Commit graph

408 commits

Author SHA1 Message Date
2744ce7d36 Tenancy Posture draft-6: the first review changed the document
tenant-engine assessed itself against the ladders and came back with
corrections. All five are adopted, because the ratification test says that if a
repo cannot express itself the ladders are wrong - and it could not, in three
places.

I2 conflated authority with verification. Its text named tenant-engine as the
source of existence, which made the level describing canonical identity
unclaimable by the service that provides it. An axis is assessed on a service's
own inbound surface, never on its authority over the concept. tenant-engine is
the source of tenant records and is at I1, because the acting identity arrives
in the request body rather than in a verified token.

A level now reports the weakest surface. tenant-engine has PDP-authorized
mutations and three unauthorized read routes - including the one flex-auth
calls for aal2-class decisions - and reported A2 rather than A3. Publishing the
stronger surface would be accurate about that surface and misleading about the
service. A per-surface vector was considered and rejected as premature.

The E ladder assumed all data is tenant-keyed. A registry whose rows ARE the
tenants has no predicate to scope a policy by, and enforcing one would break
the service rather than secure it. Mixed-shape services now declare an E level
plus a named registry exception; an unnamed exception is an overclaim. Without
this they overclaim or sit at E2 forever, which is what tenant-engine was
facing.

Retention and erasure are two dimensions and one level cannot carry both.
tenant-engine is R1 on backup and R0 on erasure - its lifecycle contract
deliberately defines no hard-delete, so a tenant record cannot be deleted ever,
by design, while carrying display_name and contact_email. Declared R1/R0 now.
And the compounding - personal data, no erasure path, a backup window set by
the longest-retaining co-resident - is the substrate owner's to surface,
because each part looks locally reasonable alone.

My own error, corrected: I listed tenant-engine as a live P1 occupant in both
the ladder and the E/P matrix. They are on SQLite. P1 is TEN-WP-0009's target
and the provisioning is my own unapplied intake. Asserting a placement that a
workplan exists to create is exactly the kind of claim this document forbids.

Worth recording: they found an unfiltered cross-tenant read in their own event
accessor while assessing against the ladder, before publishing anything.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 21:38:35 +02:00
cb32f6d68c Correct question 3: whitehat is NetKingdom's
An earlier revision of this section asserted the adversarial facility was
deliberately not NetKingdom's, on independence grounds. Overruled, and the
counter-argument is better: offensive security is security work.

The facility is also framed more broadly than this document assumed - it is
pointed at infrastructure we choose, our own estate among them, and testing
conformance to this framework is one use of a general capability rather than
its purpose.

The tension I raised is left in the text rather than deleted, because it is
real: NetKingdom now owns both this framework and the facility that tests
conformance to it. The mitigation is that findings leave for risk-nexus under
separate ownership instead of being closed in place, and the trigger to
revisit is conformance findings starting to close quietly.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 18:01:17 +02:00
e25545d9d0 Tenancy Posture §8.3: service class, and why there is no QoS axis
Question 12 asked whether to add a quality-of-service dimension. No - because
we could not enforce it. Community PostgreSQL has no resource governor, so a
declared priority would be an unenforced claim in a declaration, which is what
retiring tenantIsolation was about. An axis implies graduation and enforcement
and this has neither.

Co-residents are equal, and a consumer whose latency cannot survive an
unprioritised neighbour escalates to P2. Service class is still declared, as a
category not a level: it informs placement, acts as a trigger, and gives
"acceptable degradation" in the noisy-neighbour artifact something to be
acceptable relative to - what batch tolerates is an outage for latency-critical.

Class mixture must be visible, because an unenforceable risk nobody can see is
worse than one that is stated. rapp-postgres now reports it and the live
instance already flags latency-critical beside batch.

Gateway-level prioritisation in a connection proxy is recorded as the known
escalation short of P2 - real, and infrastructure we do not run.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 17:41:12 +02:00
101e659725 Tenancy Posture: question 3 has an owner
whitehat-security takes the adversarial evidence artifacts - the framework's
highest-severity gap, unowned since it was drafted. audit-core and tenant-engine
were right to decline it as fleet-scope work; the answer was a home of its own
rather than a volunteer.

Recorded here with the part that bears on this document: the facility is
deliberately not owned by NetKingdom, which owns this framework. Verifying
conformance to a standard while reporting to the standard's owner is
self-grading one level up.

Two consequences land back on the framework. Cadence becomes a security
parameter rather than a schedule, since for a detection-based control the
interval between runs is the exposure window. And a passing suite is proof that
the attacks attempted did not work, not proof of isolation - recording a green
run as "E2 verified" would be exactly the overclaim section 6 prohibits.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 16:41:56 +02:00
c31a5e3f8b Refresh completed ad-hoc work index
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-14 20:12:52 +02:00
custodian-sync
a9b1cd98ff chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-08-14:
  - update .custodian-brief.md for net-kingdom
2026-08-14 19:59:17 +02:00
6f755d2615 Finish audit sender custody residual
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Has been cancelled
2026-08-14 19:59:14 +02:00
797a941dd3 Remove duplicate ad-hoc State Hub binding
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-14 19:50:46 +02:00
52f9b200e8 Track and harden NK-WP-0025 residuals
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-14 19:35:46 +02:00
custodian-sync
d9871e4de8 chore(consistency): sync task status from DB [auto]
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
Updated by fix-consistency on 2026-08-14:
  - update .custodian-brief.md for net-kingdom
2026-08-14 19:35:45 +02:00
custodian-sync
b47eec5a42 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-08-14:
  - update .custodian-brief.md for net-kingdom
2026-08-14 19:35:16 +02:00
9448384a69 Refresh completed registration work record
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-14 19:16:12 +02:00
custodian-sync
b93836b97b chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-08-14:
  - update .custodian-brief.md for net-kingdom
2026-08-14 19:16:11 +02:00
ded2398bb3 Finish public registration and JIT acceptance
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
2026-08-14 19:15:06 +02:00
2a2d8ba055 Align provisioned identities with OIDC subjects
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-14 18:53:37 +02:00
cbbd66697f Refresh NetKingdom work records
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-14 17:42:09 +02:00
custodian-sync
bd83dbe60a chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-08-14:
  - update .custodian-brief.md for net-kingdom
2026-08-14 17:41:06 +02:00
custodian-sync
afa32d9ec6 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-08-14:
  - update .custodian-brief.md for net-kingdom
2026-08-14 17:40:25 +02:00
custodian-sync
84869f548f chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-14:
  - NK-WP-0025-T05: progress → wait
2026-08-14 17:40:20 +02:00
94f27cb546 Complete live registration acceptance
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-14 17:39:08 +02:00
2f25226c68 Sync integration task completion
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-14 00:43:07 +02:00
custodian-sync
b1853b059d chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-08-14:
  - update .custodian-brief.md for net-kingdom
2026-08-14 00:42:50 +02:00
c56465e32d Enable public registration and prove event delivery
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-14 00:42:14 +02:00
8070dd4b14 Sync user-engine rollout work records
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-13 17:36:52 +02:00
dbbccc1a80 Deploy scoped user-engine delivery lanes
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-13 17:34:29 +02:00
custodian-sync
af8a6889d0 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-08-13:
  - update .custodian-brief.md for net-kingdom
2026-08-13 14:58:09 +02:00
custodian-sync
67ef59c8a4 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-13:
  - NK-WP-0024-T04: wait → progress
2026-08-13 14:58:04 +02:00
custodian-sync
b9f5fbd2f0 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-13:
  - NK-WP-0024-T03: wait → progress
2026-08-13 14:58:04 +02:00
custodian-sync
956bc44f44 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-13:
  - NK-WP-0024-T02: wait → progress
2026-08-13 14:58:04 +02:00
custodian-sync
685c439796 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-13:
  - NK-WP-0024-T01: wait → progress
2026-08-13 14:58:04 +02:00
96266b9371 Resume user-engine integration rollout
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-13 14:56:53 +02:00
20d4d8af04 Allow user-engine egress to email-connect; record T04 hand-back.
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
NetworkPolicy egress to email-connect:8080 for transactional invitation send;
NK-WP-0024 note points at EMAIL-WP-0004 failure evidence.
2026-08-12 13:32:11 +02:00
custodian-sync
ea6cc01872 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-08-12:
  - update .custodian-brief.md for net-kingdom
2026-08-12 13:25:55 +02:00
custodian-sync
586ef5c282 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Updated by fix-consistency on 2026-08-11:
  - update .custodian-brief.md for net-kingdom
2026-08-11 14:47:42 +02:00
1bb7bce99b ADR-0015: NetKingdom Railiance packaging and relational platform
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Settles two questions raised by bringing NetKingdom under Railiance
governance:

1. Separate rapp-* repos per engine (rapp-tenant-engine, rapp-user-engine),
   following repository-axes.md's one-workload rule. The decisive property is
   independent rollback -- a single rapp would need one rollback contract
   across independently versioned services. secrets-engine is not packaged as
   a rapp: it has no deployed workload.

2. CloudNative PG via rapp-postgres is the default relational platform for
   production. Per-workload SQLite-on-a-PVC is dev/test only, and
   rail-kubernetes wave-1 does not support the persistent-storage contract it
   depends on. tenant-engine migrates; its TenantStore Protocol makes this a
   backend swap behind an existing seam.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 14:46:33 +02:00
4511a43f7a Wire user-engine authorization runtime
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-10 19:15:18 +02:00
dfdd3163b7 Deploy registration-aware identity provisioner
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-10 15:49:34 +02:00
0be8a03b99 Honor validated registration usernames
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
2026-08-10 13:23:45 +02:00
83508915db Register app.coulomb.social OIDC redirect for coulomb-social
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Parallel public host while apex stays Bubble; keep apex redirect for later.
2026-08-09 23:20:30 +02:00
0e3a24d888 Deploy KeyCape client MFA override for coulomb-social
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Register coulomb-social with mfaRequired: false, roll key-cape image that
honors client policy, and track NK-WP-0025 public registration orchestration.
2026-08-09 22:42:51 +02:00
custodian-sync
74faee98c4 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-08-09:
  - update .custodian-brief.md for net-kingdom
2026-08-09 22:27:37 +02:00
custodian-sync
ceb7da2d9d chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-08-09:
  - update .custodian-brief.md for net-kingdom
2026-08-09 21:58:30 +02:00
custodian-sync
566fef39d6 chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-08-09:
  - update .custodian-brief.md for net-kingdom
2026-08-09 20:56:17 +02:00
0165ac8d14 Deploy user-engine flex-auth policy service
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-09 02:21:41 +02:00
29ae3e70c6 Activate expanded portal integration gate
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-09 02:00:58 +02:00
27656916db Add KeyCape client registration for coulomb.social
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Idempotent patch of sso/keycape-config with public PKCE client and
redirect URIs for local :8008 and production coulomb.social callbacks.
2026-08-09 01:50:52 +02:00
62b1ea3d59 Deploy tenant authority for user portal
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
2026-08-09 01:39:57 +02:00
custodian-sync
c4de9bab0a chore(consistency): sync task status from DB [auto]
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Updated by fix-consistency on 2026-08-08:
  - update .custodian-brief.md for net-kingdom
2026-08-08 23:22:10 +02:00
03cc0c5a91 Deploy expanded user-engine portal
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
2026-08-08 23:18:29 +02:00
0ec6f8c75d Move identity secret stores to local OpenBao
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-03 21:37:17 +02:00