Refresh operating guidance and standardize new workplan naming
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
This commit is contained in:
parent
36303d25a3
commit
63e3bb6f7d
7 changed files with 360 additions and 139 deletions
|
|
@ -2,11 +2,23 @@
|
||||||
# Custodian Brief — net-kingdom
|
# Custodian Brief — net-kingdom
|
||||||
|
|
||||||
**Domain:** infotech
|
**Domain:** infotech
|
||||||
**Last synced:** 2026-09-27 22:02 UTC
|
**Last synced:** 2026-09-28 10:35 UTC
|
||||||
**State Hub:** http://127.0.0.1:8000 *(adjust if running on a remote machine)*
|
**State Hub:** http://127.0.0.1:8000 *(adjust if running on a remote machine)*
|
||||||
|
|
||||||
## Active Workstreams
|
## Active Workstreams
|
||||||
|
|
||||||
|
### Implement deterministic posture and evidence feedback
|
||||||
|
Progress: 4/5 done | workplan_id: `9d7b04f9-3803-5613-b7a5-8bd606c77f5a`
|
||||||
|
|
||||||
|
**Open tasks:**
|
||||||
|
- ! Obtain audit-core freshness adoption `7d2029d2`
|
||||||
|
|
||||||
|
### Publish the NetKingdom emission-cadence security profile
|
||||||
|
Progress: 4/5 done | workplan_id: `04685f94-1991-5e62-80d2-5669913e99fc`
|
||||||
|
|
||||||
|
**Open tasks:**
|
||||||
|
- ! Bind and hand off the published contract `e3fbc8b8`
|
||||||
|
|
||||||
### Reconcile reef placement and security-zone canon dependencies
|
### Reconcile reef placement and security-zone canon dependencies
|
||||||
Progress: 3/6 done | workplan_id: `965ad365-6b81-50a1-a2a3-2d0c1fcce0b4`
|
Progress: 3/6 done | workplan_id: `965ad365-6b81-50a1-a2a3-2d0c1fcce0b4`
|
||||||
|
|
||||||
|
|
@ -15,29 +27,17 @@ Progress: 3/6 done | workplan_id: `965ad365-6b81-50a1-a2a3-2d0c1fcce0b4`
|
||||||
- ! T03 — Reconcile reef ceilings mechanically `e3f0bb0f`
|
- ! T03 — Reconcile reef ceilings mechanically `e3f0bb0f`
|
||||||
- ! T06 — Resolve the `DataClassification` mismatch `bf8b3e1d`
|
- ! T06 — Resolve the `DataClassification` mismatch `bf8b3e1d`
|
||||||
|
|
||||||
### Publish the NetKingdom emission-cadence security profile
|
|
||||||
Progress: 4/5 done | workplan_id: `04685f94-1991-5e62-80d2-5669913e99fc`
|
|
||||||
|
|
||||||
**Open tasks:**
|
|
||||||
- ! Bind and hand off the published contract `e3fbc8b8`
|
|
||||||
|
|
||||||
### Implement deterministic posture and evidence feedback
|
|
||||||
Progress: 4/5 done | workplan_id: `9d7b04f9-3803-5613-b7a5-8bd606c77f5a`
|
|
||||||
|
|
||||||
**Open tasks:**
|
|
||||||
- ! Obtain audit-core freshness adoption `7d2029d2`
|
|
||||||
|
|
||||||
### Let workloads require MFA for all or part of their features
|
### Let workloads require MFA for all or part of their features
|
||||||
Progress: 1/2 done | workplan_id: `3f702215-704b-5788-8ca0-b8b9ba2dd3f8`
|
Progress: 1/2 done | workplan_id: `3f702215-704b-5788-8ca0-b8b9ba2dd3f8`
|
||||||
|
|
||||||
**Open tasks:**
|
**Open tasks:**
|
||||||
- ! Agree the user-facing step-up and enrollment journey `4e51585d`
|
- ! Agree the user-facing step-up and enrollment journey `4e51585d`
|
||||||
|
|
||||||
### Define an execution-attribution receipt for Railiance runs
|
### Cut over NetKingdom identity to railiance01 and retire CoulombCore
|
||||||
Progress: 1/2 done | workplan_id: `e2533f3a-aa43-59b3-bff3-8e64b6149487`
|
Progress: 7/8 done | workplan_id: `d76ddccc-00c8-548a-b141-2cd660fa38da`
|
||||||
|
|
||||||
**Open tasks:**
|
**Open tasks:**
|
||||||
- ! Agree the evidence holder and schema with audit-core and Railiance `963120c1`
|
- ! T08 - Final deletion and closure `42a3b4c0`
|
||||||
|
|
||||||
### Take in the flex-auth to access-engine repository-coordinate rename
|
### Take in the flex-auth to access-engine repository-coordinate rename
|
||||||
Progress: 2/4 done | workplan_id: `284a8ac2-61dc-5bee-b74a-0a62d9808edb`
|
Progress: 2/4 done | workplan_id: `284a8ac2-61dc-5bee-b74a-0a62d9808edb`
|
||||||
|
|
@ -46,18 +46,11 @@ Progress: 2/4 done | workplan_id: `284a8ac2-61dc-5bee-b74a-0a62d9808edb`
|
||||||
- ! Update repository-coordinate references once access-engine resolves `6e62919d`
|
- ! Update repository-coordinate references once access-engine resolves `6e62919d`
|
||||||
- ! Retire or reconcile the stale flex-auth/tenant-engine reference manifest `2541f523`
|
- ! Retire or reconcile the stale flex-auth/tenant-engine reference manifest `2541f523`
|
||||||
|
|
||||||
### Admit the operator-tunneled OpenBao browser callback
|
### Define an execution-attribution receipt for Railiance runs
|
||||||
Progress: 2/4 done | workplan_id: `516ee5b9-685b-5986-88d2-bde66c2ba96c`
|
Progress: 1/2 done | workplan_id: `e2533f3a-aa43-59b3-bff3-8e64b6149487`
|
||||||
|
|
||||||
**Open tasks:**
|
**Open tasks:**
|
||||||
- ! T03 — Apply and prove the live OpenBao role addition `73b77110`
|
- ! Agree the evidence holder and schema with audit-core and Railiance `963120c1`
|
||||||
- ! T04 — Return attended-login evidence to Railiance Platform `f62bda4a`
|
|
||||||
|
|
||||||
### Cut over NetKingdom identity to railiance01 and retire CoulombCore
|
|
||||||
Progress: 7/8 done | workplan_id: `d76ddccc-00c8-548a-b141-2cd660fa38da`
|
|
||||||
|
|
||||||
**Open tasks:**
|
|
||||||
- ! T08 - Final deletion and closure `42a3b4c0`
|
|
||||||
|
|
||||||
---
|
---
|
||||||
## MCP Orientation (when available)
|
## MCP Orientation (when available)
|
||||||
|
|
|
||||||
17
AGENTS.md
17
AGENTS.md
|
|
@ -169,10 +169,14 @@ get wrong.
|
||||||
Work items originate as files in this repo — not in the hub. The hub is a
|
Work items originate as files in this repo — not in the hub. The hub is a
|
||||||
read/cache/index layer that rebuilds from files.
|
read/cache/index layer that rebuilds from files.
|
||||||
|
|
||||||
**File location:** `workplans/NET-WP-NNNN-<slug>.md`
|
New workplans use the registered **`NK-WP-`** prefix. Existing `NK-WP`,
|
||||||
|
`NET-WP` and `ADHOC` IDs, filenames and hub UUIDs remain unchanged; do not
|
||||||
|
renumber historical records to match this convention.
|
||||||
|
|
||||||
|
**File location:** `workplans/NK-WP-NNNN-<slug>.md`
|
||||||
|
|
||||||
**Archived location:** finished workplans may move to
|
**Archived location:** finished workplans may move to
|
||||||
`workplans/archived/YYMMDD-NET-WP-NNNN-<slug>.md`. The `YYMMDD` prefix is
|
`workplans/archived/YYMMDD-NK-WP-NNNN-<slug>.md`. The `YYMMDD` prefix is
|
||||||
the completion/archive date; the frontmatter `id` does not change.
|
the completion/archive date; the frontmatter `id` does not change.
|
||||||
|
|
||||||
**Ad Hoc Tasks:** small opportunistic fixes discovered during a session use
|
**Ad Hoc Tasks:** small opportunistic fixes discovered during a session use
|
||||||
|
|
@ -184,7 +188,7 @@ anything needing analysis, design, approval, dependencies, or multiple phases.
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
---
|
---
|
||||||
id: NET-WP-NNNN
|
id: NK-WP-NNNN
|
||||||
type: workplan
|
type: workplan
|
||||||
title: "..."
|
title: "..."
|
||||||
domain: infotech
|
domain: infotech
|
||||||
|
|
@ -208,7 +212,7 @@ derived health labels, not frontmatter statuses.
|
||||||
## Task Title
|
## Task Title
|
||||||
|
|
||||||
` ` `task
|
` ` `task
|
||||||
id: NET-WP-NNNN-T01
|
id: NK-WP-NNNN-T01
|
||||||
status: wait | todo | progress | done | cancel
|
status: wait | todo | progress | done | cancel
|
||||||
priority: high | medium | low
|
priority: high | medium | low
|
||||||
state_hub_task_id: "<uuid>" # written by fix-consistency — do not edit
|
state_hub_task_id: "<uuid>" # written by fix-consistency — do not edit
|
||||||
|
|
@ -221,5 +225,6 @@ Status progression: `todo` → `progress` → `done`; use `wait` for waiting/blo
|
||||||
|
|
||||||
To create a new workplan:
|
To create a new workplan:
|
||||||
1. Write the file following the format above
|
1. Write the file following the format above
|
||||||
2. Notify the custodian operator to run `make fix-consistency REPO=net-kingdom`
|
2. Run `statehub fix-consistency --repo net-kingdom` directly, as required by
|
||||||
(or send a message to the hub agent via `POST /messages/`)
|
the session close protocol. Ask the operator only if the CLI or API is
|
||||||
|
unavailable.
|
||||||
|
|
|
||||||
42
SCOPE.md
42
SCOPE.md
|
|
@ -116,13 +116,41 @@ repositories while NetKingdom retains the contracts and reference evidence.
|
||||||
| C5 — Enterprise federation | Keycloak/SAML/enterprise-IdP design | Backlog; not a current provided runtime capability |
|
| C5 — Enterprise federation | Keycloak/SAML/enterprise-IdP design | Backlog; not a current provided runtime capability |
|
||||||
| C6 — Self-optimizing security | Declarations, validators, evidence freshness, and deterministic owner-routed remediation proposals | First proposal-only feedback loop delivered; no autonomous policy mutation or closed loop |
|
| C6 — Self-optimizing security | Declarations, validators, evidence freshness, and deterministic owner-routed remediation proposals | First proposal-only feedback loop delivered; no autonomous policy mutation or closed loop |
|
||||||
|
|
||||||
Current open work as of 2026-08-23 is either externally blocked, date-gated, or
|
The [2026-09-28 infrastructure review](history/2026-09-28-open-workplan-infrastructure-review.md)
|
||||||
explicit backlog: reef carrier/public-classification decisions in NK-WP-0027,
|
records the current evidence baseline: one Railiance node, ready lightweight
|
||||||
the NK-WP-0022 retirement gate, security tutorials in NK-WP-0009, and
|
identity services, six flex-auth consumers enforcing caller authentication,
|
||||||
enterprise federation in NK-WP-0011. NK-WP-0030 has delivered the local C0
|
and private OpenBao access. Readiness and replica counts do not establish HA,
|
||||||
and externally declared KeyCape C1+C2b plan-only composition slices. NK-WP-0031
|
user acceptance, or complete recovery. Keycloak remains backlog.
|
||||||
has delivered the local proposal-only feedback evaluator and waits for
|
|
||||||
authoritative freshness adoption by `audit-core`.
|
OpenBao callback/login admission (NK-WP-0032) is complete from the platform's
|
||||||
|
September receipts. Operators use the named `openbao-ui-railiance01` tunnel;
|
||||||
|
`bao.coulomb.social` is retired. Scoped optional-enrollment policy and
|
||||||
|
privileged MFA guards are delivered for the portal and Vergabe demo clients;
|
||||||
|
NK-WP-0042 still needs a workload pilot agreement and accepted step-up/recovery
|
||||||
|
journey. IAM v0.4 and Playbook Capability v0.2 remain proposed amendments.
|
||||||
|
|
||||||
|
The current owner/evidence gates are:
|
||||||
|
|
||||||
|
- NK-WP-0022: final identity-resource retirement needs recovery evidence and
|
||||||
|
explicit deletion approval; its August 29 retention minimum has elapsed.
|
||||||
|
- NK-WP-0027: reef provider carrier/ceiling agreement and the authoritative
|
||||||
|
public-classification maturity mapping remain external dependencies.
|
||||||
|
- NK-WP-0031: the implemented proposal-only evaluator still needs Audit Core's
|
||||||
|
machine-readable authoritative ownership and E2 freshness metadata.
|
||||||
|
- NK-WP-0035: corrected candidate contract pins do not resolve source migration,
|
||||||
|
local-identity's missing heartbeat, or the absent source/observer proof.
|
||||||
|
- NK-WP-0039: obsolete flex-auth reference objects have been removed; remaining
|
||||||
|
tenant-engine references and repository-rename pointers await their owners.
|
||||||
|
- NK-WP-0040: execution-attribution receipt emission, custody and schema require
|
||||||
|
owner agreement before an end-to-end implementation claim.
|
||||||
|
- NK-WP-0042: reuse delivered enrollment/policy components for the agreed pilot;
|
||||||
|
generic workload step-up is not established by those two scoped clients.
|
||||||
|
|
||||||
|
Tutorials (NK-WP-0009) and enterprise federation (NK-WP-0011) remain backlog.
|
||||||
|
NK-WP-0030's deterministic composition and NK-WP-0031's local feedback tooling
|
||||||
|
are implemented; neither autonomously changes policy. Use the workplan files
|
||||||
|
and generated `WORK-RECORDS.md` for changing task state, rather than treating
|
||||||
|
this dated operating baseline as a live health report.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -25,7 +25,7 @@
|
||||||
| workplan | NK-WP-0029 | finished | — | workplans/NK-WP-0029-scope-and-intent-reconciliation.md |
|
| workplan | NK-WP-0029 | finished | — | workplans/NK-WP-0029-scope-and-intent-reconciliation.md |
|
||||||
| workplan | NK-WP-0030 | finished | — | workplans/NK-WP-0030-deterministic-security-scenario-composition.md |
|
| workplan | NK-WP-0030 | finished | — | workplans/NK-WP-0030-deterministic-security-scenario-composition.md |
|
||||||
| workplan | NK-WP-0031 | blocked | — | workplans/NK-WP-0031-deterministic-posture-feedback.md |
|
| workplan | NK-WP-0031 | blocked | — | workplans/NK-WP-0031-deterministic-posture-feedback.md |
|
||||||
| workplan | NK-WP-0032 | blocked | — | workplans/NK-WP-0032-openbao-operator-loopback-callback.md |
|
| workplan | NK-WP-0032 | finished | — | workplans/NK-WP-0032-openbao-operator-loopback-callback.md |
|
||||||
| workplan | NK-WP-0033 | finished | — | workplans/NK-WP-0033-keycape-secret-exposure-rotation.md |
|
| workplan | NK-WP-0033 | finished | — | workplans/NK-WP-0033-keycape-secret-exposure-rotation.md |
|
||||||
| workplan | NK-WP-0034 | finished | — | workplans/NK-WP-0034-verification-that-verifies.md |
|
| workplan | NK-WP-0034 | finished | — | workplans/NK-WP-0034-verification-that-verifies.md |
|
||||||
| workplan | NK-WP-0035 | blocked | — | workplans/NK-WP-0035-emission-cadence-security-profile.md |
|
| workplan | NK-WP-0035 | blocked | — | workplans/NK-WP-0035-emission-cadence-security-profile.md |
|
||||||
|
|
@ -36,6 +36,7 @@
|
||||||
| workplan | NK-WP-0040 | blocked | — | workplans/NK-WP-0040-execution-attribution-receipt.md |
|
| workplan | NK-WP-0040 | blocked | — | workplans/NK-WP-0040-execution-attribution-receipt.md |
|
||||||
| workplan | NK-WP-0041 | finished | — | workplans/NK-WP-0041-onboarding-journey-usability.md |
|
| workplan | NK-WP-0041 | finished | — | workplans/NK-WP-0041-onboarding-journey-usability.md |
|
||||||
| workplan | NK-WP-0042 | blocked | — | workplans/NK-WP-0042-workload-mfa-step-up.md |
|
| workplan | NK-WP-0042 | blocked | — | workplans/NK-WP-0042-workload-mfa-step-up.md |
|
||||||
|
| workplan | NK-WP-0043 | finished | — | workplans/NK-WP-0043-cadence-assessment-and-operating-guidance.md |
|
||||||
| task | NK-WP-ADHOC-2026-07-02-T01 | done | — | workplans/ADHOC-2026-07-02.md |
|
| task | NK-WP-ADHOC-2026-07-02-T01 | done | — | workplans/ADHOC-2026-07-02.md |
|
||||||
| task | NK-WP-ADHOC-2026-07-02-T02 | done | — | workplans/ADHOC-2026-07-02.md |
|
| task | NK-WP-ADHOC-2026-07-02-T02 | done | — | workplans/ADHOC-2026-07-02.md |
|
||||||
| task | NK-WP-ADHOC-2026-08-14-T01 | done | — | workplans/ADHOC-2026-08-14.md |
|
| task | NK-WP-ADHOC-2026-08-14-T01 | done | — | workplans/ADHOC-2026-08-14.md |
|
||||||
|
|
@ -119,8 +120,8 @@
|
||||||
| task | NK-WP-0031-T05 | done | — | workplans/NK-WP-0031-deterministic-posture-feedback.md |
|
| task | NK-WP-0031-T05 | done | — | workplans/NK-WP-0031-deterministic-posture-feedback.md |
|
||||||
| task | NK-WP-0032-T01 | done | — | workplans/NK-WP-0032-openbao-operator-loopback-callback.md |
|
| task | NK-WP-0032-T01 | done | — | workplans/NK-WP-0032-openbao-operator-loopback-callback.md |
|
||||||
| task | NK-WP-0032-T02 | done | — | workplans/NK-WP-0032-openbao-operator-loopback-callback.md |
|
| task | NK-WP-0032-T02 | done | — | workplans/NK-WP-0032-openbao-operator-loopback-callback.md |
|
||||||
| task | NK-WP-0032-T03 | wait | — | workplans/NK-WP-0032-openbao-operator-loopback-callback.md |
|
| task | NK-WP-0032-T03 | done | — | workplans/NK-WP-0032-openbao-operator-loopback-callback.md |
|
||||||
| task | NK-WP-0032-T04 | wait | — | workplans/NK-WP-0032-openbao-operator-loopback-callback.md |
|
| task | NK-WP-0032-T04 | done | — | workplans/NK-WP-0032-openbao-operator-loopback-callback.md |
|
||||||
| task | NK-WP-0033-T01 | done | — | workplans/NK-WP-0033-keycape-secret-exposure-rotation.md |
|
| task | NK-WP-0033-T01 | done | — | workplans/NK-WP-0033-keycape-secret-exposure-rotation.md |
|
||||||
| task | NK-WP-0033-T02 | done | — | workplans/NK-WP-0033-keycape-secret-exposure-rotation.md |
|
| task | NK-WP-0033-T02 | done | — | workplans/NK-WP-0033-keycape-secret-exposure-rotation.md |
|
||||||
| task | NK-WP-0033-T03 | done | — | workplans/NK-WP-0033-keycape-secret-exposure-rotation.md |
|
| task | NK-WP-0033-T03 | done | — | workplans/NK-WP-0033-keycape-secret-exposure-rotation.md |
|
||||||
|
|
@ -156,6 +157,9 @@
|
||||||
| task | NK-WP-0041-T03 | done | — | workplans/NK-WP-0041-onboarding-journey-usability.md |
|
| task | NK-WP-0041-T03 | done | — | workplans/NK-WP-0041-onboarding-journey-usability.md |
|
||||||
| task | NK-WP-0042-T01 | done | — | workplans/NK-WP-0042-workload-mfa-step-up.md |
|
| task | NK-WP-0042-T01 | done | — | workplans/NK-WP-0042-workload-mfa-step-up.md |
|
||||||
| task | NK-WP-0042-T02 | wait | — | workplans/NK-WP-0042-workload-mfa-step-up.md |
|
| task | NK-WP-0042-T02 | wait | — | workplans/NK-WP-0042-workload-mfa-step-up.md |
|
||||||
|
| task | NK-WP-0043-T01 | done | — | workplans/NK-WP-0043-cadence-assessment-and-operating-guidance.md |
|
||||||
|
| task | NK-WP-0043-T02 | done | — | workplans/NK-WP-0043-cadence-assessment-and-operating-guidance.md |
|
||||||
|
| task | NK-WP-0043-T03 | done | — | workplans/NK-WP-0043-cadence-assessment-and-operating-guidance.md |
|
||||||
| intake | NK-IN-0001 | closed | blue | docs/intakes/activity-core-ops-sso-operators.md |
|
| intake | NK-IN-0001 | closed | blue | docs/intakes/activity-core-ops-sso-operators.md |
|
||||||
| intake | NK-IN-0002 | closed | blue | docs/intakes/activity-core-ops-sso-operators.md |
|
| intake | NK-IN-0002 | closed | blue | docs/intakes/activity-core-ops-sso-operators.md |
|
||||||
| intake | NET-IN-0001 | open | — | intakes/intakes.md |
|
| intake | NET-IN-0001 | open | — | intakes/intakes.md |
|
||||||
|
|
|
||||||
119
sso-mfa/k8s/FOUNDATIONS-HISTORICAL.md
Normal file
119
sso-mfa/k8s/FOUNDATIONS-HISTORICAL.md
Normal file
|
|
@ -0,0 +1,119 @@
|
||||||
|
# Historical T02 — Kubernetes foundations
|
||||||
|
|
||||||
|
Exercise status: unknown for the procedures in this runbook; no per-procedure successful-run receipt with operator attribution was established in the 2026-09-05 review. See [procedure inventory](../../docs/attended-procedure-inventory.md).
|
||||||
|
|
||||||
|
Archived procedure from Phase 1 of NK-WP-0001: namespaces, NetworkPolicies,
|
||||||
|
cert-manager, StorageClass. These commands describe the original bootstrap,
|
||||||
|
not maintenance of the current Railiance cluster. The ThreePhoenix/KeePassXC
|
||||||
|
prerequisites and network table below are historical assumptions, not current
|
||||||
|
operating claims. See [current operations](README.md) for owner routing.
|
||||||
|
|
||||||
|
Use this only as a starting point for a separately reviewed isolated lab
|
||||||
|
exercise. It is not a production apply, repair or recovery recipe.
|
||||||
|
|
||||||
|
## SSO stack overview
|
||||||
|
|
||||||
|
The `sso` namespace hosts three components:
|
||||||
|
- **KeyCape** (`kc.coulomb.social`) — OIDC orchestration layer, stateless
|
||||||
|
- **Authelia** (`auth.coulomb.social`) — password authentication frontend
|
||||||
|
- **LLDAP** (`lldap.coulomb.social`) — lightweight LDAP directory (admin UI restricted)
|
||||||
|
|
||||||
|
The `mfa` namespace hosts:
|
||||||
|
- **privacyIDEA** (`pink.coulomb.social`) — MFA engine, called by KeyCape
|
||||||
|
|
||||||
|
## Prerequisites
|
||||||
|
|
||||||
|
- K3s cluster running (ThreePhoenix HA or single-node dev)
|
||||||
|
- T01 Phase 0a complete (KeePassXC vault populated, ops bundle exported)
|
||||||
|
- `kubectl` configured with cluster access
|
||||||
|
|
||||||
|
## Apply order
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# 1. Install cert-manager (if not already on cluster)
|
||||||
|
helm repo add jetstack https://charts.jetstack.io
|
||||||
|
helm repo update
|
||||||
|
helm install cert-manager jetstack/cert-manager \
|
||||||
|
--namespace cert-manager --create-namespace \
|
||||||
|
--set crds.enabled=true
|
||||||
|
|
||||||
|
# Wait for cert-manager to be ready
|
||||||
|
kubectl rollout status deployment/cert-manager -n cert-manager
|
||||||
|
|
||||||
|
# 2. Create namespaces
|
||||||
|
kubectl apply -f namespaces/namespaces.yaml
|
||||||
|
|
||||||
|
# 3. Apply NetworkPolicies
|
||||||
|
kubectl apply -f network-policies/netpol-sso.yaml
|
||||||
|
kubectl apply -f network-policies/netpol-mfa.yaml
|
||||||
|
kubectl apply -f network-policies/netpol-databases.yaml
|
||||||
|
|
||||||
|
# 4. Create ClusterIssuers
|
||||||
|
# Edit issuers.yaml first: replace ACME_EMAIL with your address
|
||||||
|
kubectl apply -f cert-manager/issuers.yaml
|
||||||
|
|
||||||
|
# 5. Verify cert-manager with test certificate
|
||||||
|
kubectl apply -f cert-manager/test-certificate.yaml
|
||||||
|
kubectl wait --for=condition=Ready certificate/selfsigned-test \
|
||||||
|
-n cert-manager-test --timeout=60s
|
||||||
|
kubectl delete namespace cert-manager-test
|
||||||
|
|
||||||
|
# 6. Verify StorageClass
|
||||||
|
kubectl apply -f storage/verify-pvc.yaml
|
||||||
|
kubectl wait --for=condition=Ready pod/storage-test \
|
||||||
|
-n storage-test --timeout=60s
|
||||||
|
kubectl logs -n storage-test storage-test
|
||||||
|
kubectl delete namespace storage-test
|
||||||
|
|
||||||
|
# 7. Run the full verification script
|
||||||
|
chmod +x verify-t02.sh
|
||||||
|
./verify-t02.sh
|
||||||
|
```
|
||||||
|
|
||||||
|
## NetworkPolicy design
|
||||||
|
|
||||||
|
All three namespaces follow a default-deny-all posture. Only the minimal
|
||||||
|
required paths are opened:
|
||||||
|
|
||||||
|
| Source | Destination | Port | Purpose |
|
||||||
|
|--------|-------------|------|---------|
|
||||||
|
| Traefik (kube-system) | KeyCape (sso) | 8080 | OIDC endpoints — public |
|
||||||
|
| Traefik (kube-system) | Authelia (sso) | 9091 | Login portal — public |
|
||||||
|
| Traefik (kube-system) | LLDAP (sso) | 17170 | Admin web UI — IP-restricted |
|
||||||
|
| Traefik (kube-system) | privacyIDEA (mfa) | 8080 | MFA portal — public |
|
||||||
|
| KeyCape (sso) | Authelia (sso) | 9091 | OIDC token exchange |
|
||||||
|
| KeyCape (sso) | LLDAP (sso) | 3890 | User attribute lookup |
|
||||||
|
| KeyCape (sso) | privacyIDEA (mfa) | 8080 | MFA challenge + validation |
|
||||||
|
| Authelia (sso) | LLDAP (sso) | 3890 | Credential validation |
|
||||||
|
| privacyIDEA (mfa) | PostgreSQL (databases) | 5432 | DB |
|
||||||
|
| CNPG operator (cnpg-system) | PostgreSQL (databases) | 5432/9187 | Operator + metrics |
|
||||||
|
| All pods | kube-dns (kube-system) | 53 | DNS resolution |
|
||||||
|
| CNPG pods | K8s API | 6443 | Status updates |
|
||||||
|
|
||||||
|
## Verifying denied paths (manual)
|
||||||
|
|
||||||
|
After applying NetworkPolicies, confirm that illegal paths are blocked:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Test: KeyCape → privacyIDEA (should be ALLOWED)
|
||||||
|
kubectl run test-allowed -n sso --rm -it --image=busybox --restart=Never \
|
||||||
|
-- nc -zv privacyidea.mfa.svc.cluster.local 8080
|
||||||
|
|
||||||
|
# Test: Authelia → privacyIDEA (should be DENIED — only KeyCape calls privacyIDEA)
|
||||||
|
kubectl run test-denied -n sso --rm -it --image=busybox --restart=Never \
|
||||||
|
-l app.kubernetes.io/name=authelia \
|
||||||
|
-- nc -zv -w3 privacyidea.mfa.svc.cluster.local 8080
|
||||||
|
|
||||||
|
# Test: databases → sso (should be DENIED — DB pods must not initiate connections)
|
||||||
|
kubectl run test-denied2 -n databases --rm -it --image=busybox --restart=Never \
|
||||||
|
-- nc -zw3 keycape.sso.svc.cluster.local 8080
|
||||||
|
```
|
||||||
|
|
||||||
|
## Notes
|
||||||
|
|
||||||
|
- `net-kingdom/component` labels on namespaces are used by NetworkPolicy
|
||||||
|
`namespaceSelector` rules. Do not remove them.
|
||||||
|
- `cnpg.io/cluster: net-kingdom-pg` in `netpol-databases.yaml` must match
|
||||||
|
the name of the CloudNativePG `Cluster` CR you create in T03.
|
||||||
|
- The `letsencrypt-prod` ClusterIssuer requires public DNS and port 80 open
|
||||||
|
to Let's Encrypt servers. Update `ACME_EMAIL` before applying.
|
||||||
|
|
@ -1,112 +1,71 @@
|
||||||
# T02 — K8s Foundations
|
# NetKingdom Kubernetes integration guidance
|
||||||
|
|
||||||
Exercise status: unknown for the procedures in this runbook; no per-procedure successful-run receipt with operator attribution was established in the 2026-09-05 review. See [procedure inventory](../../docs/attended-procedure-inventory.md).
|
This directory holds bootstrap tooling, integration references and migration
|
||||||
|
history. Current managed deployment belongs to the service/package owners
|
||||||
|
under [ADR-0015](../../docs/adr/ADR-0015-netkingdom-railiance-workload-packaging-and-relational-platform.md).
|
||||||
|
The [original foundation procedure](FOUNDATIONS-HISTORICAL.md) is retained as
|
||||||
|
historical material, including its old prerequisites and apply commands.
|
||||||
|
|
||||||
Phase 1 of NK-WP-0001: namespaces, NetworkPolicies, cert-manager, StorageClass.
|
## Operating baseline
|
||||||
|
|
||||||
## SSO stack overview
|
The [September 28 review](../../history/2026-09-28-open-workplan-infrastructure-review.md)
|
||||||
|
observed one Ready Railiance01 node at `92.205.62.239`, healthy lightweight
|
||||||
|
identity components and single-instance CNPG databases. This is a dated
|
||||||
|
inventory, not an HA, recovery or user-login acceptance claim.
|
||||||
|
|
||||||
The `sso` namespace hosts three components:
|
| Surface | Current role and owner |
|
||||||
- **KeyCape** (`kc.coulomb.social`) — OIDC orchestration layer, stateless
|
| --- | --- |
|
||||||
- **Authelia** (`auth.coulomb.social`) — password authentication frontend
|
| KeyCape / Authelia / LLDAP (`sso`) and privacyIDEA (`mfa`) | Lightweight identity composition; issuer implementation in `key-cape`, integration contracts here |
|
||||||
- **LLDAP** (`lldap.coulomb.social`) — lightweight LDAP directory (admin UI restricted)
|
| User Engine | [rapp-user-engine](../../../rapp-user-engine/README.md) owns managed manifests, rollout and rollback |
|
||||||
|
| Tenant Engine | [rapp-tenant-engine](../../../rapp-tenant-engine/README.md) owns managed runtime and database-consumption configuration |
|
||||||
|
| flex-auth consumer services | [Owner values and chart pointers](tenant-engine/README.md); caller authentication is enforced by the owner declarations |
|
||||||
|
| OpenBao and database custody | `railiance-platform`, with managed packages and consumer declarations in their owning repositories |
|
||||||
|
| Kubernetes and host substrate | [railiance-cluster operator runbook](../../../railiance-cluster/docs/operator-runbook.md) and `railiance-infra` |
|
||||||
|
|
||||||
The `mfa` namespace hosts:
|
OpenBao's public browser endpoint `bao.coulomb.social` is retired. Operators
|
||||||
- **privacyIDEA** (`pink.coulomb.social`) — MFA engine, called by KeyCape
|
use the named `openbao-ui-railiance01` tunnel at `http://127.0.0.1:18200`;
|
||||||
|
workloads use the internal Service. Follow the platform's
|
||||||
|
[operator-only cutover record](../../../railiance-platform/workplans/RPF-WP-0025-openbao-operator-only-access.md)
|
||||||
|
and credential routing in [AGENTS.md](../../AGENTS.md). Route access before
|
||||||
|
requesting credentials; never copy tokens or Secret values into evidence.
|
||||||
|
|
||||||
## Prerequisites
|
## Read-only orientation
|
||||||
|
|
||||||
- K3s cluster running (ThreePhoenix HA or single-node dev)
|
Check the context before interpreting these results. All commands below read
|
||||||
- T01 Phase 0a complete (KeePassXC vault populated, ops bundle exported)
|
resource metadata and readiness; none applies manifests or initiates login.
|
||||||
- `kubectl` configured with cluster access
|
|
||||||
|
|
||||||
## Apply order
|
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# 1. Install cert-manager (if not already on cluster)
|
kubectl config current-context
|
||||||
helm repo add jetstack https://charts.jetstack.io
|
kubectl get nodes -o wide
|
||||||
helm repo update
|
kubectl -n sso get deployments
|
||||||
helm install cert-manager jetstack/cert-manager \
|
kubectl -n mfa get deployments
|
||||||
--namespace cert-manager --create-namespace \
|
kubectl -n user-engine get deployments
|
||||||
--set crds.enabled=true
|
kubectl -n tenant-engine get deployments
|
||||||
|
kubectl -n flex-auth get deployments
|
||||||
# Wait for cert-manager to be ready
|
kubectl -n openbao get statefulsets,deployments,services,ingresses
|
||||||
kubectl rollout status deployment/cert-manager -n cert-manager
|
kubectl get clusters.postgresql.cnpg.io -A
|
||||||
|
|
||||||
# 2. Create namespaces
|
|
||||||
kubectl apply -f namespaces/namespaces.yaml
|
|
||||||
|
|
||||||
# 3. Apply NetworkPolicies
|
|
||||||
kubectl apply -f network-policies/netpol-sso.yaml
|
|
||||||
kubectl apply -f network-policies/netpol-mfa.yaml
|
|
||||||
kubectl apply -f network-policies/netpol-databases.yaml
|
|
||||||
|
|
||||||
# 4. Create ClusterIssuers
|
|
||||||
# Edit issuers.yaml first: replace ACME_EMAIL with your address
|
|
||||||
kubectl apply -f cert-manager/issuers.yaml
|
|
||||||
|
|
||||||
# 5. Verify cert-manager with test certificate
|
|
||||||
kubectl apply -f cert-manager/test-certificate.yaml
|
|
||||||
kubectl wait --for=condition=Ready certificate/selfsigned-test \
|
|
||||||
-n cert-manager-test --timeout=60s
|
|
||||||
kubectl delete namespace cert-manager-test
|
|
||||||
|
|
||||||
# 6. Verify StorageClass
|
|
||||||
kubectl apply -f storage/verify-pvc.yaml
|
|
||||||
kubectl wait --for=condition=Ready pod/storage-test \
|
|
||||||
-n storage-test --timeout=60s
|
|
||||||
kubectl logs -n storage-test storage-test
|
|
||||||
kubectl delete namespace storage-test
|
|
||||||
|
|
||||||
# 7. Run the full verification script
|
|
||||||
chmod +x verify-t02.sh
|
|
||||||
./verify-t02.sh
|
|
||||||
```
|
```
|
||||||
|
|
||||||
## NetworkPolicy design
|
Ready replicas do not prove negative authorization, actual-user MFA, successful
|
||||||
|
backup restoration or independent failure domains. Use the relevant owner's
|
||||||
|
verification and recovery procedure for those claims.
|
||||||
|
|
||||||
All three namespaces follow a default-deny-all posture. Only the minimal
|
## Deployment and recovery
|
||||||
required paths are opened:
|
|
||||||
|
|
||||||
| Source | Destination | Port | Purpose |
|
Start with the owning package's current declaration, immutable image and
|
||||||
|--------|-------------|------|---------|
|
reviewed rollout/rollback procedure. Do not recursively apply this tree.
|
||||||
| Traefik (kube-system) | KeyCape (sso) | 8080 | OIDC endpoints — public |
|
`tenant-engine/runtime.yaml` remains **REFERENCE ONLY — DO NOT APPLY** while
|
||||||
| Traefik (kube-system) | Authelia (sso) | 9091 | Login portal — public |
|
its owner decides the disposition of the five retained historical objects.
|
||||||
| Traefik (kube-system) | LLDAP (sso) | 17170 | Admin web UI — IP-restricted |
|
Its obsolete flex-auth objects have been replaced with owner pointers.
|
||||||
| Traefik (kube-system) | privacyIDEA (mfa) | 8080 | MFA portal — public |
|
|
||||||
| KeyCape (sso) | Authelia (sso) | 9091 | OIDC token exchange |
|
|
||||||
| KeyCape (sso) | LLDAP (sso) | 3890 | User attribute lookup |
|
|
||||||
| KeyCape (sso) | privacyIDEA (mfa) | 8080 | MFA challenge + validation |
|
|
||||||
| Authelia (sso) | LLDAP (sso) | 3890 | Credential validation |
|
|
||||||
| privacyIDEA (mfa) | PostgreSQL (databases) | 5432 | DB |
|
|
||||||
| CNPG operator (cnpg-system) | PostgreSQL (databases) | 5432/9187 | Operator + metrics |
|
|
||||||
| All pods | kube-dns (kube-system) | 53 | DNS resolution |
|
|
||||||
| CNPG pods | K8s API | 6443 | Status updates |
|
|
||||||
|
|
||||||
## Verifying denied paths (manual)
|
The scripts and manifests elsewhere in this directory have individual scopes;
|
||||||
|
their presence here does not make them current production repair commands.
|
||||||
|
The [attended procedure inventory](../../docs/attended-procedure-inventory.md)
|
||||||
|
records their exercise limits. Use the [custody model](../../docs/openbao-unseal-custody-models.md)
|
||||||
|
and current owner runbooks to prepare recovery. A database-only drill does not
|
||||||
|
prove restoration of LLDAP, Authelia, privacyIDEA and its matching encryption
|
||||||
|
material, or all identity database state.
|
||||||
|
|
||||||
After applying NetworkPolicies, confirm that illegal paths are blocked:
|
CoulombCore identity cutover is complete; final retained-resource deletion
|
||||||
|
remains gated by [NK-WP-0022](../../workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md).
|
||||||
```bash
|
Expiration of the retention minimum does not authorize deletion.
|
||||||
# Test: KeyCape → privacyIDEA (should be ALLOWED)
|
|
||||||
kubectl run test-allowed -n sso --rm -it --image=busybox --restart=Never \
|
|
||||||
-- nc -zv privacyidea.mfa.svc.cluster.local 8080
|
|
||||||
|
|
||||||
# Test: Authelia → privacyIDEA (should be DENIED — only KeyCape calls privacyIDEA)
|
|
||||||
kubectl run test-denied -n sso --rm -it --image=busybox --restart=Never \
|
|
||||||
-l app.kubernetes.io/name=authelia \
|
|
||||||
-- nc -zv -w3 privacyidea.mfa.svc.cluster.local 8080
|
|
||||||
|
|
||||||
# Test: databases → sso (should be DENIED — DB pods must not initiate connections)
|
|
||||||
kubectl run test-denied2 -n databases --rm -it --image=busybox --restart=Never \
|
|
||||||
-- nc -zw3 keycape.sso.svc.cluster.local 8080
|
|
||||||
```
|
|
||||||
|
|
||||||
## Notes
|
|
||||||
|
|
||||||
- `net-kingdom/component` labels on namespaces are used by NetworkPolicy
|
|
||||||
`namespaceSelector` rules. Do not remove them.
|
|
||||||
- `cnpg.io/cluster: net-kingdom-pg` in `netpol-databases.yaml` must match
|
|
||||||
the name of the CloudNativePG `Cluster` CR you create in T03.
|
|
||||||
- The `letsencrypt-prod` ClusterIssuer requires public DNS and port 80 open
|
|
||||||
to Let's Encrypt servers. Update `ACME_EMAIL` before applying.
|
|
||||||
|
|
|
||||||
|
|
@ -0,0 +1,113 @@
|
||||||
|
---
|
||||||
|
id: NK-WP-0043
|
||||||
|
type: workplan
|
||||||
|
title: "Make cadence assessment explicit and refresh operating guidance"
|
||||||
|
domain: infotech
|
||||||
|
repo: net-kingdom
|
||||||
|
status: finished
|
||||||
|
flavor: implementation
|
||||||
|
owner: codex
|
||||||
|
topic_slug: netkingdom
|
||||||
|
created: "2026-09-28"
|
||||||
|
updated: "2026-09-28"
|
||||||
|
related: [NK-WP-0035, NK-WP-0039]
|
||||||
|
state_hub_workstream_id: "866807af-b4a9-56d8-ac10-3d05a33aef0c"
|
||||||
|
---
|
||||||
|
|
||||||
|
User-authorized follow-through to the September 28 infrastructure review.
|
||||||
|
Existing changes and historical workplan identifiers remain intact. This work
|
||||||
|
changes local verification and guidance, not deployment or source emission.
|
||||||
|
|
||||||
|
## Distinguish schema validity from a security-profile assessment
|
||||||
|
|
||||||
|
```task
|
||||||
|
id: NK-WP-0043-T01
|
||||||
|
status: done
|
||||||
|
priority: high
|
||||||
|
state_hub_task_id: "7e450a12-9ccd-51f1-a98b-bc28b069affe"
|
||||||
|
```
|
||||||
|
|
||||||
|
Before this change, an empty supplied inventory produced `conformant: true` while no
|
||||||
|
class-specific obligation is checked. Return an explicit unassessed result and
|
||||||
|
a nonzero default exit; offer an intentional schema-only mode. Record the
|
||||||
|
supplied inventory so a scoped assessment cannot be mistaken for fleet-wide
|
||||||
|
adoption. Never infer classification or rarity from the declaration.
|
||||||
|
|
||||||
|
Acceptance: CLI and report regressions cover omitted inventory, schema-only
|
||||||
|
success/failure, invalid option combinations and existing profile checks.
|
||||||
|
The real local-identity declaration remains generic-valid and fails its two
|
||||||
|
rare heartbeat obligations with explicit source inventory.
|
||||||
|
|
||||||
|
Completed: the checker returns `profile_assessed`, exact inventory and
|
||||||
|
assessment scope; `conformant` is null when unassessed. No inventory in default
|
||||||
|
mode exits 2, explicit schema-only success exits 0, and validation failures
|
||||||
|
exit 1. Schema-only rejects profile options and blank class arguments are
|
||||||
|
rejected. Updated the tool README and proposed profile with compatibility and
|
||||||
|
exit-code guidance. Existing profile/classification rules are unchanged.
|
||||||
|
|
||||||
|
Verification: the new regressions failed against the old implementation
|
||||||
|
(including the demonstrated exit-0 empty-inventory defect). The final focused
|
||||||
|
suite passes 27 tests. Process-level checks against the current owner schema
|
||||||
|
and real local-identity declaration verify default exit 2 / null, schema-only
|
||||||
|
exit 0 / null, and explicit rare inventory exit 1 / two missing-heartbeat
|
||||||
|
findings. Python compilation passes. Ruff was unavailable in this environment;
|
||||||
|
no Ruff result is claimed.
|
||||||
|
|
||||||
|
## Separate current operations from historical bootstrap instructions
|
||||||
|
|
||||||
|
```task
|
||||||
|
id: NK-WP-0043-T02
|
||||||
|
status: done
|
||||||
|
priority: medium
|
||||||
|
state_hub_task_id: "5d95bc2d-f940-5989-aacb-0f1865778e7b"
|
||||||
|
```
|
||||||
|
|
||||||
|
Refresh SCOPE and the Kubernetes entry README against the dated September 28
|
||||||
|
review. Preserve old foundation commands in an explicitly historical document;
|
||||||
|
route current deployment, custody and recovery to the owning repositories.
|
||||||
|
Acceptance: links resolve, read-only examples are non-mutating, current versus
|
||||||
|
historical claims are explicit, and no HA or fresh recovery claim is inferred.
|
||||||
|
|
||||||
|
Completed: SCOPE now describes the dated September 28 topology and actual
|
||||||
|
owner/evidence gates. The Kubernetes README provides owner links and read-only
|
||||||
|
orientation, with original commands preserved in `FOUNDATIONS-HISTORICAL.md`.
|
||||||
|
All updated Markdown links resolve. New command examples are metadata reads;
|
||||||
|
no deployment, login or recovery operation was performed.
|
||||||
|
|
||||||
|
## Use one naming convention for new workplans
|
||||||
|
|
||||||
|
```task
|
||||||
|
id: NK-WP-0043-T03
|
||||||
|
status: done
|
||||||
|
priority: low
|
||||||
|
state_hub_task_id: "d51e878f-fbbb-5684-bccc-edd050ed87a5"
|
||||||
|
```
|
||||||
|
|
||||||
|
Use the registered `NK-WP-` prefix throughout AGENTS.md's new-plan examples and
|
||||||
|
archive convention. Preserve all existing IDs and UUIDs, including NET-WP
|
||||||
|
records. Align creation sync guidance with the existing direct CLI requirement.
|
||||||
|
Acceptance: no conflicting new-plan example remains and historical IDs match
|
||||||
|
before/after. Reconcile the completed workplan to State Hub.
|
||||||
|
|
||||||
|
Completed: all new-plan examples and archive guidance use NK-WP. Creation
|
||||||
|
instructions now use the existing direct consistency CLI protocol. Compared
|
||||||
|
every pre-existing workplan's IDs against HEAD; no ID changed. Authored files
|
||||||
|
pass `git diff --check`; the generated brief retains its generator's Markdown
|
||||||
|
hard-break whitespace. State Hub reconciliation follows at session close.
|
||||||
|
|
||||||
|
## Final review — 2026-09-28
|
||||||
|
|
||||||
|
Reviewed the accumulated infrastructure, reference, checker and guidance diff
|
||||||
|
before committing. Corrected the federation plan's unconditional
|
||||||
|
realm-per-tenant implementation/acceptance wording to follow its topology
|
||||||
|
ADR, clarified historical cutover prose and labelled the initial review
|
||||||
|
snapshot separately from later implementation. No checker defect was found.
|
||||||
|
|
||||||
|
Broader integration validation: `python3 -m pytest tests tools -q` passes
|
||||||
|
118 tests. All changed Markdown links resolve. Parsed YAML confirms the five
|
||||||
|
retained tenant-engine objects are identical to HEAD and exactly seven
|
||||||
|
flex-auth objects were removed. Every archived bootstrap shell example matches
|
||||||
|
the original README. Existing workplan IDs remain unchanged. The only default
|
||||||
|
whitespace-check finding is the generated brief's intentional Markdown line
|
||||||
|
break; authored files pass. Changes are grouped into infrastructure/reference,
|
||||||
|
cadence assessment, and operating guidance commits.
|
||||||
Loading…
Add table
Add a link
Reference in a new issue