Open security core for dev sec ops on kubernetes
Find a file
tegwick 116643fafe
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Declare local-identity audit emission cadence for InfoTechCanon adoption
Source-owned declaration pinned to contract digest 972c0b6701d1693f
(INFO-WP-0029-T02). Valid against the generic contract; fails the
NetKingdom profile's rare-heartbeat MUST because local-identity emits no
heartbeat. Findings record the session-scoped-silence incompatibility.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 236552@bnt-lap001
Assistant-Session: 8916a2bd-1a44-4ff9-83c1-96b34058e603
2026-09-21 14:00:17 +02:00
.claude docs: workplan-first agent guidance prose (CUST-WP-0055 T04 batch 2) 2026-07-08 16:41:16 +02:00
.forgejo/workflows Surface redacted directory bind failures before native onboarding 2026-09-14 04:46:29 +02:00
.githooks feat(creds): implement NK-WP-0004 Credential Management Foundation 2026-03-20 23:39:35 +00:00
.repo-manager Security Layer Model v0.5 — four reviews, nine changes 2026-08-29 02:54:25 +02:00
canon Register the tenant-provenance gap in 13 (GH-DEC-2026-013) 2026-09-09 23:20:22 +02:00
capabilities/playbooks feat(orchestration): compose security scenarios 2026-08-23 12:40:52 +02:00
docs Pin identity-provisioner digest and readiness to directory preflight 2026-09-14 04:57:39 +02:00
examples feat(orchestration): compose KeyCape C1 and C2b 2026-08-23 13:24:55 +02:00
history Declare net-kingdom's own layer and record positions on the v0.8 hold and §11 amendments. 2026-09-21 12:36:10 +02:00
identity-provisioner Surface redacted directory bind failures before native onboarding 2026-09-14 04:46:29 +02:00
intakes Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
keys feat(creds): implement NK-WP-0004 Credential Management Foundation 2026-03-20 23:39:35 +00:00
local-identity Declare local-identity audit emission cadence for InfoTechCanon adoption 2026-09-21 14:00:17 +02:00
registry feat(posture): add deterministic feedback proposals 2026-08-23 13:16:34 +02:00
sso-mfa Pin identity-provisioner digest and readiness to directory preflight 2026-09-14 04:57:39 +02:00
tests Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
tools Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
wiki Add CLAUDE.md, wiki protoplans, and NK-WP-0001 workplan 2026-02-28 17:21:51 +01:00
workplans Classify open workplans with flavor (CUST-WP-0072). 2026-09-14 15:50:43 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-09-21 12:39:01 +02:00
.gitignore chore: ignore patch backups 2026-08-28 11:54:39 +02:00
.repo-classification.yaml Human-review .repo-classification.yaml (CUST-WP-0050 follow-up) 2026-06-22 17:56:17 +02:00
.sops.yaml feat(creds): implement NK-WP-0004 Credential Management Foundation 2026-03-20 23:39:35 +00:00
AGENTS.md docs(agents): repoint remote State Hub URL to the in-cluster address 2026-08-25 00:21:25 +02:00
CLAUDE.md Add credential routing instructions for all agent runtimes 2026-06-18 22:48:38 +02:00
CONFIG.md feat(sso-mfa): T05 SSO stack pivot — Keycloak → Authelia + LLDAP + KeyCape (NK-WP-0001-T05) 2026-03-19 08:31:51 +00:00
DECISIONS.md Decision for KeyCape Implementation Language Go 2026-03-26 09:21:17 +01:00
INTENT.md Declare net-kingdom's own layer and record positions on the v0.8 hold and §11 amendments. 2026-09-21 12:36:10 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-29 23:43:45 +02:00
Makefile Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
README.md Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
SCOPE.md feat(orchestration): compose KeyCape C1 and C2b 2026-08-23 13:24:55 +02:00
SECURITY-COMPANION.md Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
WORK-RECORDS.md Pin identity-provisioner digest and readiness to directory preflight 2026-09-14 04:57:39 +02:00

NetKingdom

NetKingdom is the canonical security architecture, integration boundary, and bootstrap/reference implementation for NetKingdom environments. It defines identity, tenancy, credential, workload-zone, and security-composition contracts while leaving provider and Railiance execution in their owning repositories.

The dynamic, self-optimizing security platform is the long-term direction in INTENT.md, not a claim about current delivery.

Orientation

  • SCOPE.md — what this repo owns, current state, and when it is relevant
  • SECURITY-COMPANION.md — start here. The working form of the security layer model: what to declare, what binds you, what you may never claim about evidence, and the two things the estate cannot do yet
  • Security layer model — the statute the companion serves (accepted 2026-08-29): how the security estate is layered (Taxonomy / Tooling / Engines / Staff) and what each layer may own
  • Security scenario composition — deterministic, plan-only capability and trust composition
  • Posture feedback — deterministic, proposal-only posture and evidence remediation findings
  • Emission cadence security profile — NetKingdom obligations over the InfoTechCanon declaration contract; proposed pending owner-instance migration

Security Infrastructure Documents

  • secrets-engine security infrastructure boundary defines how secrets-engine participates in the NetKingdom security infrastructure and how it interacts with OpenBao, flex-auth, user-engine, ops-warden, ops-bridge, info-tech-canon, State Hub, and agents.