From 63e3bb6f7df77afe9cf9e437ae2e491c69e80c57 Mon Sep 17 00:00:00 2001 From: tegwick Date: Mon, 28 Sep 2026 12:40:10 +0200 Subject: [PATCH] Refresh operating guidance and standardize new workplan naming Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4 --- .custodian-brief.md | 45 +++--- AGENTS.md | 17 +- SCOPE.md | 42 ++++- WORK-RECORDS.md | 10 +- sso-mfa/k8s/FOUNDATIONS-HISTORICAL.md | 119 ++++++++++++++ sso-mfa/k8s/README.md | 153 +++++++----------- ...dence-assessment-and-operating-guidance.md | 113 +++++++++++++ 7 files changed, 360 insertions(+), 139 deletions(-) create mode 100644 sso-mfa/k8s/FOUNDATIONS-HISTORICAL.md create mode 100644 workplans/NK-WP-0043-cadence-assessment-and-operating-guidance.md diff --git a/.custodian-brief.md b/.custodian-brief.md index 29c1a2a..eecdba3 100644 --- a/.custodian-brief.md +++ b/.custodian-brief.md @@ -2,11 +2,23 @@ # Custodian Brief — net-kingdom **Domain:** infotech -**Last synced:** 2026-09-27 22:02 UTC +**Last synced:** 2026-09-28 10:35 UTC **State Hub:** http://127.0.0.1:8000 *(adjust if running on a remote machine)* ## Active Workstreams +### Implement deterministic posture and evidence feedback +Progress: 4/5 done | workplan_id: `9d7b04f9-3803-5613-b7a5-8bd606c77f5a` + +**Open tasks:** +- ! Obtain audit-core freshness adoption `7d2029d2` + +### Publish the NetKingdom emission-cadence security profile +Progress: 4/5 done | workplan_id: `04685f94-1991-5e62-80d2-5669913e99fc` + +**Open tasks:** +- ! Bind and hand off the published contract `e3fbc8b8` + ### Reconcile reef placement and security-zone canon dependencies Progress: 3/6 done | workplan_id: `965ad365-6b81-50a1-a2a3-2d0c1fcce0b4` @@ -15,29 +27,17 @@ Progress: 3/6 done | workplan_id: `965ad365-6b81-50a1-a2a3-2d0c1fcce0b4` - ! T03 — Reconcile reef ceilings mechanically `e3f0bb0f` - ! T06 — Resolve the `DataClassification` mismatch `bf8b3e1d` -### Publish the NetKingdom emission-cadence security profile -Progress: 4/5 done | workplan_id: `04685f94-1991-5e62-80d2-5669913e99fc` - -**Open tasks:** -- ! Bind and hand off the published contract `e3fbc8b8` - -### Implement deterministic posture and evidence feedback -Progress: 4/5 done | workplan_id: `9d7b04f9-3803-5613-b7a5-8bd606c77f5a` - -**Open tasks:** -- ! Obtain audit-core freshness adoption `7d2029d2` - ### Let workloads require MFA for all or part of their features Progress: 1/2 done | workplan_id: `3f702215-704b-5788-8ca0-b8b9ba2dd3f8` **Open tasks:** - ! Agree the user-facing step-up and enrollment journey `4e51585d` -### Define an execution-attribution receipt for Railiance runs -Progress: 1/2 done | workplan_id: `e2533f3a-aa43-59b3-bff3-8e64b6149487` +### Cut over NetKingdom identity to railiance01 and retire CoulombCore +Progress: 7/8 done | workplan_id: `d76ddccc-00c8-548a-b141-2cd660fa38da` **Open tasks:** -- ! Agree the evidence holder and schema with audit-core and Railiance `963120c1` +- ! T08 - Final deletion and closure `42a3b4c0` ### Take in the flex-auth to access-engine repository-coordinate rename Progress: 2/4 done | workplan_id: `284a8ac2-61dc-5bee-b74a-0a62d9808edb` @@ -46,18 +46,11 @@ Progress: 2/4 done | workplan_id: `284a8ac2-61dc-5bee-b74a-0a62d9808edb` - ! Update repository-coordinate references once access-engine resolves `6e62919d` - ! Retire or reconcile the stale flex-auth/tenant-engine reference manifest `2541f523` -### Admit the operator-tunneled OpenBao browser callback -Progress: 2/4 done | workplan_id: `516ee5b9-685b-5986-88d2-bde66c2ba96c` +### Define an execution-attribution receipt for Railiance runs +Progress: 1/2 done | workplan_id: `e2533f3a-aa43-59b3-bff3-8e64b6149487` **Open tasks:** -- ! T03 — Apply and prove the live OpenBao role addition `73b77110` -- ! T04 — Return attended-login evidence to Railiance Platform `f62bda4a` - -### Cut over NetKingdom identity to railiance01 and retire CoulombCore -Progress: 7/8 done | workplan_id: `d76ddccc-00c8-548a-b141-2cd660fa38da` - -**Open tasks:** -- ! T08 - Final deletion and closure `42a3b4c0` +- ! Agree the evidence holder and schema with audit-core and Railiance `963120c1` --- ## MCP Orientation (when available) diff --git a/AGENTS.md b/AGENTS.md index aa3bf72..ce9f55f 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -169,10 +169,14 @@ get wrong. Work items originate as files in this repo — not in the hub. The hub is a read/cache/index layer that rebuilds from files. -**File location:** `workplans/NET-WP-NNNN-.md` +New workplans use the registered **`NK-WP-`** prefix. Existing `NK-WP`, +`NET-WP` and `ADHOC` IDs, filenames and hub UUIDs remain unchanged; do not +renumber historical records to match this convention. + +**File location:** `workplans/NK-WP-NNNN-.md` **Archived location:** finished workplans may move to -`workplans/archived/YYMMDD-NET-WP-NNNN-.md`. The `YYMMDD` prefix is +`workplans/archived/YYMMDD-NK-WP-NNNN-.md`. The `YYMMDD` prefix is the completion/archive date; the frontmatter `id` does not change. **Ad Hoc Tasks:** small opportunistic fixes discovered during a session use @@ -184,7 +188,7 @@ anything needing analysis, design, approval, dependencies, or multiple phases. ```yaml --- -id: NET-WP-NNNN +id: NK-WP-NNNN type: workplan title: "..." domain: infotech @@ -208,7 +212,7 @@ derived health labels, not frontmatter statuses. ## Task Title ` ` `task -id: NET-WP-NNNN-T01 +id: NK-WP-NNNN-T01 status: wait | todo | progress | done | cancel priority: high | medium | low state_hub_task_id: "" # written by fix-consistency — do not edit @@ -221,5 +225,6 @@ Status progression: `todo` → `progress` → `done`; use `wait` for waiting/blo To create a new workplan: 1. Write the file following the format above -2. Notify the custodian operator to run `make fix-consistency REPO=net-kingdom` - (or send a message to the hub agent via `POST /messages/`) +2. Run `statehub fix-consistency --repo net-kingdom` directly, as required by + the session close protocol. Ask the operator only if the CLI or API is + unavailable. diff --git a/SCOPE.md b/SCOPE.md index bf80971..9c698a4 100644 --- a/SCOPE.md +++ b/SCOPE.md @@ -116,13 +116,41 @@ repositories while NetKingdom retains the contracts and reference evidence. | C5 — Enterprise federation | Keycloak/SAML/enterprise-IdP design | Backlog; not a current provided runtime capability | | C6 — Self-optimizing security | Declarations, validators, evidence freshness, and deterministic owner-routed remediation proposals | First proposal-only feedback loop delivered; no autonomous policy mutation or closed loop | -Current open work as of 2026-08-23 is either externally blocked, date-gated, or -explicit backlog: reef carrier/public-classification decisions in NK-WP-0027, -the NK-WP-0022 retirement gate, security tutorials in NK-WP-0009, and -enterprise federation in NK-WP-0011. NK-WP-0030 has delivered the local C0 -and externally declared KeyCape C1+C2b plan-only composition slices. NK-WP-0031 -has delivered the local proposal-only feedback evaluator and waits for -authoritative freshness adoption by `audit-core`. +The [2026-09-28 infrastructure review](history/2026-09-28-open-workplan-infrastructure-review.md) +records the current evidence baseline: one Railiance node, ready lightweight +identity services, six flex-auth consumers enforcing caller authentication, +and private OpenBao access. Readiness and replica counts do not establish HA, +user acceptance, or complete recovery. Keycloak remains backlog. + +OpenBao callback/login admission (NK-WP-0032) is complete from the platform's +September receipts. Operators use the named `openbao-ui-railiance01` tunnel; +`bao.coulomb.social` is retired. Scoped optional-enrollment policy and +privileged MFA guards are delivered for the portal and Vergabe demo clients; +NK-WP-0042 still needs a workload pilot agreement and accepted step-up/recovery +journey. IAM v0.4 and Playbook Capability v0.2 remain proposed amendments. + +The current owner/evidence gates are: + +- NK-WP-0022: final identity-resource retirement needs recovery evidence and + explicit deletion approval; its August 29 retention minimum has elapsed. +- NK-WP-0027: reef provider carrier/ceiling agreement and the authoritative + public-classification maturity mapping remain external dependencies. +- NK-WP-0031: the implemented proposal-only evaluator still needs Audit Core's + machine-readable authoritative ownership and E2 freshness metadata. +- NK-WP-0035: corrected candidate contract pins do not resolve source migration, + local-identity's missing heartbeat, or the absent source/observer proof. +- NK-WP-0039: obsolete flex-auth reference objects have been removed; remaining + tenant-engine references and repository-rename pointers await their owners. +- NK-WP-0040: execution-attribution receipt emission, custody and schema require + owner agreement before an end-to-end implementation claim. +- NK-WP-0042: reuse delivered enrollment/policy components for the agreed pilot; + generic workload step-up is not established by those two scoped clients. + +Tutorials (NK-WP-0009) and enterprise federation (NK-WP-0011) remain backlog. +NK-WP-0030's deterministic composition and NK-WP-0031's local feedback tooling +are implemented; neither autonomously changes policy. Use the workplan files +and generated `WORK-RECORDS.md` for changing task state, rather than treating +this dated operating baseline as a live health report. --- diff --git a/WORK-RECORDS.md b/WORK-RECORDS.md index 3a8f451..f9dd1b4 100644 --- a/WORK-RECORDS.md +++ b/WORK-RECORDS.md @@ -25,7 +25,7 @@ | workplan | NK-WP-0029 | finished | — | workplans/NK-WP-0029-scope-and-intent-reconciliation.md | | workplan | NK-WP-0030 | finished | — | workplans/NK-WP-0030-deterministic-security-scenario-composition.md | | workplan | NK-WP-0031 | blocked | — | workplans/NK-WP-0031-deterministic-posture-feedback.md | -| workplan | NK-WP-0032 | blocked | — | workplans/NK-WP-0032-openbao-operator-loopback-callback.md | +| workplan | NK-WP-0032 | finished | — | workplans/NK-WP-0032-openbao-operator-loopback-callback.md | | workplan | NK-WP-0033 | finished | — | workplans/NK-WP-0033-keycape-secret-exposure-rotation.md | | workplan | NK-WP-0034 | finished | — | workplans/NK-WP-0034-verification-that-verifies.md | | workplan | NK-WP-0035 | blocked | — | workplans/NK-WP-0035-emission-cadence-security-profile.md | @@ -36,6 +36,7 @@ | workplan | NK-WP-0040 | blocked | — | workplans/NK-WP-0040-execution-attribution-receipt.md | | workplan | NK-WP-0041 | finished | — | workplans/NK-WP-0041-onboarding-journey-usability.md | | workplan | NK-WP-0042 | blocked | — | workplans/NK-WP-0042-workload-mfa-step-up.md | +| workplan | NK-WP-0043 | finished | — | workplans/NK-WP-0043-cadence-assessment-and-operating-guidance.md | | task | NK-WP-ADHOC-2026-07-02-T01 | done | — | workplans/ADHOC-2026-07-02.md | | task | NK-WP-ADHOC-2026-07-02-T02 | done | — | workplans/ADHOC-2026-07-02.md | | task | NK-WP-ADHOC-2026-08-14-T01 | done | — | workplans/ADHOC-2026-08-14.md | @@ -119,8 +120,8 @@ | task | NK-WP-0031-T05 | done | — | workplans/NK-WP-0031-deterministic-posture-feedback.md | | task | NK-WP-0032-T01 | done | — | workplans/NK-WP-0032-openbao-operator-loopback-callback.md | | task | NK-WP-0032-T02 | done | — | workplans/NK-WP-0032-openbao-operator-loopback-callback.md | -| task | NK-WP-0032-T03 | wait | — | workplans/NK-WP-0032-openbao-operator-loopback-callback.md | -| task | NK-WP-0032-T04 | wait | — | workplans/NK-WP-0032-openbao-operator-loopback-callback.md | +| task | NK-WP-0032-T03 | done | — | workplans/NK-WP-0032-openbao-operator-loopback-callback.md | +| task | NK-WP-0032-T04 | done | — | workplans/NK-WP-0032-openbao-operator-loopback-callback.md | | task | NK-WP-0033-T01 | done | — | workplans/NK-WP-0033-keycape-secret-exposure-rotation.md | | task | NK-WP-0033-T02 | done | — | workplans/NK-WP-0033-keycape-secret-exposure-rotation.md | | task | NK-WP-0033-T03 | done | — | workplans/NK-WP-0033-keycape-secret-exposure-rotation.md | @@ -156,6 +157,9 @@ | task | NK-WP-0041-T03 | done | — | workplans/NK-WP-0041-onboarding-journey-usability.md | | task | NK-WP-0042-T01 | done | — | workplans/NK-WP-0042-workload-mfa-step-up.md | | task | NK-WP-0042-T02 | wait | — | workplans/NK-WP-0042-workload-mfa-step-up.md | +| task | NK-WP-0043-T01 | done | — | workplans/NK-WP-0043-cadence-assessment-and-operating-guidance.md | +| task | NK-WP-0043-T02 | done | — | workplans/NK-WP-0043-cadence-assessment-and-operating-guidance.md | +| task | NK-WP-0043-T03 | done | — | workplans/NK-WP-0043-cadence-assessment-and-operating-guidance.md | | intake | NK-IN-0001 | closed | blue | docs/intakes/activity-core-ops-sso-operators.md | | intake | NK-IN-0002 | closed | blue | docs/intakes/activity-core-ops-sso-operators.md | | intake | NET-IN-0001 | open | — | intakes/intakes.md | diff --git a/sso-mfa/k8s/FOUNDATIONS-HISTORICAL.md b/sso-mfa/k8s/FOUNDATIONS-HISTORICAL.md new file mode 100644 index 0000000..7e4be3d --- /dev/null +++ b/sso-mfa/k8s/FOUNDATIONS-HISTORICAL.md @@ -0,0 +1,119 @@ +# Historical T02 — Kubernetes foundations + +Exercise status: unknown for the procedures in this runbook; no per-procedure successful-run receipt with operator attribution was established in the 2026-09-05 review. See [procedure inventory](../../docs/attended-procedure-inventory.md). + +Archived procedure from Phase 1 of NK-WP-0001: namespaces, NetworkPolicies, +cert-manager, StorageClass. These commands describe the original bootstrap, +not maintenance of the current Railiance cluster. The ThreePhoenix/KeePassXC +prerequisites and network table below are historical assumptions, not current +operating claims. See [current operations](README.md) for owner routing. + +Use this only as a starting point for a separately reviewed isolated lab +exercise. It is not a production apply, repair or recovery recipe. + +## SSO stack overview + +The `sso` namespace hosts three components: +- **KeyCape** (`kc.coulomb.social`) — OIDC orchestration layer, stateless +- **Authelia** (`auth.coulomb.social`) — password authentication frontend +- **LLDAP** (`lldap.coulomb.social`) — lightweight LDAP directory (admin UI restricted) + +The `mfa` namespace hosts: +- **privacyIDEA** (`pink.coulomb.social`) — MFA engine, called by KeyCape + +## Prerequisites + +- K3s cluster running (ThreePhoenix HA or single-node dev) +- T01 Phase 0a complete (KeePassXC vault populated, ops bundle exported) +- `kubectl` configured with cluster access + +## Apply order + +```bash +# 1. Install cert-manager (if not already on cluster) +helm repo add jetstack https://charts.jetstack.io +helm repo update +helm install cert-manager jetstack/cert-manager \ + --namespace cert-manager --create-namespace \ + --set crds.enabled=true + +# Wait for cert-manager to be ready +kubectl rollout status deployment/cert-manager -n cert-manager + +# 2. Create namespaces +kubectl apply -f namespaces/namespaces.yaml + +# 3. Apply NetworkPolicies +kubectl apply -f network-policies/netpol-sso.yaml +kubectl apply -f network-policies/netpol-mfa.yaml +kubectl apply -f network-policies/netpol-databases.yaml + +# 4. Create ClusterIssuers +# Edit issuers.yaml first: replace ACME_EMAIL with your address +kubectl apply -f cert-manager/issuers.yaml + +# 5. Verify cert-manager with test certificate +kubectl apply -f cert-manager/test-certificate.yaml +kubectl wait --for=condition=Ready certificate/selfsigned-test \ + -n cert-manager-test --timeout=60s +kubectl delete namespace cert-manager-test + +# 6. Verify StorageClass +kubectl apply -f storage/verify-pvc.yaml +kubectl wait --for=condition=Ready pod/storage-test \ + -n storage-test --timeout=60s +kubectl logs -n storage-test storage-test +kubectl delete namespace storage-test + +# 7. Run the full verification script +chmod +x verify-t02.sh +./verify-t02.sh +``` + +## NetworkPolicy design + +All three namespaces follow a default-deny-all posture. Only the minimal +required paths are opened: + +| Source | Destination | Port | Purpose | +|--------|-------------|------|---------| +| Traefik (kube-system) | KeyCape (sso) | 8080 | OIDC endpoints — public | +| Traefik (kube-system) | Authelia (sso) | 9091 | Login portal — public | +| Traefik (kube-system) | LLDAP (sso) | 17170 | Admin web UI — IP-restricted | +| Traefik (kube-system) | privacyIDEA (mfa) | 8080 | MFA portal — public | +| KeyCape (sso) | Authelia (sso) | 9091 | OIDC token exchange | +| KeyCape (sso) | LLDAP (sso) | 3890 | User attribute lookup | +| KeyCape (sso) | privacyIDEA (mfa) | 8080 | MFA challenge + validation | +| Authelia (sso) | LLDAP (sso) | 3890 | Credential validation | +| privacyIDEA (mfa) | PostgreSQL (databases) | 5432 | DB | +| CNPG operator (cnpg-system) | PostgreSQL (databases) | 5432/9187 | Operator + metrics | +| All pods | kube-dns (kube-system) | 53 | DNS resolution | +| CNPG pods | K8s API | 6443 | Status updates | + +## Verifying denied paths (manual) + +After applying NetworkPolicies, confirm that illegal paths are blocked: + +```bash +# Test: KeyCape → privacyIDEA (should be ALLOWED) +kubectl run test-allowed -n sso --rm -it --image=busybox --restart=Never \ + -- nc -zv privacyidea.mfa.svc.cluster.local 8080 + +# Test: Authelia → privacyIDEA (should be DENIED — only KeyCape calls privacyIDEA) +kubectl run test-denied -n sso --rm -it --image=busybox --restart=Never \ + -l app.kubernetes.io/name=authelia \ + -- nc -zv -w3 privacyidea.mfa.svc.cluster.local 8080 + +# Test: databases → sso (should be DENIED — DB pods must not initiate connections) +kubectl run test-denied2 -n databases --rm -it --image=busybox --restart=Never \ + -- nc -zw3 keycape.sso.svc.cluster.local 8080 +``` + +## Notes + +- `net-kingdom/component` labels on namespaces are used by NetworkPolicy + `namespaceSelector` rules. Do not remove them. +- `cnpg.io/cluster: net-kingdom-pg` in `netpol-databases.yaml` must match + the name of the CloudNativePG `Cluster` CR you create in T03. +- The `letsencrypt-prod` ClusterIssuer requires public DNS and port 80 open + to Let's Encrypt servers. Update `ACME_EMAIL` before applying. diff --git a/sso-mfa/k8s/README.md b/sso-mfa/k8s/README.md index d989529..40af842 100644 --- a/sso-mfa/k8s/README.md +++ b/sso-mfa/k8s/README.md @@ -1,112 +1,71 @@ -# T02 — K8s Foundations +# NetKingdom Kubernetes integration guidance -Exercise status: unknown for the procedures in this runbook; no per-procedure successful-run receipt with operator attribution was established in the 2026-09-05 review. See [procedure inventory](../../docs/attended-procedure-inventory.md). +This directory holds bootstrap tooling, integration references and migration +history. Current managed deployment belongs to the service/package owners +under [ADR-0015](../../docs/adr/ADR-0015-netkingdom-railiance-workload-packaging-and-relational-platform.md). +The [original foundation procedure](FOUNDATIONS-HISTORICAL.md) is retained as +historical material, including its old prerequisites and apply commands. -Phase 1 of NK-WP-0001: namespaces, NetworkPolicies, cert-manager, StorageClass. +## Operating baseline -## SSO stack overview +The [September 28 review](../../history/2026-09-28-open-workplan-infrastructure-review.md) +observed one Ready Railiance01 node at `92.205.62.239`, healthy lightweight +identity components and single-instance CNPG databases. This is a dated +inventory, not an HA, recovery or user-login acceptance claim. -The `sso` namespace hosts three components: -- **KeyCape** (`kc.coulomb.social`) — OIDC orchestration layer, stateless -- **Authelia** (`auth.coulomb.social`) — password authentication frontend -- **LLDAP** (`lldap.coulomb.social`) — lightweight LDAP directory (admin UI restricted) +| Surface | Current role and owner | +| --- | --- | +| KeyCape / Authelia / LLDAP (`sso`) and privacyIDEA (`mfa`) | Lightweight identity composition; issuer implementation in `key-cape`, integration contracts here | +| User Engine | [rapp-user-engine](../../../rapp-user-engine/README.md) owns managed manifests, rollout and rollback | +| Tenant Engine | [rapp-tenant-engine](../../../rapp-tenant-engine/README.md) owns managed runtime and database-consumption configuration | +| flex-auth consumer services | [Owner values and chart pointers](tenant-engine/README.md); caller authentication is enforced by the owner declarations | +| OpenBao and database custody | `railiance-platform`, with managed packages and consumer declarations in their owning repositories | +| Kubernetes and host substrate | [railiance-cluster operator runbook](../../../railiance-cluster/docs/operator-runbook.md) and `railiance-infra` | -The `mfa` namespace hosts: -- **privacyIDEA** (`pink.coulomb.social`) — MFA engine, called by KeyCape +OpenBao's public browser endpoint `bao.coulomb.social` is retired. Operators +use the named `openbao-ui-railiance01` tunnel at `http://127.0.0.1:18200`; +workloads use the internal Service. Follow the platform's +[operator-only cutover record](../../../railiance-platform/workplans/RPF-WP-0025-openbao-operator-only-access.md) +and credential routing in [AGENTS.md](../../AGENTS.md). Route access before +requesting credentials; never copy tokens or Secret values into evidence. -## Prerequisites +## Read-only orientation -- K3s cluster running (ThreePhoenix HA or single-node dev) -- T01 Phase 0a complete (KeePassXC vault populated, ops bundle exported) -- `kubectl` configured with cluster access - -## Apply order +Check the context before interpreting these results. All commands below read +resource metadata and readiness; none applies manifests or initiates login. ```bash -# 1. Install cert-manager (if not already on cluster) -helm repo add jetstack https://charts.jetstack.io -helm repo update -helm install cert-manager jetstack/cert-manager \ - --namespace cert-manager --create-namespace \ - --set crds.enabled=true - -# Wait for cert-manager to be ready -kubectl rollout status deployment/cert-manager -n cert-manager - -# 2. Create namespaces -kubectl apply -f namespaces/namespaces.yaml - -# 3. Apply NetworkPolicies -kubectl apply -f network-policies/netpol-sso.yaml -kubectl apply -f network-policies/netpol-mfa.yaml -kubectl apply -f network-policies/netpol-databases.yaml - -# 4. Create ClusterIssuers -# Edit issuers.yaml first: replace ACME_EMAIL with your address -kubectl apply -f cert-manager/issuers.yaml - -# 5. Verify cert-manager with test certificate -kubectl apply -f cert-manager/test-certificate.yaml -kubectl wait --for=condition=Ready certificate/selfsigned-test \ - -n cert-manager-test --timeout=60s -kubectl delete namespace cert-manager-test - -# 6. Verify StorageClass -kubectl apply -f storage/verify-pvc.yaml -kubectl wait --for=condition=Ready pod/storage-test \ - -n storage-test --timeout=60s -kubectl logs -n storage-test storage-test -kubectl delete namespace storage-test - -# 7. Run the full verification script -chmod +x verify-t02.sh -./verify-t02.sh +kubectl config current-context +kubectl get nodes -o wide +kubectl -n sso get deployments +kubectl -n mfa get deployments +kubectl -n user-engine get deployments +kubectl -n tenant-engine get deployments +kubectl -n flex-auth get deployments +kubectl -n openbao get statefulsets,deployments,services,ingresses +kubectl get clusters.postgresql.cnpg.io -A ``` -## NetworkPolicy design +Ready replicas do not prove negative authorization, actual-user MFA, successful +backup restoration or independent failure domains. Use the relevant owner's +verification and recovery procedure for those claims. -All three namespaces follow a default-deny-all posture. Only the minimal -required paths are opened: +## Deployment and recovery -| Source | Destination | Port | Purpose | -|--------|-------------|------|---------| -| Traefik (kube-system) | KeyCape (sso) | 8080 | OIDC endpoints — public | -| Traefik (kube-system) | Authelia (sso) | 9091 | Login portal — public | -| Traefik (kube-system) | LLDAP (sso) | 17170 | Admin web UI — IP-restricted | -| Traefik (kube-system) | privacyIDEA (mfa) | 8080 | MFA portal — public | -| KeyCape (sso) | Authelia (sso) | 9091 | OIDC token exchange | -| KeyCape (sso) | LLDAP (sso) | 3890 | User attribute lookup | -| KeyCape (sso) | privacyIDEA (mfa) | 8080 | MFA challenge + validation | -| Authelia (sso) | LLDAP (sso) | 3890 | Credential validation | -| privacyIDEA (mfa) | PostgreSQL (databases) | 5432 | DB | -| CNPG operator (cnpg-system) | PostgreSQL (databases) | 5432/9187 | Operator + metrics | -| All pods | kube-dns (kube-system) | 53 | DNS resolution | -| CNPG pods | K8s API | 6443 | Status updates | +Start with the owning package's current declaration, immutable image and +reviewed rollout/rollback procedure. Do not recursively apply this tree. +`tenant-engine/runtime.yaml` remains **REFERENCE ONLY — DO NOT APPLY** while +its owner decides the disposition of the five retained historical objects. +Its obsolete flex-auth objects have been replaced with owner pointers. -## Verifying denied paths (manual) +The scripts and manifests elsewhere in this directory have individual scopes; +their presence here does not make them current production repair commands. +The [attended procedure inventory](../../docs/attended-procedure-inventory.md) +records their exercise limits. Use the [custody model](../../docs/openbao-unseal-custody-models.md) +and current owner runbooks to prepare recovery. A database-only drill does not +prove restoration of LLDAP, Authelia, privacyIDEA and its matching encryption +material, or all identity database state. -After applying NetworkPolicies, confirm that illegal paths are blocked: - -```bash -# Test: KeyCape → privacyIDEA (should be ALLOWED) -kubectl run test-allowed -n sso --rm -it --image=busybox --restart=Never \ - -- nc -zv privacyidea.mfa.svc.cluster.local 8080 - -# Test: Authelia → privacyIDEA (should be DENIED — only KeyCape calls privacyIDEA) -kubectl run test-denied -n sso --rm -it --image=busybox --restart=Never \ - -l app.kubernetes.io/name=authelia \ - -- nc -zv -w3 privacyidea.mfa.svc.cluster.local 8080 - -# Test: databases → sso (should be DENIED — DB pods must not initiate connections) -kubectl run test-denied2 -n databases --rm -it --image=busybox --restart=Never \ - -- nc -zw3 keycape.sso.svc.cluster.local 8080 -``` - -## Notes - -- `net-kingdom/component` labels on namespaces are used by NetworkPolicy - `namespaceSelector` rules. Do not remove them. -- `cnpg.io/cluster: net-kingdom-pg` in `netpol-databases.yaml` must match - the name of the CloudNativePG `Cluster` CR you create in T03. -- The `letsencrypt-prod` ClusterIssuer requires public DNS and port 80 open - to Let's Encrypt servers. Update `ACME_EMAIL` before applying. +CoulombCore identity cutover is complete; final retained-resource deletion +remains gated by [NK-WP-0022](../../workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md). +Expiration of the retention minimum does not authorize deletion. diff --git a/workplans/NK-WP-0043-cadence-assessment-and-operating-guidance.md b/workplans/NK-WP-0043-cadence-assessment-and-operating-guidance.md new file mode 100644 index 0000000..814c11d --- /dev/null +++ b/workplans/NK-WP-0043-cadence-assessment-and-operating-guidance.md @@ -0,0 +1,113 @@ +--- +id: NK-WP-0043 +type: workplan +title: "Make cadence assessment explicit and refresh operating guidance" +domain: infotech +repo: net-kingdom +status: finished +flavor: implementation +owner: codex +topic_slug: netkingdom +created: "2026-09-28" +updated: "2026-09-28" +related: [NK-WP-0035, NK-WP-0039] +state_hub_workstream_id: "866807af-b4a9-56d8-ac10-3d05a33aef0c" +--- + +User-authorized follow-through to the September 28 infrastructure review. +Existing changes and historical workplan identifiers remain intact. This work +changes local verification and guidance, not deployment or source emission. + +## Distinguish schema validity from a security-profile assessment + +```task +id: NK-WP-0043-T01 +status: done +priority: high +state_hub_task_id: "7e450a12-9ccd-51f1-a98b-bc28b069affe" +``` + +Before this change, an empty supplied inventory produced `conformant: true` while no +class-specific obligation is checked. Return an explicit unassessed result and +a nonzero default exit; offer an intentional schema-only mode. Record the +supplied inventory so a scoped assessment cannot be mistaken for fleet-wide +adoption. Never infer classification or rarity from the declaration. + +Acceptance: CLI and report regressions cover omitted inventory, schema-only +success/failure, invalid option combinations and existing profile checks. +The real local-identity declaration remains generic-valid and fails its two +rare heartbeat obligations with explicit source inventory. + +Completed: the checker returns `profile_assessed`, exact inventory and +assessment scope; `conformant` is null when unassessed. No inventory in default +mode exits 2, explicit schema-only success exits 0, and validation failures +exit 1. Schema-only rejects profile options and blank class arguments are +rejected. Updated the tool README and proposed profile with compatibility and +exit-code guidance. Existing profile/classification rules are unchanged. + +Verification: the new regressions failed against the old implementation +(including the demonstrated exit-0 empty-inventory defect). The final focused +suite passes 27 tests. Process-level checks against the current owner schema +and real local-identity declaration verify default exit 2 / null, schema-only +exit 0 / null, and explicit rare inventory exit 1 / two missing-heartbeat +findings. Python compilation passes. Ruff was unavailable in this environment; +no Ruff result is claimed. + +## Separate current operations from historical bootstrap instructions + +```task +id: NK-WP-0043-T02 +status: done +priority: medium +state_hub_task_id: "5d95bc2d-f940-5989-aacb-0f1865778e7b" +``` + +Refresh SCOPE and the Kubernetes entry README against the dated September 28 +review. Preserve old foundation commands in an explicitly historical document; +route current deployment, custody and recovery to the owning repositories. +Acceptance: links resolve, read-only examples are non-mutating, current versus +historical claims are explicit, and no HA or fresh recovery claim is inferred. + +Completed: SCOPE now describes the dated September 28 topology and actual +owner/evidence gates. The Kubernetes README provides owner links and read-only +orientation, with original commands preserved in `FOUNDATIONS-HISTORICAL.md`. +All updated Markdown links resolve. New command examples are metadata reads; +no deployment, login or recovery operation was performed. + +## Use one naming convention for new workplans + +```task +id: NK-WP-0043-T03 +status: done +priority: low +state_hub_task_id: "d51e878f-fbbb-5684-bccc-edd050ed87a5" +``` + +Use the registered `NK-WP-` prefix throughout AGENTS.md's new-plan examples and +archive convention. Preserve all existing IDs and UUIDs, including NET-WP +records. Align creation sync guidance with the existing direct CLI requirement. +Acceptance: no conflicting new-plan example remains and historical IDs match +before/after. Reconcile the completed workplan to State Hub. + +Completed: all new-plan examples and archive guidance use NK-WP. Creation +instructions now use the existing direct consistency CLI protocol. Compared +every pre-existing workplan's IDs against HEAD; no ID changed. Authored files +pass `git diff --check`; the generated brief retains its generator's Markdown +hard-break whitespace. State Hub reconciliation follows at session close. + +## Final review — 2026-09-28 + +Reviewed the accumulated infrastructure, reference, checker and guidance diff +before committing. Corrected the federation plan's unconditional +realm-per-tenant implementation/acceptance wording to follow its topology +ADR, clarified historical cutover prose and labelled the initial review +snapshot separately from later implementation. No checker defect was found. + +Broader integration validation: `python3 -m pytest tests tools -q` passes +118 tests. All changed Markdown links resolve. Parsed YAML confirms the five +retained tenant-engine objects are identical to HEAD and exactly seven +flex-auth objects were removed. Every archived bootstrap shell example matches +the original README. Existing workplan IDs remain unchanged. The only default +whitespace-check finding is the generated brief's intentional Markdown line +break; authored files pass. Changes are grouped into infrastructure/reference, +cadence assessment, and operating guidance commits.