Refresh operating guidance and standardize new workplan naming
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 12s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
This commit is contained in:
tegwick 2026-09-28 12:40:10 +02:00
parent 36303d25a3
commit 63e3bb6f7d
7 changed files with 360 additions and 139 deletions

View file

@ -116,13 +116,41 @@ repositories while NetKingdom retains the contracts and reference evidence.
| C5 — Enterprise federation | Keycloak/SAML/enterprise-IdP design | Backlog; not a current provided runtime capability |
| C6 — Self-optimizing security | Declarations, validators, evidence freshness, and deterministic owner-routed remediation proposals | First proposal-only feedback loop delivered; no autonomous policy mutation or closed loop |
Current open work as of 2026-08-23 is either externally blocked, date-gated, or
explicit backlog: reef carrier/public-classification decisions in NK-WP-0027,
the NK-WP-0022 retirement gate, security tutorials in NK-WP-0009, and
enterprise federation in NK-WP-0011. NK-WP-0030 has delivered the local C0
and externally declared KeyCape C1+C2b plan-only composition slices. NK-WP-0031
has delivered the local proposal-only feedback evaluator and waits for
authoritative freshness adoption by `audit-core`.
The [2026-09-28 infrastructure review](history/2026-09-28-open-workplan-infrastructure-review.md)
records the current evidence baseline: one Railiance node, ready lightweight
identity services, six flex-auth consumers enforcing caller authentication,
and private OpenBao access. Readiness and replica counts do not establish HA,
user acceptance, or complete recovery. Keycloak remains backlog.
OpenBao callback/login admission (NK-WP-0032) is complete from the platform's
September receipts. Operators use the named `openbao-ui-railiance01` tunnel;
`bao.coulomb.social` is retired. Scoped optional-enrollment policy and
privileged MFA guards are delivered for the portal and Vergabe demo clients;
NK-WP-0042 still needs a workload pilot agreement and accepted step-up/recovery
journey. IAM v0.4 and Playbook Capability v0.2 remain proposed amendments.
The current owner/evidence gates are:
- NK-WP-0022: final identity-resource retirement needs recovery evidence and
explicit deletion approval; its August 29 retention minimum has elapsed.
- NK-WP-0027: reef provider carrier/ceiling agreement and the authoritative
public-classification maturity mapping remain external dependencies.
- NK-WP-0031: the implemented proposal-only evaluator still needs Audit Core's
machine-readable authoritative ownership and E2 freshness metadata.
- NK-WP-0035: corrected candidate contract pins do not resolve source migration,
local-identity's missing heartbeat, or the absent source/observer proof.
- NK-WP-0039: obsolete flex-auth reference objects have been removed; remaining
tenant-engine references and repository-rename pointers await their owners.
- NK-WP-0040: execution-attribution receipt emission, custody and schema require
owner agreement before an end-to-end implementation claim.
- NK-WP-0042: reuse delivered enrollment/policy components for the agreed pilot;
generic workload step-up is not established by those two scoped clients.
Tutorials (NK-WP-0009) and enterprise federation (NK-WP-0011) remain backlog.
NK-WP-0030's deterministic composition and NK-WP-0031's local feedback tooling
are implemented; neither autonomously changes policy. Use the workplan files
and generated `WORK-RECORDS.md` for changing task state, rather than treating
this dated operating baseline as a live health report.
---