprise-federation-saml.md", + "uuid": "d62d7683-24b1-458c-9fd6-96e576b52a64", + "parent_id": "NK-WP-0011", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0011-T05", + "status": "todo", + "title": "Tasks", + "source_path": "workplans/NK-WP-0011-enterprise-federation-saml.md", + "uuid": "85319768-5d81-460d-89dc-8de76b63e0dc", + "parent_id": "NK-WP-0011", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0011-T06", + "status": "todo", + "title": "Tasks", + "source_path": "workplans/NK-WP-0011-enterprise-federation-saml.md", + "uuid": "53801dc2-7bdb-4fa3-9fa0-c1450ef1003b", + "parent_id": "NK-WP-0011", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0011-T07", + "status": "todo", + "title": "Tasks", + "source_path": "workplans/NK-WP-0011-enterprise-federation-saml.md", + "uuid": "981f79bd-63ee-4da0-8d7d-9af8e468715e", + "parent_id": "NK-WP-0011", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0011-T08", + "status": "todo", + "title": "Tasks", + "source_path": "workplans/NK-WP-0011-enterprise-federation-saml.md", + "uuid": "13634760-7817-40c0-b7db-5e0f4196dbf0", + "parent_id": "NK-WP-0011", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0021", + "status": "finished", + "title": "Activity-core ops/Temporal UI least-privilege SSO", + "source_path": "workplans/NK-WP-0021-activity-core-ops-sso-operators.md", + "uuid": "eba95b9e-372c-5efd-b69a-870f11582149", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0021-T01", + "status": "done", + "title": "T01 \u2014 LLDAP group `activity-core-operators` in bootstrap", + "source_path": "workplans/NK-WP-0021-activity-core-ops-sso-operators.md", + "uuid": "4b4a93fc-ad63-59ae-9658-ad59c2a2bfbb", + "parent_id": "NK-WP-0021", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0021-T02", + "status": "done", + "title": "T02 \u2014 Operator membership runbook", + "source_path": "workplans/NK-WP-0021-activity-core-ops-sso-operators.md", + "uuid": "032d6d66-20bc-52e8-8490-aa3a77275ad0", + "parent_id": "NK-WP-0021", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0021-T03", + "status": "done", + "title": "T03 \u2014 Authelia domain rules for activity + temporal hosts", + "source_path": "workplans/NK-WP-0021-activity-core-ops-sso-operators.md", + "uuid": "17543b91-39aa-5b03-971c-b696f8f36489", + "parent_id": "NK-WP-0021", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0021-T04", + "status": "done", + "title": "T04 \u2014 Live apply and verification matrix", + "source_path": "workplans/NK-WP-0021-activity-core-ops-sso-operators.md", + "uuid": "0bbdf44c-283a-57be-8bd4-4b8b42b39803", + "parent_id": "NK-WP-0021", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0021-T05", + "status": "done", + "title": "T05 \u2014 Close loop with intakes and activity-core", + "source_path": "workplans/NK-WP-0021-activity-core-ops-sso-operators.md", + "uuid": "327c4a7c-94a6-50cd-8f36-7a452428a70d", + "parent_id": "NK-WP-0021", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0022", + "status": "blocked", + "title": "Cut over NetKingdom identity to railiance01 and retire CoulombCore", + "source_path": "workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md", + "uuid": "d76ddccc-00c8-548a-b141-2cd660fa38da", + "parent_id": null, + "extra": { + "depends_on": [ + "USER-WP-0020", + "NK-WP-0023", + "KEY-WP-0004" + ] + } + }, + { + "kind": "task", + "id": "NK-WP-0022-T01", + "status": "done", + "title": "T01 - Freeze the migration contract and inventory both stacks", + "source_path": "workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md", + "uuid": "244ef874-8ee4-5969-bcbf-42a7cb47f246", + "parent_id": "NK-WP-0022", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0022-T02", + "status": "done", + "title": "T02 - Prove recoverable backups before changing state", + "source_path": "workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md", + "uuid": "12658d0f-eee9-5553-92b6-956ccde094bf", + "parent_id": "NK-WP-0022", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0022-T03", + "status": "done", + "title": "T03 - Reconcile persistent identity state onto railiance01", + "source_path": "workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md", + "uuid": "642cec3f-fd96-5c05-a37a-8696ed118811", + "parent_id": "NK-WP-0022", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0022-T04", + "status": "done", + "title": "T04 - Align configuration, secrets, and internal dependencies", + "source_path": "workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md", + "uuid": "8aab3b5d-ec9e-5bc0-a884-ee418e78d5f4", + "parent_id": "NK-WP-0022", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0022-T05", + "status": "done", + "title": "T05 - Run full pre-cutover identity conformance", + "source_path": "workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md", + "uuid": "a66acc29-33a7-5c20-8816-c3acedd6595d", + "parent_id": "NK-WP-0022", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0022-T06", + "status": "done", + "title": "T06 - Cut over remaining DNS with monitored rollback", + "source_path": "workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md", + "uuid": "fc9ed5fb-fd5c-5b04-990b-5a5b7f32fa0f", + "parent_id": "NK-WP-0022", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0022-T07", + "status": "done", + "title": "T07 - Retire CoulombCore identity workloads reversibly", + "source_path": "workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md", + "uuid": "2a6d4c0b-2565-5bf5-9c04-1b63e992ce99", + "parent_id": "NK-WP-0022", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0022-T08", + "status": "wait", + "title": "T08 - Final deletion and closure", + "source_path": "workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md", + "uuid": "42a3b4c0-3481-5cfa-bdc2-66d05e751829", + "parent_id": "NK-WP-0022", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0023", + "status": "finished", + "title": "Integrate and deploy the user-engine onboarding portal", + "source_path": "workplans/NK-WP-0023-user-engine-portal-platform-integration.md", + "uuid": "fdb3deee-06c3-5d12-91ce-9c50b2ac0618", + "parent_id": null, + "extra": { + "depends_on": [ + "USER-WP-0020", + "KEY-WP-0004" + ] + } + }, + { + "kind": "task", + "id": "NK-WP-0023-T01", + "status": "done", + "title": "T01 - Define source-of-truth and provisioning contracts", + "source_path": "workplans/NK-WP-0023-user-engine-portal-platform-integration.md", + "uuid": "05d69347-ec34-59b7-a107-80db015ef0e6", + "parent_id": "NK-WP-0023", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0023-T02", + "status": "done", + "title": "T02 - Implement the NetKingdom identity provisioning adapter", + "source_path": "workplans/NK-WP-0023-user-engine-portal-platform-integration.md", + "uuid": "22113719-905b-54df-9ecb-0a0c456e0d35", + "parent_id": "NK-WP-0023", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0023-T03", + "status": "done", + "title": "T03 - Integrate KeyCape login, claims, and MFA handoffs", + "source_path": "workplans/NK-WP-0023-user-engine-portal-platform-integration.md", + "uuid": "5721c5f9-6161-522c-a439-95f2613b5460", + "parent_id": "NK-WP-0023", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0023-T04", + "status": "done", + "title": "T04 - Integrate authorization, email, audit, and events", + "source_path": "workplans/NK-WP-0023-user-engine-portal-platform-integration.md", + "uuid": "efad8829-5d75-5ea1-9564-1618b1846525", + "parent_id": "NK-WP-0023", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0023-T05", + "status": "done", + "title": "T05 - Deploy on reef-railiance", + "source_path": "workplans/NK-WP-0023-user-engine-portal-platform-integration.md", + "uuid": "0c454447-c14f-586b-835b-4f00d43943d0", + "parent_id": "NK-WP-0023", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0023-T06", + "status": "done", + "title": "T06 - Prove role-scoped administration and failure safety", + "source_path": "workplans/NK-WP-0023-user-engine-portal-platform-integration.md", + "uuid": "f5f0d5d0-09fa-59de-b83f-7a6d4ff736a8", + "parent_id": "NK-WP-0023", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0023-T07", + "status": "done", + "title": "T07 - Complete KEY-WP-0004 through the reusable portal", + "source_path": "workplans/NK-WP-0023-user-engine-portal-platform-integration.md", + "uuid": "04664946-c38d-50e8-bc3f-5533801494d8", + "parent_id": "NK-WP-0023", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0023-T08", + "status": "done", + "title": "T08 - Document enterprise integration extension points", + "source_path": "workplans/NK-WP-0023-user-engine-portal-platform-integration.md", + "uuid": "83a00e26-aab9-51f1-afb4-cb5d354ab436", + "parent_id": "NK-WP-0023", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0024", + "status": "finished", + "title": "Expand user-engine platform integrations beyond the Binky MVP", + "source_path": "workplans/NK-WP-0024-user-engine-portal-integration-expansion.md", + "uuid": "635a73d4-b3cb-5c38-af22-56a6a66beb0e", + "parent_id": null, + "extra": { + "depends_on": [ + "NK-WP-0023", + "USER-WP-0021", + "FLEX-WP-0009", + "AUDIT-WP-0003", + "EMAIL-WP-0004" + ] + } + }, + { + "kind": "task", + "id": "NK-WP-0024-T01", + "status": "done", + "title": "T01 - Establish flex-auth production authorization", + "source_path": "workplans/NK-WP-0024-user-engine-portal-integration-expansion.md", + "uuid": "4bad414d-b0c1-52df-914f-cdc602192124", + "parent_id": "NK-WP-0024", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0024-T02", + "status": "done", + "title": "T02 - Add invitation and verification mail delivery", + "source_path": "workplans/NK-WP-0024-user-engine-portal-integration-expansion.md", + "uuid": "88098a55-f2ca-5636-9a98-ae8a98cdeaf4", + "parent_id": "NK-WP-0024", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0024-T03", + "status": "done", + "title": "T03 - Operate durable event delivery", + "source_path": "workplans/NK-WP-0024-user-engine-portal-integration-expansion.md", + "uuid": "59d3a6b5-7b9a-52a5-adc1-dd9fe74e3eba", + "parent_id": "NK-WP-0024", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0024-T04", + "status": "done", + "title": "T04 - Run expanded integration failure matrix", + "source_path": "workplans/NK-WP-0024-user-engine-portal-integration-expansion.md", + "uuid": "68eb8659-acd9-5188-bd12-b67fb18c6144", + "parent_id": "NK-WP-0024", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0025", + "status": "finished", + "title": "Provide NetKingdom self-registration and application first-login provisioning", + "source_path": "workplans/NK-WP-0025-public-self-registration-and-application-jit.md", + "uuid": "2412a251-d6b5-5f05-8082-3eb7697c51dc", + "parent_id": null, + "extra": { + "depends_on": [ + "NK-WP-0024", + "USER-WP-0022", + "KEY-WP-0008", + "CSOC-WP-0003" + ] + } + }, + { + "kind": "task", + "id": "NK-WP-0025-T01", + "status": "done", + "title": "T01 - Ratify identity and account-linking semantics", + "source_path": "workplans/NK-WP-0025-public-self-registration-and-application-jit.md", + "uuid": "f6fba00e-1fb6-59be-9b9a-242aed991892", + "parent_id": "NK-WP-0025", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0025-T02", + "status": "done", + "title": "T02 - Provide secure LLDAP self-registration orchestration", + "source_path": "workplans/NK-WP-0025-public-self-registration-and-application-jit.md", + "uuid": "b0d7ac51-54ae-508b-b62d-8ac8dff34497", + "parent_id": "NK-WP-0025", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0025-T03", + "status": "done", + "title": "T03 - Integrate registration entry points and return flow", + "source_path": "workplans/NK-WP-0025-public-self-registration-and-application-jit.md", + "uuid": "ed93741b-8bb7-5b37-b5c5-a06e7f826735", + "parent_id": "NK-WP-0025", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0025-T04", + "status": "done", + "title": "T04 - Apply optional MFA policy safely", + "source_path": "workplans/NK-WP-0025-public-self-registration-and-application-jit.md", + "uuid": "2b9a60cc-44a2-5874-8e7e-21db96da88f0", + "parent_id": "NK-WP-0025", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0025-T05", + "status": "done", + "title": "T05 - Prove both cases end to end", + "source_path": "workplans/NK-WP-0025-public-self-registration-and-application-jit.md", + "uuid": "68bf6fe7-7b68-5189-ad1c-4ba5e0d0ad6e", + "parent_id": "NK-WP-0025", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0026", + "status": "finished", + "title": "Promote user-engine workload identity to flex-auth", + "source_path": "workplans/NK-WP-0026-flex-auth-caller-identity-rollout.md", + "uuid": "3e8965aa-494a-5dcf-a11d-b768c196c548", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0026-T01", + "status": "done", + "title": "NK-WP-0026 \u2014 user-engine caller identity rollout", + "source_path": "workplans/NK-WP-0026-flex-auth-caller-identity-rollout.md", + "uuid": "294eb50e-2d54-59f1-a793-d10e53e33020", + "parent_id": "NK-WP-0026", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0026-T02", + "status": "done", + "title": "NK-WP-0026 \u2014 user-engine caller identity rollout", + "source_path": "workplans/NK-WP-0026-flex-auth-caller-identity-rollout.md", + "uuid": "d24461e9-c378-58ac-97ed-60ad6e563d47", + "parent_id": "NK-WP-0026", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0027", + "status": "blocked", + "title": "Reconcile reef placement and security-zone canon dependencies", + "source_path": "workplans/NK-WP-0027-reef-placement-reconciliation.md", + "uuid": "965ad365-6b81-50a1-a2a3-2d0c1fcce0b4", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0027-T01", + "status": "done", + "title": "T01 \u2014 Establish the reef and `P` boundary", + "source_path": "workplans/NK-WP-0027-reef-placement-reconciliation.md", + "uuid": "d88714a4-0bcb-567e-8542-d5b4c556b8ec", + "parent_id": "NK-WP-0027", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0027-T02", + "status": "wait", + "title": "T02 \u2014 Extend provider declarations to reefs", + "source_path": "workplans/NK-WP-0027-reef-placement-reconciliation.md", + "uuid": "5b35b646-a525-55da-852a-6005613d42ea", + "parent_id": "NK-WP-0027", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0027-T03", + "status": "wait", + "title": "T03 \u2014 Reconcile reef ceilings mechanically", + "source_path": "workplans/NK-WP-0027-reef-placement-reconciliation.md", + "uuid": "e3f0bb0f-0c85-5cb9-a5ab-75f668cd3447", + "parent_id": "NK-WP-0027", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0027-T04", + "status": "done", + "title": "T04 \u2014 Rule on zone policy subject and absence", + "source_path": "workplans/NK-WP-0027-reef-placement-reconciliation.md", + "uuid": "132658cb-5ea0-528c-86e2-095254c36cd7", + "parent_id": "NK-WP-0027", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0027-T05", + "status": "done", + "title": "T05 \u2014 Broaden workload declaration coverage", + "source_path": "workplans/NK-WP-0027-reef-placement-reconciliation.md", + "uuid": "d60e209d-3090-59e7-afc4-0a3780507403", + "parent_id": "NK-WP-0027", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0027-T06", + "status": "wait", + "title": "T06 \u2014 Resolve the `DataClassification` mismatch", + "source_path": "workplans/NK-WP-0027-reef-placement-reconciliation.md", + "uuid": "bf8b3e1d-7ee0-5ad0-8705-5a580a9fb546", + "parent_id": "NK-WP-0027", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0028", + "status": "finished", + "title": "Publish zone canon and clarify tenant grouping semantics", + "source_path": "workplans/NK-WP-0028-canon-publication-and-grouping-semantics.md", + "uuid": "869a6cfe-60e3-52af-8fad-895e3204a9e8", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0028-T01", + "status": "done", + "title": "Publish and integrate Security Zones v0.1", + "source_path": "workplans/NK-WP-0028-canon-publication-and-grouping-semantics.md", + "uuid": "e2fb5fe9-0453-5a7b-b619-7001ccf4d345", + "parent_id": "NK-WP-0028", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0028-T02", + "status": "done", + "title": "Clarify current grouping versus historical identifier segment", + "source_path": "workplans/NK-WP-0028-canon-publication-and-grouping-semantics.md", + "uuid": "320bde34-ca8e-5e69-894f-f8c64f63d3f2", + "parent_id": "NK-WP-0028", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0028-T03", + "status": "done", + "title": "Add publication metadata and ignore generated architecture cache", + "source_path": "workplans/NK-WP-0028-canon-publication-and-grouping-semantics.md", + "uuid": "1016e683-f247-5029-b7da-d5289d10dba3", + "parent_id": "NK-WP-0028", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0028-T04", + "status": "done", + "title": "Verification", + "source_path": "workplans/NK-WP-0028-canon-publication-and-grouping-semantics.md", + "uuid": "339bcd81-484a-5040-831c-fea5b8c74bf0", + "parent_id": "NK-WP-0028", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0029", + "status": "finished", + "title": "Reconcile repository scope with implemented capability and intent", + "source_path": "workplans/NK-WP-0029-scope-and-intent-reconciliation.md", + "uuid": "065d7911-c41d-5021-b77b-d414fecbfa4c", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0029-T01", + "status": "done", + "title": "Inventory current capability and authority", + "source_path": "workplans/NK-WP-0029-scope-and-intent-reconciliation.md", + "uuid": "6d4d47ac-838a-5b04-9929-ecb558646a2c", + "parent_id": "NK-WP-0029", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0029-T02", + "status": "done", + "title": "Rewrite repository scope", + "source_path": "workplans/NK-WP-0029-scope-and-intent-reconciliation.md", + "uuid": "79d392fc-46da-5248-b1b7-59601921a35e", + "parent_id": "NK-WP-0029", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0029-T03", + "status": "done", + "title": "Assess current scope against intent", + "source_path": "workplans/NK-WP-0029-scope-and-intent-reconciliation.md", + "uuid": "cc7bea86-e149-55cb-b8d8-2f7e936a26de", + "parent_id": "NK-WP-0029", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0029-T04", + "status": "done", + "title": "Verify and reconcile records", + "source_path": "workplans/NK-WP-0029-scope-and-intent-reconciliation.md", + "uuid": "1cee140f-081c-563d-b157-8079b12d2f26", + "parent_id": "NK-WP-0029", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0030", + "status": "finished", + "title": "Implement deterministic security scenario composition", + "source_path": "workplans/NK-WP-0030-deterministic-security-scenario-composition.md", + "uuid": "8a884593-b7f9-508a-9e15-bfd901463ac1", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0030-T01", + "status": "done", + "title": "Define the scenario composition contract", + "source_path": "workplans/NK-WP-0030-deterministic-security-scenario-composition.md", + "uuid": "c071698f-6a5a-5845-9f22-042d100f3958", + "parent_id": "NK-WP-0030", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0030-T02", + "status": "done", + "title": "Implement the canonical composer", + "source_path": "workplans/NK-WP-0030-deterministic-security-scenario-composition.md", + "uuid": "0372da5c-83ee-5e03-bb45-5cae81e5330b", + "parent_id": "NK-WP-0030", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0030-T03", + "status": "done", + "title": "Publish a C0 reference composition", + "source_path": "workplans/NK-WP-0030-deterministic-security-scenario-composition.md", + "uuid": "99392b0f-c0a4-5abd-afdb-ef15c964ae1f", + "parent_id": "NK-WP-0030", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0030-T04", + "status": "done", + "title": "Obtain lightweight-provider declarations", + "source_path": "workplans/NK-WP-0030-deterministic-security-scenario-composition.md", + "uuid": "41fd145d-7a37-5c65-ae72-142ac6d49144", + "parent_id": "NK-WP-0030", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0030-T05", + "status": "done", + "title": "Verify the fail-closed and reference paths", + "source_path": "workplans/NK-WP-0030-deterministic-security-scenario-composition.md", + "uuid": "7db26092-35c4-52c6-9a3e-3f24bc3e26c7", + "parent_id": "NK-WP-0030", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0031", + "status": "blocked", + "title": "Implement deterministic posture and evidence feedback", + "source_path": "workplans/NK-WP-0031-deterministic-posture-feedback.md", + "uuid": "9d7b04f9-3803-5613-b7a5-8bd606c77f5a", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0031-T01", + "status": "done", + "title": "Define freshness, owner, and proposal semantics", + "source_path": "workplans/NK-WP-0031-deterministic-posture-feedback.md", + "uuid": "917f8856-091e-59f9-b9e4-71a8c9a0d029", + "parent_id": "NK-WP-0031", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0031-T02", + "status": "done", + "title": "Implement the posture feedback evaluator", + "source_path": "workplans/NK-WP-0031-deterministic-posture-feedback.md", + "uuid": "63486c21-2ca2-5930-bc27-f8acde3eec8f", + "parent_id": "NK-WP-0031", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0031-T03", + "status": "done", + "title": "Publish reference workflow and tests", + "source_path": "workplans/NK-WP-0031-deterministic-posture-feedback.md", + "uuid": "0372c168-b34d-5ad5-8315-be3af74758de", + "parent_id": "NK-WP-0031", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0031-T04", + "status": "wait", + "title": "Obtain audit-core freshness adoption", + "source_path": "workplans/NK-WP-0031-deterministic-posture-feedback.md", + "uuid": "7d2029d2-db8d-526e-ab73-a0751becb193", + "parent_id": "NK-WP-0031", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0031-T05", + "status": "done", + "title": "Verify and reconcile", + "source_path": "workplans/NK-WP-0031-deterministic-posture-feedback.md", + "uuid": "b646e6a0-20ba-5377-a3d1-7ae92eb9e936", + "parent_id": "NK-WP-0031", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0032", + "status": "blocked", + "title": "Admit the operator-tunneled OpenBao browser callback", + "source_path": "workplans/NK-WP-0032-openbao-operator-loopback-callback.md", + "uuid": "516ee5b9-685b-5986-88d2-bde66c2ba96c", + "parent_id": null, + "extra": { + "related": [ + "RMASTER-WP-0020-T09", + "RAILIANCE-WP-0027-T03" + ] + } + }, + { + "kind": "task", + "id": "NK-WP-0032-T01", + "status": "done", + "title": "T01 \u2014 Update and validate the code-defined callback contract", + "source_path": "workplans/NK-WP-0032-openbao-operator-loopback-callback.md", + "uuid": "f231077e-7440-5f20-9045-afab90fa8286", + "parent_id": "NK-WP-0032", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0032-T02", + "status": "done", + "title": "T02 \u2014 Apply and prove the live KeyCape client addition", + "source_path": "workplans/NK-WP-0032-openbao-operator-loopback-callback.md", + "uuid": "360bc410-d7ed-53b6-b5fc-2ce8b37b653f", + "parent_id": "NK-WP-0032", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0032-T03", + "status": "wait", + "title": "T03 \u2014 Apply and prove the live OpenBao role addition", + "source_path": "workplans/NK-WP-0032-openbao-operator-loopback-callback.md", + "uuid": "73b77110-2d4f-527e-98eb-2ec33897681e", + "parent_id": "NK-WP-0032", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0032-T04", + "status": "wait", + "title": "T04 \u2014 Return attended-login evidence to Railiance Platform", + "source_path": "workplans/NK-WP-0032-openbao-operator-loopback-callback.md", + "uuid": "f62bda4a-7607-5c50-9e04-664cc1b829ac", + "parent_id": "NK-WP-0032", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0033", + "status": "active", + "title": "Contain and rotate the exposed KeyCape credential bundle", + "source_path": "workplans/NK-WP-0033-keycape-secret-exposure-rotation.md", + "uuid": "63665674-6880-593e-96e6-bab3211b1352", + "parent_id": null, + "extra": { + "related": [ + "NK-WP-0032" + ] + } + }, + { + "kind": "task", + "id": "NK-WP-0033-T01", + "status": "done", + "title": "T01 \u2014 Contain, classify, and route the exposure", + "source_path": "workplans/NK-WP-0033-keycape-secret-exposure-rotation.md", + "uuid": "28a655da-7cd6-58e2-8ca8-64d192de63a6", + "parent_id": "NK-WP-0033", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0033-T02", + "status": "done", + "title": "T02 \u2014 Agree the value-safe rotation and issuer-continuity contract", + "source_path": "workplans/NK-WP-0033-keycape-secret-exposure-rotation.md", + "uuid": "c5ca817c-d601-5172-a106-1546c0743635", + "parent_id": "NK-WP-0033", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0033-T03", + "status": "progress", + "title": "T03 \u2014 Implement a non-printing, non-stale rotation path", + "source_path": "workplans/NK-WP-0033-keycape-secret-exposure-rotation.md", + "uuid": "f0f6d6c3-9c45-56b7-9fd6-52fb0ea9054a", + "parent_id": "NK-WP-0033", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0033-T04", + "status": "done", + "title": "T04 \u2014 Execute the governed replacement cutover", + "source_path": "workplans/NK-WP-0033-keycape-secret-exposure-rotation.md", + "uuid": "751cca48-2bc9-5d44-80a0-60478717e99e", + "parent_id": "NK-WP-0033", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0033-T05", + "status": "progress", + "title": "T05 \u2014 Prove replacement, predecessor rejection, and cleanup", + "source_path": "workplans/NK-WP-0033-keycape-secret-exposure-rotation.md", + "uuid": "41e55d5c-ae28-5ee2-be25-b9a3758428f7", + "parent_id": "NK-WP-0033", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0034", + "status": "proposed", + "title": "Make the SSO/MFA verification actually verify", + "source_path": "workplans/NK-WP-0034-verification-that-verifies.md", + "uuid": "c87e142c-4eda-5c1b-84a9-ee5a848f3f63", + "parent_id": null, + "extra": { + "related": [ + "NK-WP-0033", + "CUST-ADR-012" + ] + } + }, + { + "kind": "task", + "id": "NK-WP-0034-T01", + "status": "todo", + "title": "Assert the property, not the objects", + "source_path": "workplans/NK-WP-0034-verification-that-verifies.md", + "uuid": "9b5d8034-0ef1-53f9-ad4d-37de536bdc62", + "parent_id": "NK-WP-0034", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0034-T02", + "status": "todo", + "title": "Audit the other verify scripts for the same shape", + "source_path": "workplans/NK-WP-0034-verification-that-verifies.md", + "uuid": "0bd09a40-8b4d-5f9d-8d4c-81c55aa0c565", + "parent_id": "NK-WP-0034", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0034-T03", + "status": "todo", + "title": "Label every attended procedure with its exercise status", + "source_path": "workplans/NK-WP-0034-verification-that-verifies.md", + "uuid": "becb4dce-4971-5755-888f-5276c4a56fe7", + "parent_id": "NK-WP-0034", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0034-T04", + "status": "todo", + "title": "One helper per API", + "source_path": "workplans/NK-WP-0034-verification-that-verifies.md", + "uuid": "d43ae8e8-eda6-5c1d-9e1b-01966b0e92da", + "parent_id": "NK-WP-0034", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0015", + "status": "archived", + "title": "User Engine Isolated MVP", + "source_path": "workplans/archived/260522-NK-WP-0015-user-engine-isolated-mvp.md", + "uuid": "343e035d-41e1-4fc4-b209-6872e4a5fdc8", + "parent_id": null, + "extra": { + "depends_on": [ + "NK-WP-0014" + ] + } + }, + { + "kind": "task", + "id": "NK-WP-0015-T1", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0015-user-engine-isolated-mvp.md", + "uuid": "81a88eaa-df2e-4b9f-85f4-a1570c9c9f86", + "parent_id": "NK-WP-0015", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0015-T2", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0015-user-engine-isolated-mvp.md", + "uuid": "fc4172f7-e7f1-4ad9-98c3-37ccb08c7386", + "parent_id": "NK-WP-0015", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0015-T3", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0015-user-engine-isolated-mvp.md", + "uuid": "8aa5a9e9-3f23-4124-aa3b-01c099ce88bc", + "parent_id": "NK-WP-0015", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0015-T4", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0015-user-engine-isolated-mvp.md", + "uuid": "cedd6319-e4c2-460c-888c-d0d95d7bdbef", + "parent_id": "NK-WP-0015", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0015-T5", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0015-user-engine-isolated-mvp.md", + "uuid": "62ecafaa-237a-4cae-ac78-1ed79ca881a1", + "parent_id": "NK-WP-0015", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0015-T6", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0015-user-engine-isolated-mvp.md", + "uuid": "d627db12-2019-4870-a255-354fc77a1d22", + "parent_id": "NK-WP-0015", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0015-T7", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0015-user-engine-isolated-mvp.md", + "uuid": "803e979d-a83a-43d8-a93d-ce97c83015ec", + "parent_id": "NK-WP-0015", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0016", + "status": "archived", + "title": "User Engine Multi-Tenancy", + "source_path": "workplans/archived/260522-NK-WP-0016-user-engine-multi-tenancy.md", + "uuid": "2d592e18-e63d-4856-97a1-f8c3e019e150", + "parent_id": null, + "extra": { + "depends_on": [ + "NK-WP-0015" + ] + } + }, + { + "kind": "task", + "id": "NK-WP-0016-T1", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0016-user-engine-multi-tenancy.md", + "uuid": "d4bb49a9-dffe-4317-aea2-761d737c5627", + "parent_id": "NK-WP-0016", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0016-T2", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0016-user-engine-multi-tenancy.md", + "uuid": "4a9083c0-f0bd-4dad-b221-c4563ed53209", + "parent_id": "NK-WP-0016", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0016-T3", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0016-user-engine-multi-tenancy.md", + "uuid": "4fd57616-53dc-4c10-bf95-553319186005", + "parent_id": "NK-WP-0016", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0016-T4", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0016-user-engine-multi-tenancy.md", + "uuid": "dc0fc00a-5228-4b99-9fa1-6a7f6b557aac", + "parent_id": "NK-WP-0016", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0016-T5", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0016-user-engine-multi-tenancy.md", + "uuid": "17460786-7af0-4e67-8169-80c2c29934e6", + "parent_id": "NK-WP-0016", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0016-T6", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0016-user-engine-multi-tenancy.md", + "uuid": "a899832f-63e6-4417-bc1d-ca3c5ea89061", + "parent_id": "NK-WP-0016", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0016-T7", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0016-user-engine-multi-tenancy.md", + "uuid": "187cdc5d-7cba-432e-8201-34bb437ba8e8", + "parent_id": "NK-WP-0016", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0017", + "status": "archived", + "title": "User Engine Multi-Application And Catalog Support", + "source_path": "workplans/archived/260522-NK-WP-0017-user-engine-multi-application-catalogs.md", + "uuid": "08398d26-cadf-44bc-97ee-67da790040e6", + "parent_id": null, + "extra": { + "depends_on": [ + "NK-WP-0015" + ] + } + }, + { + "kind": "task", + "id": "NK-WP-0017-T1", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0017-user-engine-multi-application-catalogs.md", + "uuid": "9363492d-49af-4929-bb64-576ed8c47ddb", + "parent_id": "NK-WP-0017", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0017-T2", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0017-user-engine-multi-application-catalogs.md", + "uuid": "cd9dff26-d570-4f9f-9ebf-6f20eddf3ef0", + "parent_id": "NK-WP-0017", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0017-T3", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0017-user-engine-multi-application-catalogs.md", + "uuid": "6bbe4250-a6e7-4ecf-b916-7e79eddd76f6", + "parent_id": "NK-WP-0017", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0017-T4", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0017-user-engine-multi-application-catalogs.md", + "uuid": "29012ed5-f6c2-455f-8999-037a653d14e1", + "parent_id": "NK-WP-0017", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0017-T5", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0017-user-engine-multi-application-catalogs.md", + "uuid": "a3226c20-1278-409e-a49d-965e4783dc7a", + "parent_id": "NK-WP-0017", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0017-T6", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0017-user-engine-multi-application-catalogs.md", + "uuid": "ada5a9f5-19f6-4e9e-a176-b1b47ec36ca7", + "parent_id": "NK-WP-0017", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0017-T7", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0017-user-engine-multi-application-catalogs.md", + "uuid": "09f38d5c-af6c-4d95-a570-e5a5c25d7cfe", + "parent_id": "NK-WP-0017", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0018", + "status": "archived", + "title": "User Engine Integrated Test Scenarios", + "source_path": "workplans/archived/260522-NK-WP-0018-user-engine-integrated-test-scenarios.md", + "uuid": "6f75035a-e056-4eab-8fdb-00a18bacdf87", + "parent_id": null, + "extra": { + "depends_on": [ + "NK-WP-0016", + "NK-WP-0017" + ] + } + }, + { + "kind": "task", + "id": "NK-WP-0018-T1", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0018-user-engine-integrated-test-scenarios.md", + "uuid": "6da86ef6-ea8b-49b9-8897-cbed00f6e61d", + "parent_id": "NK-WP-0018", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0018-T2", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0018-user-engine-integrated-test-scenarios.md", + "uuid": "e3424148-90d6-4c43-8f15-988f2a21d166", + "parent_id": "NK-WP-0018", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0018-T3", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0018-user-engine-integrated-test-scenarios.md", + "uuid": "23fa4617-e7ce-4cdc-b753-489ec361757b", + "parent_id": "NK-WP-0018", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0018-T4", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0018-user-engine-integrated-test-scenarios.md", + "uuid": "33c53479-7856-42ee-b9ee-8795aa73c39a", + "parent_id": "NK-WP-0018", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0018-T5", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0018-user-engine-integrated-test-scenarios.md", + "uuid": "fc2d73e4-1f45-4891-9c31-1a4dc2f3a002", + "parent_id": "NK-WP-0018", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0018-T6", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0018-user-engine-integrated-test-scenarios.md", + "uuid": "26b63aa0-deb6-4b4d-9388-6b7e531bd4ff", + "parent_id": "NK-WP-0018", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0018-T7", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0018-user-engine-integrated-test-scenarios.md", + "uuid": "a46e6e78-71a1-4518-881f-85b39269f4a8", + "parent_id": "NK-WP-0018", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0019", + "status": "archived", + "title": "User Engine Implementation Assessment And Polish", + "source_path": "workplans/archived/260522-NK-WP-0019-user-engine-finalization-polish.md", + "uuid": "d2daa8b4-8ecf-4377-b382-492e653735f7", + "parent_id": null, + "extra": { + "depends_on": [ + "NK-WP-0018" + ] + } + }, + { + "kind": "task", + "id": "NK-WP-0019-T1", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0019-user-engine-finalization-polish.md", + "uuid": "116b5362-ebbf-4d21-83e8-bbc82e80a71a", + "parent_id": "NK-WP-0019", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0019-T2", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0019-user-engine-finalization-polish.md", + "uuid": "08bd8ca3-dd7e-41c9-b8d2-c9b7c72ceb0a", + "parent_id": "NK-WP-0019", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0019-T3", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0019-user-engine-finalization-polish.md", + "uuid": "b8ff89a1-cdfb-445a-ae4d-ca4fd4a455eb", + "parent_id": "NK-WP-0019", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0019-T4", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0019-user-engine-finalization-polish.md", + "uuid": "f57d87d7-fdc8-485c-ba93-86c5a8342f04", + "parent_id": "NK-WP-0019", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0019-T5", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0019-user-engine-finalization-polish.md", + "uuid": "42a01f4e-c646-4551-bd94-e122c9c16226", + "parent_id": "NK-WP-0019", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0019-T6", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0019-user-engine-finalization-polish.md", + "uuid": "7838d62b-94eb-437a-8418-7a900cde9716", + "parent_id": "NK-WP-0019", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0019-T7", + "status": "cancelled", + "title": "Tasks", + "source_path": "workplans/archived/260522-NK-WP-0019-user-engine-finalization-polish.md", + "uuid": "19569b30-c8df-441a-b815-c9217a82abaf", + "parent_id": "NK-WP-0019", + "extra": {} + }, + { + "kind": "workplan", + "id": "NET-WP-0015", + "status": "finished", + "title": "King Credential And OpenBao Identity Bootstrap", + "source_path": "workplans/archived/260603-NET-WP-0015-platform-root-custody-and-openbao-identity-bootstrap.md", + "uuid": "6b9c25e4-1008-429a-8de6-54361872c0dd", + "parent_id": null, + "extra": { + "depends_on": [ + "NK-WP-0006", + "NK-WP-0012" + ] + } + }, + { + "kind": "task", + "id": "NET-WP-0015-T01", + "status": "done", + "title": "T01 - Record Setup Operator And King Credential Model", + "source_path": "workplans/archived/260603-NET-WP-0015-platform-root-custody-and-openbao-identity-bootstrap.md", + "uuid": "60659e25-fed1-478e-b8a3-4bc7b2f3846b", + "parent_id": "NET-WP-0015", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0015-T02", + "status": "done", + "title": "T02 - Define King Credential Kit", + "source_path": "workplans/archived/260603-NET-WP-0015-platform-root-custody-and-openbao-identity-bootstrap.md", + "uuid": "1a1c45a2-be66-4667-89f8-581f4fe9970b", + "parent_id": "NET-WP-0015", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0015-T03", + "status": "done", + "title": "T03 - Approve King Custody Mode", + "source_path": "workplans/archived/260603-NET-WP-0015-platform-root-custody-and-openbao-identity-bootstrap.md", + "uuid": "56a6266a-4acd-41e6-a395-85e90a5c35c6", + "parent_id": "NET-WP-0015", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0015-T04", + "status": "done", + "title": "T04 - Complete Railiance OpenBao Bootstrap Ceremony", + "source_path": "workplans/archived/260603-NET-WP-0015-platform-root-custody-and-openbao-identity-bootstrap.md", + "uuid": "2102366e-064b-4071-8b6a-574d9d37d109", + "parent_id": "NET-WP-0015", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0015-T05", + "status": "done", + "title": "T05 - Provision First NetKingdom Admin Identity", + "source_path": "workplans/archived/260603-NET-WP-0015-platform-root-custody-and-openbao-identity-bootstrap.md", + "uuid": "d2a81d7b-9964-4bd5-9b8c-ef1324e02cd4", + "parent_id": "NET-WP-0015", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0015-T06", + "status": "done", + "title": "T06 - Bind OpenBao Admin Auth To NetKingdom IAM", + "source_path": "workplans/archived/260603-NET-WP-0015-platform-root-custody-and-openbao-identity-bootstrap.md", + "uuid": "ef97f3cb-9792-4b9d-bd2b-8871d368a50f", + "parent_id": "NET-WP-0015", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0015-T07", + "status": "done", + "title": "T07 - Verify Recovery, Audit, And Rotation", + "source_path": "workplans/archived/260603-NET-WP-0015-platform-root-custody-and-openbao-identity-bootstrap.md", + "uuid": "aa40cbb4-36d3-405d-b59d-0c21ae8c9539", + "parent_id": "NET-WP-0015", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0015-T08", + "status": "done", + "title": "T08 - Reset, Rotate, And Reopen Under King Oversight", + "source_path": "workplans/archived/260603-NET-WP-0015-platform-root-custody-and-openbao-identity-bootstrap.md", + "uuid": "e6a60dca-547b-4493-a36c-f6b668d1bf52", + "parent_id": "NET-WP-0015", + "extra": {} + }, + { + "kind": "workplan", + "id": "NET-WP-0016", + "status": "finished", + "title": "Guided Security Bootstrap Experience", + "source_path": "workplans/archived/260603-NET-WP-0016-guided-security-bootstrap-experience.md", + "uuid": "16069174-6698-4855-ad9e-5092c8571f38", + "parent_id": null, + "extra": { + "depends_on": [ + "NET-WP-0015", + "NK-WP-0012" + ] + } + }, + { + "kind": "task", + "id": "NET-WP-0016-T01", + "status": "done", + "title": "T01 - Define Bootstrap Use Cases", + "source_path": "workplans/archived/260603-NET-WP-0016-guided-security-bootstrap-experience.md", + "uuid": "67af8a29-7ca1-4a9d-be3e-bdc48dd2d1fd", + "parent_id": "NET-WP-0016", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0016-T02", + "status": "done", + "title": "T02 - Design The First Operator Journey", + "source_path": "workplans/archived/260603-NET-WP-0016-guided-security-bootstrap-experience.md", + "uuid": "662e439b-5fba-4e17-bc62-0ace97ba8788", + "parent_id": "NET-WP-0016", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0016-T03", + "status": "done", + "title": "T03 - Define King Credential Kit Output", + "source_path": "workplans/archived/260603-NET-WP-0016-guided-security-bootstrap-experience.md", + "uuid": "98aba75f-a7c1-4486-be7f-e8d1148d5303", + "parent_id": "NET-WP-0016", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0016-T04", + "status": "done", + "title": "T04 - Define User Lifecycle Flows", + "source_path": "workplans/archived/260603-NET-WP-0016-guided-security-bootstrap-experience.md", + "uuid": "44766b45-21b8-45cd-8c0a-0ca8281ae8e9", + "parent_id": "NET-WP-0016", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0016-T05", + "status": "done", + "title": "T05 - Define OpenBao Ceremony UX", + "source_path": "workplans/archived/260603-NET-WP-0016-guided-security-bootstrap-experience.md", + "uuid": "53f55c99-8403-4b58-9ed4-b03e68c1ef3c", + "parent_id": "NET-WP-0016", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0016-T06", + "status": "done", + "title": "T06 - Prototype Local Bootstrap Console", + "source_path": "workplans/archived/260603-NET-WP-0016-guided-security-bootstrap-experience.md", + "uuid": "ef1c8ee4-250c-479a-b0fb-0b5cf4249bd9", + "parent_id": "NET-WP-0016", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0016-T07", + "status": "done", + "title": "T07 - Define Handover And Cleanup Gates", + "source_path": "workplans/archived/260603-NET-WP-0016-guided-security-bootstrap-experience.md", + "uuid": "46c7e3dc-e824-46ef-833d-9a83189735e0", + "parent_id": "NET-WP-0016", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0016-T08", + "status": "done", + "title": "T08 - Review Related Workplans On Closeout", + "source_path": "workplans/archived/260603-NET-WP-0016-guided-security-bootstrap-experience.md", + "uuid": "7665f6ac-6b0e-4a09-8a9b-9d2150310114", + "parent_id": "NET-WP-0016", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0003", + "status": "completed", + "title": "KeyCape + privacyIDEA Stack \u2014 Cluster Deployment", + "source_path": "workplans/archived/260603-NK-WP-0003-keycape-privacyidea-cluster-deployment.md", + "uuid": "f24cefd4-a09b-4fa1-9b25-94bf783b425e", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0003-T01", + "status": "done", + "title": "T01 \u2014 Credential setup", + "source_path": "workplans/archived/260603-NK-WP-0003-keycape-privacyidea-cluster-deployment.md", + "uuid": "6a22e17e-5854-4f8b-b419-9dc86d490357", + "parent_id": "NK-WP-0003", + "extra": {} + }, + { + "kind": "task", + "id": null, + "status": null, + "title": "T02 \u2014 Apply cluster foundations", + "source_path": "workplans/archived/260603-NK-WP-0003-keycape-privacyidea-cluster-deployment.md", + "uuid": null, + "parent_id": "NK-WP-0003", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0003-T03", + "status": "done", + "title": "T03 \u2014 Deploy PostgreSQL (CloudNativePG)", + "source_path": "workplans/archived/260603-NK-WP-0003-keycape-privacyidea-cluster-deployment.md", + "uuid": "19e375d0-66bd-4cf0-9c2d-59d5c0d5989e", + "parent_id": "NK-WP-0003", + "extra": {} + }, + { + "kind": "task", + "id": null, + "status": null, + "title": "T04 \u2014 Deploy privacyIDEA", + "source_path": "workplans/archived/260603-NK-WP-0003-keycape-privacyidea-cluster-deployment.md", + "uuid": null, + "parent_id": "NK-WP-0003", + "extra": {} + }, + { + "kind": "task", + "id": null, + "status": null, + "title": "T05 \u2014 Deploy LLDAP", + "source_path": "workplans/archived/260603-NK-WP-0003-keycape-privacyidea-cluster-deployment.md", + "uuid": null, + "parent_id": "NK-WP-0003", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0003-T06", + "status": "done", + "title": "T06 \u2014 Deploy Authelia", + "source_path": "workplans/archived/260603-NK-WP-0003-keycape-privacyidea-cluster-deployment.md", + "uuid": "3a28ff10-fbfa-443b-a64d-bbfe6153c544", + "parent_id": "NK-WP-0003", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0003-T07", + "status": "done", + "title": "T07 \u2014 Deploy KeyCape", + "source_path": "workplans/archived/260603-NK-WP-0003-keycape-privacyidea-cluster-deployment.md", + "uuid": "496a97c9-3e2a-486e-ba62-18449868c6cf", + "parent_id": "NK-WP-0003", + "extra": {} + }, + { + "kind": "task", + "id": null, + "status": null, + "title": "T08 \u2014 End-to-end authentication test", + "source_path": "workplans/archived/260603-NK-WP-0003-keycape-privacyidea-cluster-deployment.md", + "uuid": null, + "parent_id": "NK-WP-0003", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0003-T08a", + "status": "done", + "title": "T08a \u2014 Create Cloudflare DNS A records", + "source_path": "workplans/archived/260603-NK-WP-0003-keycape-privacyidea-cluster-deployment.md", + "uuid": "c614f839-61c4-41f6-bfeb-b3f9525a7625", + "parent_id": "NK-WP-0003", + "extra": {} + }, + { + "kind": "task", + "id": null, + "status": null, + "title": "T08b \u2014 Install Go on RAILIANCE01", + "source_path": "workplans/archived/260603-NK-WP-0003-keycape-privacyidea-cluster-deployment.md", + "uuid": null, + "parent_id": "NK-WP-0003", + "extra": {} + }, + { + "kind": "task", + "id": null, + "status": null, + "title": "T09 \u2014 Backup, DR, and monitoring", + "source_path": "workplans/archived/260603-NK-WP-0003-keycape-privacyidea-cluster-deployment.md", + "uuid": null, + "parent_id": "NK-WP-0003", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0004", + "status": "done", + "title": "Credential Management Foundation", + "source_path": "workplans/archived/260603-NK-WP-0004-credential-management-foundation.md", + "uuid": "d9cf7c4b-886b-4cd1-ad7b-99c4e1929c9e", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0004-T01", + "status": "done", + "title": "T01 \u2014 SOPS integration", + "source_path": "workplans/archived/260603-NK-WP-0004-credential-management-foundation.md", + "uuid": "2340f2a3-9c11-44a8-b264-41d75b6dbc3e", + "parent_id": "NK-WP-0004", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0004-T02", + "status": "done", + "title": "T02 \u2014 Makefile: SOPS targets", + "source_path": "workplans/archived/260603-NK-WP-0004-credential-management-foundation.md", + "uuid": "f6ad469c-e1d3-4253-b855-e0554e43f612", + "parent_id": "NK-WP-0004", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0004-T03", + "status": "done", + "title": "T03 \u2014 Credential orchestrator: `creds-apply` ordering", + "source_path": "workplans/archived/260603-NK-WP-0004-credential-management-foundation.md", + "uuid": "4b386b92-8db9-440c-b116-52dbb2bd68cb", + "parent_id": "NK-WP-0004", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0004-T04", + "status": "done", + "title": "T04 \u2014 Credential state file", + "source_path": "workplans/archived/260603-NK-WP-0004-credential-management-foundation.md", + "uuid": "5bc125a7-ae42-40a3-864c-c356e5fc122d", + "parent_id": "NK-WP-0004", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0004-T05", + "status": "done", + "title": "T05 \u2014 git pre-commit hook + `check-secrets` gate", + "source_path": "workplans/archived/260603-NK-WP-0004-credential-management-foundation.md", + "uuid": "d8ea8fbf-ae89-4675-afba-958187ca37f1", + "parent_id": "NK-WP-0004", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0004-T06", + "status": "done", + "title": "T06 \u2014 Claude Code skill: `/creds-bootstrap`", + "source_path": "workplans/archived/260603-NK-WP-0004-credential-management-foundation.md", + "uuid": "b9ecbd3f-17f0-4c1d-97e5-84bfbb43d360", + "parent_id": "NK-WP-0004", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0004-T07", + "status": "done", + "title": "T07 \u2014 Secret rotation runbook", + "source_path": "workplans/archived/260603-NK-WP-0004-credential-management-foundation.md", + "uuid": "e27762d9-aa6a-4a7e-9c34-f8c546797548", + "parent_id": "NK-WP-0004", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0005", + "status": "done", + "title": "Agent-Driven Credential Bootstrap \u2014 Zero Human Ops", + "source_path": "workplans/archived/260603-NK-WP-0005-agent-driven-credential-bootstrap.md", + "uuid": "75bc472b-cc0a-48f2-afb6-62b896f7cc19", + "parent_id": null, + "extra": { + "depends_on": "NK-WP-0004" + } + }, + { + "kind": "task", + "id": "NK-WP-0005-T01", + "status": "done", + "title": "T01 \u2014 Redesign creds-state.yaml for agent mode", + "source_path": "workplans/archived/260603-NK-WP-0005-agent-driven-credential-bootstrap.md", + "uuid": "6748cf8d-a7c7-47a2-b32a-2e26e05c4cba", + "parent_id": "NK-WP-0005", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0005-T02", + "status": "done", + "title": "T02 \u2014 Agent bootstrap script: `creds-bootstrap-agent.sh`", + "source_path": "workplans/archived/260603-NK-WP-0005-agent-driven-credential-bootstrap.md", + "uuid": "22940c39-8645-40e1-b947-17e85ea6d902", + "parent_id": "NK-WP-0005", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0005-T03", + "status": "done", + "title": "T03 \u2014 Emergency bundle format and delivery", + "source_path": "workplans/archived/260603-NK-WP-0005-agent-driven-credential-bootstrap.md", + "uuid": "42ce1486-5322-4cf2-9c71-1c1c61db5f46", + "parent_id": "NK-WP-0005", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0005-T04", + "status": "done", + "title": "T04 \u2014 `/creds-init` Claude Code skill (autonomous)", + "source_path": "workplans/archived/260603-NK-WP-0005-agent-driven-credential-bootstrap.md", + "uuid": "ca713ce7-6f2c-4f0c-8b6c-88fc6e559190", + "parent_id": "NK-WP-0005", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0005-T05", + "status": "done", + "title": "T05 \u2014 Makefile: `creds-agent-init` target", + "source_path": "workplans/archived/260603-NK-WP-0005-agent-driven-credential-bootstrap.md", + "uuid": "ac5d887e-c499-4cf6-91e7-90e2e0e78d4a", + "parent_id": "NK-WP-0005", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0005-T06", + "status": "done", + "title": "T06 \u2014 Agent-driven rotation", + "source_path": "workplans/archived/260603-NK-WP-0005-agent-driven-credential-bootstrap.md", + "uuid": "2f0782f7-db5d-4b8a-920b-582548c4591f", + "parent_id": "NK-WP-0005", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0005-T07", + "status": "done", + "title": "T07 \u2014 Update credential management standard", + "source_path": "workplans/archived/260603-NK-WP-0005-agent-driven-credential-bootstrap.md", + "uuid": "42ac193d-7b56-48f7-8eba-757a6dad2fba", + "parent_id": "NK-WP-0005", + "extra": {} + }, + { + "kind": "workplan", + "id": "NET-WP-0018", + "status": "finished", + "title": "Bootstrap Automation And Rebuild Readiness", + "source_path": "workplans/archived/260604-NET-WP-0018-bootstrap-automation-and-rebuild-readiness.md", + "uuid": "800f9f16-bc44-4bbf-a771-58a630a3b698", + "parent_id": null, + "extra": { + "depends_on": [ + "NET-WP-0015", + "NET-WP-0017" + ] + } + }, + { + "kind": "task", + "id": "NET-WP-0018-T01", + "status": "done", + "title": "T01 - Close Or Hand Off NET-WP-0015 Remaining Gates", + "source_path": "workplans/archived/260604-NET-WP-0018-bootstrap-automation-and-rebuild-readiness.md", + "uuid": "7ff22629-838b-41df-9feb-bb36c5d57cc1", + "parent_id": "NET-WP-0018", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0018-T02", + "status": "done", + "title": "T02 - Document The Runtime Architecture", + "source_path": "workplans/archived/260604-NET-WP-0018-bootstrap-automation-and-rebuild-readiness.md", + "uuid": "121ee797-e3f5-4d3e-9baa-cfa8c92f8a66", + "parent_id": "NET-WP-0018", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0018-T03", + "status": "done", + "title": "T03 - Produce A Bootstrap Retrospective And Automation Gap Matrix", + "source_path": "workplans/archived/260604-NET-WP-0018-bootstrap-automation-and-rebuild-readiness.md", + "uuid": "1a3c4261-4133-4021-bd53-ea3dc77021a0", + "parent_id": "NET-WP-0018", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0018-T04", + "status": "done", + "title": "T04 - Review Repository Intent And Scope Boundaries", + "source_path": "workplans/archived/260604-NET-WP-0018-bootstrap-automation-and-rebuild-readiness.md", + "uuid": "9c286579-b7bc-46ae-9789-801b2b27b26d", + "parent_id": "NET-WP-0018", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0018-T05", + "status": "done", + "title": "T05 - Create The Smooth Bootstrap Guide", + "source_path": "workplans/archived/260604-NET-WP-0018-bootstrap-automation-and-rebuild-readiness.md", + "uuid": "e7b45fc8-8ee7-4914-ac4b-d0c8a35fad13", + "parent_id": "NET-WP-0018", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0018-T06", + "status": "done", + "title": "T06 - Align The Control Surface With The Bootstrap Guide", + "source_path": "workplans/archived/260604-NET-WP-0018-bootstrap-automation-and-rebuild-readiness.md", + "uuid": "9bba26b3-b1be-4e58-a18b-a0533683d63b", + "parent_id": "NET-WP-0018", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0018-T07", + "status": "done", + "title": "T07 - Add Automated Tests For Bootstrap UI Sections And Runbooks", + "source_path": "workplans/archived/260604-NET-WP-0018-bootstrap-automation-and-rebuild-readiness.md", + "uuid": "c412d9e0-a2ca-4849-b6ee-bd4450b5a4a5", + "parent_id": "NET-WP-0018", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0018-T08", + "status": "done", + "title": "T08 - Integrate Validations Into The UI State Model", + "source_path": "workplans/archived/260604-NET-WP-0018-bootstrap-automation-and-rebuild-readiness.md", + "uuid": "32f05fb1-269c-421c-ae34-57d2ceb7e47a", + "parent_id": "NET-WP-0018", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0018-T09", + "status": "done", + "title": "T09 - Assess Scratch-Rebuild Risk And Define A Rehearsal Plan", + "source_path": "workplans/archived/260604-NET-WP-0018-bootstrap-automation-and-rebuild-readiness.md", + "uuid": "a9e60fd5-fac6-46e9-bc63-b2979cca548e", + "parent_id": "NET-WP-0018", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-ADHOC-2026-06-14", + "status": "finished", + "title": "Ad hoc NetKingdom operator usability fixes", + "source_path": "workplans/archived/260702-ADHOC-2026-06-14.md", + "uuid": "3ad3848e-00be-55a7-99e2-bc31047ea847", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-ADHOC-2026-06-14-T01", + "status": "done", + "title": "SOPS Custody Unlock Helper", + "source_path": "workplans/archived/260702-ADHOC-2026-06-14.md", + "uuid": null, + "parent_id": "NK-WP-ADHOC-2026-06-14", + "extra": {} + }, + { + "kind": "workplan", + "id": "NET-WP-0017", + "status": "finished", + "title": "IT Security Readiness For User Onboarding", + "source_path": "workplans/archived/260702-NET-WP-0017-it-security-readiness-for-user-onboarding.md", + "uuid": "385de708-fd59-4bab-a4f4-28c1c476b3ea", + "parent_id": null, + "extra": { + "depends_on": [ + "NET-WP-0015", + "NET-WP-0016", + "RAIL-PL-WP-0002" + ] + } + }, + { + "kind": "task", + "id": "NET-WP-0017-T01", + "status": "done", + "title": "T01 - Finish OIDC-Backed OpenBao Admin Login", + "source_path": "workplans/archived/260702-NET-WP-0017-it-security-readiness-for-user-onboarding.md", + "uuid": "9b087bbd-631b-4316-b94d-a8265a05b065", + "parent_id": "NET-WP-0017", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0017-T02", + "status": "done", + "title": "T02 - Close OpenBao Audit And Recovery Production Gates", + "source_path": "workplans/archived/260702-NET-WP-0017-it-security-readiness-for-user-onboarding.md", + "uuid": "909944bd-843a-4a63-8c87-536cea052a88", + "parent_id": "NET-WP-0017", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0017-T03", + "status": "done", + "title": "T03 - Close Trial Taint And Retire Bootstrap Admin Paths", + "source_path": "workplans/archived/260702-NET-WP-0017-it-security-readiness-for-user-onboarding.md", + "uuid": "a6cd4325-8f3b-46bb-b810-ca816c35cb29", + "parent_id": "NET-WP-0017", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0017-T04", + "status": "done", + "title": "T04 - Harden Bootstrap Infrastructure Before User Onboarding", + "source_path": "workplans/archived/260702-NET-WP-0017-it-security-readiness-for-user-onboarding.md", + "uuid": "12c31f76-68f4-4d2b-853a-f3185cfc761c", + "parent_id": "NET-WP-0017", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0017-T05", + "status": "done", + "title": "T05 - Implement First User Lifecycle Operator Flow", + "source_path": "workplans/archived/260702-NET-WP-0017-it-security-readiness-for-user-onboarding.md", + "uuid": "aec3ac45-18be-4b04-a863-0c8c70693739", + "parent_id": "NET-WP-0017", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0017-T06", + "status": "done", + "title": "T06 - Run A Non-Root Onboarding Dry Run", + "source_path": "workplans/archived/260702-NET-WP-0017-it-security-readiness-for-user-onboarding.md", + "uuid": "c149b2f0-c9ee-4c95-a1df-b25ed0d20579", + "parent_id": "NET-WP-0017", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0017-T07", + "status": "done", + "title": "T07 - Review And Retire Superseded Bootstrap Workplans", + "source_path": "workplans/archived/260702-NET-WP-0017-it-security-readiness-for-user-onboarding.md", + "uuid": "e9ceafb2-14c0-4352-9ac7-e31628feb045", + "parent_id": "NET-WP-0017", + "extra": {} + }, + { + "kind": "workplan", + "id": "NET-WP-0019", + "status": "finished", + "title": "T06-adjacent Polish: Non-Root User Lifecycle Dry-Run Automation And Control Surface Improvements", + "source_path": "workplans/archived/260702-NET-WP-0019-t06-adjacent-user-lifecycle-dry-run-polish.md", + "uuid": "75d388b6-7ec1-4e1b-8c87-6ff44f953210", + "parent_id": null, + "extra": { + "depends_on": [ + "NET-WP-0017", + "NET-WP-0018" + ], + "related": [ + "docs/user-engine-netkingdom-integration-assessment.md (broader user-engine vs net-kingdom fit, gaps, and recommendations)" + ] + } + }, + { + "kind": "task", + "id": "NET-WP-0019-T01", + "status": "done", + "title": "T01 - Add Dedicated Dry-Run Orchestrator Script", + "source_path": "workplans/archived/260702-NET-WP-0019-t06-adjacent-user-lifecycle-dry-run-polish.md", + "uuid": "03e03868-a07d-478c-9808-f9decaeab2e8", + "parent_id": "NET-WP-0019", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0019-T02", + "status": "done", + "title": "T02 - Safer Secret Handling In User Lifecycle Scripts", + "source_path": "workplans/archived/260702-NET-WP-0019-t06-adjacent-user-lifecycle-dry-run-polish.md", + "uuid": "564631a6-9b28-4e23-a852-5d85ade94a76", + "parent_id": "NET-WP-0019", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0019-T03", + "status": "done", + "title": "T03 - Console And Make Integration For Dry-Run", + "source_path": "workplans/archived/260702-NET-WP-0019-t06-adjacent-user-lifecycle-dry-run-polish.md", + "uuid": "7a264b8a-1b71-4a3e-835b-3c27676d28ef", + "parent_id": "NET-WP-0019", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0019-T04", + "status": "done", + "title": "T04 - Add Test User Cleanup Helper And Repeatable Dry-Run Support", + "source_path": "workplans/archived/260702-NET-WP-0019-t06-adjacent-user-lifecycle-dry-run-polish.md", + "uuid": "e0053d13-bc7a-41e8-900b-4a18a76e19d0", + "parent_id": "NET-WP-0019", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0019-T05", + "status": "done", + "title": "T05 - Better OIDC Claims And Verification Hooks For Dry-Runs", + "source_path": "workplans/archived/260702-NET-WP-0019-t06-adjacent-user-lifecycle-dry-run-polish.md", + "uuid": "33f88f24-98bd-4a4d-b70e-f5811816f196", + "parent_id": "NET-WP-0019", + "extra": {} + }, + { + "kind": "task", + "id": "NET-WP-0019-T06", + "status": "done", + "title": "T06 - Expose Dry-Run In Web UI And Cross-Link To 0018", + "source_path": "workplans/archived/260702-NET-WP-0019-t06-adjacent-user-lifecycle-dry-run-polish.md", + "uuid": "aa8ddc00-e77e-4153-aaba-c4e464d4d1a4", + "parent_id": "NET-WP-0019", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0001", + "status": "archived", + "title": "SSO & MFA Platform \u2014 Keycloak + privacyIDEA on Kubernetes", + "source_path": "workplans/archived/260702-NK-WP-0001-sso-mfa-platform.md", + "uuid": "39263c4b-ef70-4053-b782-350834b7e1be", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0001-T01", + "status": "done", + "title": "T01 \u2014 Phase 0: Vault & secret bootstrap (single-credential principle)", + "source_path": "workplans/archived/260702-NK-WP-0001-sso-mfa-platform.md", + "uuid": "7992528c-d533-44e5-bcce-f92aaa2b75b2", + "parent_id": "NK-WP-0001", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0001-T02", + "status": "done", + "title": "T02 \u2014 Phase 1: K8s foundations (namespaces, NetworkPolicies, cert-manager)", + "source_path": "workplans/archived/260702-NK-WP-0001-sso-mfa-platform.md", + "uuid": "721ca6b2-0cf4-4008-a966-87b1563550fa", + "parent_id": "NK-WP-0001", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0001-T03", + "status": "done", + "title": "T03 \u2014 Phase 2: PostgreSQL deployment (Keycloak + privacyIDEA DBs)", + "source_path": "workplans/archived/260702-NK-WP-0001-sso-mfa-platform.md", + "uuid": "7fa60004-deb2-4db5-a470-f95dda07f6ab", + "parent_id": "NK-WP-0001", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0001-T04", + "status": "cancel", + "title": "T04 \u2014 Phase 3: Deploy privacyIDEA (MFA core)", + "source_path": "workplans/archived/260702-NK-WP-0001-sso-mfa-platform.md", + "uuid": "6ad1296a-a488-4031-b665-f77030e971ed", + "parent_id": "NK-WP-0001", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0001-T05", + "status": "cancel", + "title": "T05 \u2014 Phase 4: Deploy Keycloak (SSO core)", + "source_path": "workplans/archived/260702-NK-WP-0001-sso-mfa-platform.md", + "uuid": "b9f73aa6-9035-4643-9905-64e73a29b298", + "parent_id": "NK-WP-0001", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0001-T06", + "status": "cancel", + "title": "T06 \u2014 Phase 5: Realm config & MFA authentication flow", + "source_path": "workplans/archived/260702-NK-WP-0001-sso-mfa-platform.md", + "uuid": "3b6379a4-a27b-4d25-82be-bc600879f036", + "parent_id": "NK-WP-0001", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0001-T07", + "status": "cancel", + "title": "T07 \u2014 Phase 6: User management, policies & self-service portal", + "source_path": "workplans/archived/260702-NK-WP-0001-sso-mfa-platform.md", + "uuid": "c7cf902a-b480-4545-a536-293070945206", + "parent_id": "NK-WP-0001", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0001-T08", + "status": "cancel", + "title": "T08 \u2014 Phase 7: Backups, DR, break-glass & monitoring", + "source_path": "workplans/archived/260702-NK-WP-0001-sso-mfa-platform.md", + "uuid": "9cbd1d89-b5bf-491e-9d16-b1c7d57076fb", + "parent_id": "NK-WP-0001", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0002", + "status": "finished", + "title": "Local Identity \u2014 Bootstrap User Store & Minimal OIDC", + "source_path": "workplans/archived/260702-NK-WP-0002-local-identity.md", + "uuid": "7c9021b1-319c-4b4a-a8be-0642239a1893", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0002-T01", + "status": "done", + "title": "T01 \u2014 Stage 1: Core file store", + "source_path": "workplans/archived/260702-NK-WP-0002-local-identity.md", + "uuid": "656652dd-05af-4fa4-95b2-17ce029ac7bd", + "parent_id": "NK-WP-0002", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0002-T02", + "status": "done", + "title": "T02 \u2014 Stage 2: Bootstrap integration", + "source_path": "workplans/archived/260702-NK-WP-0002-local-identity.md", + "uuid": "5ea6e68d-7ebe-4ea7-b92e-61aac17ff04c", + "parent_id": "NK-WP-0002", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0002-T03", + "status": "done", + "title": "T03 \u2014 Stage 3: Minimal native OIDC provider", + "source_path": "workplans/archived/260702-NK-WP-0002-local-identity.md", + "uuid": "eb09d287-8e08-4c88-8bd1-6f0501ef5fc8", + "parent_id": "NK-WP-0002", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0002-T04", + "status": "done", + "title": "T04 \u2014 Stage 4: Security hardening", + "source_path": "workplans/archived/260702-NK-WP-0002-local-identity.md", + "uuid": "936de7fa-dfb4-48a2-804f-6b9bd7271a05", + "parent_id": "NK-WP-0002", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0006", + "status": "finished", + "title": "Recursive platform identity and security architecture", + "source_path": "workplans/archived/260702-NK-WP-0006-recursive-platform-identity-security-architecture.md", + "uuid": "2eb8a5e0-4e33-4ed3-8996-a2eec3aad862", + "parent_id": null, + "extra": { + "depends_on": [ + "NK-WP-0001", + "NK-WP-0004", + "NK-WP-0005" + ] + } + }, + { + "kind": "task", + "id": "NK-WP-0006-T1", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0006-recursive-platform-identity-security-architecture.md", + "uuid": "3e1c432a-f1ef-4c96-bb7a-79d1b955cd82", + "parent_id": "NK-WP-0006", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0006-T2", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0006-recursive-platform-identity-security-architecture.md", + "uuid": "194fe3d5-d47c-449e-a32d-50996fd39e66", + "parent_id": "NK-WP-0006", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0006-T3", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0006-recursive-platform-identity-security-architecture.md", + "uuid": "842ba5a7-5199-490a-8af5-3150388e0d42", + "parent_id": "NK-WP-0006", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0006-T4", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0006-recursive-platform-identity-security-architecture.md", + "uuid": "ce153339-f493-44ed-a2c5-befb578334fe", + "parent_id": "NK-WP-0006", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0006-T5", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0006-recursive-platform-identity-security-architecture.md", + "uuid": "6c9a3561-4e63-4acd-87a7-bf0f374fa6b2", + "parent_id": "NK-WP-0006", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0006-T6", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0006-recursive-platform-identity-security-architecture.md", + "uuid": "27760e30-f773-4552-97f4-7fbe56507f9e", + "parent_id": "NK-WP-0006", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0006-T7", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0006-recursive-platform-identity-security-architecture.md", + "uuid": "f09519ac-cf97-4f8b-8a7b-6ff828bbd8d9", + "parent_id": "NK-WP-0006", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0007", + "status": "finished", + "title": "Object Storage STS Credential Vending", + "source_path": "workplans/archived/260702-NK-WP-0007-object-storage-sts-credential-vending.md", + "uuid": "3cbc81ec-7ad5-46cf-a4a0-fc5fe9873695", + "parent_id": null, + "extra": { + "depends_on": [ + "NK-WP-0004", + "NK-WP-0005", + "NK-WP-0006" + ] + } + }, + { + "kind": "task", + "id": "NK-WP-0007-T1", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0007-object-storage-sts-credential-vending.md", + "uuid": "3b50c48f-1ab2-4631-b176-d49d9d705f1e", + "parent_id": "NK-WP-0007", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0007-T2", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0007-object-storage-sts-credential-vending.md", + "uuid": "5b942d22-6f29-4975-88fb-e3e5bcaf4029", + "parent_id": "NK-WP-0007", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0007-T3", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0007-object-storage-sts-credential-vending.md", + "uuid": "8d27e5b4-9bbb-4a53-a079-0df1047d755e", + "parent_id": "NK-WP-0007", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0007-T4", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0007-object-storage-sts-credential-vending.md", + "uuid": "c0c4f297-6cff-419b-9ce3-be5537c92e93", + "parent_id": "NK-WP-0007", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0007-T5", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0007-object-storage-sts-credential-vending.md", + "uuid": "ccb10b2d-6378-4824-90b1-c31bd882d93d", + "parent_id": "NK-WP-0007", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0007-T6", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0007-object-storage-sts-credential-vending.md", + "uuid": "63c6859b-980e-44da-a5a6-b92a8a3225dd", + "parent_id": "NK-WP-0007", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0008", + "status": "done", + "title": "IT Security Architecture Patterns Infospace", + "source_path": "workplans/archived/260702-NK-WP-0008-it-security-architecture-patterns-infospace.md", + "uuid": "053c6d96-9396-40c9-a2e5-c36531e7810d", + "parent_id": null, + "extra": { + "depends_on": [ + "NK-WP-0006" + ] + } + }, + { + "kind": "task", + "id": "NK-WP-0008-T1", + "status": "done", + "title": "T01 - Promote The Seed Into A Valid Infospace", + "source_path": "workplans/archived/260702-NK-WP-0008-it-security-architecture-patterns-infospace.md", + "uuid": "d1b7213c-3315-49d2-90c9-efdf2bea3563", + "parent_id": "NK-WP-0008", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0008-T2", + "status": "done", + "title": "T02 - Extract The Initial Capability And Pattern Catalogs", + "source_path": "workplans/archived/260702-NK-WP-0008-it-security-architecture-patterns-infospace.md", + "uuid": "59966187-27f1-4b9c-9dfc-e59d11ff115c", + "parent_id": "NK-WP-0008", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0008-T3", + "status": "done", + "title": "T03 - Map Patterns To NetKingdom And Ecosystem Ownership", + "source_path": "workplans/archived/260702-NK-WP-0008-it-security-architecture-patterns-infospace.md", + "uuid": "927c08a5-1a7e-4634-a514-0f562e286708", + "parent_id": "NK-WP-0008", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0008-T4", + "status": "done", + "title": "T04 - Build The Index, Maturity Matrix, And Report", + "source_path": "workplans/archived/260702-NK-WP-0008-it-security-architecture-patterns-infospace.md", + "uuid": "884626ea-243e-4806-9267-77ef643158b7", + "parent_id": "NK-WP-0008", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0008-T5", + "status": "done", + "title": "T05 - Define Admission And Review Criteria", + "source_path": "workplans/archived/260702-NK-WP-0008-it-security-architecture-patterns-infospace.md", + "uuid": "d3b29f3d-0da5-43b5-a93a-d95fb8a0ceef", + "parent_id": "NK-WP-0008", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0010", + "status": "finished", + "title": "Genesis Security Pattern Completion", + "source_path": "workplans/archived/260702-NK-WP-0010-genesis-security-pattern-completion.md", + "uuid": "f4faf8b4-ae57-40cf-a881-6fe66ca6ad74", + "parent_id": null, + "extra": { + "depends_on": [ + "NK-WP-0008" + ] + } + }, + { + "kind": "task", + "id": "NK-WP-0010-T1", + "status": "done", + "title": "T01 - Reconcile The Genesis Inventory", + "source_path": "workplans/archived/260702-NK-WP-0010-genesis-security-pattern-completion.md", + "uuid": "61160df5-7305-4a0f-a34d-2a763c29eab4", + "parent_id": "NK-WP-0010", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0010-T2", + "status": "done", + "title": "T02 - Complete Identity And Access Patterns", + "source_path": "workplans/archived/260702-NK-WP-0010-genesis-security-pattern-completion.md", + "uuid": "dad43681-9404-47b8-b58c-39b7218c2542", + "parent_id": "NK-WP-0010", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0010-T3", + "status": "done", + "title": "T03 - Complete Tenant Isolation Patterns", + "source_path": "workplans/archived/260702-NK-WP-0010-genesis-security-pattern-completion.md", + "uuid": "dee39f82-aa3a-4824-ba61-7fbdbd5c3d21", + "parent_id": "NK-WP-0010", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0010-T4", + "status": "done", + "title": "T04 - Complete Kubernetes And Platform Patterns", + "source_path": "workplans/archived/260702-NK-WP-0010-genesis-security-pattern-completion.md", + "uuid": "19def7b4-4f1a-45ad-b15b-6a56e675be41", + "parent_id": "NK-WP-0010", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0010-T5", + "status": "done", + "title": "T05 - Complete Secrets And Cryptography Patterns", + "source_path": "workplans/archived/260702-NK-WP-0010-genesis-security-pattern-completion.md", + "uuid": "622c3bbe-77a7-4049-b6f4-0cd1f54f3783", + "parent_id": "NK-WP-0010", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0010-T6", + "status": "done", + "title": "T06 - Complete Application And API Security Patterns", + "source_path": "workplans/archived/260702-NK-WP-0010-genesis-security-pattern-completion.md", + "uuid": "e792f598-4dfc-4598-ba86-facd13cd8a12", + "parent_id": "NK-WP-0010", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0010-T7", + "status": "done", + "title": "T07 - Complete Supply-Chain Patterns", + "source_path": "workplans/archived/260702-NK-WP-0010-genesis-security-pattern-completion.md", + "uuid": "a43b189a-d1b4-4692-94d7-9c7e140808ca", + "parent_id": "NK-WP-0010", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0010-T8", + "status": "done", + "title": "T08 - Complete Detection And Response Patterns", + "source_path": "workplans/archived/260702-NK-WP-0010-genesis-security-pattern-completion.md", + "uuid": "78a2d242-5a56-40a7-8499-ba7c72150700", + "parent_id": "NK-WP-0010", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0010-T9", + "status": "done", + "title": "T09 - Refresh Relationships, Indexes, And Reports", + "source_path": "workplans/archived/260702-NK-WP-0010-genesis-security-pattern-completion.md", + "uuid": "8ec9bc00-1f7b-4f34-b02e-33fdacda9da5", + "parent_id": "NK-WP-0010", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0010-T10", + "status": "done", + "title": "T10 - Verify Completion And Feed NK-WP-0009", + "source_path": "workplans/archived/260702-NK-WP-0010-genesis-security-pattern-completion.md", + "uuid": "a5449bc6-8529-4350-822b-7c758bf790cb", + "parent_id": "NK-WP-0010", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0012", + "status": "finished", + "title": "NetKingdom IAM Profile Specification", + "source_path": "workplans/archived/260702-NK-WP-0012-iam-profile-specification.md", + "uuid": "9b8e4afc-eb71-47d9-8750-799a082b320a", + "parent_id": null, + "extra": { + "depends_on": [ + "NK-WP-0006" + ] + } + }, + { + "kind": "task", + "id": "NK-WP-0012-T1", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0012-iam-profile-specification.md", + "uuid": "284dda38-b778-445a-a7dc-9b5a12fa380f", + "parent_id": "NK-WP-0012", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0012-T2", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0012-iam-profile-specification.md", + "uuid": "0070398d-b0a4-4c11-a6fa-000166e1108f", + "parent_id": "NK-WP-0012", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0012-T3", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0012-iam-profile-specification.md", + "uuid": "6fc2a5e1-1480-42f1-86a2-3e714359e1ba", + "parent_id": "NK-WP-0012", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0012-T4", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0012-iam-profile-specification.md", + "uuid": "0e52ed45-afa7-4832-9d6a-1ebbbab43872", + "parent_id": "NK-WP-0012", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0012-T5", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0012-iam-profile-specification.md", + "uuid": "f0a62e77-b781-4625-b8bd-d191b48af58e", + "parent_id": "NK-WP-0012", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0012-T6", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0012-iam-profile-specification.md", + "uuid": "a1fd53a9-526f-4d87-89db-6073710c885d", + "parent_id": "NK-WP-0012", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0013", + "status": "finished", + "title": "Playbook Capability Contract", + "source_path": "workplans/archived/260702-NK-WP-0013-playbook-capability-contract.md", + "uuid": "32a54d8e-8633-42a6-8ec1-104842c581c1", + "parent_id": null, + "extra": { + "depends_on": [ + "NK-WP-0006" + ] + } + }, + { + "kind": "task", + "id": "NK-WP-0013-T1", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0013-playbook-capability-contract.md", + "uuid": "d40f8b29-e983-4d52-bc1f-5f1c51709e7d", + "parent_id": "NK-WP-0013", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0013-T2", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0013-playbook-capability-contract.md", + "uuid": "ece4b5b1-e1c2-449d-b0f4-83b7010bc838", + "parent_id": "NK-WP-0013", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0013-T3", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0013-playbook-capability-contract.md", + "uuid": "c956f4a8-b9fa-44ab-8174-31999b98e3b1", + "parent_id": "NK-WP-0013", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0013-T4", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0013-playbook-capability-contract.md", + "uuid": "e7de05a6-528a-4213-b6db-2c2e90353996", + "parent_id": "NK-WP-0013", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0013-T5", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0013-playbook-capability-contract.md", + "uuid": "05a2ff7d-86c4-4de9-9ea8-39a9ad5352a8", + "parent_id": "NK-WP-0013", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0013-T6", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0013-playbook-capability-contract.md", + "uuid": "769ed490-c091-41c1-b2e2-e8e378470b6b", + "parent_id": "NK-WP-0013", + "extra": {} + }, + { + "kind": "workplan", + "id": "NK-WP-0014", + "status": "finished", + "title": "User Engine Preparation And Boundary Contracts", + "source_path": "workplans/archived/260702-NK-WP-0014-user-engine-preparation-boundary-contracts.md", + "uuid": "b9bf56bc-7ef6-43eb-badc-fa0f4896c63c", + "parent_id": null, + "extra": { + "depends_on": [ + "NK-WP-0012", + "NK-WP-0013" + ] + } + }, + { + "kind": "task", + "id": "NK-WP-0014-T1", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0014-user-engine-preparation-boundary-contracts.md", + "uuid": "4e941174-ac55-4f6e-8568-40f45b1ed821", + "parent_id": "NK-WP-0014", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0014-T2", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0014-user-engine-preparation-boundary-contracts.md", + "uuid": "5ddc46bb-6238-4944-a023-d8b46b410c76", + "parent_id": "NK-WP-0014", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0014-T3", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0014-user-engine-preparation-boundary-contracts.md", + "uuid": "696bc65b-0f8d-47b5-bccc-65ed285b42e6", + "parent_id": "NK-WP-0014", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0014-T4", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0014-user-engine-preparation-boundary-contracts.md", + "uuid": "99ab4535-cbbf-4e13-a2c5-adfc814d5aeb", + "parent_id": "NK-WP-0014", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0014-T5", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0014-user-engine-preparation-boundary-contracts.md", + "uuid": "d35a1356-a9fe-4cf3-8fb0-6f45cfbbccee", + "parent_id": "NK-WP-0014", + "extra": {} + }, + { + "kind": "task", + "id": "NK-WP-0014-T6", + "status": "done", + "title": "Tasks", + "source_path": "workplans/archived/260702-NK-WP-0014-user-engine-preparation-boundary-contracts.md", + "uuid": "04fd2f92-3aa4-468d-9e9e-9b092890507e", + "parent_id": "NK-WP-0014", + "extra": {} + }, + { + "kind": "intake", + "id": "NK-IN-0001", + "status": "closed", + "title": "Create LLDAP group activity-core-operators and membership runbook", + "source_path": "docs/intakes/activity-core-ops-sso-operators.md", + "uuid": "019f88ff-c5f1-7433-9d13-4ffe37dfef00", + "parent_id": null, + "extra": { + "record": { + "id": "NK-IN-0001", + "kind": "intake", + "title": "Create LLDAP group activity-core-operators and membership runbook", + "lane": "blue", + "status": "closed", + "outcome": "promoted", + "promoted_to": "NK-WP-0021", + "priority": "high", + "owner": "net-kingdom", + "repo": "net-kingdom", + "origin": "ACTIVITY-WP-0025-T06", + "origin_ref": "activity-core/workplans/ACTIVITY-WP-0025-ops-ui-sso-access.md", + "routed_note": "Promoted 2026-07-22 into NK-WP-0021 (T01\u2013T02). Implement in net-kingdom sso-mfa.", + "description": "activity-core shipped Authelia SSO for the ops console and Temporal UI\n(ACTIVITY-WP-0025). MVP accepts any authenticated Authelia user.\n\nNeeded in net-kingdom (LLDAP + ops docs), not in activity-core:\n\n1. Create LLDAP group `activity-core-operators` (same style as\n net-kingdom-users / net-kingdom-admins in sso-mfa/k8s/lldap/bootstrap-users.sh).\n2. Document how to add/remove human operators (WebUI checklist and/or\n script extension). Named founders/operators only \u2014 least privilege.\n3. Do not invent OIDC clients in KeyCape for this path: activity-core uses\n Traefik Middleware \u2192 Authelia `/api/verify` (ForwardAuth), not a new\n oauth2-proxy/Keycloak client.\n\nAcceptance: group exists in LLDAP; membership procedure written under\nsso-mfa docs or CONFIG; at least one test operator can be assigned.\n", + "notes": "Related Authelia domain rules are NK-IN-0002 (depends on this group existing).\nRequester residual task: ACTIVITY-WP-0025-T06 (status wait).\nPromoted to NK-WP-0021 (combined workplan with NK-IN-0002).\n", + "state_hub_intake_id": "019f88ff-c5f1-7433-9d13-4ffe37dfef00" + } + } + }, + { + "kind": "intake", + "id": "NK-IN-0002", + "status": "closed", + "title": "Authelia access_control for activity + temporal.coulomb.social", + "source_path": "docs/intakes/activity-core-ops-sso-operators.md", + "uuid": "019f88ff-cc9e-76b4-8ce3-eb354aabefe7", + "parent_id": null, + "extra": { + "record": { + "id": "NK-IN-0002", + "kind": "intake", + "title": "Authelia access_control for activity + temporal.coulomb.social", + "lane": "blue", + "status": "closed", + "outcome": "promoted", + "promoted_to": "NK-WP-0021", + "priority": "high", + "owner": "net-kingdom", + "repo": "net-kingdom", + "origin": "ACTIVITY-WP-0025-T06", + "origin_ref": "activity-core/workplans/ACTIVITY-WP-0025-ops-ui-sso-access.md", + "routed_note": "Promoted 2026-07-22 into NK-WP-0021 (T03\u2013T04). Depends on NK-IN-0001 group.", + "description": "Restrict browser access to activity-core public SSO hosts to members of\nLLDAP group `activity-core-operators` (see NK-IN-0001).\n\nImplementation target (live config):\n- File: sso-mfa/k8s/authelia/configmap.yaml\n- Today: access_control.default_policy: one_factor (no domain rules)\n- Add domain rules for:\n - activity.coulomb.social\n - temporal.coulomb.social\n requiring subject/group activity-core-operators (exact Authelia\n subject syntax per current Authelia version \u2014 use fleet patterns if any\n domain rules already exist for other apps).\n\nKeep MFA posture consistent with fleet (KeyCape / privacyIDEA path; do\nnot set two_factor on Authelia itself unless that is the established\npattern for similar apps).\n\nRollout: apply Authelia ConfigMap + restart/reload Authelia in ns sso;\nverify unauthenticated \u2192 login; authenticated non-member \u2192 deny/403;\nmember \u2192 pass-through to Traefik backends.\n\nAcceptance:\n- Unprivileged Authelia user cannot open ops UI or Temporal UI\n- Member of activity-core-operators can open both hosts after login\n- activity-core break-glass (ClusterIP port-forward + operator token)\n remains documented and independent of Authelia groups\n", + "notes": "Depends on NK-IN-0001 (group must exist). activity-core Ingress + middleware\nalready applied (k8s/railiance/30\u201332). No activity-core code change required\nfor group enforcement \u2014 headers already carry Remote-Groups.\nPromoted to NK-WP-0021 (combined workplan with NK-IN-0001).\n", + "state_hub_intake_id": "019f88ff-cc9e-76b4-8ce3-eb354aabefe7" + } + } + }, + { + "kind": "intake", + "id": "NET-IN-0001", + "status": "open", + "title": "Declaration requested: state this repository's layer in INTENT.md (security layer model \u00a711)", + "source_path": "intakes/intakes.md", + "uuid": null, + "parent_id": null, + "extra": { + "record": { + "id": "NET-IN-0001", + "kind": "intake", + "title": "Declaration requested: state this repository's layer in INTENT.md (security layer model \u00a711)", + "status": "open", + "origin": "cross-repo", + "origin_ref": "net-kingdom security-layer-model_v0.4 \u00a711", + "priority": "low", + "owner": "net-kingdom", + "requested_by": "gate-house", + "proposed_layer": "Taxonomy", + "description": "A conformance sweep on 2026-08-28 found this repository has no layer declaration of its own. It carries a layering review note gate-house wrote into the top of its INTENT.md on 2026-08-24, and that note names a layer \u2014 but the words are gate-house's, sitting above a line admitting the body is unadapted. Section 11 has since been amended to say so explicitly: a layer stated about a repository by another repository is not a declaration; only the repository's own file, in its own voice, conforms. Seven of fifteen estate-authored repositories have declared; this is one of the eight that have not, and the standard does not claim adoption on the basis of notes gate-house wrote. REQUESTED: state the layer in INTENT.md in your own voice, or contest it. PROPOSED LAYER: Taxonomy. NetKingdom standards of record and publication. Note this repository publishes the layer model but has not declared its own place in it. Contesting is a real option and costs nothing \u2014 the three repositories that reviewed this model each returned a correction, two of which changed the standard. If the proposed layer is wrong for what this repository actually does, that is more useful to us than a label added to close a checkbox. Standard: net-kingdom/canon/standards/security-layer-model_v0.4.md.", + "created": "2026-08-28T21:01:51.894396Z", + "updated": "2026-08-28T21:01:51.894396Z" + } + } + } + ], + "events": [ + { + "type": "repo.command.applied", + "command": "repo.work.create_intake", + "operation": "create", + "correlation_id": "980dc589-1d44-4097-b2f6-419e5bd21fd1", + "kind": "intake", + "id": "NET-IN-0001", + "git_sha": "f4f013279d2aae8b0612b56d97d4556589774a4a", + "files_touched": [ + "intakes/intakes.md" + ], + "source": "repo-manager", + "emitted_at": "2026-08-28T21:01:53.439742Z" + } + ] +} diff --git a/README.md b/README.md index 9ba5d0c..29fdbcf 100644 --- a/README.md +++ b/README.md @@ -12,7 +12,7 @@ The dynamic, self-optimizing security platform is the long-term direction in ## Orientation - [SCOPE.md](SCOPE.md) — what this repo owns, current state, and when it is relevant -- [Security layer model](canon/standards/security-layer-model_v0.4.md) — how the +- [Security layer model](canon/standards/security-layer-model_v0.5.md) — how the security estate is layered (Taxonomy / Tooling / Engines / Staff) and what each layer may own - [Security scenario composition](canon/standards/security-scenario-composition_v0.1.md) diff --git a/canon/standards/security-layer-model_v0.4.md b/canon/standards/security-layer-model_v0.4.md index 7fe6e0a..22b5ec5 100644 --- a/canon/standards/security-layer-model_v0.4.md +++ b/canon/standards/security-layer-model_v0.4.md @@ -3,7 +3,7 @@ id: netkingdom-security-layer-model-v0.4 type: standard title: "NetKingdom Security Layer Model v0.4" domain: netkingdom -status: proposed +status: superseded version: "0.4" supersedes: canon/standards/security-layer-model_v0.3.md owner: gate-house @@ -14,6 +14,7 @@ last_reviewed: "2026-08-28" review_interval: 3m source_revision: "gate-house@516ed4e" standard_token: security-layer-model_v0.4 +superseded_by: canon/standards/security-layer-model_v0.5.md assented_by: - "flex-auth FLEX-DEC-2026-001" - "kings-guard KG-DEC-2026-001" @@ -29,6 +30,11 @@ related: # NetKingdom Security Layer Model v0.4 +> **Superseded 2026-08-29 by [v0.5](security-layer-model_v0.5.md).** All four +> reviewing repositories returned findings; `flex-auth` contested §9.3 and was +> right. v0.5 splits §9.1 into two marks, rewrites §9.3, scopes §5, requires a +> local outbox in §9.4, and gives §11 a fourth conformance state. + ## 1. Purpose This standard states how NetKingdom's IT-security estate is layered, and what diff --git a/canon/standards/security-layer-model_v0.5.md b/canon/standards/security-layer-model_v0.5.md new file mode 100644 index 0000000..8e12dfc --- /dev/null +++ b/canon/standards/security-layer-model_v0.5.md @@ -0,0 +1,776 @@ +--- +id: netkingdom-security-layer-model-v0.5 +type: standard +title: "NetKingdom Security Layer Model v0.5" +domain: netkingdom +status: proposed +version: "0.5" +supersedes: canon/standards/security-layer-model_v0.4.md +owner: gate-house +publication_owner: net-kingdom +created: "2026-08-28" +updated: "2026-08-28" +last_reviewed: "2026-08-28" +review_interval: 3m +source_revision: "gate-house@516ed4e" +standard_token: security-layer-model_v0.5 +assented_by: + - "flex-auth FLEX-DEC-2026-001" + - "kings-guard KG-DEC-2026-001" + - "ops-warden ADR-0010" + - "audit-core AUDIT-IN-0001, and v0.4 review with three findings" + - "flex-auth FLEX-DEC-2026-002 (v0.4, §9.3 contested)" + - "kings-guard v0.4 review, four findings" + - "ops-warden 2026-08-29 v0.4 review, three findings" +related: + - canon/standards/security-zones_v0.1.md + - canon/standards/tenancy-posture_v0.1.md + - canon/standards/credential-management_v0.2.md + - gate-house/decisions/decisions.md + - gate-house/history/2026-08-28-security-layer-model-and-gate-house-recut.md +--- + +# NetKingdom Security Layer Model v0.5 + +## 1. Purpose + +This standard states how NetKingdom's IT-security estate is layered, and what +each layer may and may not do. It answers one question: + +> **Given a repository, which layer is it in, and what does that permit it to +> own?** + +The layers are distinguished by **determinism** and by **the kind of artifact +the layer produces**, not by technical tier, deployment topology, or team. + +It is not an org chart, not a network model, not a deployment topology, and not +a dependency graph. It does not assign work, and it does not replace any +repository's boundary contract; it constrains what such a contract may claim. + +**What changed in v0.5.** All four reviewing repositories returned findings on +v0.4, and one contested a rule. §9.3 was wrong: it collapsed *engine reachable +but degraded* with *engine not reachable at all*, and the second case has no +evaluator in the path to express anything. §9.1 collapsed *no route exists* with +*route exists under a declared gap*, which would have forced a false "pending" +onto a production capability. §11 claimed mechanical checkability for a rule +that cannot be checked in prose. §13 filed two opposite conformance states in one +table and recorded proposed owners as owners. §9.6 needed the load-bearing +distinction it implied but never drew. §15 records the change list. + +**What changed in v0.4.** `audit-core` assented to the approval evidence half +and corrected the rationale twice. v0.3 rested §9.4 on that repository's INTENT +principle 6, which is an aspiration; the shipped bound in its `docs/integrity.md` +is weaker and conditional. More consequentially, no append-only archive can prove +**omission at source** — a suppressed revocation leaves the chain intact — which +is now stated as an estate-wide doctrine constraint (§9.6) rather than left +implicit. `audit-core` was also referenced as an owner in v0.3 without appearing +in the §4 catalog at all; it is catalogued here, as an Engine, on its own +declaration. §15 records the change list. + +**What changed in v0.3.** Two engines were seeded to own concepts v0.2 recorded +as unowned: `approval-engine` takes the approval object that §13 left homeless, +and `maturity-engine` takes graded progression — closing a §9.1 defect in +gate-house's own catalog claim, which asserted conformance review with no engine +to act through. §15 records the change list. v0.3 is **proposed**: the two new +engines are seeded by owner direction and have no other side to assent yet, and +the evidence half of the approval split needs `audit-core`'s assent. + +**What changed in v0.2.** v0.1 was assented to by all three repositories whose +boundaries moved, and each returned a finding. v0.1 had one lane for a Staff +repository that legitimately touches Tooling — read-only diagnostics — which is +narrower than the estate as it actually stands, and a rule with no lane for a +real sanctioned case is satisfied by relabelling rather than by closing the gap. +v0.1 also catalogued a capability (§4, containment) that §5 forbade discharging, +and applied its reconstructability test to engines but not to the doctrine +gate-house feeds them. §15 records the full change list. + +## 2. Authority and conformance + +| Fact or rule | Authority | +| --- | --- | +| The layers, their definitions, and the rules between them | This standard, owned by gate-house | +| Which layer a given repository is in | This standard, §4 catalog | +| What a repository owns within its layer | That repository's `INTENT.md` and boundary contract | +| Whether a specific request is permitted | `access-engine` — never this standard | +| Whether a Tooling contact is sanctioned | The declaring repository, under the shapes in §5, reviewable by gate-house | +| Security doctrine and invariants | gate-house | +| Publication | net-kingdom canon | + +A repository conforms when its `INTENT.md` declares its layer, its claims fall +within that layer's permissions (§3), and its Tooling contacts take one of the +sanctioned shapes in §5 or are declared as gaps under §5.3. + +## 3. The layers + +| Layer | Character | Produces | Deterministic | +| --- | --- | --- | --- | +| **Taxonomy** | cross-cutting language | terms, semantic contracts, standards | n/a — describes | +| **Tooling** | infrastructure and state | data structures, persistence | yes | +| **Engines** | interfaces for a modeled concept | APIs, contracts | yes | +| **Staff** | management, operations, change, controlling | specifications, decisions, workplans, tasks | **no** | + +### 3.1 Taxonomy + +Cross-cutting language. Taxonomy repositories define terms and semantic +contracts so the other layers interoperate without integration by +interpretation. They own no runtime position and no state any layer depends on. + +`info-tech-canon` holds ecosystem-wide semantic contracts. NetKingdom-specific +security architecture — including this standard — is net-kingdom canon's. + +### 3.2 Tooling + +Deterministic infrastructure: data structures, persistence, and the consistent, +performant, scalable keeping of state. Much of it is third-party. + +### 3.3 Engines + +Deterministic APIs for a modeled concept — a user, a tenant, a zone, a secret, +an access rule. An engine's defining property is that **the same authoritative +input state yields the same result**. Engines are where the estate's +deterministic guarantees live, and therefore where every enforcement boundary +MUST sit. + +A repository whose core function is inference or judgment fails this test by +construction and is Staff, however much of its work happens at runtime. + +### 3.4 Staff + +Interactive and non-deterministic. Staff is the management layer: operations, +change, innovation, and controlling. It works through agentic capability — +assistants and autonomous agents — and its artifacts are specifications, +decisions, workplans, and tasks. + +Staff repositories MUST NOT hold state that another layer depends on at +runtime, and MUST NOT render or cache any decision an Engine is responsible for. + +Acting at runtime does not make a repository an Engine. Being agentic makes it +Staff, and §5 governs how it acts. + +## 4. Layer catalog + +| Repository | Layer | Owns | +| --- | --- | --- | +| `info-tech-canon` | Taxonomy | ecosystem-wide semantic contracts and terminology | +| `net-kingdom` | Taxonomy | NetKingdom standards of record; publication | +| `key-cape` | Tooling | packaged identity tooling; IAM profile; authentication | +| `OpenBao` | Tooling | secret storage, leases, PKI, dynamic secret engines | +| `user-engine` | Engine | users, accounts, memberships | +| `tenant-engine` | Engine | tenant-as-an-entity facts | +| `zone-engine` | Engine | zone identity and membership — offline reference conformance per its 2026-08-23 disposition | +| `secrets-engine` | Engine | credential abstraction, custody, lifecycle | +| `audit-core` | Engine | audit event custody, retention, integrity verification, export — explicitly not a decision point (§9.6) | +| `access-engine` | Engine | **the policy decision** — the only decision point (§6) | +| `approval-engine` | Engine | the approval object — durable, authenticated, consumable, atomically supersedable (§9.4) | +| `maturity-engine` | Engine | graded progression against declared criteria and evidence; the gap register; capability readiness (§9.5) | +| `gate-house` | Staff | security doctrine, authority context, curriculum; **conformance review — through `maturity-engine` (§9.5)** | +| `ops-mason` | Staff | building and tearing down access routes and perimeters | +| `ops-warden` | Staff | operational access lanes, stewardship, runbooks; SSH certificate issuance — **declared-gap** (§9.1, §13) | +| `kings-guard` | Staff | adaptive defence; observation of Staff-reachable sources — identity and secret observation **pending**; containment **pending** (§9.2) | +| `whitehat-security` | Staff | offensive validation | + +`access-engine` is the ruled name for the repository currently called +`flex-auth`; both denote the same authority until the governed rename completes. +Execution conditions for that rename are recorded in its migration decision, not +here. + +## 5. The binding rule + +> **Staff never touches Tooling directly. It acts only through Engine APIs.** + +A Staff repository MUST NOT hold a direct client for a Tooling-layer system — +no direct database connection, no direct OpenBao client, no direct cluster +mutation — outside the shapes below. This is the architectural form of *no +privilege from cognition*, and it is deliberately mechanically checkable. + +**Scope.** "Tooling-layer system" means a system catalogued as Tooling in §4. +Infrastructure the estate runs but has not catalogued — the State Hub, +`llm-connect`, and similar — is outside this rule, because a rule that silently +covered them would put every Staff repository in undeclared violation on +adoption day: they all write progress events. Such clients SHOULD be recorded +in the repository's declaration as non-Tooling for completeness of the check, +and the way to bring one under §5 is to catalogue it in §4, deliberately. + +Raised by `ops-warden`, which held clients for both and declined to resolve the +scope question on gate-house's behalf. + +Three shapes are sanctioned. Everything else is a violation. + +### 5.1 Read-only diagnostic observation + +A Staff repository MAY read Tooling state for diagnostics where the owning +engine exposes no equivalent. It MUST be declared in the repository's +`INTENT.md`. It grants no write, and it is an engine gap to close, not a +standing arrangement. + +### 5.2 Conduit + +A Staff repository MAY run the **owner's** tool under the **caller's** identity, +supplying no authority of its own. The test is the supplied-authority property: +the conduit MUST NOT present its own credential, MUST NOT widen what the caller +could already do, and MUST be reconstructable as the caller's action in audit. + +A conduit that presents its own token is not a conduit; it is §5.3 or a +violation. This shape MUST be declared, and the no-authority property SHOULD be +covered by a test. + +The reconstructability requirement is an audit-dependent claim and is therefore +bounded by §9.6: the archive shows the conduit actions it received, not that it +received all of them. + +### 5.3 Declared engine gap + +Where a Staff repository must contact Tooling directly and no engine exposes the +capability, it MUST declare the contact rather than take an exemption. A +declared gap carries, machine-readably: + +| Field | Meaning | +| --- | --- | +| `capability` | what the contact does | +| `intended_owner` | the engine that should own it | +| `blocked_on` | why it cannot move today | +| `review` | a date, not "when convenient" | + +A declared gap is **tracked non-conformance**, not conformance. It does not +expire on its own and it is not a licence to add more. It exists because a rule +offering no lane for a real sanctioned case gets satisfied by relabelling rather +than by closing the gap — and a tracked gap is visible, whereas a relabelled one +is not. + +Prior art: `ops-warden` runs equivalent machinery for delegated lanes (27 +catalog entries carrying `delegation:`, queryable via `warden route gaps`), and +has offered it as reusable. + +## 6. One decision point + +`access-engine` is the only policy decision point in NetKingdom. No other +repository, in any layer, may render or cache authorization decisions. + +First ruled in `zone-engine/INTENT.md` §5 — *"flex-auth is the policy decision +point. It stays the only one."* The failure mode, from the same source: *"It +becomes a second decision point… it would arrive as a small convenience."* + +### 6.1 Compiled data that determines an outcome is still deciding + +A registry, cache, or schema that resolves a result before the engine runs has +decided early. Provenance MUST remain reconstructable from the engine's decision +record. + +### 6.2 Doctrine reaches the decision as an input, or it is not applied + +This rule binds gate-house on the same terms. **An authority ceiling, mandate +constraint, or operating-mode restriction that determines an outcome MUST reach +the decision either as an input claim on the request or as a rule in the +versioned policy package**, so that its application is reconstructable from the +decision record. + +Doctrine that influences outcomes by any other route is a second decision point +wearing an author's hat. This is not a limit on gate-house's authorship; it is +what keeps that authorship auditable at decision time. + +### 6.3 No Staff repository may host a decision point + +A deterministic authority boundary inside a non-deterministic layer contradicts +the invariant the estate is built on. gate-house was re-cut on this ground. + +## 7. Relationship to the Active Secrets Management Canon + +```text +Staff interactive, non-deterministic ≈ Cognitive Plane +Engines deterministic APIs ≈ Authority Plane +Tooling deterministic state ≈ Execution Plane +Taxonomy cross-cutting language +``` + +*Cognition proposes. Authority disposes. Infrastructure executes.* is therefore +NetKingdom's layering rule, not only its security maxim. §5 and §6 are that +principle applied to repositories rather than to requests. + +## 8. Vocabulary demarcations + +| Term | Belongs to | Not | +| --- | --- | --- | +| **access lane** | ops-warden, ops-mason (Staff) — how a worker reaches a host | the decision whether they may | +| **access rule** | access-engine (Engine) — whether an actor may act | the route by which they arrive | +| **control plane** | Engine layer | a Staff repository's self-description | +| **doctrine** | gate-house | a lane owner's runbook | +| **runbook** | the Staff repository stewarding the lane | a substitute for doctrine | +| **posture** | kings-guard publishes; gate-house defines its authority meaning; access-engine renders it | a privilege source | + +Posture carries an asymmetry that MUST hold: adaptive systems may reduce +authority, require step-up, or request containment. They MUST NOT +probabilistically manufacture additional authority. + +The asymmetry is what bounds the damage when observation is incomplete (§9.6): +suppressed evidence can only prevent a tightening that should have happened, never +engineer a loosening. That is an argument for keeping it absolute rather than +situational. + +## 9. Capability assignment + +### 9.1 The catalog may not assign what the rules forbid discharging + +A Staff repository MUST NOT be catalogued in §4 as owning a capability it cannot +discharge under these rules. Two marks distinguish the two ways that happens, and +they are not interchangeable: + +| Mark | Meaning | +| --- | --- | +| **pending** | No route exists. No engine exposes the capability, the repository makes no Tooling contact, and the capability is **zero** — not degraded. | +| **declared-gap** | A route exists through a §5.3 declared gap. The capability **works** and is tracked, with an intended owner and a review date in §13. | + +v0.4 had only `pending`, which forced a false choice. `ops-warden` holds +production-verified SSH certificate issuance through a declared OpenBao contact; +marking it `pending` would have told readers the repository does not do the one +thing it demonstrably does daily, while leaving it unmarked left §4 disagreeing +with §13. Neither is acceptable, and the defect was in this section rather than +in the catalog. + +`pending` was written for `kings-guard`'s containment — no route, capability +zero — and remains correct there. `declared-gap` is the case §5.3 was added to +sanction. Raised by `ops-warden`. + +Both marks apply per capability, not per repository. A repository may hold one +capability outright, another under a declared gap, and a third pending. + +### 9.2 Containment is pending an engine surface + +No engine exposes a containment surface today — nothing to reduce authority, +require step-up, or isolate a workload as a deterministic API. kings-guard's +containment claim is marked pending in §4 until one exists. + +### 9.3 Degraded mode: two failure cases, two owners + +v0.4 collapsed two failures into one rule. They have different owners because +one has an evaluator in the path and the other does not. + +**Input degradation — the engine's.** Where `access-engine` is reachable but +cannot reach its own inputs, the deterministic *fail to reduced authority* +default belongs to the engine. This keeps the decision at the decision point and +keeps the fallback deterministic, which a Staff-layer fallback could never be. + +**Engine unreachable — necessarily the consumer's.** Where `access-engine` is +not reachable at all, it applies nothing, because it is not running. Whatever +happens next is the consumer's behaviour by construction: fail-open is not +expressible by a policy decision point, since there is no evaluator in the path +to express it. A standard that assigns this to the engine assigns it to nobody. + +The consumer's residue is bounded rather than free. A protected system MUST +declare its unreachable-engine stance ahead of time, per zone or equivalent +scope, and that stance MUST be auditable and total — no implicit default, no +per-call discretion. `ops-warden` `ADR-0009` already satisfies this: a total +per-zone map, open for `z0`–`z2` and unknown, closed for `z3-critical`, +replacing the global `policy.enabled` / `policy.fail_closed` switches it +superseded. + +**Unchanged: engine-unavailable is not grounds for a Staff break-glass path.** +The distinction is whether an engine is there to ask. A bypass around a +*reachable* engine is a second decision point, and an incident is when an +attacker most wants that shortcut. A consumer choosing its declared behaviour +when there is no engine to ask is not a bypass; it is the only thing left. + +Contested by `flex-auth` (`FLEX-DEC-2026-002`), which has held since 2026-08-19 +that fail-open is not expressible by a PDP, and which noted v0.4 collided with +shipped behaviour in a repository that had assented to this standard. + +### 9.4 Approvals are an engine concept, not a Staff or audit concern + +The approval object — durable, authenticated entries, distinct-approver +counting, atomic supersession, single consumption, revocation without holder +cooperation — is owned by `approval-engine`. + +It is not Staff's: §3.4 forbids Staff holding state another layer depends on at +runtime. It is not the decision point's: an evaluator that owns the object it +evaluates is self-dealing. It is not the audit fabric's: an approval needs +mutable, in-path, current-state semantics, and an append-only archive is built +for the opposite property. + +`access-engine` consumes approvals as **input claims** under §6.2 and never +mutates them. Every issuance, use, supersession, and revocation is emitted to +`audit-core`: the operative state and the evidence record are different +artifacts with different owners. + +The evidence guarantee is bounded, and the bound is `audit-core`'s +`docs/integrity.md`, not its INTENT principle 6. An in-database hash chain +detects a rewritten payload only if the attacker does not also recompute the +suffix — which a database owner can. Detection against that class requires the +external chain-head attestation, and even with it the store is not WORM, object +lock, or archival custody. `tamper_evidence` is therefore conditional on live +preconditions, not a property of the store at rest, and approval events receive +exactly the guarantee every other source receives. + +**Emission atomicity is `approval-engine`'s obligation.** An approval MUST NOT be +issued, consumed, superseded, or revoked without the corresponding event being +durably queued in the same transaction. + +**The queue MUST be local.** The durable queue MUST live in `approval-engine`'s +own transactional store, and **no synchronous dependency on `audit-core` may sit +inside the state-change transaction**. With a genuine local outbox, fail-closed +triggers only when `approval-engine`'s own store is unavailable — where the +change could not have been recorded anyway — and an `audit-core` outage does not +block a revocation. Satisfying the requirement by emitting synchronously to +`audit-core` inside the transaction is also atomic, and turns an audit outage +into an inability to revoke: the operation least tolerable to block during an +incident, and the same coupling this section rejects for reads. Raised by +`audit-core`. +`audit-core` reports what it received and does not imply it is everything that +happened; without atomic emission the evidence half is silently incomplete and +nothing detects the gap. This is a condition of `audit-core`'s assent +(`AUDIT-IN-0001`) and belongs in `approval-engine`'s contract before the evidence +half is treated as load-bearing. + +`audit-core` MUST NOT expose an approval-validity query. Records, yes; a verdict +on whether an approval is still valid, never — a consumer branching on that +answer would route an authorization decision through the audit fabric, which is +what this section exists to prevent. Callers needing current state ask +`approval-engine`. + +### 9.5 Graded progression is an engine concept + +Maturity — how far a subject has progressed against declared criteria and +submitted evidence — is owned by `maturity-engine`. Given the same criteria and +the same evidence it MUST return the same level; that determinism is what makes +it an Engine rather than an opinion. + +The division with Staff: **gate-house judges and proposes; maturity-engine +computes and remembers.** Interpretation is inference and stays Staff. A +criterion that cannot be evaluated by rule is not yet a criterion. + +This closes a defect in v0.2's own catalog: `gate-house` was assigned +conformance review with no engine to act through, which is exactly the §9.1 +problem raised against the containment claim. Staff acts only through Engine +APIs, including gate-house. + +**A maturity level MUST NOT be compiled into registry content.** Until +`access-engine`'s decision provenance carries a registry-snapshot digest — a gap +it self-declared in §13 — a level reaching a decision through the registry is not +reconstructable from the decision record. Levels arrive as request claims or as +versioned policy rules. Same constraint, and same reason, as zone stance. + +**A maturity level MUST NOT gate a decision directly.** Under §6.1, compiled +data that determines an outcome is still deciding. If a level determines whether +an action is permitted, it MUST reach `access-engine` as an input claim or a +versioned policy rule under §6.2, never by a consumer branching on a fetched +level. + +Approvals and maturity are deliberate opposites — a closed binary state machine +against an open graded ladder — and neither engine may drift toward the other. + +### 9.6 Evidence proves alteration and truncation, not omission at source + +An append-only archive with a verified hash chain proves that records were not +**altered or truncated after arrival**. It cannot prove that a record was never +sent. Against a compromised or buggy source, a suppressed event leaves the chain +perfectly intact and verification reports intact. + +This bound is estate-wide. Statements of the form *"the audit record proves it +happened"* are unsound; the sound form is *"the archive proves the records it +holds were not altered or truncated after arrival"*. Its mirror is equally +unsound: **absence of a record is not evidence of non-occurrence**, and no +control may read it as such. + +**Load-bearing versus attributive evidence.** The atomicity obligation attaches +to the first, not to both: + +| Kind | Test | Obligation | +| --- | --- | --- | +| **Load-bearing** | a control's soundness depends on the event being present or absent — an approval revocation, a containment action, a denial | emission MUST be atomic with the state change (§9.4) | +| **Attributive** | the event supports forensic reconstruction and attribution, and no control branches on its presence | atomicity SHOULD be sought; where it is deliberately traded away, the trade MUST be declared and completeness MUST NOT be claimed | + +Where a repository deliberately makes emission non-atomic — `ops-warden`'s +`# audit must not block signing` is the estate's live example, chosen so that an +audit-store failure cannot remove production host access — the trade is +legitimate for attributive evidence, MUST be declared where the trail is +documented, and MUST NOT be described in terms that imply completeness. The +availability argument is real in both directions: making it atomic gives the +estate's operational access lane a new dependency on its own evidence store. + +**Consequence for adaptive systems.** Suppression does not degrade observation +neutrally, it biases it optimistic, and silently: an event never emitted is never +evaluated, so no finding is raised and the last posture stands. A confidence +score computed from the richness of the record in hand cannot express doubt about +the completeness of the stream — a well-formed observation from a 90%-suppressed +stream scores high. That is this section's failure reproduced one layer up, in +the consumer. + +Two things follow. + +1. **The §8 asymmetry bounds the damage, and this is its clearest payoff.** + Because an adaptive system may only reduce authority and never manufacture it, + suppression can only prevent a tightening that should have happened. It cannot + be used to engineer a loosening. The harm is a missed reduction, not an + invented privilege — which is an argument for keeping the asymmetry absolute. +2. **Silence is a signal.** A source SHOULD declare an expected emission cadence, + and a drop below it SHOULD become a finding in its own right — the stream + observed, not only its contents. This converts the blind spot into something + detectable without any Tooling contact and without any engine gap, because the + source publishes its own stream. + +Raised by `audit-core` against its own principle; extended by `kings-guard` from +its own evaluator and confidence model. + +## 10. Changing layer + +A repository's layer is not permanent. `zone-engine` changed layer in practice +when its runtime hypothesis was falsified. + +A layer change MUST be recorded as a decision, MUST update the repository's +`INTENT.md`, and MUST obtain assent from the repositories whose boundaries move. +A repository MUST NOT acquire a new layer's permissions by gradual practice. + +## 11. Conformance + +Conformance has four states, and the distinction between the last two is the +point: + +| State | Meaning | +| --- | --- | +| **Conforming** | no Tooling contact, or only §5.1/§5.2 shapes, declared | +| **Blocked-clean** | the capability does not exist because no engine exposes it, and the repository makes **no** Tooling contact — §9.1 `pending`, and not a non-conformance | +| **Declared gap** | a §5.3 contact with owner, blocker, and review date — tracked non-conformance | +| **Undeclared violation** | anything else — a finding | + +**Blocked-clean is not a lesser state than conforming.** A repository that +declined a break-glass path and left a capability at zero has complied at cost; +a repository that quietly opened a direct client and declared nothing has not. +Any downstream scoring — `maturity-engine` included (§9.5) — MUST NOT rank the +first below the second. Raised by `kings-guard`, whose three gaps are all of +this kind and which would otherwise have been graded down three times for +having taken the standard seriously. + +**Who must declare.** A repository the estate authors declares its layer in its +own `INTENT.md`. For a component the estate catalogues but does not author — +third-party or vendored, such as `OpenBao` — the §4 catalog row **is** the +declaration, and no `INTENT.md` obligation attaches. A rule that assigns an +obligation the holder cannot discharge is the §9.1 defect applied to conformance +rather than capability. + +A layer stated *about* a repository by another repository is not a declaration. +Review notes, catalog rows, and correspondence record an intent to adopt; only +the repository's own file conforms. + +**Declaration form.** Because prose cannot distinguish a declaration from a +transcribed review, a declaration MUST carry a machine-readable form: a `layer:` +key in the `INTENT.md` frontmatter, or an equivalent declaration file. Without +it this section asserts a property it cannot deliver — the defect this standard +has now corrected three times elsewhere. `ops-warden` has implemented a reference +form (`layer.yaml`, a conformance script, and a test covering the §5.2 +no-authority property) and offered it to the repositories that have yet to +declare. Raised by `audit-core`, which noted that `flex-auth`'s conforming +declaration is legible as one only by following its decision trail. + +Mechanically checkable: + +- every estate-authored repository in §4 carries a machine-readable layer + declaration; +- every direct Tooling client in a Staff repository maps to a declared §5.1, + §5.2, or §5.3 entry, and non-Tooling clients are recorded so the check is + total; +- no repository other than `access-engine` exposes an authorization decision + surface; +- no §4 capability is catalogued without an engine surface, a `pending` mark, or + a `declared-gap` mark. + +Requires review: whether claims stay inside layer permissions; whether compiled +or cached data has become an early decision (§6.1); whether doctrine is reaching +decisions as declared inputs (§6.2); whether the §8 vocabulary is used correctly. + +## 12. The conformance loop + +Doctrine no engine implements is fiction. The loop is normative, not +aspirational: + +```text +gate-house asserts an invariant + → the engines implement it, or declare a gap + → whitehat-security tries to break it + → kings-guard observes it in operation + → findings return to gate-house as doctrine change +``` + +A finding that a rule is unsatisfiable is a **success** of this loop, not a +failure of the reporting repository. Four of this standard's five versions exist +because a reviewing repository used it. + +**Step four is currently aspiration.** `kings-guard` has disclosed that it has +never observed anything in operation: the pilot is specified and scaffolded, every +input is a hand-built fixture, and no test has met a real event. Until it reports +otherwise, no argument in this estate may assume an invariant is being watched in +practice because §12 lists a repository against that step. + +## 13. Open gaps + +Two different things are recorded here, and they are opposite conformance states +(§11). A **declared contact** means the repository touches Tooling because no +engine exposes the capability. An **unowned capability** means no route exists +and the repository makes no contact at all. Reading them as one list would grade +restraint as though it were non-conformance. + +An `intended owner` is a **proposal to** the named repository, not an assignment +**onto** it. §2 keeps ownership in the repository's own `INTENT.md`, so the +register distinguishes proposed from assented. + +| Gap | State | Declared by | Owner | Owner status | +| --- | --- | --- | --- | --- | +| SSH-CA signing write (`VaultCA`, `bao kv put`) | declared-contact | ops-warden | secrets-engine | proposed | +| Authentication / assurance evidence | unowned-capability | kings-guard | identity layer + audit-core | **access-engine declined** | +| Secret-use evidence | unowned-capability | kings-guard | secrets-engine | proposed | +| Containment surface | unowned-capability | kings-guard | access-engine + runtime engines | proposed | +| Identity and secret observation | unowned-capability | kings-guard | as above | proposed | +| Registry-snapshot digest in decision provenance | declared-contact | flex-auth | flex-auth | self-declared | +| Approval storage and lifecycle | — | flex-auth | approval-engine | assigned (§9.4) | +| Approval evidence | — | gate-house | audit-core | **assented** (`AUDIT-IN-0001`) | +| Approval evidence custody stronger than the shipped bound — WORM, object lock, transparency log | unowned-capability | audit-core | — | unassigned | +| Emission atomicity for approval state changes | — | audit-core | approval-engine | assigned (§9.4) | +| Non-atomic audit emission on the SSH signing lane | declared-contact | ops-warden | ops-warden | self-declared, attributive (§9.6) | + +`access-engine` declined authentication and assurance evidence +(`FLEX-DEC-2026-002`): it consumes assurance claims as input and never redefines +them, so evidence of authentication belongs to the identity layer and +`audit-core`. It owns evidence of the decision, which it already emits. The +containment surface is recorded as proposed and remains `pending` under §9.2. + +Whether approvals warrant custody stronger than every other source is doctrine +work not yet done; until it is, approval evidence carries the same guarantee as +any other source and §9.6 bounds what may be claimed from it. + +Gaps are recorded here but tracked in `maturity-engine` (§9.5) once it exists; +this table is the interim register and should not outlive it. The `state` column +MUST survive that migration. + +## 14. Adoption + +Status is **proposed** — the frontmatter is authoritative, and v0.2 was the last +version to reach `accepted`. Four repositories have assented, each with a record, +and all four returned findings on the versions since: + +| Repository | Record | Outcome | +| --- | --- | --- | +| flex-auth | `FLEX-DEC-2026-001` | assent to all three items; one self-declared non-conformance; two rename conditions | +| kings-guard | `KG-DEC-2026-001` | assent; declined the offered §5 relaxation; raised §9.1 | +| ops-warden | `ADR-0010` | assent to all three; veto not exercised; offered the §5.3 amendment | +| audit-core | `AUDIT-IN-0001` | assent to the evidence half with conditions; corrected the rationale twice; raised §9.6 | + +Adoption for a repository means its `INTENT.md` declares its layer, its +ownership claims fall inside that layer, its Tooling contacts are declared under +§5, and any shared boundary has been assented to by the other side. + +**Adoption status as of 2026-08-29: seven of sixteen** estate-authored §4 +repositories have declared in their own voice — `gate-house`, `flex-auth`, +`kings-guard`, `ops-warden`, `audit-core`, `approval-engine`, `maturity-engine`. +The remaining nine — `info-tech-canon`, `net-kingdom`, `key-cape`, +`user-engine`, `tenant-engine`, `zone-engine`, `secrets-engine`, `ops-mason`, +`whitehat-security` — carry a layering review note authored by `gate-house` and +have not answered it. Those notes state a layer but do not constitute a +declaration, and this standard does not claim estate-wide adoption on their +basis. Declaration requests are open as intakes in each. + +## 15. Change log + +v0.1 → v0.2: + +1. **§5 restructured** into three sanctioned shapes. Added §5.2 conduit + (ops-warden's question, ruled) and §5.3 declared engine gap (ops-warden's + amendment, accepted). +2. **§6.2 added** — doctrine must reach the decision as an input claim or a + versioned policy rule (flex-auth's boundary drawn back, accepted). +3. **§9 added** — the catalog may not assign a capability the rules forbid + discharging; containment marked pending; degraded-mode fallback ruled into + the engine (kings-guard's finding). +4. **§11 restructured** — conformance now has three states, distinguishing a + tracked gap from an undeclared violation. +5. **§12 made normative**, with the explicit statement that an + unsatisfiability finding is a success of the loop. +6. **§13 added** — open gaps register, including the unowned approval storage + and lifecycle capability. +7. §4 catalog gained the pending mark and ops-warden's SSH certificate lane. + +v0.2 → v0.3: + +1. **§9.4 added** — approvals assigned to `approval-engine`, with the operative + state and the evidence record separated between it and `audit-core`. +2. **§9.5 added** — graded progression assigned to `maturity-engine`, closing + the §9.1 defect in gate-house's own conformance-review claim, and carrying + the guardrail that a level may never gate a decision directly. +3. §4 catalog gained both engines; gate-house's conformance-review claim now + names the engine it acts through. +4. §13 register updated: the approval hole is assigned, two new entries added. + +v0.4 → v0.5, all from review findings: + +1. **§9.1 split into two marks** — `pending` (no route, capability zero) and + `declared-gap` (route exists under §5.3, capability works and is tracked). + v0.4's single mark would have forced a false `pending` onto ops-warden's + production SSH issuance. Raised by `ops-warden`. +2. **§9.3 rewritten** — input degradation is the engine's; engine-unreachability + is necessarily the consumer's, bounded by a declared, auditable, total stance. + Contested by `flex-auth`: fail-open is not expressible by a PDP, and v0.4 + collided with `ops-warden` `ADR-0009`. +3. **§5 gained a scope rule** — "Tooling-layer system" means a §4 Tooling row; + uncatalogued infrastructure is outside §5 and recorded rather than policed. + Without it every Staff repository was in undeclared violation for writing + progress events. Raised by `ops-warden`. +4. **§9.4 requires a local outbox** — no synchronous dependency on `audit-core` + inside the state-change transaction, so an audit outage cannot block a + revocation. Raised by `audit-core`. +5. **§9.5 forbids compiling maturity levels into registry content** until + decision provenance carries a registry-snapshot digest. Raised by `flex-auth`. +6. **§9.6 gained the load-bearing / attributive distinction**, the mirror rule + that absence is not evidence of non-occurrence, the optimistic-bias + consequence for adaptive systems, and silence-as-signal. Raised by + `kings-guard` on top of `audit-core`'s original. +7. **§11 gained a fourth state** — blocked-clean, which MUST NOT rank below + conforming — and a machine-readable declaration form. Raised by `kings-guard` + and `audit-core`. +8. **§13 gained state and owner-status columns** — declared-contact versus + unowned-capability, proposed versus assented owner. `access-engine`'s + decline of authentication evidence is recorded. Raised by `kings-guard` and + `flex-auth`. +9. **§8** records the asymmetry's payoff under incomplete observation; **§12** + records that its fourth step is unstaffed; **§14** corrects the adoption + arithmetic and the status contradiction. + +Amended in place while `proposed`, 2026-08-28: §11 gained the who-must-declare +rule after a conformance sweep found the standard required an `INTENT.md` +declaration from `OpenBao`, which the estate does not author; and §14 gained the +honest adoption count. + +v0.3 → v0.4: + +1. **§4 catalog gained `audit-core`** as an Engine, on its own declaration. v0.3 + named it as an owner in §9.4 and §13 without cataloguing it — a §11 defect in + the standard itself, raised by `audit-core`. +2. **§9.4 evidence rationale rewritten** to cite `audit-core`'s shipped + `docs/integrity.md` bound rather than its INTENT principle 6, and to state + that `tamper_evidence` is conditional on live preconditions. +3. **§9.4 gained emission atomicity** as `approval-engine`'s obligation, and the + prohibition on `audit-core` exposing an approval-validity query. +4. **§9.6 added** — evidence proves alteration and truncation, not omission at + source. Estate-wide; the sound and unsound forms of the claim are stated. +5. **§13** — evidence half recorded as assented with conditions; two new gaps: + stronger approval custody (unassigned) and emission atomicity + (`approval-engine`). + +## 16. Open questions + +- Whether approvals warrant archival custody stronger than every other audit + source (§13), and if so which mechanism and who owns it. +- Whether SSH certificate issuance evidence is load-bearing or attributive + (§9.6). Ruled attributive here on the argument that no control branches on the + presence of a signing record; `ops-warden` asked for the ruling and the trade + is genuinely two-sided, so it is flagged rather than settled. +- Who marks an approval consumed, and at what point relative to the decision + (§9.4). `flex-auth` notes the decision precedes the action and the action + precedes consumption, so an allow rendered against an approval then never + consumed, or consumed twice by a racing caller, is a gap neither engine closes + alone. Needed before `FLEX-WP-0017` T05. +- Whether other §4 repositories are missing layer declarations; `audit-core` + flagged its own absence and asked whether the catalog needs the same + correction elsewhere. +- Whether the gap register migrates from this standard into `maturity-engine` + once that engine exists, leaving the standard to state the rules only. +- Whether Tooling warrants subdivision between third-party and homegrown. +- How a future `role-engine` divides responsibility with `access-engine`. +- Whether declared gaps need an estate-wide register rather than per-repository + declarations; ops-warden's `warden route gaps` is candidate machinery. +- Whether non-security repositories adopt the same model.