Open security core for dev sec ops on kubernetes
Find a file
tegwick 64394e99b9
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Apply the v0.8 assent round: nine corrections, one request declined
The round returned findings from access-engine, approval-engine,
ops-warden and net-kingdom. v0.8 stayed proposed throughout, so these
are corrections to an uncut standard rather than amendments to an
accepted one. §15 items 12-20 list them; §14 records what the round
did and did not cover.

The load-bearing one is §6.4 obligation 1. The obligation said a PEP
must hold "a decision from access-engine", and obligation 2 supplied a
digest test emphatic that it was mechanical rather than a matter of
judgement. That test establishes which request a decision is for and
nothing about who issued it, and it cannot: every input to it is either
sent by the caller or published. Fail-closed protects against a
decision point that is absent, not against one that lies. Obligation 5
was then written over a pair of artifacts whose authenticity only one
half of could be validated, since §9.4 requires the approval object to
have authenticated entries and nothing required it of the decision.
The obligation now requires attribution, states that the digest
comparison does not discharge it, and carries a declared §13 gap with
access-engine as owner rather than a mechanism the standard does not
get to choose.

Obligation 3 gains three things: the drift test promoted SHOULD to MUST
(the strongest obligation in the section had the weakest verification,
in a paragraph arguing that drift is worse than no publication), a
prohibition on totality satisfied by a catch-all, and the requirement
that an absent scope be distinguishable in the record from an unknown
one. The last closes the §16 question opened at the cut: absent fails
closed too, for the stronger reason, and the distinction is in the
record rather than in the stance.

ops-warden asked for a dated transitional unknown: fail_open converting
on coverage. Declined, with its reasons in §6.4: a sanctioned
transitional fail_open is indistinguishable at runtime from the stance
the rule forbids, and would make the rule optional at the only moment
it costs anything. Its second preference is adopted instead — §13.1
records a dated classification-coverage figure beside each stance, so a
strict consumer and an unclassified one stop reading alike. Its measured
figures are in the register, and ops-mason's unpublished map is now
marked as the plainer violation of the same obligation it always was.

§6.4 announced four obligations and listed five. §17 called ownership
of three artifacts unsettled while settling one of them in the same
sentence. §14's tally could not be checked because item 2b's numbering
left a reader unable to tell whether it was a change or a sub-clause.
§19's hole was explained where nobody looks. All four found by
approval-engine.

21 tests pass.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
2026-09-09 20:10:55 +02:00
.claude docs: workplan-first agent guidance prose (CUST-WP-0055 T04 batch 2) 2026-07-08 16:41:16 +02:00
.forgejo/workflows Add Forgejo CI smoke workflow (enablement template) 2026-07-08 12:37:33 +02:00
.githooks feat(creds): implement NK-WP-0004 Credential Management Foundation 2026-03-20 23:39:35 +00:00
.repo-manager Security Layer Model v0.5 — four reviews, nine changes 2026-08-29 02:54:25 +02:00
canon Apply the v0.8 assent round: nine corrections, one request declined 2026-09-09 20:10:55 +02:00
capabilities/playbooks feat(orchestration): compose security scenarios 2026-08-23 12:40:52 +02:00
docs feat: accept KeyCape approval clients with tested recovery 2026-09-09 02:18:12 +02:00
examples feat(orchestration): compose KeyCape C1 and C2b 2026-08-23 13:24:55 +02:00
history Security Layer Model v0.6 — type the engines, name the gate, hold actuation at zero 2026-08-29 03:32:58 +02:00
identity-provisioner Track and harden NK-WP-0025 residuals 2026-08-14 19:35:46 +02:00
intakes Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
keys feat(creds): implement NK-WP-0004 Credential Management Foundation 2026-03-20 23:39:35 +00:00
local-identity Local Identity OICD bootstrap 2026-05-02 16:58:44 +02:00
registry feat(posture): add deterministic feedback proposals 2026-08-23 13:16:34 +02:00
sso-mfa feat: accept KeyCape approval clients with tested recovery 2026-09-09 02:18:12 +02:00
tests Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
tools Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
wiki Add CLAUDE.md, wiki protoplans, and NK-WP-0001 workplan 2026-02-28 17:21:51 +01:00
workplans chore(consistency): register NK-WP-0035 workplan and task identifiers 2026-09-07 08:47:38 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-09-07 13:45:29 +02:00
.gitignore chore: ignore patch backups 2026-08-28 11:54:39 +02:00
.repo-classification.yaml Human-review .repo-classification.yaml (CUST-WP-0050 follow-up) 2026-06-22 17:56:17 +02:00
.sops.yaml feat(creds): implement NK-WP-0004 Credential Management Foundation 2026-03-20 23:39:35 +00:00
AGENTS.md docs(agents): repoint remote State Hub URL to the in-cluster address 2026-08-25 00:21:25 +02:00
CLAUDE.md Add credential routing instructions for all agent runtimes 2026-06-18 22:48:38 +02:00
CONFIG.md feat(sso-mfa): T05 SSO stack pivot — Keycloak → Authelia + LLDAP + KeyCape (NK-WP-0001-T05) 2026-03-19 08:31:51 +00:00
DECISIONS.md Decision for KeyCape Implementation Language Go 2026-03-26 09:21:17 +01:00
INTENT.md Point layering note at the published standard 2026-08-28 21:21:07 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-29 23:43:45 +02:00
Makefile Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
README.md Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
SCOPE.md feat(orchestration): compose KeyCape C1 and C2b 2026-08-23 13:24:55 +02:00
SECURITY-COMPANION.md Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
WORK-RECORDS.md chore(consistency): register NK-WP-0035 workplan and task identifiers 2026-09-07 08:47:38 +02:00

NetKingdom

NetKingdom is the canonical security architecture, integration boundary, and bootstrap/reference implementation for NetKingdom environments. It defines identity, tenancy, credential, workload-zone, and security-composition contracts while leaving provider and Railiance execution in their owning repositories.

The dynamic, self-optimizing security platform is the long-term direction in INTENT.md, not a claim about current delivery.

Orientation

  • SCOPE.md — what this repo owns, current state, and when it is relevant
  • SECURITY-COMPANION.md — start here. The working form of the security layer model: what to declare, what binds you, what you may never claim about evidence, and the two things the estate cannot do yet
  • Security layer model — the statute the companion serves (accepted 2026-08-29): how the security estate is layered (Taxonomy / Tooling / Engines / Staff) and what each layer may own
  • Security scenario composition — deterministic, plan-only capability and trust composition
  • Posture feedback — deterministic, proposal-only posture and evidence remediation findings
  • Emission cadence security profile — NetKingdom obligations over the InfoTechCanon declaration contract; proposed pending owner-instance migration

Security Infrastructure Documents

  • secrets-engine security infrastructure boundary defines how secrets-engine participates in the NetKingdom security infrastructure and how it interacts with OpenBao, flex-auth, user-engine, ops-warden, ops-bridge, info-tech-canon, State Hub, and agents.