Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
13 KiB
Open workplans versus infrastructure — 2026-09-28
Reviewed all ten nonterminal root workplans (eight blocked, two backlog). Initial review result: one finished, one active, six blocked, two backlog. The follow-through section below records subsequent implementation and statuses. Existing task IDs and State Hub UUIDs are preserved. This is a planning reconciliation; no runtime, credential, policy, DNS or destructive change was performed.
Evidence boundary
Read-only kubectl checks against context default found one Ready node at
92.205.62.239, Kubernetes v1.35.1+k3s1. KeyCape, Authelia, LLDAP,
privacyIDEA, user-engine, tenant-engine and audit-core each had one ready
Deployment replica. All six flex-auth consumer Deployments were ready and
contained --caller-auth-mode enforce. This is configuration/readiness
proof, not fresh user login, negative authorization or recovery testing.
All eight CNPG clusters reported one instance and one ready instance: apps-pg, forgejo-db, net-kingdom-pg, platform-pg, platform-pg-2, state-hub-db, target-revenue-pg and user-engine-pg. A healthy single-node cluster does not prove HA or off-host recovery. No Keycloak Deployment was present.
OpenBao StatefulSet and UI gateway were ready; gateway/API Services were ClusterIP and the namespace had no Ingress. CoulombCore, retained backup contents, public DNS withdrawal and browser sessions were not reverified. Owner receipts below support historical completion, not a fresh execution. Sibling repositories were inspected as available local checkouts; their state was not assumed to be a newly fetched remote head.
The State Hub inbox supplied flex-auth's September 27 approval of its reference
cleanup (77b26d1e-550b-4926-9610-44fc3a566273); it was marked read. The
human-needed task query returned no NK-/NET-prefixed records. This does not
remove the explicit approval gate written in NK-WP-0022. Topic-wide active
workplans include other repositories and are not the NetKingdom plan inventory.
Plan dispositions at the initial review
| Plan | Updated state and next acceptance gate |
|---|---|
| 0009 tutorials | Backlog. Start with existing private OpenBao and SSH paths, caller-auth refusal checks and executable verification. STS tutorial needs an actual owner-backed service. |
| 0011 federation | Backlog. Correct issuer to kc.coulomb.social, accepted IAM to v0.3, database admission and managed-package ownership. Require a named enterprise demand before broker implementation. |
| 0022 retirement | Blocked. Cutover was completed in July; August 29 retention minimum has elapsed. T08 still needs retained-resource inventory, identity recovery evidence and explicit deletion approval. |
| 0027 reef/posture | Blocked. Carrier agreement still absent. Include railiance-infra as substrate owner. Public classification exists upstream; maturity mapping versus synthetic provenance remains unresolved. |
| 0031 freshness | Blocked. Audit Core still lacks structured owner/freshness fields; September V1 recovery evidence does not replace August E2 boundary evidence. |
| 0032 Bao callback | Finished. T03/T04 closed from September 15 callback/login receipts and September 22 platform handoff. Public callback rollback text is historical. |
| 0035 cadence | Blocked. Update upstream version/pin metadata; migrate source envelopes and obtain real observer evidence. Include local-identity's known profile incompatibility. |
| 0039 rename/reference | Active. T04 now has an actionable flex-auth reference-cleanup portion. Tenant-engine agreement and T03 rename notification remain separate gates. |
| 0040 execution receipt | Blocked. Agree emitter/custodian/schema; require an actual run-to-audit receipt proof, preserving unknown attribution and clock bounds. |
| 0042 step-up | Blocked. Reuse delivered P06 enrollment and scoped optional policies; agree and accept one workload's step-up/recovery journey. |
The two oldest plans now have one task per second-level section, conforming to the file-backed workplan format. Completed implementation tasks were not reopened merely because their historical validation dates are old.
Necessary changes and conflicts
- Stale deployment copies can remove a live security control.
sso-mfa/k8s/tenant-engine/runtime.yamllacks live caller enforcement and other owner changes. Keep DO-NOT-APPLY. Flex-auth approved pointers to itsvalues/<consumer>.yaml; tenant-engine's portion remains separately owned. Repository rename does not rename the runtime, token audience or OCI package. Source: FLEX-WP-0020 (locate by workplan ID if the owner filename changes), inbox receipt above. - Recovery claims must follow the actual failure domain. Reef declarations still omit provider ceilings; one node and single-instance databases cannot establish independent failover. Proposed V0/V1 carrier semantics require owner agreement and workload evidence. A platform database drill does not satisfy full identity restoration for destructive retirement. Sources: reef declaration, provider proposal.
- Declared evidence remains behind runtime improvements. Audit Core's tenancy file still describes flex-auth as unauthenticated A0, despite the observed enforcement flags. Its E2 review metadata is unstructured and old. Have the owner reconcile this; do not infer A/E upgrades from flags or tests. Source: audit tenancy.
- Generic cadence validity is not profile compliance or observation. Approval Engine and Qonto still fail the owner schema. Local-identity passes that schema but fails the rare-class heartbeat obligation when its source inventory is explicitly supplied. Audit Core holds no local-identity feed. Upstream corrected its candidate bundle digest; profile and declaration metadata need reconciliation without changing historical findings. Sources: local findings, upstream review.
- Existing MFA work and proposed generic step-up are different scopes. P06 already delivered optional policies for two clients, enrollment checks and privileged guards. IAM v0.4 remains proposed; it is not evidence of arbitrary workload step-up support. Reuse the implementation and close the pilot UX/interop gap. Sources: USER-WP-0033, KEY-WP-0035 and P06 evidence.
- Public Bao is retired. September 24 removed public role callbacks; current client source rejects their return. Do not repeat completed login admission or preserve public URLs as a future default. DNS withdrawal is a railiance-infra residual. Sources: callback receipt, login/retraction receipt, callback pruning, platform closure.
- Accepted canon and proposals must stay distinct. IAM v0.3, Playbook Capability v0.1 and security layer v0.7 remain the accepted baselines; proposed amendments do not authorize runtime implementation or replace owner agreement. New federation work must follow ADR-0015 packaging and current tenant identity contracts, not the original greenfield assumptions.
Most valuable future implementation
Recommended order; this is prioritization, not approval of deployment or deletion.
- Remove stale reference authority (0039). Small, locally actionable work that prevents a caller-auth regression. Replace the approved flex-auth objects with exact owner pointers; finish tenant-engine's portion after its answer. No rollout is needed.
- Close one real workload MFA journey (0042). High user value with existing provider work available. Pick a pilot with its owner, demonstrate enrollment, return to action, recovery and denial with stale/insufficient assurance. Coordinate existing actual-user gates rather than create another onboarding implementation.
- Make evidence freshness and emission operational (0031 + 0035). Add authoritative metadata first, then migrate a source already sending to Audit Core and prove heartbeat/reconciliation through its observer. This makes missing or stale security evidence detectable. Resolve local-identity activity-scope incompatibility explicitly; do not force a bootstrap tool into a permanent service just to pass the profile.
- Bind a real execution to evidence (0040). Agree the receipt and implement one Railiance emitter/receiver integration with actor, artifact, decision, approval and bounded time. This unblocks clock attribution and gives more value than a schema-only finish.
- Mechanize recovery ceilings and finish retirement safely (0027 + 0022). Agree reef provider declarations, implement the three-valued join, and use measured recovery evidence. Prepare the exact old identity deletion package only after its recovery gate passes; approval remains a separate final step.
Tutorials should capture these proven paths incrementally. Enterprise federation is lower priority until a concrete tenant/IdP demand justifies its additional issuer, trust mapping, database and recovery burden.
Validation
- Current read-only node, Deployment, CNPG and OpenBao resource inventories.
- Existing cadence checker against the current owner schema: Approval Engine
fails with three generic findings; Qonto fails with five. Local-identity is
generic-valid; supplying both documented load-bearing/rare classes yields
two
rare-heartbeat-missingfailures. Omitting inventory flags checks no rare-class obligations and must not be used to claim adoption. - Existing posture evaluator at explicit
2026-09-28T12:00:00Zconfirms unknown owner/freshness and overdue review for audit-core. This is a chosen reproducible evaluation instant, not the observation timestamp. - Workplan frontmatter, task-ID preservation, task statuses and local Markdown
links checked; authored files pass
git diff --check. The generated brief retains its generator's Markdown hard-break whitespace. No application code changed.
State Hub lifecycle reconciliation classifies partially completed 0039 with an
actionable task as active; its file follows that convention. Existing
NK-WP/NET-WP prefix warnings are retained rather than renumbering historical
work records. At the initial review, repository instructions contained conflicting prefix
conventions. NK-WP-0043 subsequently standardized new plans on NK-WP while
preserving historical IDs.
Follow-through — 2026-09-28
After the user requested implementation, the approved part of NK-WP-0039-T04 was completed: seven obsolete flex-auth objects were removed from the combined reference manifest and replaced with owner links in sso-mfa/k8s/tenant-engine/README.md. Parsed before/after YAML confirms all five tenant-engine objects are unchanged. No repository apply path consumes the combined manifest; the user-engine verifier uses its own file. Owner values enforce caller authentication and bind each consumer to its own ServiceAccount. The remaining YAML stays DO-NOT-APPLY. T04 now waits only for tenant-engine's disposition; T03 still waits for the rename. This returns 0039 to blocked: the current disposition of the original ten is one finished, seven blocked and two backlog.
The locally owned portion of NK-WP-0035-T04 also advanced: corrected the profile's imported document maturity/version/revision and the local-identity candidate bundle pin. The old pin and its correction remain in historical findings. Schema SHA-256 is unchanged. All 15 focused checker tests pass; explicit rare-class revalidation remains generic-valid with exactly two missing-heartbeat failures. The profile stays proposed and source/observer adoption remains open. No runtime or external-owner source was changed.