Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02929-244b-7391-b933-c04010e8eedb
1.4 KiB
KeyCape C1 and C2b composition evidence
Date: 2026-08-23 Workplan: NK-WP-0030 Mode: plan-only
KeyCape published provider-owned Playbook Capability Contract v0.1
declarations for key-cape.lightweight-sso and
key-cape.privacyidea-token-authority. The implementation content originates
at KeyCape revision efce3e9; its file-first workplan and State Hub identifiers
were reconciled by revision 34fadae. NetKingdom received the handoff in State
Hub message 1d5f5f15-d137-4c11-8386-c8cc58c17bb8.
Both owner declarations passed NetKingdom's canonical playbook capability
validator. The reference request in
examples/security-scenarios/c1-c2b-key-cape.yaml then composed successfully
with:
- initial trust:
cluster_trust,runtime_secret_trust; - step 1:
key-cape.lightweight-ssoprovides C1 and establishesruntime_identity_trust; - step 2:
key-cape.privacyidea-token-authorityprovides C2b after consuming that identity trust; - final trust:
cluster_trust,runtime_secret_trust, andruntime_identity_trust; and - composition digest:
sha256:cd7aeba3c83c83e2de7bc9a64d2dd9922f4f39a4de81c41760f9f9a431a820a6.
The plan retains KeyCape, railiance-platform, and privacyIDEA ownership exactly
as declared. It sets execution.mode: plan-only and
execution.permitted: false; no provider entry point was invoked. C2a built-in
factors are not part of the scenario, and neither NetKingdom nor KeyCape claims
them through this composition.