Reconcile infrastructure workplans and retire stale flex-auth references

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
This commit is contained in:
tegwick 2026-09-28 12:40:03 +02:00
parent 019e8f21a7
commit 9383b94019
12 changed files with 494 additions and 149 deletions

View file

@ -11,7 +11,7 @@ topic_slug: netkingdom
planning_priority: medium
planning_order: 9
created: 2026-05-17
updated: 2026-07-08
updated: "2026-09-28"
depends_on:
- NK-WP-0008
state_hub_workstream_id: "d4d02dbf-3974-502d-8b87-b776fc63e17e"
@ -64,7 +64,7 @@ Out of scope:
- hiding provider-specific security differences behind one generic
command
## Tasks
## Create the tutorial template
```task
id: NK-WP-0009-T01
@ -77,6 +77,8 @@ Create a tutorial template with prerequisites, architecture context,
commands, manifests, verification, rollback, threat checks, and
cross-repo ownership notes.
## Demonstrate temporary object credentials
```task
id: NK-WP-0009-T02
status: todo
@ -89,6 +91,8 @@ NetKingdom identity token", covering key-cape/Keycloak identity,
flex-auth authorization, object-store STS exchange, and SDK consumer
configuration.
## Document the existing OpenBao operating path
```task
id: NK-WP-0009-T03
status: todo
@ -101,6 +105,8 @@ NetKingdom-enabled Railiance platform", linking to the Railiance
Platform workplan and covering auth methods, secret engines, CSI/ESO
integration, leases, unseal, backup, and break-glass.
## Document SSH certificates and tunnels
```task
id: NK-WP-0009-T04
status: todo
@ -112,6 +118,8 @@ Write "Use short-lived SSH credentials for admins, agents, and
automations", using ops-warden and ops-bridge as the reference
implementation.
## Integrate a protected flex-auth consumer
```task
id: NK-WP-0009-T05
status: todo
@ -123,6 +131,8 @@ Write "Add a protected system to flex-auth", covering resource
manifests, action vocabulary, claim envelopes, policy packages,
decision envelopes, and delegated PDP options.
## Verify the tutorial outcomes
```task
id: NK-WP-0009-T06
status: todo
@ -142,3 +152,22 @@ clear "done when" outcome and does not become prose-only guidance.
step.
- Tutorials include verification and rollback guidance, not just happy
path commands.
## Infrastructure review — 2026-09-28
Keep this plan in backlog, with the first implementation slice T01 + T03 +
T04 + T06: document the paths already operated and capture safe verification
and recovery outcomes. OpenBao is already deployed and private; T03 should
teach consumption, attended access and recovery, with greenfield deployment
kept as an isolated lab exercise. Use the named `openbao-ui-railiance01`
tunnel and owner runbooks, not a public Bao URL or copied runtime manifest.
T02 is conditional on an owner-backed object-store STS issuer and refusal/lease
proof; ADR-0008 is architecture, not evidence that the endpoint is live. T05
must include projected caller identity, audience, binding and unauthorized
caller rejection: all six live consumers now enforce caller authentication.
Use accepted IAM v0.3 and owner package declarations under ADR-0015. T06
requires executable safe fixtures or repeatable outcome checks; never teach
operators to apply the stale tenant-engine reference YAML.
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).