feat(orchestration): compose KeyCape C1 and C2b
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02929-244b-7391-b933-c04010e8eedb
This commit is contained in:
tegwick 2026-08-23 13:24:55 +02:00
parent 21f477f699
commit 7f4e4e9f57
8 changed files with 133 additions and 15 deletions

View file

@ -142,9 +142,12 @@ NK-WP-0030 subsequently implemented the first bounded G1 increment: proposed
Security Scenario Composition v0.1 canon, a fail-closed plan-only composer, and
a real C0 local-identity declaration and reference scenario. This establishes
deterministic provider pins, trust ordering, responsibility mapping, and
readiness handoff without executing provider actions. G1 remains open for the
lightweight SSO path until the KeyCape/Railiance owners publish conformant C1
and C2 declarations.
readiness handoff without executing provider actions. KeyCape subsequently
published conformant owner declarations for C1 and C2b. NetKingdom's checked-in
reference now composes them in trust order and preserves their responsibility
map without claiming C2a. G1 remains open beyond this bounded increment because
the composer neither executes the provider entry points nor closes their
readiness obligations into verified turn-key state.
NK-WP-0031 subsequently implemented the first bounded G2 increment: proposed
Posture Feedback v0.1 canon and a deterministic evaluator that turns explicit