net-kingdom/registry/capabilities/capability.security.iam-tooling-suite.md
tegwick cfc9e7d0cb
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
feat(posture): add deterministic feedback proposals
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02929-244b-7391-b933-c04010e8eedb
2026-08-23 13:16:34 +02:00

5.4 KiB

id name summary owner status domain tags maturity external_evidence discovery availability relations evidence consumer_guidance promotion_history
capability.security.iam-tooling-suite NetKingdom Security/IAM Tooling Suite Canonical security architecture and executable reference tooling for IAM, bootstrap, posture validation, deterministic plan-only security scenario composition, and proposal-only posture feedback. net-kingdom draft infotech
security
iam
kubernetes
conformance
discovery availability
current target confidence rationale
D3 D5 medium SCOPE plus docs/secrets-engine-security-infrastructure-boundary.md describe an explicit integration boundary with OpenBao, flex-auth, user-engine, ops-warden, ops-bridge, info-tech-canon, and State Hub; canon/standards/ holds versioned IAM v0.3, playbook capability, scenario composition, tenancy, zone, and boundary standards that provider repos implement against.
current target confidence rationale
A2 A3 medium No top-level package manifest, but tools/ holds independently documented and runnable conformance, posture, posture-feedback, scenario-composition, and guarded bootstrap tools; local-identity is separately packaged and tested.
completeness reliability
level confidence basis satisfied_expectations broken_expectations out_of_scope_expectations
C1 low scope_vs_intent_and_consumer_expectations
versioned canon standards already implemented by a sibling repo (key-cape)
documented, runnable conformance, posture, composition, and bootstrap tools under tools/
level confidence basis known_reliability_risks
R1 low consumer_quality_signals
no top-level packaging; each tool under tools/ has its own runtime dependencies, no unified install path yet
intent includes excludes assumptions use_cases research_memos
Own canonical NetKingdom security semantics and provide executable reference and conformance tooling so provider implementations can integrate without inferred authority or hidden deployment coupling.
canon/standards/ versioned IAM, tenancy, zone, credential, boundary, and composition standards
IAM profile conformance checker
playbook capability contract validator
deterministic plan-only security scenario composer
tenancy posture schema and validator
deterministic proposal-only posture feedback evaluator
security bootstrap console (local, non-secret-collecting)
packaged local bootstrap identity CLI
concrete IAM implementations themselves (see key-cape for lightweight mode)
live secret value handling (bootstrap console explicitly refuses live OpenBao initialization)
current_level target_level current_artifacts target_artifacts consumption_modes
A2 A3
tools/iam-profile-conformance
tools/playbook-capability-contract
tools/security-scenario-composer
tools/tenancy-posture
tools/posture-feedback
tools/security-bootstrap-console
local-identity
cli
local web ui
depends_on supports related_to
documentation tests consumer_feedback bug_reports incidents
README.md
docs/secrets-engine-security-infrastructure-boundary.md
tools/*/README.md
tools/iam-profile-conformance (pytest fixtures)
recommended_for not_recommended_for known_limitations
implementers needing to verify IAM/security conformance against Coulomb's canonical standards
needs for a packaged, single-install security suite (currently three separate tools)
no unified top-level packaging across the three tools

NetKingdom Security/IAM Tooling Suite

Overview

net-kingdom provides canonical IAM and security architecture, executable conformance and posture checks, deterministic plan-only scenario composition, proposal-only posture feedback, a local bootstrap identity package, and a non-secret-collecting security bootstrap console. Provider implementations remain in sibling repositories such as key-cape; the self-optimizing platform remains an intent rather than a current delivery claim.

Assessment notes

Discovery

SCOPE plus docs/secrets-engine-security-infrastructure-boundary.md describe an explicit integration boundary with OpenBao, flex-auth, user-engine, ops-warden, ops-bridge, info-tech-canon, and State Hub. canon/standards/ holds the current IAM v0.3 and related boundary, posture, zone, credential, playbook, and scenario composition standards.

Availability

No top-level package manifest exists. The independently runnable surfaces are documented under tools/, and local-identity has its own package manifest and test environment.

Completeness

First-pass honest assessment from the REUSE-WP-0017 coverage campaign (reuse-surface). No external consumer feedback exists yet; levels reflect scope-vs-intent documentation quality, not internal code quality.

Reliability

No production consumer telemetry exists yet; reliability level is intentionally conservative pending REUSE-WP-0019 reuse-telemetry evidence.

Promotion checklist

  • ID follows capability.<domain>.<name> pattern
  • Maturity enums match specs/CapabilityMaturityStandard.md
  • external_evidence is populated separately from maturity
  • Relations reference valid capability IDs (none yet)
  • Index entry added in registry/indexes/capabilities.yaml