From 6204184930b13f032b21629296867ebdf1fa6d44 Mon Sep 17 00:00:00 2001 From: tegwick Date: Sun, 23 Aug 2026 11:58:39 +0200 Subject: [PATCH] docs(scope): reconcile capability with intent Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02929-244b-7391-b933-c04010e8eedb --- SCOPE.md | 254 ++++++++++-------- WORK-RECORDS.md | 5 + .../2026-08-23-scope-intent-gap-assessment.md | 137 ++++++++++ ...WP-0029-scope-and-intent-reconciliation.md | 72 +++++ 4 files changed, 351 insertions(+), 117 deletions(-) create mode 100644 history/2026-08-23-scope-intent-gap-assessment.md create mode 100644 workplans/NK-WP-0029-scope-and-intent-reconciliation.md diff --git a/SCOPE.md b/SCOPE.md index 9ffecc4..5af89e6 100644 --- a/SCOPE.md +++ b/SCOPE.md @@ -1,168 +1,188 @@ # SCOPE -> This file helps you quickly understand what this repository is about, -> when it is relevant, and when it is not. -> It is intentionally lightweight and may be incomplete. +> This file describes the repository's current capability and authority. +> `INTENT.md` remains the aspirational direction; the difference is assessed in +> `history/2026-08-23-scope-intent-gap-assessment.md`. --- ## One-liner -Platform domain for NetKingdom identity and security services — owns the IAM Profile specification, SSO/MFA platform (Keycloak), and bootstrap local-identity infrastructure for Kubernetes deployments. +Canonical security architecture and bootstrap/reference implementation for +NetKingdom: defines identity, tenancy, workload-zone, credential, and +orchestration contracts; supplies conformance and bootstrap tooling; and +coordinates their realization across KeyCape, flex-auth, OpenBao, and +Railiance. --- ## Core Idea -NetKingdom is a self-optimizing security platform for Kubernetes-based IT infrastructure. This repo owns identity at the platform level: the NetKingdom IAM Profile specification (the versioned OIDC/PKCE contract all applications target), the enterprise Keycloak-based SSO/MFA platform, and a lightweight file-based local-identity service for bootstrap environments before the full cluster is available. +This repository is NetKingdom's security canon and integration hub. It defines +provider-neutral contracts and responsibility boundaries, provides executable +validators and bootstrap/reference tooling, and records how independently owned +services compose into a security control plane. + +It does not own every runtime that realizes those contracts. Service +implementations, Kubernetes infrastructure, platform data services, and managed +deployment packages remain in their respective repositories. The dynamic, +self-optimizing platform in `INTENT.md` is the direction of travel, not a claim +about the current implementation. --- ## In Scope -- NetKingdom IAM Profile specification (versioned OIDC/PKCE contract; - canonical spec: `canon/standards/iam-profile_v0.3.md`) -- SSO/MFA Platform: Keycloak with LDAP/Entra federation, enterprise identity (NK-WP-0001, finished) -- Local Identity: file-based user store + minimal OIDC server for bootstrap phase (NK-WP-0002, finished) -- User Engine Boundary Contract: source-of-truth, membership, - application-onboarding, projection, authorization, and audit contracts for - `user-engine` integration (`canon/standards/user-engine-boundary-contract_v0.1.md`) -- Security bootstrapping: credential management, SOPS/age integration, - platform-root custody, OpenBao runtime secret authority -- OpenBao init/unseal custody models (NET-WP-0020): `sops-held-automation` - (lab, unattended greenfield rebuilds via `creds-bootstrap-agent` Phase 7b), - `attended-ceremony` (production, runbook + non-secret evidence records), and - `auto-unseal-transit` (production HA; seal stanza lives in - railiance-platform) — all gated by the security bootstrap console and a - lab/production deployment profile -- Security bootstrap console (`tools/security-bootstrap-console/`): custody - gates, roster, evidence validators, refuse-live-init boundary -- Architectural decisions (DECISIONS.md): identity source, secrets, GitOps, bootstrap user store +### Canon and architecture + +- NetKingdom IAM Profile v0.3: the accepted provider-neutral OIDC/PKCE, + principal, tenant, workload-identity, assurance, and flex-auth input contract. +- Accepted user-engine and tenant-engine boundary contracts. +- Credential Management Standard v0.2 and the platform-root/OpenBao custody + model. +- Playbook Capability Contract v0.1 for the boundary between NetKingdom + selection/parameterization and Railiance execution. +- Tenancy Posture v0.1 and Security Zones v0.1 proposed standards, their schemas, + validators, evidence rules, and publication stewardship. Zone semantics are + owned by `zone-engine`; NetKingdom owns their canon publication. +- Architecture decisions and the cross-repository responsibility map for + identity, authorization, credentials, tenancy, and bootstrap trust. + +### Executable reference and verification surfaces + +- `local-identity/`: minimal file-backed OIDC identity for bootstrap, + development, test, and sandbox use. +- IAM Profile, playbook-capability, tenancy-posture, custody, evidence, and + bootstrap-policy validators. +- `tools/security-bootstrap-console/`: guarded platform-root and OpenBao + bootstrap workflow, including refusal of unsafe live initialization. +- SOPS/age bootstrap integration, credential-generation and rotation helpers, + and documented attended, automated-lab, and auto-unseal custody paths. +- Reference and migration-stage manifests/runbooks for the current lightweight + identity stack: KeyCape, Authelia, LLDAP, and privacyIDEA. + +### Integration and meta-orchestration contracts + +- Capability selection, safe parameterization, trust-state requirements, and + responsibility assignment across Railiance playbooks. +- User/tenant onboarding boundaries, issuer/client registration patterns, + caller identity, workload identity, authorization inputs, and audit evidence. +- Cross-repository workplans and decision records needed to converge security + providers without absorbing their implementations into this repository. --- -## Out of Scope +## Authority Boundaries -- Kubernetes runtime concerns → railiance-cluster -- Platform services (PostgreSQL, storage, caches) → railiance-platform -- Application deployments → railiance-apps -- KeyCape implementation details → key-cape +This repository owns security semantics and composition rules. It does not own: + +- KeyCape's implementation (`key-cape`) +- authorization service implementation or policy evaluation (`flex-auth` and + its PDP adapters) +- runtime secret-service deployment (`railiance-platform` / OpenBao) +- Kubernetes and host infrastructure (`railiance-cluster`, + `railiance-infra`) +- SSH certificate issuance or tunnels (`ops-warden`, `ops-bridge`) +- user or tenant service implementation (`user-engine`, `tenant-engine`) +- managed application packages (`rapp-*` repositories) +- generic platform data services such as PostgreSQL and storage + (`railiance-platform`) + +The material under `sso-mfa/k8s/` includes live-proven integration history and +migration inputs. It is not blanket authority for managed runtime deployment. +ADR-0015 moves package/application ownership to the relevant `rapp-*` +repositories while NetKingdom retains the contracts and reference evidence. + +--- + +## Current Capability + +| Tier | Current repository/estate capability | Delivery state | +| --- | --- | --- | +| C0 — Bootstrap identity | Local OIDC identity, SOPS/age bootstrap, guarded credential workflow, and greenfield OpenBao init/unseal proof | Implemented as reference/bootstrap tooling | +| C1 — Lightweight SSO | IAM-profile-based KeyCape composition using Authelia and LLDAP | Live-proven integration; implementation externally owned | +| C2 — MFA/token authority | Authelia factors and privacyIDEA integration | Live-proven integration; implementation externally owned | +| C3 — Runtime secrets | OpenBao custody, bootstrap, policy, delivery, and recovery contracts | Integrated with an externally deployed runtime; production evidence remains gated | +| C4 — Fine-grained authorization | flex-auth caller identity and boundary integration | Partially delivered; full estate/PDP readiness is not established here | +| C5 — Enterprise federation | Keycloak/SAML/enterprise-IdP design | Backlog; not a current provided runtime capability | +| C6 — Self-optimizing security | Declarations, validators, evidence freshness, workplans, and drift surfacing | Early governance mechanisms only; no autonomous closed loop | + +Current open work as of 2026-08-23 is either externally blocked, date-gated, or +explicit backlog: reef carrier/public-classification decisions in NK-WP-0027, +the NK-WP-0022 retirement gate, security tutorials in NK-WP-0009, and +enterprise federation in NK-WP-0011. --- ## Relevant When -- Setting up identity for a NetKingdom/Railiance deployment -- Designing or using the guided security bootstrap experience -- Applications need OIDC authentication; deciding between lightweight (KeyCape) and expanded (Keycloak) modes -- Bootstrap scenario: cluster not yet available, need minimal OIDC for dev/test/sandbox -- Reviewing IAM Profile specification or architectural identity decisions - ---- +- Defining or reviewing identity, tenancy, workload-zone, credential, and + security-composition canon. +- Bootstrapping identity and trust before the normal platform is available. +- Validating an IAM issuer, posture declaration, or Railiance capability + declaration against NetKingdom contracts. +- Integrating KeyCape, flex-auth, OpenBao, user-engine, tenant-engine, or a + Railiance package across an explicit security boundary. +- Deciding which repository owns a security semantic, runtime, deployment, or + evidence obligation. ## Not Relevant When -- Infrastructure provisioning (use railiance-infra) -- Platform services configuration (use railiance-platform) -- Application-level auth code (use the IAM Profile spec as reference only) - ---- - -## Current State - -- Status: active — core identity and bootstrap phases delivered; follow-on work - in backlog -- Implementation: NK-WP-0001 (SSO/MFA), NK-WP-0002 (local identity), the - security bootstrap arc (NET-WP-0015–0017, 0019), the IAM Profile spec - (NK-WP-0012), user-engine boundary contracts (NK-WP-0014), and OpenBao - unseal custody + SSH automation (NET-WP-0020) are all finished — see - `workplans/archived/` -- Backlog: NK-WP-0009 (security pattern tutorials) and NK-WP-0011 (enterprise - federation / SAML) — postponed, not yet started -- Stability: stabilizing — bootstrap/custody tooling is live-proven (greenfield - OpenBao init/unseal proof 2026-07-02); production custody models are gated - by evidence -- Usage: foundational authentication layer for all NetKingdom deployments -- Sister-repo maturity: [reuse.coulomb.social](https://reuse.coulomb.social) - federated capability registry - ---- - -## How It Fits - -- Upstream dependencies: KeyCape (lightweight IAM implementation), Authelia, Keycloak, LLDAP, privacyIDEA -- Downstream consumers: railiance (all Railiance deployments), applications targeting the NetKingdom IAM Profile -- Often used with: key-cape (lightweight mode), railiance-platform (identity services integration), railiance-cluster (deployed on Kubernetes) - ---- - -## Terminology - -- Preferred terms: NetKingdom IAM Profile, local identity, SSO/MFA platform, bootstrap, lightweight mode, expanded mode -- Also known as: "net-kingdom" -- Potentially confusing terms: "local identity" = file-based bootstrap store (not a full LDAP); "SSO/MFA platform" = production Keycloak deployment - ---- - -## Related / Overlapping - -- `key-cape` — lightweight IAM implementation (KeyCape orchestrates Authelia+LLDAP+privacyIDEA) -- `railiance-platform` — net-kingdom identity services integrate at the platform services layer +- Implementing a provider's internal service behavior: work in that service's + repository. +- Provisioning hosts or Kubernetes: use `railiance-infra` and + `railiance-cluster`. +- Operating generic platform services: use `railiance-platform`. +- Shipping a managed application package: use its `rapp-*` repository. +- Treating the proposed Keycloak expanded mode or autonomous adaptation as an + already delivered feature. --- ## Provided Capabilities ```capability -type: security -title: NetKingdom IAM Profile specification -description: Versioned OIDC/PKCE contract that all NetKingdom applications target — canonical v0.2 defines discovery, PKCE, token, JWKS, tenant, principal-type, assurance, and flex-auth claim inputs. -keywords: [iam, oidc, pkce, profile, specification, identity, authentication] +type: governance +title: NetKingdom security canon +description: Provider-neutral IAM v0.3, user/tenant boundaries, credential, playbook-composition, tenancy-posture, and workload-zone standards with explicit ownership and conformance rules. +keywords: [iam, oidc, tenancy, workload-identity, security-zones, credentials, canon] ``` ```capability -type: security -title: SSO/MFA platform (Keycloak) -description: Enterprise-grade Keycloak-based SSO with LDAP/Entra federation, MFA, and full OIDC/PKCE support for production deployments. -keywords: [sso, mfa, keycloak, ldap, entra, federation, oidc, enterprise] +type: validation +title: Security contract conformance +description: Executable validation for IAM Profile issuers, playbook capability declarations, tenancy posture, bootstrap custody, and non-secret evidence records. +keywords: [validation, conformance, iam, posture, evidence, playbooks] ``` ```capability -type: security -title: OpenBao unseal custody models and bootstrap automation -description: Three gated init/unseal custody models — SOPS-held automation for unattended lab rebuilds (greenfield-proven), attended ceremony with non-secret evidence records for production, and transit/KMS auto-unseal for production HA — enforced by the security bootstrap console and a lab/production deployment profile. -keywords: [openbao, unseal, custody, bootstrap, sops, age, ceremony, transit, auto-unseal, console] +type: tooling +title: Guarded security bootstrap +description: Local bootstrap identity plus SOPS/age and OpenBao custody workflows that establish trust while refusing unsafe or unevidenced live initialization. +keywords: [bootstrap, local-identity, openbao, sops, age, custody, recovery] ``` ```capability -type: security -title: Bootstrap local identity service -description: Minimal file-based OIDC server for environments where the full cluster is not yet available — covers dev, test, and sandbox bootstrapping scenarios. -keywords: [bootstrap, local-identity, oidc, minimal, dev, sandbox] +type: governance +title: Security meta-orchestration boundary +description: Contracts and responsibility maps for selecting and parameterizing externally executed Railiance security capabilities without reimplementing their deployment mechanics. +keywords: [meta-orchestration, railiance, responsibility, capability, trust-state] ``` --- ## Getting Oriented -- Start with: `wiki/` (specifications and decisions), `DECISIONS.md` (key - architectural choices D1–D5) -- Key files / directories: `docs/platform-root-custody.md`, `sso-mfa/` - (SSO/MFA platform + bootstrap scripts), `local-identity/`, - `tools/security-bootstrap-console/`, `workplans/` (finished plans in - `workplans/archived/`) -- Backlog entry points: `workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md` - and `workplans/NK-WP-0011-enterprise-federation-saml.md`; finished context - in `workplans/archived/` -- User-domain boundary contract: - `canon/standards/user-engine-boundary-contract_v0.1.md` -- User-engine integration assessment (intent/scope fit, gaps, and recommendations): - `docs/user-engine-netkingdom-integration-assessment.md` -- Bootstrap/custody entry points: - `docs/platform-root-custody.md`, +- Direction: `INTENT.md` +- Current-vs-intended assessment: + `history/2026-08-23-scope-intent-gap-assessment.md` +- Canon: `canon/standards/`, `canon/schemas/`, and `docs/adr/` +- Architecture and ownership: `docs/platform-identity-security-architecture.md` + and `docs/responsibility-map.md` +- Bootstrap/custody: `docs/platform-root-custody.md`, `docs/security-bootstrap-use-cases.md`, - `docs/openbao-unseal-custody-models.md` (three custody models + deployment - profile), and `docs/openbao-attended-ceremony-runbook.md` (production - ceremony); history of the custody/bootstrap arc in `workplans/archived/` - (NET-WP-0015–0017, 0019) and - `workplans/NET-WP-0020-openbao-unseal-custody-and-ssh-automation.md` + `docs/openbao-unseal-custody-models.md`, and + `tools/security-bootstrap-console/` +- Executable surfaces: `local-identity/`, `tools/iam-profile-conformance/`, + `tools/playbook-capability-contract/`, and `tools/tenancy-posture/` +- Work state: `.custodian-brief.md` and `workplans/` diff --git a/WORK-RECORDS.md b/WORK-RECORDS.md index 6d86289..3df803d 100644 --- a/WORK-RECORDS.md +++ b/WORK-RECORDS.md @@ -22,6 +22,7 @@ | workplan | NK-WP-0026 | finished | — | workplans/NK-WP-0026-flex-auth-caller-identity-rollout.md | | workplan | NK-WP-0027 | blocked | — | workplans/NK-WP-0027-reef-placement-reconciliation.md | | workplan | NK-WP-0028 | finished | — | workplans/NK-WP-0028-canon-publication-and-grouping-semantics.md | +| workplan | NK-WP-0029 | finished | — | workplans/NK-WP-0029-scope-and-intent-reconciliation.md | | task | ADHOC-2026-07-02-T01 | done | — | workplans/ADHOC-2026-07-02.md | | task | ADHOC-2026-07-02-T02 | done | — | workplans/ADHOC-2026-07-02.md | | task | ADHOC-2026-08-14-T01 | done | — | workplans/ADHOC-2026-08-14.md | @@ -89,5 +90,9 @@ | task | NK-WP-0028-T02 | done | — | workplans/NK-WP-0028-canon-publication-and-grouping-semantics.md | | task | NK-WP-0028-T03 | done | — | workplans/NK-WP-0028-canon-publication-and-grouping-semantics.md | | task | NK-WP-0028-T04 | done | — | workplans/NK-WP-0028-canon-publication-and-grouping-semantics.md | +| task | NK-WP-0029-T01 | done | — | workplans/NK-WP-0029-scope-and-intent-reconciliation.md | +| task | NK-WP-0029-T02 | done | — | workplans/NK-WP-0029-scope-and-intent-reconciliation.md | +| task | NK-WP-0029-T03 | done | — | workplans/NK-WP-0029-scope-and-intent-reconciliation.md | +| task | NK-WP-0029-T04 | done | — | workplans/NK-WP-0029-scope-and-intent-reconciliation.md | | intake | NK-IN-0001 | closed | blue | docs/intakes/activity-core-ops-sso-operators.md | | intake | NK-IN-0002 | closed | blue | docs/intakes/activity-core-ops-sso-operators.md | diff --git a/history/2026-08-23-scope-intent-gap-assessment.md b/history/2026-08-23-scope-intent-gap-assessment.md new file mode 100644 index 0000000..ed23cb6 --- /dev/null +++ b/history/2026-08-23-scope-intent-gap-assessment.md @@ -0,0 +1,137 @@ +# NetKingdom scope-to-intent gap assessment + +Date: 2026-08-23 +Assessment target: `SCOPE.md` against `INTENT.md` +Status: current-state assessment, not an architectural decision + +## Executive assessment + +NetKingdom is coherent and useful today as a **security canon, +integration-architecture, and bootstrap/reference-tooling repository**. Its +strongest delivered surfaces are bootstrap identity and custody, a +provider-neutral identity contract, live lightweight SSO/MFA integration, +explicit user/tenant/credential boundaries, and executable conformance checks. + +It is not yet the **dynamic, self-optimizing, full-circle security platform** +described by `INTENT.md`. In particular, it does not yet select and execute a +scenario to turn-key readiness, run a closed audit-to-policy improvement loop, +or provide enterprise federation. Those remain valid intent; they must not be +represented as current capability. + +The revised `SCOPE.md` therefore narrows current claims without narrowing the +mission. NetKingdom owns security semantics, contracts, bootstrap/reference +tools, and cross-repository composition. The runtime services and managed +deployment packages remain with their implementation owners. + +## Evidence basis + +The assessment used the repository state and work records current on the date +above, especially: + +- `INTENT.md` and `docs/platform-identity-security-architecture.md` +- `canon/standards/` and their executable schemas/validators +- `docs/responsibility-map.md` and ADR-0006 through ADR-0015 +- `local-identity/`, `tools/security-bootstrap-console/`, and other validators + under `tools/` +- `sso-mfa/` deployment/integration assets and runbooks +- current and archived workplans, including NK-WP-0001/0002/0006/0011/0012, + NET-WP-0015 through NET-WP-0020, and NK-WP-0022/0027/0028 +- the 2026-07-02 greenfield OpenBao proof in `history/` + +## Assessment by intent principle + +| Intent principle | Current evidence | Assessment | Material gap | +| --- | --- | --- | --- | +| Bootstrap First | `local-identity`, SOPS/age helpers, bootstrap agent, guarded console, and a greenfield OpenBao init/unseal proof | Substantially implemented as a reference path | Production HA/auto-unseal, attended ceremony, restore, and break-glass evidence are not all closed; legacy retirement remains date-gated in NK-WP-0022 | +| Identity is the Control Plane | IAM Profile v0.3, lightweight KeyCape integration, explicit tenant roles/grouping, workload identity, user/tenant boundaries, and flex-auth caller identity | Strong contract layer with meaningful live integration | Authoritative identity/zone coverage is incomplete across the estate; some operational paths still rely on compatibility credentials; expanded enterprise identity is absent | +| Open & Replaceable Core | Provider-neutral OIDC contract, conformance tests, explicit provider boundaries, and open components | Contractually strong, operationally partial | Replacement/transition has not been proven with a second production issuer; Keycloak coexistence and migration rules remain backlog work | +| Progressive Capability Expansion | C0-C6 ladder is defined; C0-C3 have delivered components; C4 has partial integration | Architecture is clear and lower tiers are useful | There is no executable tier/scenario composer, C4 is not demonstrated end-to-end for the whole estate, and C5 is not delivered | +| Self-Optimization | Posture declarations, validators, evidence freshness, workplan/state reconciliation, and drift surfacing | Early feedback mechanisms only | No closed telemetry-to-policy loop, learned policy adaptation, autonomous mitigation, or bounded kaizen-agent control loop exists | +| Minimize Threat Exposure | Default-deny boundaries, scoped identities, short-lived token patterns, OpenBao custody, non-secret evidence, and separation of platform root from tenant admin | Strong design and several live proofs | Durable audit, restore, dual-control/break-glass evidence, remaining static credentials, and complete zone/data-classification adoption remain open | +| Meta-Orchestration | Playbook Capability Contract and responsibility map define selection, parameter, trust-state, and ownership semantics | Contract layer implemented | No turn-key scenario orchestrator composes and drives the selected playbooks; reef carrier/provider authority needed by NK-WP-0027 is unresolved | +| Kaizen-agent operating model | File-first workplans, State Hub reconciliation, freshness dates, cross-repo routing, and agent-executed verification | Process foundation exists | No standing, explicitly assigned and scheduled workforce covers recurring rotation, audit, drift, restore, and remediation duties end-to-end | + +## Prioritized gaps + +### G1 — Executable meta-orchestration + +The largest mission gap is between a declared playbook contract and an +operator-selectable scenario that reaches verified, ready-to-run state. +NetKingdom can describe responsibilities and capability inputs, but it does not +yet compose a requested C0-Cn target, resolve providers, execute Railiance +playbooks, and verify the resulting trust state as one bounded workflow. + +Next evidence should be one narrow scenario—preferably the already proven +lightweight identity path—expressed as capability declarations, selected by a +small composer, executed by owning repositories, and closed by machine-readable +readiness evidence. + +### G2 — C6 feedback and continuous evidence + +Posture and evidence records can expose drift, but no supported loop turns that +signal into a reviewed policy or remediation change. A safe first C6 increment +should be deterministic rather than self-learning: freshness expiry or a failed +posture assertion opens owner-scoped work, proposes a bounded remediation, and +requires evidence before closure. Autonomous policy mutation should remain out +of scope until authority, rollback, and human-review boundaries are explicit. + +### G3 — Enterprise federation and provider transition + +NK-WP-0011 remains backlog. Until a Keycloak/enterprise-IdP path and coexistence +rules are implemented and conformance-tested, this repository provides the +expanded-mode architecture only. It must not advertise enterprise Keycloak, +LDAP/Entra federation, SAML brokering, or multi-realm operation as delivered. + +### G4 — Runtime/package authority convergence + +The repository still contains Kubernetes assets with operational history while +ADR-0015 assigns managed application packages to `rapp-user-engine`, +`rapp-tenant-engine`, and analogous package owners. Each retained manifest must +be classified as canonical reference, test fixture, migration input, or retired +asset. Apply authority should become unambiguous without discarding useful +evidence. + +### G5 — Ratification and estate adoption of newer canon + +Tenancy Posture v0.1 and Security Zones v0.1 remain proposed. Their local schema +and validation surfaces exist, but adoption depends on external declarations, +zone-engine semantic ownership, reef carrier resolution, and an InfoTech Canon +classification ruling. NK-WP-0027 tracks these dependencies. Missing or +ambiguous authoritative membership must continue to resolve to `unknown`, never +to an inferred permissive zone. + +### G6 — Production custody, audit, and recovery evidence + +The bootstrap/custody arc is technically substantial, including a live +greenfield OpenBao proof. Production readiness still needs durable evidence for +HA/auto-unseal or attended ceremony, audit shipping and restoration, +break-glass review, credential rotation, and removal of superseded compatibility +credentials. NK-WP-0022 carries the immediate date-gated retirement work. + +### G7 — Operator learning and repeatability + +NK-WP-0009 remains backlog. Tutorials are not the primary architectural gap, +but concise operator paths are necessary if the capability ladder is to be +selectable and repeatable by humans and agents other than its original authors. + +## Scope ruling + +Until G1 and G2 are delivered, the repository should describe itself as: + +> NetKingdom's canonical security architecture, integration boundary, and +> bootstrap/reference implementation. + +It should not describe itself as an already self-optimizing platform, a general +deployment repository, or the implementation owner of Keycloak, KeyCape, +flex-auth, OpenBao, user-engine, tenant-engine, Kubernetes, or Railiance +packages. `INTENT.md` should remain unchanged: it is an appropriately ambitious +destination and already labels itself aspirational. + +## Work-state conclusion + +At assessment time there was no locally actionable ready/active implementation +task beyond this reconciliation. Remaining work was blocked on external canon +or provider inputs (NK-WP-0027), date-gated (NK-WP-0022), or explicitly backlog +(NK-WP-0009 and NK-WP-0011). This is not an assertion that the intended system +is complete; it is a statement about the executable queue in this repository on +2026-08-23. diff --git a/workplans/NK-WP-0029-scope-and-intent-reconciliation.md b/workplans/NK-WP-0029-scope-and-intent-reconciliation.md new file mode 100644 index 0000000..2409b07 --- /dev/null +++ b/workplans/NK-WP-0029-scope-and-intent-reconciliation.md @@ -0,0 +1,72 @@ +--- +id: NK-WP-0029 +type: workplan +title: "Reconcile repository scope with implemented capability and intent" +domain: infotech +repo: net-kingdom +status: finished +owner: codex +topic_slug: netkingdom +planning_priority: P1 +created: "2026-08-23" +updated: "2026-08-23" +--- + +# NK-WP-0029 — Scope and intent reconciliation + +Authorized by the operator after repository triage found no locally actionable +ready/active work beyond documentation reconciliation. This work corrects stale +delivery claims in `SCOPE.md` and preserves `INTENT.md` as the aspirational +direction while recording evidence-backed gaps under `history/`. + +## Inventory current capability and authority + +```task +id: NK-WP-0029-T01 +status: done +priority: high +``` + +Reviewed current and archived workplans, standards, ADRs, architecture, +responsibility boundaries, bootstrap/reference implementations, validators, +deployment assets, and open State Hub work. Distinguished repository-owned +canon/tooling from externally owned runtime implementations and managed +packages. + +## Rewrite repository scope + +```task +id: NK-WP-0029-T02 +status: done +priority: high +``` + +Replaced the stale identity-only scope and removed the incorrect claim that +enterprise Keycloak federation is delivered. Documented the current canon, +bootstrap/reference tooling, integration role, C0-C6 delivery state, runtime +authority boundaries, and remaining work gates. + +## Assess current scope against intent + +```task +id: NK-WP-0029-T03 +status: done +priority: high +``` + +Added `history/2026-08-23-scope-intent-gap-assessment.md`, assessing every +`INTENT.md` principle and prioritizing gaps in executable meta-orchestration, +C6 feedback loops, federation, package authority, canon adoption, production +custody evidence, and operator repeatability. + +## Verify and reconcile records + +```task +id: NK-WP-0029-T04 +status: done +priority: medium +``` + +Checked links and named repository paths, Markdown whitespace, workplan +formatting, and repository tests applicable to the documented capabilities. +Reconciled the completed workplan with State Hub and the canonical registrar.