--- id: NK-WP-0043 type: workplan title: "Make cadence assessment explicit and refresh operating guidance" domain: infotech repo: net-kingdom status: finished flavor: implementation owner: codex topic_slug: netkingdom created: "2026-09-28" updated: "2026-09-28" related: [NK-WP-0035, NK-WP-0039] state_hub_workstream_id: "866807af-b4a9-56d8-ac10-3d05a33aef0c" --- User-authorized follow-through to the September 28 infrastructure review. Existing changes and historical workplan identifiers remain intact. This work changes local verification and guidance, not deployment or source emission. ## Distinguish schema validity from a security-profile assessment ```task id: NK-WP-0043-T01 status: done priority: high state_hub_task_id: "7e450a12-9ccd-51f1-a98b-bc28b069affe" ``` Before this change, an empty supplied inventory produced `conformant: true` while no class-specific obligation is checked. Return an explicit unassessed result and a nonzero default exit; offer an intentional schema-only mode. Record the supplied inventory so a scoped assessment cannot be mistaken for fleet-wide adoption. Never infer classification or rarity from the declaration. Acceptance: CLI and report regressions cover omitted inventory, schema-only success/failure, invalid option combinations and existing profile checks. The real local-identity declaration remains generic-valid and fails its two rare heartbeat obligations with explicit source inventory. Completed: the checker returns `profile_assessed`, exact inventory and assessment scope; `conformant` is null when unassessed. No inventory in default mode exits 2, explicit schema-only success exits 0, and validation failures exit 1. Schema-only rejects profile options and blank class arguments are rejected. Updated the tool README and proposed profile with compatibility and exit-code guidance. Existing profile/classification rules are unchanged. Verification: the new regressions failed against the old implementation (including the demonstrated exit-0 empty-inventory defect). The final focused suite passes 27 tests. Process-level checks against the current owner schema and real local-identity declaration verify default exit 2 / null, schema-only exit 0 / null, and explicit rare inventory exit 1 / two missing-heartbeat findings. Python compilation passes. Ruff was unavailable in this environment; no Ruff result is claimed. ## Separate current operations from historical bootstrap instructions ```task id: NK-WP-0043-T02 status: done priority: medium state_hub_task_id: "5d95bc2d-f940-5989-aacb-0f1865778e7b" ``` Refresh SCOPE and the Kubernetes entry README against the dated September 28 review. Preserve old foundation commands in an explicitly historical document; route current deployment, custody and recovery to the owning repositories. Acceptance: links resolve, read-only examples are non-mutating, current versus historical claims are explicit, and no HA or fresh recovery claim is inferred. Completed: SCOPE now describes the dated September 28 topology and actual owner/evidence gates. The Kubernetes README provides owner links and read-only orientation, with original commands preserved in `FOUNDATIONS-HISTORICAL.md`. All updated Markdown links resolve. New command examples are metadata reads; no deployment, login or recovery operation was performed. ## Use one naming convention for new workplans ```task id: NK-WP-0043-T03 status: done priority: low state_hub_task_id: "d51e878f-fbbb-5684-bccc-edd050ed87a5" ``` Use the registered `NK-WP-` prefix throughout AGENTS.md's new-plan examples and archive convention. Preserve all existing IDs and UUIDs, including NET-WP records. Align creation sync guidance with the existing direct CLI requirement. Acceptance: no conflicting new-plan example remains and historical IDs match before/after. Reconcile the completed workplan to State Hub. Completed: all new-plan examples and archive guidance use NK-WP. Creation instructions now use the existing direct consistency CLI protocol. Compared every pre-existing workplan's IDs against HEAD; no ID changed. Authored files pass `git diff --check`; the generated brief retains its generator's Markdown hard-break whitespace. State Hub reconciliation follows at session close. ## Final review — 2026-09-28 Reviewed the accumulated infrastructure, reference, checker and guidance diff before committing. Corrected the federation plan's unconditional realm-per-tenant implementation/acceptance wording to follow its topology ADR, clarified historical cutover prose and labelled the initial review snapshot separately from later implementation. No checker defect was found. Broader integration validation: `python3 -m pytest tests tools -q` passes 118 tests. All changed Markdown links resolve. Parsed YAML confirms the five retained tenant-engine objects are identical to HEAD and exactly seven flex-auth objects were removed. Every archived bootstrap shell example matches the original README. Existing workplan IDs remain unchanged. The only default whitespace-check finding is the generated brief's intentional Markdown line break; authored files pass. Changes are grouped into infrastructure/reference, cadence assessment, and operating guidance commits.