0d460e3c02
Activate NK-WP-0009/0011; add tutorials slice and proposed ADR-0009
...
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
- docs/tutorials: template, OpenBao and SSH tutorials (unexercised)
- tools/tutorial-verify + make tutorials-verify (NK-WP-0009-T06)
- ADR-0009 proposed: expanded-mode Keycloak trigger and topology
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 295952@bnt-lap001
Assistant-Session: e93f64ad-516c-46eb-9666-aad8d300c477
2026-09-28 23:31:48 +02:00
36303d25a3
Require explicit cadence profile assessment and correct contract pins
...
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
2026-09-28 12:40:07 +02:00
4e07d60ff1
Validate cadence contract and require functional MFA verification
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ea3-7939-7b63-8125-699f8b50bedd
2026-09-05 01:28:05 +02:00
7f4e4e9f57
feat(orchestration): compose KeyCape C1 and C2b
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02929-244b-7391-b933-c04010e8eedb
2026-08-23 13:24:55 +02:00
cfc9e7d0cb
feat(posture): add deterministic feedback proposals
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02929-244b-7391-b933-c04010e8eedb
2026-08-23 13:16:34 +02:00
d96aab2321
feat(orchestration): compose security scenarios
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02929-244b-7391-b933-c04010e8eedb
2026-08-23 12:40:52 +02:00
bee22db620
docs(canon): reconcile workload and tenant grouping semantics
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02929-244b-7391-b933-c04010e8eedb
2026-08-22 14:53:31 +02:00
cced59d3aa
Publish tenancy posture draft-8 contract
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
2026-08-18 12:15:41 +02:00
dbbccc1a80
Deploy scoped user-engine delivery lanes
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-13 17:34:29 +02:00
85a781b7a4
NET-WP-0020 finished: attended-ceremony + auto-unseal-transit profiles, greenfield init/unseal proof
...
T2: greenfield live proof against a fresh uninitialized OpenBao 2.5.5 —
caught and fixed 'bao operator unseal -' not reading stdin (now
'bao write sys/unseal key=-'); init and reseal-replay paths proven.
T3: attended-ceremony selectable — runbook, non-secret ceremony-record
template + validator, and a lab/production deployment profile that blocks
sops-held-automation in console selection, gates, and the init script.
T4: console gate + evidence flags for auto-unseal-transit (Helm seal stanza
prepared in railiance-platform).
Also: SCOPE.md refreshed to current repo state; adhoc fix for the broken
check-secrets Make target (unescaped $).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 22:08:33 +02:00
f625dd0681
feat: OpenBao unseal custody models — automation-first with blocked alternatives
...
Document three init/unseal custody paths; default sops-held-automation for
fast rebuild cycles. Security bootstrap console lists models, blocks planned
attended-ceremony and auto-unseal-transit with hints, and gates init ceremony
on implemented selection. NET-WP-0020 tracks downstream SSH automation.
2026-06-18 00:51:48 +02:00
9a3228489e
fix(NET-WP-0018-T08): add missing import os for the keycape deployed validator
2026-06-04 00:28:05 +02:00
4232e62a50
feat(NET-WP-0018-T08): integrate validations into the UI state model
...
- Extended computed validation pattern into main gates:
- Added keycape_openbao_client_deployed() (invokes verify-openbao-client.sh for live check).
- Updated 'KeyCape OpenBao client deployed' gate in build_gates to 'done' if metadata or validator succeeds (T08: UI now proves via validation not just manual flag).
- Added validate-keycape-client subparser, dispatch (prints source+live status), and make target.
- Updated printed available actions list to include it.
- Updated T08 workplan section: status done + detailed 2026-06-03 implementation note (extended from 0019 note; covers one key target as example, pattern for others like LLDAP/privacyIDEA/Authelia using existing verify-*.sh).
- T07 tests + console-test cover; console status gates now reflect more validator output.
- Pragmatic: progress log with task_id, file notes, commit.
- Brief/fix next (expect 8/9 done).
This fulfills T08: more gates compute from validators (ok/fail) rather than manual only; live setup can satisfy checks via the integrated commands.
2026-06-04 00:25:45 +02:00
e20b322a2e
feat(NET-WP-0018-T07): add automated tests for bootstrap UI sections and runbooks
...
- Created tools/security-bootstrap-console/tests/test_security_bootstrap_console.py (pytest-based, 8 tests covering templates (incl. 0019 dry-run fields), runbook_payloads (T06 entry), audit_core_posture, etc. per layered spec + 0019 note)
- Makefile: added security-bootstrap-console-test (pytest), security-bootstrap-scripts-syntax (bash -n for key sh scripts like dry-run-nonroot-user.sh); integrated into .PHONY and bootstrap lists
- Updated workplan T07 status done + detailed note with pragmatic refs
- Tests pass (python -m pytest)
- Commit + will sync/fix/progress
- Covers console UI, validators, 0019 polish artifacts (orchestrator, cmds, claims, evidence) as required for T07
T07 complete. 6/9 now.
2026-06-03 17:28:21 +02:00
0c66154966
feat(NET-WP-0018-T06): finish control surface alignment to T05 smooth guide
...
- console.py print_status: added explicit 'Follow the NET-WP-0018 Smooth Bootstrap Guide' block after Next safe action, with doc path + lifecycle-guide/make entrypoint. Updated 'Available actions' #9 to note the guide.
- Previously refreshed lifecycle_guide T06 DRY-RUN to 0019 + new guide.
- workplan: T06 status done + detailed 2026-06-03 completion note (supersedes old 0019 'awaits' note); start note already present.
- Pragmatic: progress events (task_id), file notes, this commit.
- UI (status + guide print + 0019 actions/validators/runbooks) now guides the sequence from docs/smooth-bootstrap-guide.md and makes the recommended path clear/hard to go wrong-order.
T06 complete. Brief/fix next (expect 5/9).
2026-06-03 17:11:26 +02:00
f3147186e9
feat(NET-WP-0018-T06): align control surface - refresh console lifecycle_guide T06 DRY-RUN to 0019 orchestrator + new smooth guide
...
- Updated print_lifecycle_guide in console.py: replaced old manual secret-mkdir steps (pre-0019) with preferred make security-bootstrap-onboarding-dry-run + dry-run-nonroot-user.sh + validate + claims + cleanup. References docs/smooth-bootstrap-guide.md Step 7 + NET-WP-0019.
- Workplan T06 start note + in_progress (alignment per T05 guide + T03 recs; leverages existing 0019 validators/console for passive->validator).
- Pragmatic: progress log, file notes, this commit.
- This makes the printed guide align with T05 consolidated guide, deprecates fragile manual path.
T06 alignment complete for guide/control surface. Next T07 tests (use new guide + 0019 as cases) or T04/T08.
2026-06-03 16:59:39 +02:00
92bf7d1d1c
NET-WP-0019: implement T05 (OIDC claims helper + integration in script/console) and T06 (add dry-run to runbook_payloads for web-ui exposure; cross-link update in 0018 T07). Update workplan notes.
2026-06-03 07:10:56 +02:00
23af9b0a84
NET-WP-0019: fix arg parsing in orchestrator for --cleanup-only early, fix delegate path in console cleanup command.
2026-06-03 02:21:22 +02:00
140fff6773
NET-WP-0019: register T06-adjacent polish workplan + implement core (orchestrator script, safer secret fallback in create-user, console dry-run + cleanup commands, make targets, cross-link from 0017 T06). See workplan file for task status.
2026-06-03 02:17:55 +02:00
fe052f3a37
polish: T06-adjacent improvements to lifecycle flow (add onboarding-dry-run-template + concrete T06 dry-run execution section in lifecycle-guide; wiring for parser/dispatch/status/Makefile for consistency with T05)
2026-06-03 02:11:56 +02:00
1f0e8490fd
NET-WP-0017: implement T05 first user lifecycle operator flow (console template+guide, evidence, validate support, docs integration)
2026-06-03 01:55:43 +02:00
5e7844debd
NET-WP-0017: complete T03 Close Trial Taint And Retire Bootstrap Admin Paths + T04 Harden (evidence, console template, metadata flags, inventories, reviews)
2026-06-03 01:50:29 +02:00
0ab7c14ec9
Add signed custody roster workflow
2026-06-02 01:11:42 +02:00
31e6d6660f
Add NET-WP-0017 T02 closure validator
2026-06-02 00:24:18 +02:00
cd82285efe
Require emergency drill evidence validation
2026-06-02 00:08:16 +02:00
6bd822ae71
Require concrete OpenBao restore evidence
2026-06-01 23:57:00 +02:00
dc4fe883a5
Add OpenBao authenticated proof runbook
2026-06-01 22:46:15 +02:00
c48e076429
Close OpenBao OIDC admin bootstrap path
2026-06-01 21:20:53 +02:00
ed991860fa
Fix interactive MFA repair prompt
2026-05-29 03:18:44 +02:00
c7b82df267
Add KeyCape privacyIDEA token repair flow
2026-05-29 03:07:17 +02:00
d797ce5b62
Improve OpenBao OIDC login callback command
2026-05-29 02:31:54 +02:00
dafcd329b2
Fix OpenBao public route action state
2026-05-29 02:22:52 +02:00
cac59a37c1
openbao and itsec tooling integration
2026-05-27 18:56:30 +02:00
1edcfbb17d
Use helper for OpenBao OIDC auth setup
2026-05-26 03:02:08 +02:00
59c924bc18
Patch KeyCape OpenBao client without bootstrap secrets
2026-05-26 02:36:04 +02:00
1267df148a
Harden KeyCape OpenBao client action
2026-05-26 02:22:24 +02:00
f3c8d70270
Split OpenBao admin identity tasks
2026-05-26 02:13:55 +02:00
9dc7e140b8
Refine OpenBao taint resolution
2026-05-26 01:50:57 +02:00
500e616202
Add OpenBao admin identity stage
2026-05-26 01:17:42 +02:00
cfd8231849
Add OpenBao admin token action
2026-05-26 00:23:06 +02:00
d0c7ff9f3b
Clarify OpenBao rotation flow
2026-05-26 00:09:19 +02:00
8520ae8d7d
Fix OpenBao rotation commands
2026-05-25 23:56:55 +02:00
d39dbe14b8
Add bootstrap stage rail
2026-05-25 23:36:45 +02:00
cd043ca471
Refine bootstrap actions and runbook templates
2026-05-25 23:10:02 +02:00
82d69e006f
Add OpenBao restore drill actions
2026-05-25 18:48:23 +02:00
e2540529f0
Add OpenBao emergency lockdown runbook
2026-05-25 18:31:48 +02:00
b9bad47a21
Split OpenBao initial config progress
2026-05-25 15:14:59 +02:00
9afe30f49f
Show compromised OpenBao paths as tainted
2026-05-25 14:57:53 +02:00
907675b4f4
Track OpenBao post-unseal verification
2026-05-25 14:30:57 +02:00
d964cf46a3
Fix OpenBao unseal command card
2026-05-25 13:54:21 +02:00