An earlier revision of this section asserted the adversarial facility was
deliberately not NetKingdom's, on independence grounds. Overruled, and the
counter-argument is better: offensive security is security work.
The facility is also framed more broadly than this document assumed - it is
pointed at infrastructure we choose, our own estate among them, and testing
conformance to this framework is one use of a general capability rather than
its purpose.
The tension I raised is left in the text rather than deleted, because it is
real: NetKingdom now owns both this framework and the facility that tests
conformance to it. The mitigation is that findings leave for risk-nexus under
separate ownership instead of being closed in place, and the trigger to
revisit is conformance findings starting to close quietly.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Question 12 asked whether to add a quality-of-service dimension. No - because
we could not enforce it. Community PostgreSQL has no resource governor, so a
declared priority would be an unenforced claim in a declaration, which is what
retiring tenantIsolation was about. An axis implies graduation and enforcement
and this has neither.
Co-residents are equal, and a consumer whose latency cannot survive an
unprioritised neighbour escalates to P2. Service class is still declared, as a
category not a level: it informs placement, acts as a trigger, and gives
"acceptable degradation" in the noisy-neighbour artifact something to be
acceptable relative to - what batch tolerates is an outage for latency-critical.
Class mixture must be visible, because an unenforceable risk nobody can see is
worse than one that is stated. rapp-postgres now reports it and the live
instance already flags latency-critical beside batch.
Gateway-level prioritisation in a connection proxy is recorded as the known
escalation short of P2 - real, and infrastructure we do not run.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
whitehat-security takes the adversarial evidence artifacts - the framework's
highest-severity gap, unowned since it was drafted. audit-core and tenant-engine
were right to decline it as fleet-scope work; the answer was a home of its own
rather than a volunteer.
Recorded here with the part that bears on this document: the facility is
deliberately not owned by NetKingdom, which owns this framework. Verifying
conformance to a standard while reporting to the standard's owner is
self-grading one level up.
Two consequences land back on the framework. Cadence becomes a security
parameter rather than a schedule, since for a detection-based control the
interval between runs is the exposure window. And a passing suite is proof that
the attacks attempted did not work, not proof of isolation - recording a green
run as "E2 verified" would be exactly the overclaim section 6 prohibits.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Settles two questions raised by bringing NetKingdom under Railiance
governance:
1. Separate rapp-* repos per engine (rapp-tenant-engine, rapp-user-engine),
following repository-axes.md's one-workload rule. The decisive property is
independent rollback -- a single rapp would need one rollback contract
across independently versioned services. secrets-engine is not packaged as
a rapp: it has no deployed workload.
2. CloudNative PG via rapp-postgres is the default relational platform for
production. Per-workload SQLite-on-a-PVC is dev/test only, and
rail-kubernetes wave-1 does not support the persistent-storage contract it
depends on. tenant-engine migrates; its TenantStore Protocol makes this a
backend swap behind an existing seam.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Register coulomb-social with mfaRequired: false, roll key-cape image that
honors client policy, and track NK-WP-0025 public registration orchestration.