Open security core for dev sec ops on kubernetes
Find a file
tegwick 66eeabad38 Cut security-layer-model v0.8 (proposed) from gate-house's amendment set
Authored by gate-house under GH-WP-0003-T06; published here. v0.7 stays
accepted and unedited until v0.8 is accepted in its place.

Eleven changes across §6.4, §8, §9.5, §9.7.3, §11, §12, §13.1, §16 and
§17, each carrying the decision record that already governs its
implementers. Three correct a rule that was unsafe or unfalsifiable as
written — consume ordering, the volatility boundary, and a permissive
unknown. Three close gaps between rules already made. One corrects an
ownership paragraph that a later decision made false, and §11/§12 gain
the general form of that failure after six instances in one week.

Ten of the eleven were requested by another repository, seven by a
repository arguing against its own interest. §14 is therefore rewritten:
this version is circulated for review rather than accepted on the owner's
decision as v0.7 was, because it imposes costs on named repositories —
ops-warden acquires a non-conformant stance cell, approval-engine an
issue-time obligation — and a cost imposed without a review round is what
§12 exists to catch late.

Section numbering is unchanged; the estate cites it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 14:52:42 +02:00
.claude docs: workplan-first agent guidance prose (CUST-WP-0055 T04 batch 2) 2026-07-08 16:41:16 +02:00
.forgejo/workflows Add Forgejo CI smoke workflow (enablement template) 2026-07-08 12:37:33 +02:00
.githooks feat(creds): implement NK-WP-0004 Credential Management Foundation 2026-03-20 23:39:35 +00:00
.repo-manager Security Layer Model v0.5 — four reviews, nine changes 2026-08-29 02:54:25 +02:00
canon Cut security-layer-model v0.8 (proposed) from gate-house's amendment set 2026-09-06 14:52:42 +02:00
capabilities/playbooks feat(orchestration): compose security scenarios 2026-08-23 12:40:52 +02:00
docs Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
examples feat(orchestration): compose KeyCape C1 and C2b 2026-08-23 13:24:55 +02:00
history Security Layer Model v0.6 — type the engines, name the gate, hold actuation at zero 2026-08-29 03:32:58 +02:00
identity-provisioner Track and harden NK-WP-0025 residuals 2026-08-14 19:35:46 +02:00
intakes Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
keys feat(creds): implement NK-WP-0004 Credential Management Foundation 2026-03-20 23:39:35 +00:00
local-identity Local Identity OICD bootstrap 2026-05-02 16:58:44 +02:00
registry feat(posture): add deterministic feedback proposals 2026-08-23 13:16:34 +02:00
sso-mfa Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
tests Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
tools Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
wiki Add CLAUDE.md, wiki protoplans, and NK-WP-0001 workplan 2026-02-28 17:21:51 +01:00
workplans Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-08-27 22:22:03 +02:00
.gitignore chore: ignore patch backups 2026-08-28 11:54:39 +02:00
.repo-classification.yaml Human-review .repo-classification.yaml (CUST-WP-0050 follow-up) 2026-06-22 17:56:17 +02:00
.sops.yaml feat(creds): implement NK-WP-0004 Credential Management Foundation 2026-03-20 23:39:35 +00:00
AGENTS.md docs(agents): repoint remote State Hub URL to the in-cluster address 2026-08-25 00:21:25 +02:00
CLAUDE.md Add credential routing instructions for all agent runtimes 2026-06-18 22:48:38 +02:00
CONFIG.md feat(sso-mfa): T05 SSO stack pivot — Keycloak → Authelia + LLDAP + KeyCape (NK-WP-0001-T05) 2026-03-19 08:31:51 +00:00
DECISIONS.md Decision for KeyCape Implementation Language Go 2026-03-26 09:21:17 +01:00
INTENT.md Point layering note at the published standard 2026-08-28 21:21:07 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-29 23:43:45 +02:00
Makefile Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
README.md Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
SCOPE.md feat(orchestration): compose KeyCape C1 and C2b 2026-08-23 13:24:55 +02:00
SECURITY-COMPANION.md Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
WORK-RECORDS.md Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00

NetKingdom

NetKingdom is the canonical security architecture, integration boundary, and bootstrap/reference implementation for NetKingdom environments. It defines identity, tenancy, credential, workload-zone, and security-composition contracts while leaving provider and Railiance execution in their owning repositories.

The dynamic, self-optimizing security platform is the long-term direction in INTENT.md, not a claim about current delivery.

Orientation

  • SCOPE.md — what this repo owns, current state, and when it is relevant
  • SECURITY-COMPANION.md — start here. The working form of the security layer model: what to declare, what binds you, what you may never claim about evidence, and the two things the estate cannot do yet
  • Security layer model — the statute the companion serves (accepted 2026-08-29): how the security estate is layered (Taxonomy / Tooling / Engines / Staff) and what each layer may own
  • Security scenario composition — deterministic, plan-only capability and trust composition
  • Posture feedback — deterministic, proposal-only posture and evidence remediation findings
  • Emission cadence security profile — NetKingdom obligations over the InfoTechCanon declaration contract; proposed pending owner-instance migration

Security Infrastructure Documents

  • secrets-engine security infrastructure boundary defines how secrets-engine participates in the NetKingdom security infrastructure and how it interacts with OpenBao, flex-auth, user-engine, ops-warden, ops-bridge, info-tech-canon, State Hub, and agents.