net-kingdom/tools/security-scenario-composer/README.md
tegwick 7f4e4e9f57
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
feat(orchestration): compose KeyCape C1 and C2b
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02929-244b-7391-b933-c04010e8eedb
2026-08-23 13:24:55 +02:00

1.3 KiB

Security Scenario Composer

The composer is the executable, plan-only implementation of canon/standards/security-scenario-composition_v0.1.md. It validates Playbook Capability Contract v0.1 declarations, selects exact providers, applies authority-bound overrides, orders trust transitions, and emits an owner-routed JSON handoff.

It never invokes an entry point and always emits execution.permitted: false.

Compose the checked-in C0 reference:

python3 tools/security-scenario-composer/security_scenario_composer.py \
  --scenario examples/security-scenarios/c0-local-identity.yaml \
  capabilities/playbooks/net-kingdom.local-identity.yaml

Compose the KeyCape C1 plus C2b reference from its authoritative sibling declarations:

python3 tools/security-scenario-composer/security_scenario_composer.py \
  --scenario examples/security-scenarios/c1-c2b-key-cape.yaml \
  ../key-cape/capabilities/playbooks/key-cape.lightweight-sso.yaml \
  ../key-cape/capabilities/playbooks/key-cape.privacyidea-token-authority.yaml

The scenario pins both provider ids. NetKingdom does not copy or reinterpret their execution authority; the emitted plan retains execution.permitted: false and routes readiness to the declaration owners.

Run tests:

python3 -m pytest tools/security-scenario-composer/tests