# Open workplans versus infrastructure — 2026-09-28 Reviewed all ten nonterminal root workplans (eight blocked, two backlog). Initial review result: one finished, one active, six blocked, two backlog. The follow-through section below records subsequent implementation and statuses. Existing task IDs and State Hub UUIDs are preserved. This is a planning reconciliation; no runtime, credential, policy, DNS or destructive change was performed. ## Evidence boundary Read-only `kubectl` checks against context `default` found one Ready node at 92.205.62.239, Kubernetes v1.35.1+k3s1. KeyCape, Authelia, LLDAP, privacyIDEA, user-engine, tenant-engine and audit-core each had one ready Deployment replica. All six flex-auth consumer Deployments were ready and contained `--caller-auth-mode enforce`. This is configuration/readiness proof, not fresh user login, negative authorization or recovery testing. All eight CNPG clusters reported one instance and one ready instance: apps-pg, forgejo-db, net-kingdom-pg, platform-pg, platform-pg-2, state-hub-db, target-revenue-pg and user-engine-pg. A healthy single-node cluster does not prove HA or off-host recovery. No Keycloak Deployment was present. OpenBao StatefulSet and UI gateway were ready; gateway/API Services were ClusterIP and the namespace had no Ingress. CoulombCore, retained backup contents, public DNS withdrawal and browser sessions were not reverified. Owner receipts below support historical completion, not a fresh execution. Sibling repositories were inspected as available local checkouts; their state was not assumed to be a newly fetched remote head. The State Hub inbox supplied flex-auth's September 27 approval of its reference cleanup (`77b26d1e-550b-4926-9610-44fc3a566273`); it was marked read. The human-needed task query returned no NK-/NET-prefixed records. This does not remove the explicit approval gate written in NK-WP-0022. Topic-wide active workplans include other repositories and are not the NetKingdom plan inventory. ## Plan dispositions at the initial review | Plan | Updated state and next acceptance gate | | --- | --- | | [0009 tutorials](../workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md) | Backlog. Start with existing private OpenBao and SSH paths, caller-auth refusal checks and executable verification. STS tutorial needs an actual owner-backed service. | | [0011 federation](../workplans/NK-WP-0011-enterprise-federation-saml.md) | Backlog. Correct issuer to kc.coulomb.social, accepted IAM to v0.3, database admission and managed-package ownership. Require a named enterprise demand before broker implementation. | | [0022 retirement](../workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md) | Blocked. Cutover was completed in July; August 29 retention minimum has elapsed. T08 still needs retained-resource inventory, identity recovery evidence and explicit deletion approval. | | [0027 reef/posture](../workplans/NK-WP-0027-reef-placement-reconciliation.md) | Blocked. Carrier agreement still absent. Include railiance-infra as substrate owner. Public classification exists upstream; maturity mapping versus synthetic provenance remains unresolved. | | [0031 freshness](../workplans/NK-WP-0031-deterministic-posture-feedback.md) | Blocked. Audit Core still lacks structured owner/freshness fields; September V1 recovery evidence does not replace August E2 boundary evidence. | | [0032 Bao callback](../workplans/NK-WP-0032-openbao-operator-loopback-callback.md) | Finished. T03/T04 closed from September 15 callback/login receipts and September 22 platform handoff. Public callback rollback text is historical. | | [0035 cadence](../workplans/NK-WP-0035-emission-cadence-security-profile.md) | Blocked. Update upstream version/pin metadata; migrate source envelopes and obtain real observer evidence. Include local-identity's known profile incompatibility. | | [0039 rename/reference](../workplans/NK-WP-0039-flex-auth-access-engine-coordinate-intake.md) | Active. T04 now has an actionable flex-auth reference-cleanup portion. Tenant-engine agreement and T03 rename notification remain separate gates. | | [0040 execution receipt](../workplans/NK-WP-0040-execution-attribution-receipt.md) | Blocked. Agree emitter/custodian/schema; require an actual run-to-audit receipt proof, preserving unknown attribution and clock bounds. | | [0042 step-up](../workplans/NK-WP-0042-workload-mfa-step-up.md) | Blocked. Reuse delivered P06 enrollment and scoped optional policies; agree and accept one workload's step-up/recovery journey. | The two oldest plans now have one task per second-level section, conforming to the file-backed workplan format. Completed implementation tasks were not reopened merely because their historical validation dates are old. ## Necessary changes and conflicts 1. **Stale deployment copies can remove a live security control.** `sso-mfa/k8s/tenant-engine/runtime.yaml` lacks live caller enforcement and other owner changes. Keep DO-NOT-APPLY. Flex-auth approved pointers to its `values/.yaml`; tenant-engine's portion remains separately owned. Repository rename does not rename the runtime, token audience or OCI package. Source: [FLEX-WP-0020](../../flex-auth/workplans/FLEX-WP-0020-repository-identity-migration.md) (locate by workplan ID if the owner filename changes), inbox receipt above. 2. **Recovery claims must follow the actual failure domain.** Reef declarations still omit provider ceilings; one node and single-instance databases cannot establish independent failover. Proposed V0/V1 carrier semantics require owner agreement and workload evidence. A platform database drill does not satisfy full identity restoration for destructive retirement. Sources: [reef declaration](../../reef-railiance/declarations/reef.yaml), [provider proposal](../docs/reef-posture-provider-contract.md). 3. **Declared evidence remains behind runtime improvements.** Audit Core's tenancy file still describes flex-auth as unauthenticated A0, despite the observed enforcement flags. Its E2 review metadata is unstructured and old. Have the owner reconcile this; do not infer A/E upgrades from flags or tests. Source: [audit tenancy](../../audit-core/tenancy.yaml). 4. **Generic cadence validity is not profile compliance or observation.** Approval Engine and Qonto still fail the owner schema. Local-identity passes that schema but fails the rare-class heartbeat obligation when its source inventory is explicitly supplied. Audit Core holds no local-identity feed. Upstream corrected its candidate bundle digest; profile and declaration metadata need reconciliation without changing historical findings. Sources: [local findings](../local-identity/emission-cadence-findings.md), [upstream review](../../info-tech-canon/feedback/2026-09-21-net-kingdom-emission-cadence-declaration.md). 5. **Existing MFA work and proposed generic step-up are different scopes.** P06 already delivered optional policies for two clients, enrollment checks and privileged guards. IAM v0.4 remains proposed; it is not evidence of arbitrary workload step-up support. Reuse the implementation and close the pilot UX/interop gap. Sources: USER-WP-0033, KEY-WP-0035 and [P06 evidence](../../user-engine/docs/evidence/2026-09-13-p06-authentication-policy.md). 6. **Public Bao is retired.** September 24 removed public role callbacks; current client source rejects their return. Do not repeat completed login admission or preserve public URLs as a future default. DNS withdrawal is a railiance-infra residual. Sources: [callback receipt](../../railiance-platform/docs/evidence/2026-09-15-openbao-loopback-callback-already-present.json), [login/retraction receipt](../../railiance-platform/docs/evidence/2026-09-15-openbao-public-listener-retract.json), [callback pruning](../../railiance-platform/docs/evidence/2026-09-24-platform-admin-callback-prune.json), [platform closure](../../railiance-platform/workplans/RPF-WP-0025-openbao-operator-only-access.md). 7. **Accepted canon and proposals must stay distinct.** IAM v0.3, Playbook Capability v0.1 and security layer v0.7 remain the accepted baselines; proposed amendments do not authorize runtime implementation or replace owner agreement. New federation work must follow ADR-0015 packaging and current tenant identity contracts, not the original greenfield assumptions. ## Most valuable future implementation Recommended order; this is prioritization, not approval of deployment or deletion. 1. **Remove stale reference authority (0039).** Small, locally actionable work that prevents a caller-auth regression. Replace the approved flex-auth objects with exact owner pointers; finish tenant-engine's portion after its answer. No rollout is needed. 2. **Close one real workload MFA journey (0042).** High user value with existing provider work available. Pick a pilot with its owner, demonstrate enrollment, return to action, recovery and denial with stale/insufficient assurance. Coordinate existing actual-user gates rather than create another onboarding implementation. 3. **Make evidence freshness and emission operational (0031 + 0035).** Add authoritative metadata first, then migrate a source already sending to Audit Core and prove heartbeat/reconciliation through its observer. This makes missing or stale security evidence detectable. Resolve local-identity activity-scope incompatibility explicitly; do not force a bootstrap tool into a permanent service just to pass the profile. 4. **Bind a real execution to evidence (0040).** Agree the receipt and implement one Railiance emitter/receiver integration with actor, artifact, decision, approval and bounded time. This unblocks clock attribution and gives more value than a schema-only finish. 5. **Mechanize recovery ceilings and finish retirement safely (0027 + 0022).** Agree reef provider declarations, implement the three-valued join, and use measured recovery evidence. Prepare the exact old identity deletion package only after its recovery gate passes; approval remains a separate final step. Tutorials should capture these proven paths incrementally. Enterprise federation is lower priority until a concrete tenant/IdP demand justifies its additional issuer, trust mapping, database and recovery burden. ## Validation - Current read-only node, Deployment, CNPG and OpenBao resource inventories. - Existing cadence checker against the current owner schema: Approval Engine fails with three generic findings; Qonto fails with five. Local-identity is generic-valid; supplying both documented load-bearing/rare classes yields two `rare-heartbeat-missing` failures. Omitting inventory flags checks no rare-class obligations and must not be used to claim adoption. - Existing posture evaluator at explicit `2026-09-28T12:00:00Z` confirms unknown owner/freshness and overdue review for audit-core. This is a chosen reproducible evaluation instant, not the observation timestamp. - Workplan frontmatter, task-ID preservation, task statuses and local Markdown links checked; authored files pass `git diff --check`. The generated brief retains its generator's Markdown hard-break whitespace. No application code changed. State Hub lifecycle reconciliation classifies partially completed 0039 with an actionable task as `active`; its file follows that convention. Existing NK-WP/NET-WP prefix warnings are retained rather than renumbering historical work records. At the initial review, repository instructions contained conflicting prefix conventions. NK-WP-0043 subsequently standardized new plans on NK-WP while preserving historical IDs. ## Follow-through — 2026-09-28 After the user requested implementation, the approved part of NK-WP-0039-T04 was completed: seven obsolete flex-auth objects were removed from the combined reference manifest and replaced with owner links in [sso-mfa/k8s/tenant-engine/README.md](../sso-mfa/k8s/tenant-engine/README.md). Parsed before/after YAML confirms all five tenant-engine objects are unchanged. No repository apply path consumes the combined manifest; the user-engine verifier uses its own file. Owner values enforce caller authentication and bind each consumer to its own ServiceAccount. The remaining YAML stays DO-NOT-APPLY. T04 now waits only for tenant-engine's disposition; T03 still waits for the rename. This returns 0039 to blocked: the current disposition of the original ten is one finished, seven blocked and two backlog. The locally owned portion of NK-WP-0035-T04 also advanced: corrected the profile's imported document maturity/version/revision and the local-identity candidate bundle pin. The old pin and its correction remain in historical findings. Schema SHA-256 is unchanged. All 15 focused checker tests pass; explicit rare-class revalidation remains generic-valid with exactly two missing-heartbeat failures. The profile stays proposed and source/observer adoption remains open. No runtime or external-owner source was changed.