--- id: NK-WP-0044 type: workplan title: "Provide NetKingdom runbook packs for the runbook-tutorials engine" domain: infotech repo: net-kingdom status: active flavor: implementation owner: claude topic_slug: netkingdom created: "2026-09-29" updated: "2026-09-29" related: [NK-WP-0009] --- The guided console invented here (NET-WP-0016) now has a home: the `runbook-tutorials` repository (workplans `RBT-WP-0002` to `RBT-WP-0006`). This workplan is net-kingdom's side: keep the existing console working, and offer NetKingdom runbooks as packs in `runbooks/`, following `runbook-pack/v0.1`. ## Wrap the existing console as a legacy pack ```task id: NK-WP-0044-T01 status: done priority: high ``` `runbooks/security-bootstrap-console/pack.yaml`, engine `legacy-command`. Verified end to end: `rtut launch` starts `make security-bootstrap-ui`, port 8876 answers, and the process stops on exit. The console itself is unchanged. ## Convert the SSH certificate tutorial to a native pack ```task id: NK-WP-0044-T02 status: done priority: high ``` `runbooks/ssh-certificates/pack.yaml` (parameters actor, pubkey, tunnel; owner-tagged steps; verify and rollback). It validates; it is `unexercised`. ## Convert the OpenBao and flex-auth tutorials ```task id: NK-WP-0044-T03 status: todo priority: high ``` `docs/tutorials/openbao-operating-path.md` and `protected-system-flex-auth.md` become native packs. The flex-auth pack's live part uses the informed-decision pin and the four negative tests as parameterized steps. Keep the markdown until the packs are exercised. ## Validate packs in this repository ```task id: NK-WP-0044-T04 status: done priority: medium ``` `make runbooks-validate` runs the `rtut` validator from the runbook-tutorials checkout (`RTUT_HOME`, default `~/runbook-tutorials`). ## Exercise the packs through the UI ```task id: NK-WP-0044-T05 status: wait priority: high ``` Blocked on `RBT-WP-0004` (UI). Bernd runs the SSH, OpenBao and flex-auth packs in the UI; the engine records outcomes, and NK-WP-0009 T03-T05 close on those receipts. ## Retire the markdown verifier ```task id: NK-WP-0044-T06 status: wait priority: low ``` Once the tutorials are packs, `tools/tutorial-verify` and `make tutorials-verify` are replaced by `runbooks-validate`, and `docs/tutorials/` becomes a pointer. ## Acceptance Criteria - The console still works and is launched by the engine without changes to it. - Every NetKingdom pack validates; each is honestly labelled exercised or unexercised.