Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
113 lines
5.1 KiB
Markdown
113 lines
5.1 KiB
Markdown
---
|
|
id: NK-WP-0043
|
|
type: workplan
|
|
title: "Make cadence assessment explicit and refresh operating guidance"
|
|
domain: infotech
|
|
repo: net-kingdom
|
|
status: finished
|
|
flavor: implementation
|
|
owner: codex
|
|
topic_slug: netkingdom
|
|
created: "2026-09-28"
|
|
updated: "2026-09-28"
|
|
related: [NK-WP-0035, NK-WP-0039]
|
|
state_hub_workstream_id: "866807af-b4a9-56d8-ac10-3d05a33aef0c"
|
|
---
|
|
|
|
User-authorized follow-through to the September 28 infrastructure review.
|
|
Existing changes and historical workplan identifiers remain intact. This work
|
|
changes local verification and guidance, not deployment or source emission.
|
|
|
|
## Distinguish schema validity from a security-profile assessment
|
|
|
|
```task
|
|
id: NK-WP-0043-T01
|
|
status: done
|
|
priority: high
|
|
state_hub_task_id: "7e450a12-9ccd-51f1-a98b-bc28b069affe"
|
|
```
|
|
|
|
Before this change, an empty supplied inventory produced `conformant: true` while no
|
|
class-specific obligation is checked. Return an explicit unassessed result and
|
|
a nonzero default exit; offer an intentional schema-only mode. Record the
|
|
supplied inventory so a scoped assessment cannot be mistaken for fleet-wide
|
|
adoption. Never infer classification or rarity from the declaration.
|
|
|
|
Acceptance: CLI and report regressions cover omitted inventory, schema-only
|
|
success/failure, invalid option combinations and existing profile checks.
|
|
The real local-identity declaration remains generic-valid and fails its two
|
|
rare heartbeat obligations with explicit source inventory.
|
|
|
|
Completed: the checker returns `profile_assessed`, exact inventory and
|
|
assessment scope; `conformant` is null when unassessed. No inventory in default
|
|
mode exits 2, explicit schema-only success exits 0, and validation failures
|
|
exit 1. Schema-only rejects profile options and blank class arguments are
|
|
rejected. Updated the tool README and proposed profile with compatibility and
|
|
exit-code guidance. Existing profile/classification rules are unchanged.
|
|
|
|
Verification: the new regressions failed against the old implementation
|
|
(including the demonstrated exit-0 empty-inventory defect). The final focused
|
|
suite passes 27 tests. Process-level checks against the current owner schema
|
|
and real local-identity declaration verify default exit 2 / null, schema-only
|
|
exit 0 / null, and explicit rare inventory exit 1 / two missing-heartbeat
|
|
findings. Python compilation passes. Ruff was unavailable in this environment;
|
|
no Ruff result is claimed.
|
|
|
|
## Separate current operations from historical bootstrap instructions
|
|
|
|
```task
|
|
id: NK-WP-0043-T02
|
|
status: done
|
|
priority: medium
|
|
state_hub_task_id: "5d95bc2d-f940-5989-aacb-0f1865778e7b"
|
|
```
|
|
|
|
Refresh SCOPE and the Kubernetes entry README against the dated September 28
|
|
review. Preserve old foundation commands in an explicitly historical document;
|
|
route current deployment, custody and recovery to the owning repositories.
|
|
Acceptance: links resolve, read-only examples are non-mutating, current versus
|
|
historical claims are explicit, and no HA or fresh recovery claim is inferred.
|
|
|
|
Completed: SCOPE now describes the dated September 28 topology and actual
|
|
owner/evidence gates. The Kubernetes README provides owner links and read-only
|
|
orientation, with original commands preserved in `FOUNDATIONS-HISTORICAL.md`.
|
|
All updated Markdown links resolve. New command examples are metadata reads;
|
|
no deployment, login or recovery operation was performed.
|
|
|
|
## Use one naming convention for new workplans
|
|
|
|
```task
|
|
id: NK-WP-0043-T03
|
|
status: done
|
|
priority: low
|
|
state_hub_task_id: "d51e878f-fbbb-5684-bccc-edd050ed87a5"
|
|
```
|
|
|
|
Use the registered `NK-WP-` prefix throughout AGENTS.md's new-plan examples and
|
|
archive convention. Preserve all existing IDs and UUIDs, including NET-WP
|
|
records. Align creation sync guidance with the existing direct CLI requirement.
|
|
Acceptance: no conflicting new-plan example remains and historical IDs match
|
|
before/after. Reconcile the completed workplan to State Hub.
|
|
|
|
Completed: all new-plan examples and archive guidance use NK-WP. Creation
|
|
instructions now use the existing direct consistency CLI protocol. Compared
|
|
every pre-existing workplan's IDs against HEAD; no ID changed. Authored files
|
|
pass `git diff --check`; the generated brief retains its generator's Markdown
|
|
hard-break whitespace. State Hub reconciliation follows at session close.
|
|
|
|
## Final review — 2026-09-28
|
|
|
|
Reviewed the accumulated infrastructure, reference, checker and guidance diff
|
|
before committing. Corrected the federation plan's unconditional
|
|
realm-per-tenant implementation/acceptance wording to follow its topology
|
|
ADR, clarified historical cutover prose and labelled the initial review
|
|
snapshot separately from later implementation. No checker defect was found.
|
|
|
|
Broader integration validation: `python3 -m pytest tests tools -q` passes
|
|
118 tests. All changed Markdown links resolve. Parsed YAML confirms the five
|
|
retained tenant-engine objects are identical to HEAD and exactly seven
|
|
flex-auth objects were removed. Every archived bootstrap shell example matches
|
|
the original README. Existing workplan IDs remain unchanged. The only default
|
|
whitespace-check finding is the generated brief's intentional Markdown line
|
|
break; authored files pass. Changes are grouped into infrastructure/reference,
|
|
cadence assessment, and operating guidance commits.
|