Add first-wave NetKingdom arc42 stub
Chapters 1, 3 and 9 cover identity and tenancy. IAM Profile id collision is noted, not resolved, here.
This commit is contained in:
parent
f4f885289e
commit
ba5d8642e9
1 changed files with 141 additions and 0 deletions
141
docs/architecture/net-kingdom_v0.1.md
Normal file
141
docs/architecture/net-kingdom_v0.1.md
Normal file
|
|
@ -0,0 +1,141 @@
|
|||
---
|
||||
id: net-kingdom-architecture
|
||||
title: "NetKingdom architecture"
|
||||
status: proposed
|
||||
owner: net-kingdom
|
||||
revision: "draft-1"
|
||||
version: "0.1"
|
||||
last_reviewed: "2026-08-18"
|
||||
review_interval: 6m
|
||||
---
|
||||
|
||||
# NetKingdom — Software Architecture Documentation (arc42)
|
||||
|
||||
## About this document
|
||||
|
||||
First-wave arc42 for NetKingdom: the estate's identity and tenancy
|
||||
security core. Chapter 9 lists governing ADRs and standards; it does
|
||||
not paste them.
|
||||
|
||||
---
|
||||
|
||||
## 1. Introduction and Goals
|
||||
|
||||
NetKingdom is the open security core for DevSecOps on Kubernetes. It
|
||||
owns identity, tenancy posture, and the contracts that flex-auth,
|
||||
key-cape, tenant-engine, and railiance workloads implement.
|
||||
|
||||
### 1.1 Requirements Overview
|
||||
|
||||
- One IAM profile, versioned, owned here.
|
||||
- Tenancy described as graduated axes, not a single on/off switch.
|
||||
- Workload packaging and credential vending have explicit boundaries.
|
||||
|
||||
### 1.2 Quality Goals
|
||||
|
||||
1. Provider-neutral identity contract.
|
||||
2. Recursive multi-tenant authorization that implementers can declare.
|
||||
3. Honest about what is not there yet (Tenancy Posture).
|
||||
|
||||
### 1.3 Stakeholders
|
||||
|
||||
| Role | Concern |
|
||||
| --- | --- |
|
||||
| net-kingdom | Canon owner for identity and tenancy. |
|
||||
| flex-auth / key-cape / tenant-engine | Implementers of the contracts. |
|
||||
| railiance-master | Workload packaging on the rail. |
|
||||
| the-custodian | Federation; does not redefine these concepts. |
|
||||
|
||||
---
|
||||
|
||||
## 2. Architecture Constraints
|
||||
|
||||
N/A for this stub.
|
||||
|
||||
---
|
||||
|
||||
## 3. System Scope and Context
|
||||
|
||||
**In:** IAM profile, tenancy posture, tenant/user-engine boundaries,
|
||||
credential management, playbook capability contract, NetKingdom ADRs.
|
||||
**Out:** publication (policy-nexus), rail runtime (railiance), estate
|
||||
work-factory (the-custodian).
|
||||
|
||||
### 3.1 Business Context
|
||||
|
||||
Security here is dynamic and adversarial. The system exists so
|
||||
implementers share one contract instead of copying a neighbour.
|
||||
|
||||
### 3.2 Technical Context
|
||||
|
||||
Consumers: flex-auth, key-cape, tenant-engine, audit-core, rApps.
|
||||
Published today: Tenancy Posture
|
||||
`/standards/tenancy-posture/v0.1/`.
|
||||
|
||||
---
|
||||
|
||||
## 4. Solution Strategy
|
||||
|
||||
N/A for this stub — recursive multi-tenant identity (ADR-0006) and the
|
||||
IAM profile ownership rule (ADR-0011) are the spine.
|
||||
|
||||
---
|
||||
|
||||
## 5. Building Block View
|
||||
|
||||
### 5.1 Level 1 – System/Top-Level
|
||||
|
||||
N/A for this stub.
|
||||
|
||||
---
|
||||
|
||||
## 6. Runtime View
|
||||
|
||||
N/A for this stub.
|
||||
|
||||
---
|
||||
|
||||
## 7. Deployment View
|
||||
|
||||
N/A for this stub.
|
||||
|
||||
---
|
||||
|
||||
## 8. Cross-Cutting Concepts
|
||||
|
||||
N/A for this stub.
|
||||
|
||||
---
|
||||
|
||||
## 9. Architecture Decisions
|
||||
|
||||
| Source | Status | Notes |
|
||||
| --- | --- | --- |
|
||||
| `canon/standards/tenancy-posture_v0.1.md` | proposed | Published. First publication of this site. |
|
||||
| `canon/standards/iam-profile_v0.3.md` | accepted | Current profile. Needs a unique publication id (v0.2 still shares `netkingdom-iam-profile`). |
|
||||
| `canon/standards/iam-profile_v0.2.md` | should be superseded | v0.3 supersedes it; front-matter still `accepted`. |
|
||||
| `docs/adr/ADR-0006` … `ADR-0015` | see files | Identity, orchestration, IAM ownership, tenant roles, packaging. Publish after `NK-ADR-*` prefix and review metadata. |
|
||||
|
||||
Custodian ADR-008 is superseded by Tenancy Posture and is not current.
|
||||
|
||||
---
|
||||
|
||||
## 10. Quality Requirements
|
||||
|
||||
N/A for this stub.
|
||||
|
||||
---
|
||||
|
||||
## 11. Risks and Technical Debt
|
||||
|
||||
N/A for this stub. Residual: IAM Profile id collision (WP-0003 packet).
|
||||
|
||||
---
|
||||
|
||||
## 12. Glossary
|
||||
|
||||
| Term | Meaning |
|
||||
| --- | --- |
|
||||
| IAM Profile | Provider-neutral OIDC contract owned here. |
|
||||
| Tenancy Posture | Graduated axes for describing multi-tenancy. |
|
||||
| Tenant-engine | Lifecycle and capability roles for tenants. |
|
||||
Loading…
Add table
Add a link
Reference in a new issue