Reconcile infrastructure workplans and retire stale flex-auth references
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
This commit is contained in:
parent
019e8f21a7
commit
9383b94019
12 changed files with 494 additions and 149 deletions
|
|
@ -11,7 +11,7 @@ topic_slug: netkingdom
|
|||
planning_priority: medium
|
||||
planning_order: 9
|
||||
created: 2026-05-17
|
||||
updated: 2026-07-08
|
||||
updated: "2026-09-28"
|
||||
depends_on:
|
||||
- NK-WP-0008
|
||||
state_hub_workstream_id: "d4d02dbf-3974-502d-8b87-b776fc63e17e"
|
||||
|
|
@ -64,7 +64,7 @@ Out of scope:
|
|||
- hiding provider-specific security differences behind one generic
|
||||
command
|
||||
|
||||
## Tasks
|
||||
## Create the tutorial template
|
||||
|
||||
```task
|
||||
id: NK-WP-0009-T01
|
||||
|
|
@ -77,6 +77,8 @@ Create a tutorial template with prerequisites, architecture context,
|
|||
commands, manifests, verification, rollback, threat checks, and
|
||||
cross-repo ownership notes.
|
||||
|
||||
## Demonstrate temporary object credentials
|
||||
|
||||
```task
|
||||
id: NK-WP-0009-T02
|
||||
status: todo
|
||||
|
|
@ -89,6 +91,8 @@ NetKingdom identity token", covering key-cape/Keycloak identity,
|
|||
flex-auth authorization, object-store STS exchange, and SDK consumer
|
||||
configuration.
|
||||
|
||||
## Document the existing OpenBao operating path
|
||||
|
||||
```task
|
||||
id: NK-WP-0009-T03
|
||||
status: todo
|
||||
|
|
@ -101,6 +105,8 @@ NetKingdom-enabled Railiance platform", linking to the Railiance
|
|||
Platform workplan and covering auth methods, secret engines, CSI/ESO
|
||||
integration, leases, unseal, backup, and break-glass.
|
||||
|
||||
## Document SSH certificates and tunnels
|
||||
|
||||
```task
|
||||
id: NK-WP-0009-T04
|
||||
status: todo
|
||||
|
|
@ -112,6 +118,8 @@ Write "Use short-lived SSH credentials for admins, agents, and
|
|||
automations", using ops-warden and ops-bridge as the reference
|
||||
implementation.
|
||||
|
||||
## Integrate a protected flex-auth consumer
|
||||
|
||||
```task
|
||||
id: NK-WP-0009-T05
|
||||
status: todo
|
||||
|
|
@ -123,6 +131,8 @@ Write "Add a protected system to flex-auth", covering resource
|
|||
manifests, action vocabulary, claim envelopes, policy packages,
|
||||
decision envelopes, and delegated PDP options.
|
||||
|
||||
## Verify the tutorial outcomes
|
||||
|
||||
```task
|
||||
id: NK-WP-0009-T06
|
||||
status: todo
|
||||
|
|
@ -142,3 +152,22 @@ clear "done when" outcome and does not become prose-only guidance.
|
|||
step.
|
||||
- Tutorials include verification and rollback guidance, not just happy
|
||||
path commands.
|
||||
|
||||
## Infrastructure review — 2026-09-28
|
||||
|
||||
Keep this plan in backlog, with the first implementation slice T01 + T03 +
|
||||
T04 + T06: document the paths already operated and capture safe verification
|
||||
and recovery outcomes. OpenBao is already deployed and private; T03 should
|
||||
teach consumption, attended access and recovery, with greenfield deployment
|
||||
kept as an isolated lab exercise. Use the named `openbao-ui-railiance01`
|
||||
tunnel and owner runbooks, not a public Bao URL or copied runtime manifest.
|
||||
|
||||
T02 is conditional on an owner-backed object-store STS issuer and refusal/lease
|
||||
proof; ADR-0008 is architecture, not evidence that the endpoint is live. T05
|
||||
must include projected caller identity, audience, binding and unauthorized
|
||||
caller rejection: all six live consumers now enforce caller authentication.
|
||||
Use accepted IAM v0.3 and owner package declarations under ADR-0015. T06
|
||||
requires executable safe fixtures or repeatable outcome checks; never teach
|
||||
operators to apply the stale tenant-engine reference YAML.
|
||||
|
||||
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue