Open security core for dev sec ops on kubernetes
reconcile-lldap-resolver-live.sh had never completed a run. Four defects, found by running it on 2026-08-27: 1. request() set Content-Type: application/json on every call, including bodyless GETs. Werkzeug 3.x rejects those in front of privacyIDEA, so every GET returned an HTML 400 while POSTs succeeded — the resolver write landed and the lookup immediately after it did not. bootstrap-realm.sh already fixed this in pi_api and said why; this script was written later and did not inherit it. 2. GET /user/ returns result.value as a list of user objects, not a dict carrying "users". With the 400 fixed, the lookup finally reached the parse and raised AttributeError past the except clause, so the run died as a traceback instead of a receipt. Both shapes now accepted, and the except clause catches parse errors so a failed run still names the phase it died in. 3. A resolver write replaces the whole object, so TIMEOUT, CACHE_TIMEOUT and SIZELIMIT were dropped by every --apply. A resolver with them unset still resolves users, but the WebUI refuses to save or test it — so the script silently un-repaired a resolver an operator had fixed by hand. Now sent, defaulting to the verified 5/120/500 and overridable per run. Same omission fixed in bootstrap-realm.sh, which created the resolver that way originally. 4. The predecessor prompt could not be left empty, so an operator who had lost the exposed credential had to type a placeholder — which also fails the bind and was recorded as a PASSING denial proof. --predecessor-unavailable skips the bind and records NOT-PROVEN. --note carries operator context into the receipt line itself, so the claim and its caveat travel together. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 3377672@bnt-lap001 Assistant-Session: 15463ccf-238f-4e13-b163-93aa25c6d166 |
||
|---|---|---|
| .claude | ||
| .forgejo/workflows | ||
| .githooks | ||
| canon | ||
| capabilities/playbooks | ||
| docs | ||
| examples | ||
| history | ||
| identity-provisioner | ||
| keys | ||
| local-identity | ||
| registry | ||
| sso-mfa | ||
| tests | ||
| tools | ||
| wiki | ||
| workplans | ||
| .custodian-brief.md | ||
| .gitignore | ||
| .repo-classification.yaml | ||
| .sops.yaml | ||
| AGENTS.md | ||
| CLAUDE.md | ||
| CONFIG.md | ||
| DECISIONS.md | ||
| INTENT.md | ||
| LICENSE | ||
| Makefile | ||
| README.md | ||
| SCOPE.md | ||
| WORK-RECORDS.md | ||
NetKingdom
NetKingdom is the canonical security architecture, integration boundary, and bootstrap/reference implementation for NetKingdom environments. It defines identity, tenancy, credential, workload-zone, and security-composition contracts while leaving provider and Railiance execution in their owning repositories.
The dynamic, self-optimizing security platform is the long-term direction in INTENT.md, not a claim about current delivery.
Orientation
- SCOPE.md — what this repo owns, current state, and when it is relevant
- Security scenario composition — deterministic, plan-only capability and trust composition
- Posture feedback — deterministic, proposal-only posture and evidence remediation findings
Security Infrastructure Documents
- secrets-engine security infrastructure boundary defines how secrets-engine participates in the NetKingdom security infrastructure and how it interacts with OpenBao, flex-auth, user-engine, ops-warden, ops-bridge, info-tech-canon, State Hub, and agents.