net-kingdom/.custodian-brief.md
custodian-sync 1dec1d6410
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-28:
  - update .custodian-brief.md for net-kingdom

Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 237582@bnt-lap001
Assistant-Session: f2b3d9f1-8fb9-4b9c-bc2b-837ec5dfc826
2026-09-28 23:47:48 +02:00

89 lines
3.9 KiB
Markdown

<!-- custodian-brief: generated by fix-consistency — do not edit manually -->
# Custodian Brief — net-kingdom
**Domain:** infotech
**Last synced:** 2026-09-28 21:47 UTC
**State Hub:** http://127.0.0.1:8000 *(adjust if running on a remote machine)*
## Active Workstreams
### NetKingdom Security Pattern Tutorials
Progress: 2/6 done | workplan_id: `d4d02dbf-3974-502d-8b87-b776fc63e17e`
**Open tasks:**
- ► Document the existing OpenBao operating path `16cf51a4`
- ► Document SSH certificates and tunnels `1d28e3f1`
- ► Integrate a protected flex-auth consumer `c380ef19`
- · Demonstrate temporary object credentials `d13760fd`
### Enterprise Federation & SAML — Expanded-Mode Keycloak Identity Broker
Progress: 1/9 done | workplan_id: `1075448f-d533-5f9e-94b7-c3adfe151a07`
**Open tasks:**
- · Admit the database consumer `2fe6f100`
- · Package the broker deployment `32d1411b`
- · Integrate an upstream identity provider `6697a994`
- · Define federated assurance `d845380d`
- · Verify IAM conformance and coexistence `9cb7fd93`
- · Enforce tenant and platform boundaries `38998c68`
- · Prove recovery and audit delivery `e5f44ddc`
- … and 1 more open tasks
### Implement deterministic posture and evidence feedback
Progress: 4/5 done | workplan_id: `9d7b04f9-3803-5613-b7a5-8bd606c77f5a`
**Open tasks:**
- ! Obtain audit-core freshness adoption `7d2029d2`
*(wait: audit-core must add authoritative owner and E2 freshness metadata for WH-ENG-20260822-AUDIT-E2-03; NetKingdom must not parse it from prose.)*
### Publish the NetKingdom emission-cadence security profile
Progress: 4/5 done | workplan_id: `04685f94-1991-5e62-80d2-5669913e99fc`
**Open tasks:**
- ! Bind and hand off the published contract `e3fbc8b8`
*(wait: Needs info-tech-canon's versioned contract and schema; cannot be completed by copying the draft.)*
### Reconcile reef placement and security-zone canon dependencies
Progress: 3/6 done | workplan_id: `965ad365-6b81-50a1-a2a3-2d0c1fcce0b4`
**Open tasks:**
- ! T02 — Extend provider declarations to reefs `5b35b646`
- ! T03 — Reconcile reef ceilings mechanically `e3f0bb0f`
- ! T06 — Resolve the `DataClassification` mismatch `bf8b3e1d`
### Let workloads require MFA for all or part of their features
Progress: 1/2 done | workplan_id: `3f702215-704b-5788-8ca0-b8b9ba2dd3f8`
**Open tasks:**
- ! Agree the user-facing step-up and enrollment journey `4e51585d`
*(wait: Agree the MFA-required user experience with user-engine and one pilot workload; must be accepted from a user's perspective.)*
### Cut over NetKingdom identity to railiance01 and retire CoulombCore
Progress: 7/8 done | workplan_id: `d76ddccc-00c8-548a-b141-2cd660fa38da`
**Open tasks:**
- ! T08 - Final deletion and closure `42a3b4c0`
### Take in the flex-auth to access-engine repository-coordinate rename
Progress: 2/4 done | workplan_id: `284a8ac2-61dc-5bee-b74a-0a62d9808edb`
**Open tasks:**
- ! Update repository-coordinate references once access-engine resolves `6e62919d`
*(wait: Await the flex-auth announcement that coulomb/access-engine resolves (FLEX-WP-0020), then verify repository-coordinate references.)*
- ! Retire or reconcile the stale flex-auth/tenant-engine reference manifest `2541f523`
*(wait: Retire-vs-reconcile answer routed to flex-auth (2c637dc9) and tenant-engine (9fc740da); act on whichever returns, do not pre-empt.)*
### Define an execution-attribution receipt for Railiance runs
Progress: 1/2 done | workplan_id: `e2533f3a-aa43-59b3-bff3-8e64b6149487`
**Open tasks:**
- ! Agree the evidence holder and schema with audit-core and Railiance `963120c1`
*(wait: Agree with audit-core who emits, who holds and how the execution-attribution receipt is validated.)*
---
## MCP Orientation (when available)
If the state-hub MCP server is reachable, call:
`get_domain_summary("infotech")`
This provides richer cross-domain context.
If the MCP call fails, use this file as your orientation source.