Open security core for dev sec ops on kubernetes
Find a file
tegwick 7b211acd57 Add OpenBao runtime secret authority; complete NK-WP-0006/0007/0008
Refine the recursive platform security architecture to make OpenBao the
canonical runtime secret authority, with SOPS/age, K8s Secrets, and the
emergency bundle reframed as bootstrap/delivery/break-glass mechanisms.

- credential-management standard v0.2: add OpenBao runtime authority
  section, rotation rules, and prohibited patterns (OpenBao-as-PDP,
  tenant platform-root)
- platform-identity-security-architecture: mark implemented; add
  flex-auth/Topaz implications, Coulomb onboarding path, and a
  production-readiness checklist
- NK-WP-0004/0005: document bootstrap-to-OpenBao handoff boundary
- NK-WP-0006/0007: status -> done with implementation reviews; add
  recursive platform/tenant split and OpenBao broker/audit role for
  object-storage STS vending
- NK-WP-0008: status -> done; repoint corpus to infospace-bench
- new ADR-0007 (orchestration boundary), ADR-0008 (STS vending
  boundary), and the object-storage STS credential-vending architecture

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-20 22:51:20 +02:00
.claude Refresh agent instruction files 2026-05-18 16:55:46 +02:00
.githooks feat(creds): implement NK-WP-0004 Credential Management Foundation 2026-03-20 23:39:35 +00:00
canon/standards Add OpenBao runtime secret authority; complete NK-WP-0006/0007/0008 2026-05-20 22:51:20 +02:00
docs Add OpenBao runtime secret authority; complete NK-WP-0006/0007/0008 2026-05-20 22:51:20 +02:00
keys feat(creds): implement NK-WP-0004 Credential Management Foundation 2026-03-20 23:39:35 +00:00
local-identity Local Identity OICD bootstrap 2026-05-02 16:58:44 +02:00
sso-mfa feat(t09): backup, break-glass, DR drill — NK-WP-0003-T09 done 2026-03-25 23:56:40 +00:00
wiki Add CLAUDE.md, wiki protoplans, and NK-WP-0001 workplan 2026-02-28 17:21:51 +01:00
workplans Add OpenBao runtime secret authority; complete NK-WP-0006/0007/0008 2026-05-20 22:51:20 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-05-19 04:20:30 +02:00
.gitignore feat(creds): implement NK-WP-0004 Credential Management Foundation 2026-03-20 23:39:35 +00:00
.sops.yaml feat(creds): implement NK-WP-0004 Credential Management Foundation 2026-03-20 23:39:35 +00:00
AGENTS.md Refresh agent instruction files 2026-05-18 16:55:46 +02:00
CLAUDE.md Refresh agent instruction files 2026-05-18 16:55:46 +02:00
CONFIG.md feat(sso-mfa): T05 SSO stack pivot — Keycloak → Authelia + LLDAP + KeyCape (NK-WP-0001-T05) 2026-03-19 08:31:51 +00:00
DECISIONS.md Decision for KeyCape Implementation Language Go 2026-03-26 09:21:17 +01:00
INTENT.md Formalized repo intent to INTENT.md 2026-05-03 19:38:55 +02:00
LICENSE Initial commit 2026-02-28 09:41:41 +00:00
Makefile feat(creds): NK-WP-0005 — agent-driven credential bootstrap 2026-03-21 08:38:52 +00:00
README.md Add CLAUDE.md, wiki protoplans, and NK-WP-0001 workplan 2026-02-28 17:21:51 +01:00
SCOPE.md Improved documentation 2026-05-17 22:36:31 +02:00

NetKingdom

NetKingdom provides a dynamic self optimizing full circle security-platform for kubernetes deployed IT-infrastructures.