diff --git a/.custodian-brief.md b/.custodian-brief.md index a6bf703..635e5af 100644 --- a/.custodian-brief.md +++ b/.custodian-brief.md @@ -2,7 +2,7 @@ # Custodian Brief — net-kingdom **Domain:** communication -**Last synced:** 2026-07-22 08:44 UTC +**Last synced:** 2026-07-08 10:33 UTC **State Hub:** http://127.0.0.1:8000 *(adjust if running on a remote machine)* ## Active Workstreams @@ -11,9 +11,8 @@ ## Inbox Hygiene -**Stale unread:** 3 message(s) older than 3 day(s) — triage at session start. -**Missing thread_id:** 3 unread message(s) lack supersession chains. -- ! the-custodian: DR-3 resolved: NK-WP-0011 stays proposed, gains three demand triggers `0d238b6e` +**Stale unread:** 2 message(s) older than 3 day(s) — triage at session start. +**Missing thread_id:** 2 unread message(s) lack supersession chains. --- ## MCP Orientation (when available) diff --git a/WORK-RECORDS.md b/WORK-RECORDS.md deleted file mode 100644 index 1c83cd9..0000000 --- a/WORK-RECORDS.md +++ /dev/null @@ -1,37 +0,0 @@ -# Work Records — net-kingdom - -> Generated by `statehub fix-consistency` (CUST-WP-0061-T04, work-record -> stage 3). Do not edit by hand — edit the source file/block listed for -> each record and re-run fix-consistency to refresh this index. Archived -> workplans are omitted; closed decisions/intakes/engagements stay listed -> so recently-resolved work is still visible. [auto] - -| Kind | ID | Status | Lane | Source | -| --- | --- | --- | --- | --- | -| workplan | adhoc-2026-07-02 | finished | — | workplans/ADHOC-2026-07-02.md | -| workplan | NET-WP-0020 | finished | — | workplans/NET-WP-0020-openbao-unseal-custody-and-ssh-automation.md | -| workplan | NK-WP-0009 | backlog | — | workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md | -| workplan | NK-WP-0011 | backlog | — | workplans/NK-WP-0011-enterprise-federation-saml.md | -| task | ADHOC-2026-07-02-T01 | done | — | workplans/ADHOC-2026-07-02.md | -| task | ADHOC-2026-07-02-T02 | done | — | workplans/ADHOC-2026-07-02.md | -| task | NET-WP-0020-T01 | done | — | workplans/NET-WP-0020-openbao-unseal-custody-and-ssh-automation.md | -| task | NET-WP-0020-T02 | done | — | workplans/NET-WP-0020-openbao-unseal-custody-and-ssh-automation.md | -| task | NET-WP-0020-T03 | done | — | workplans/NET-WP-0020-openbao-unseal-custody-and-ssh-automation.md | -| task | NET-WP-0020-T04 | done | — | workplans/NET-WP-0020-openbao-unseal-custody-and-ssh-automation.md | -| task | NET-WP-0020-T05 | done | — | workplans/NET-WP-0020-openbao-unseal-custody-and-ssh-automation.md | -| task | NK-WP-0009-T1 | todo | — | workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md | -| task | NK-WP-0009-T2 | todo | — | workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md | -| task | NK-WP-0009-T3 | todo | — | workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md | -| task | NK-WP-0009-T4 | todo | — | workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md | -| task | NK-WP-0009-T5 | todo | — | workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md | -| task | NK-WP-0009-T6 | todo | — | workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md | -| task | NK-WP-0011-T1 | todo | — | workplans/NK-WP-0011-enterprise-federation-saml.md | -| task | NK-WP-0011-T2 | todo | — | workplans/NK-WP-0011-enterprise-federation-saml.md | -| task | NK-WP-0011-T3 | todo | — | workplans/NK-WP-0011-enterprise-federation-saml.md | -| task | NK-WP-0011-T4 | todo | — | workplans/NK-WP-0011-enterprise-federation-saml.md | -| task | NK-WP-0011-T5 | todo | — | workplans/NK-WP-0011-enterprise-federation-saml.md | -| task | NK-WP-0011-T6 | todo | — | workplans/NK-WP-0011-enterprise-federation-saml.md | -| task | NK-WP-0011-T7 | todo | — | workplans/NK-WP-0011-enterprise-federation-saml.md | -| task | NK-WP-0011-T8 | todo | — | workplans/NK-WP-0011-enterprise-federation-saml.md | -| intake | NK-IN-0001 | open | blue | docs/intakes/activity-core-ops-sso-operators.md | -| intake | NK-IN-0002 | open | blue | docs/intakes/activity-core-ops-sso-operators.md | diff --git a/docs/intakes/activity-core-ops-sso-operators.md b/docs/intakes/activity-core-ops-sso-operators.md deleted file mode 100644 index 84d31b5..0000000 --- a/docs/intakes/activity-core-ops-sso-operators.md +++ /dev/null @@ -1,108 +0,0 @@ -# Intakes — activity-core ops / Temporal UI SSO operators - -Cross-repo handoff from **activity-core** `ACTIVITY-WP-0025` residual **T06**. -SSO edge is already live (Traefik ForwardAuth → Authelia); access is currently -any authenticated Authelia user (`default_policy: one_factor`). These intakes -request least-privilege group gating on the public hosts. - -Source design: `activity-core/docs/ops-sso-access.md` -Hosts: `activity.coulomb.social`, `temporal.coulomb.social` - -Promote with (after route + owner review): - -```bash -statehub promote-intake \ - --to workplan \ - --repo-path ~/net-kingdom \ - --repo-slug net-kingdom \ - --domain communication -# or --to task --workplan-file workplans/.md -``` - ---- - -## NK-IN-0001 — LLDAP group for activity-core operators - -```yaml -id: NK-IN-0001 -kind: intake -title: "Create LLDAP group activity-core-operators and membership runbook" -lane: blue -status: routed -priority: high -owner: net-kingdom -repo: net-kingdom -origin: "ACTIVITY-WP-0025-T06" -origin_ref: "activity-core/workplans/ACTIVITY-WP-0025-ops-ui-sso-access.md" -routed_note: "Implement in net-kingdom sso-mfa. Origin ACTIVITY-WP-0025-T06 (activity-core)." -description: | - activity-core shipped Authelia SSO for the ops console and Temporal UI - (ACTIVITY-WP-0025). MVP accepts any authenticated Authelia user. - - Needed in net-kingdom (LLDAP + ops docs), not in activity-core: - - 1. Create LLDAP group `activity-core-operators` (same style as - net-kingdom-users / net-kingdom-admins in sso-mfa/k8s/lldap/bootstrap-users.sh). - 2. Document how to add/remove human operators (WebUI checklist and/or - script extension). Named founders/operators only — least privilege. - 3. Do not invent OIDC clients in KeyCape for this path: activity-core uses - Traefik Middleware → Authelia `/api/verify` (ForwardAuth), not a new - oauth2-proxy/Keycloak client. - - Acceptance: group exists in LLDAP; membership procedure written under - sso-mfa docs or CONFIG; at least one test operator can be assigned. -notes: | - Related Authelia domain rules are NK-IN-0002 (depends on this group existing). - Requester residual task: ACTIVITY-WP-0025-T06 (status wait). -state_hub_intake_id: "019f88ff-c5f1-7433-9d13-4ffe37dfef00" -``` - ---- - -## NK-IN-0002 — Authelia domain rules for activity / temporal hosts - -```yaml -id: NK-IN-0002 -kind: intake -title: "Authelia access_control for activity + temporal.coulomb.social" -lane: blue -status: routed -priority: high -owner: net-kingdom -repo: net-kingdom -origin: "ACTIVITY-WP-0025-T06" -origin_ref: "activity-core/workplans/ACTIVITY-WP-0025-ops-ui-sso-access.md" -routed_note: "Depends on NK-IN-0001 group. Implement in Authelia ConfigMap. Origin ACTIVITY-WP-0025-T06." -description: | - Restrict browser access to activity-core public SSO hosts to members of - LLDAP group `activity-core-operators` (see NK-IN-0001). - - Implementation target (live config): - - File: sso-mfa/k8s/authelia/configmap.yaml - - Today: access_control.default_policy: one_factor (no domain rules) - - Add domain rules for: - - activity.coulomb.social - - temporal.coulomb.social - requiring subject/group activity-core-operators (exact Authelia - subject syntax per current Authelia version — use fleet patterns if any - domain rules already exist for other apps). - - Keep MFA posture consistent with fleet (KeyCape / privacyIDEA path; do - not set two_factor on Authelia itself unless that is the established - pattern for similar apps). - - Rollout: apply Authelia ConfigMap + restart/reload Authelia in ns sso; - verify unauthenticated → login; authenticated non-member → deny/403; - member → pass-through to Traefik backends. - - Acceptance: - - Unprivileged Authelia user cannot open ops UI or Temporal UI - - Member of activity-core-operators can open both hosts after login - - activity-core break-glass (ClusterIP port-forward + operator token) - remains documented and independent of Authelia groups -notes: | - Depends on NK-IN-0001 (group must exist). activity-core Ingress + middleware - already applied (k8s/railiance/30–32). No activity-core code change required - for group enforcement — headers already carry Remote-Groups. -state_hub_intake_id: "019f88ff-cc9e-76b4-8ce3-eb354aabefe7" -```