net-kingdom/workplans/NK-WP-0043-cadence-assessment-and-operating-guidance.md
tegwick 63e3bb6f7d
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 12s
Refresh operating guidance and standardize new workplan naming
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
2026-09-28 12:40:10 +02:00

113 lines
5.1 KiB
Markdown

---
id: NK-WP-0043
type: workplan
title: "Make cadence assessment explicit and refresh operating guidance"
domain: infotech
repo: net-kingdom
status: finished
flavor: implementation
owner: codex
topic_slug: netkingdom
created: "2026-09-28"
updated: "2026-09-28"
related: [NK-WP-0035, NK-WP-0039]
state_hub_workstream_id: "866807af-b4a9-56d8-ac10-3d05a33aef0c"
---
User-authorized follow-through to the September 28 infrastructure review.
Existing changes and historical workplan identifiers remain intact. This work
changes local verification and guidance, not deployment or source emission.
## Distinguish schema validity from a security-profile assessment
```task
id: NK-WP-0043-T01
status: done
priority: high
state_hub_task_id: "7e450a12-9ccd-51f1-a98b-bc28b069affe"
```
Before this change, an empty supplied inventory produced `conformant: true` while no
class-specific obligation is checked. Return an explicit unassessed result and
a nonzero default exit; offer an intentional schema-only mode. Record the
supplied inventory so a scoped assessment cannot be mistaken for fleet-wide
adoption. Never infer classification or rarity from the declaration.
Acceptance: CLI and report regressions cover omitted inventory, schema-only
success/failure, invalid option combinations and existing profile checks.
The real local-identity declaration remains generic-valid and fails its two
rare heartbeat obligations with explicit source inventory.
Completed: the checker returns `profile_assessed`, exact inventory and
assessment scope; `conformant` is null when unassessed. No inventory in default
mode exits 2, explicit schema-only success exits 0, and validation failures
exit 1. Schema-only rejects profile options and blank class arguments are
rejected. Updated the tool README and proposed profile with compatibility and
exit-code guidance. Existing profile/classification rules are unchanged.
Verification: the new regressions failed against the old implementation
(including the demonstrated exit-0 empty-inventory defect). The final focused
suite passes 27 tests. Process-level checks against the current owner schema
and real local-identity declaration verify default exit 2 / null, schema-only
exit 0 / null, and explicit rare inventory exit 1 / two missing-heartbeat
findings. Python compilation passes. Ruff was unavailable in this environment;
no Ruff result is claimed.
## Separate current operations from historical bootstrap instructions
```task
id: NK-WP-0043-T02
status: done
priority: medium
state_hub_task_id: "5d95bc2d-f940-5989-aacb-0f1865778e7b"
```
Refresh SCOPE and the Kubernetes entry README against the dated September 28
review. Preserve old foundation commands in an explicitly historical document;
route current deployment, custody and recovery to the owning repositories.
Acceptance: links resolve, read-only examples are non-mutating, current versus
historical claims are explicit, and no HA or fresh recovery claim is inferred.
Completed: SCOPE now describes the dated September 28 topology and actual
owner/evidence gates. The Kubernetes README provides owner links and read-only
orientation, with original commands preserved in `FOUNDATIONS-HISTORICAL.md`.
All updated Markdown links resolve. New command examples are metadata reads;
no deployment, login or recovery operation was performed.
## Use one naming convention for new workplans
```task
id: NK-WP-0043-T03
status: done
priority: low
state_hub_task_id: "d51e878f-fbbb-5684-bccc-edd050ed87a5"
```
Use the registered `NK-WP-` prefix throughout AGENTS.md's new-plan examples and
archive convention. Preserve all existing IDs and UUIDs, including NET-WP
records. Align creation sync guidance with the existing direct CLI requirement.
Acceptance: no conflicting new-plan example remains and historical IDs match
before/after. Reconcile the completed workplan to State Hub.
Completed: all new-plan examples and archive guidance use NK-WP. Creation
instructions now use the existing direct consistency CLI protocol. Compared
every pre-existing workplan's IDs against HEAD; no ID changed. Authored files
pass `git diff --check`; the generated brief retains its generator's Markdown
hard-break whitespace. State Hub reconciliation follows at session close.
## Final review — 2026-09-28
Reviewed the accumulated infrastructure, reference, checker and guidance diff
before committing. Corrected the federation plan's unconditional
realm-per-tenant implementation/acceptance wording to follow its topology
ADR, clarified historical cutover prose and labelled the initial review
snapshot separately from later implementation. No checker defect was found.
Broader integration validation: `python3 -m pytest tests tools -q` passes
118 tests. All changed Markdown links resolve. Parsed YAML confirms the five
retained tenant-engine objects are identical to HEAD and exactly seven
flex-auth objects were removed. Every archived bootstrap shell example matches
the original README. Existing workplan IDs remain unchanged. The only default
whitespace-check finding is the generated brief's intentional Markdown line
break; authored files pass. Changes are grouped into infrastructure/reference,
cadence assessment, and operating guidance commits.