net-kingdom/docs/tutorials
tegwick 816610a7a1
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Add NK-WP-0044 and NetKingdom runbook packs (legacy console wrapper, SSH pack)
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 295952@bnt-lap001
Assistant-Session: e93f64ad-516c-46eb-9666-aad8d300c477
2026-09-29 00:25:18 +02:00
..
openbao-operating-path.md Activate NK-WP-0009/0011; add tutorials slice and proposed ADR-0009 2026-09-28 23:31:48 +02:00
protected-system-flex-auth.md Add flex-auth protected-system tutorial (NK-WP-0009-T05) 2026-09-28 23:44:44 +02:00
README.md Add NK-WP-0044 and NetKingdom runbook packs (legacy console wrapper, SSH pack) 2026-09-29 00:25:18 +02:00
ssh-certificates-and-tunnels.md Activate NK-WP-0009/0011; add tutorials slice and proposed ADR-0009 2026-09-28 23:31:48 +02:00
TEMPLATE.md Activate NK-WP-0009/0011; add tutorials slice and proposed ADR-0009 2026-09-28 23:31:48 +02:00

NetKingdom Security Pattern Tutorials

Hands-on paths for operating the canonical NetKingdom security patterns (NK-WP-0009). Each tutorial is a file in this directory, written from TEMPLATE.md and checked by make tutorials-verify.

Moving. Tutorials are becoming runbook packs in runbooks/ for the runbook-tutorials engine (NK-WP-0044). runbooks/ssh-certificates/ is the first. These markdown files stay until their packs are exercised.

Rules

  1. Exercise status is mandatory. Per docs/attended-procedure-standard.md, a tutorial header says exercised <date> by <operator> or unexercised. Nothing is labelled exercised until someone has run it.
  2. Every concrete step names its owning repo. This repo owns canon and reference tooling only (see SCOPE.md); deployment belongs to owners.
  3. Verification and rollback are required, not optional happy-path extras.
  4. No secrets, ever. Tutorials show paths and commands, never values.
  5. Consume, don't copy. Link owner runbooks; do not paste runtime manifests. Use the named openbao-ui-railiance01 tunnel, never a public Bao URL (bao.coulomb.social is retired).

Index

Tutorial Workplan task Owners Status
OpenBao: consume, attend, recover T03 railiance-platform, net-kingdom unexercised
Short-lived SSH credentials T04 ops-warden, ops-bridge unexercised
Add a protected system to flex-auth T05 flex-auth, package owner unexercised (offline part run)

Deferred (see NK-WP-0009): T02 object-storage STS (needs an owner-backed issuer and refusal/lease proof — ADR-0008 is architecture, not evidence).

Pattern mapping

NK-WP-0008 (the pattern library) has no file in this repo, so tutorials map to the canonical documents directly: docs/platform-identity-security-architecture.md, docs/responsibility-map.md, docs/platform-root-custody.md.