# NetKingdom Security Pattern Tutorials Hands-on paths for operating the canonical NetKingdom security patterns (NK-WP-0009). Each tutorial is a file in this directory, written from [`TEMPLATE.md`](TEMPLATE.md) and checked by `make tutorials-verify`. > **Moving.** Tutorials are becoming runbook packs in `runbooks/` for the > `runbook-tutorials` engine (NK-WP-0044). Packs: `runbooks/ssh-certificates/`, `runbooks/openbao-operating-path/`, > `runbooks/protected-system-flex-auth/`. > These markdown files stay until their packs are exercised. ## Rules 1. **Exercise status is mandatory.** Per [`docs/attended-procedure-standard.md`](../attended-procedure-standard.md), a tutorial header says `exercised by ` or `unexercised`. Nothing is labelled exercised until someone has run it. 2. **Every concrete step names its owning repo.** This repo owns canon and reference tooling only (see `SCOPE.md`); deployment belongs to owners. 3. **Verification and rollback are required**, not optional happy-path extras. 4. **No secrets, ever.** Tutorials show paths and commands, never values. 5. **Consume, don't copy.** Link owner runbooks; do not paste runtime manifests. Use the named `openbao-ui-railiance01` tunnel, never a public Bao URL (`bao.coulomb.social` is retired). ## Index | Tutorial | Workplan task | Owners | Status | | --- | --- | --- | --- | | [OpenBao: consume, attend, recover](openbao-operating-path.md) | T03 | railiance-platform, net-kingdom | unexercised | | [Short-lived SSH credentials](ssh-certificates-and-tunnels.md) | T04 | ops-warden, ops-bridge | unexercised | | [Add a protected system to flex-auth](protected-system-flex-auth.md) | T05 | flex-auth, package owner | unexercised (offline part run) | Deferred (see NK-WP-0009): T02 object-storage STS (needs an owner-backed issuer and refusal/lease proof — ADR-0008 is architecture, not evidence). ## Pattern mapping NK-WP-0008 (the pattern library) has no file in this repo, so tutorials map to the canonical documents directly: `docs/platform-identity-security-architecture.md`, `docs/responsibility-map.md`, `docs/platform-root-custody.md`.