Add flex-auth protected-system tutorial (NK-WP-0009-T05)
Some checks are pending
CI Smoke / container-smoke (push) Waiting to run
CI Smoke / host-smoke (push) Waiting to run

Offline steps exercised against the secrets-engine example; live caller-auth
steps remain unexercised.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 295952@bnt-lap001
Assistant-Session: e93f64ad-516c-46eb-9666-aad8d300c477
This commit is contained in:
tegwick 2026-09-28 23:44:44 +02:00
parent 2a004a70ea
commit 923e211365
3 changed files with 127 additions and 3 deletions

View file

@ -24,10 +24,10 @@ Hands-on paths for operating the canonical NetKingdom security patterns
| --- | --- | --- | --- |
| [OpenBao: consume, attend, recover](openbao-operating-path.md) | T03 | railiance-platform, net-kingdom | unexercised |
| [Short-lived SSH credentials](ssh-certificates-and-tunnels.md) | T04 | ops-warden, ops-bridge | unexercised |
| [Add a protected system to flex-auth](protected-system-flex-auth.md) | T05 | flex-auth, package owner | unexercised (offline part run) |
Deferred (see NK-WP-0009): T02 object-storage STS (needs an owner-backed
issuer and refusal/lease proof — ADR-0008 is architecture, not evidence) and
T05 flex-auth protected consumer.
issuer and refusal/lease proof — ADR-0008 is architecture, not evidence).
## Pattern mapping