net-kingdom/workplans/NK-WP-0044-runbook-packs-for-runbook-tutorials.md
tegwick 1b549c8aec
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Sync consistency output
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 295952@bnt-lap001
Assistant-Session: e93f64ad-516c-46eb-9666-aad8d300c477
2026-09-29 00:26:35 +02:00

100 lines
2.9 KiB
Markdown

---
id: NK-WP-0044
type: workplan
title: "Provide NetKingdom runbook packs for the runbook-tutorials engine"
domain: infotech
repo: net-kingdom
status: active
flavor: implementation
owner: claude
topic_slug: netkingdom
created: "2026-09-29"
updated: "2026-09-29"
related: [NK-WP-0009]
state_hub_workstream_id: "82414324-e9cf-5581-af9e-b0122411d7bf"
---
The guided console invented here (NET-WP-0016) now has a home: the
`runbook-tutorials` repository (workplans `RBT-WP-0002` to `RBT-WP-0006`). This
workplan is net-kingdom's side: keep the existing console working, and offer
NetKingdom runbooks as packs in `runbooks/`, following `runbook-pack/v0.1`.
## Wrap the existing console as a legacy pack
```task
id: NK-WP-0044-T01
status: done
priority: high
state_hub_task_id: "44a2d9a7-c0bc-5099-89fb-f6a3fa0c2e50"
```
`runbooks/security-bootstrap-console/pack.yaml`, engine `legacy-command`. Verified
end to end: `rtut launch` starts `make security-bootstrap-ui`, port 8876
answers, and the process stops on exit. The console itself is unchanged.
## Convert the SSH certificate tutorial to a native pack
```task
id: NK-WP-0044-T02
status: done
priority: high
state_hub_task_id: "ea4b5cb2-cb7d-5349-9057-bf2657690c79"
```
`runbooks/ssh-certificates/pack.yaml` (parameters actor, pubkey, tunnel; owner-tagged
steps; verify and rollback). It validates; it is `unexercised`.
## Convert the OpenBao and flex-auth tutorials
```task
id: NK-WP-0044-T03
status: todo
priority: high
state_hub_task_id: "ba1a41a7-b40d-5312-851e-93c613ac9b27"
```
`docs/tutorials/openbao-operating-path.md` and `protected-system-flex-auth.md` become
native packs. The flex-auth pack's live part uses the informed-decision pin and the
four negative tests as parameterized steps. Keep the markdown until the packs are
exercised.
## Validate packs in this repository
```task
id: NK-WP-0044-T04
status: done
priority: medium
state_hub_task_id: "1423d9d7-ce11-5fd3-9905-3566f947b0a9"
```
`make runbooks-validate` runs the `rtut` validator from the runbook-tutorials
checkout (`RTUT_HOME`, default `~/runbook-tutorials`).
## Exercise the packs through the UI
```task
id: NK-WP-0044-T05
status: wait
priority: high
state_hub_task_id: "2d99180e-25ff-51db-8208-b0320c8ec7e3"
```
Blocked on `RBT-WP-0004` (UI). Bernd runs the SSH, OpenBao and flex-auth packs in the
UI; the engine records outcomes, and NK-WP-0009 T03-T05 close on those receipts.
## Retire the markdown verifier
```task
id: NK-WP-0044-T06
status: wait
priority: low
state_hub_task_id: "1b747058-d4df-5f5c-bd63-e85d46dd094e"
```
Once the tutorials are packs, `tools/tutorial-verify` and `make tutorials-verify` are
replaced by `runbooks-validate`, and `docs/tutorials/` becomes a pointer.
## Acceptance Criteria
- The console still works and is launched by the engine without changes to it.
- Every NetKingdom pack validates; each is honestly labelled exercised or unexercised.