Open security core for dev sec ops on kubernetes
Find a file
tegwick 8a17551103
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Add the agent companion to the security layer model
v0.6 is dense, self-referential, and written for readers who already live in the
estate. That is acceptable in canon and poor as a contract for the nine
repositories yet to declare and for the Staff agents expected to conform.

The companion is the operative form: the rules, no change log, no review
archaeology. Machine-readable layer key, the three sanctioned Tooling shapes as
a table, the PEP obligations, the evidence bound with the two unsound claims
written out, the four agent rules, and the four conformance states. The statute
governs on disagreement, and a disagreement is reportable as a finding.

Its §9 records that operations is HelixForge's responsibility — reef, rail,
rapp, rein — consuming the NetKingdom security and approval framework, and that
the interface is NOT yet specified. What holds today is only what holds for any
consumer. No mapping of those concepts onto the layer model should be assumed
until it is written; the statute's §16 carries the same open question.

Its §10 states the two things the estate cannot do yet — nothing is observed in
production, nothing can be contained automatically — so no reader plans around
a capability that does not exist.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-29 09:25:40 +02:00
.claude docs: workplan-first agent guidance prose (CUST-WP-0055 T04 batch 2) 2026-07-08 16:41:16 +02:00
.forgejo/workflows Add Forgejo CI smoke workflow (enablement template) 2026-07-08 12:37:33 +02:00
.githooks feat(creds): implement NK-WP-0004 Credential Management Foundation 2026-03-20 23:39:35 +00:00
.repo-manager Security Layer Model v0.5 — four reviews, nine changes 2026-08-29 02:54:25 +02:00
canon Add the agent companion to the security layer model 2026-08-29 09:25:40 +02:00
capabilities/playbooks feat(orchestration): compose security scenarios 2026-08-23 12:40:52 +02:00
docs docs(custody): every credential says what it is 2026-08-28 11:42:51 +02:00
examples feat(orchestration): compose KeyCape C1 and C2b 2026-08-23 13:24:55 +02:00
history Security Layer Model v0.6 — type the engines, name the gate, hold actuation at zero 2026-08-29 03:32:58 +02:00
identity-provisioner Track and harden NK-WP-0025 residuals 2026-08-14 19:35:46 +02:00
intakes repo.work.create_intake NET-IN-0001 2026-08-28 23:01:51 +02:00
keys feat(creds): implement NK-WP-0004 Credential Management Foundation 2026-03-20 23:39:35 +00:00
local-identity Local Identity OICD bootstrap 2026-05-02 16:58:44 +02:00
registry feat(posture): add deterministic feedback proposals 2026-08-23 13:16:34 +02:00
sso-mfa fix(privacyidea): repair the resolver reconciliation script (NK-WP-0033) 2026-08-27 22:20:03 +02:00
tests NK-WP-0026 finished: user-engine caller identity verified live against railiance01 2026-08-19 22:01:12 +02:00
tools feat(orchestration): compose KeyCape C1 and C2b 2026-08-23 13:24:55 +02:00
wiki Add CLAUDE.md, wiki protoplans, and NK-WP-0001 workplan 2026-02-28 17:21:51 +01:00
workplans chore(registrar): assign State Hub identifiers 2026-08-28 11:56:08 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-08-27 22:22:03 +02:00
.gitignore chore: ignore patch backups 2026-08-28 11:54:39 +02:00
.repo-classification.yaml Human-review .repo-classification.yaml (CUST-WP-0050 follow-up) 2026-06-22 17:56:17 +02:00
.sops.yaml feat(creds): implement NK-WP-0004 Credential Management Foundation 2026-03-20 23:39:35 +00:00
AGENTS.md docs(agents): repoint remote State Hub URL to the in-cluster address 2026-08-25 00:21:25 +02:00
CLAUDE.md Add credential routing instructions for all agent runtimes 2026-06-18 22:48:38 +02:00
CONFIG.md feat(sso-mfa): T05 SSO stack pivot — Keycloak → Authelia + LLDAP + KeyCape (NK-WP-0001-T05) 2026-03-19 08:31:51 +00:00
DECISIONS.md Decision for KeyCape Implementation Language Go 2026-03-26 09:21:17 +01:00
INTENT.md Point layering note at the published standard 2026-08-28 21:21:07 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-29 23:43:45 +02:00
Makefile feat(orchestration): compose KeyCape C1 and C2b 2026-08-23 13:24:55 +02:00
README.md Add the agent companion to the security layer model 2026-08-29 09:25:40 +02:00
SCOPE.md feat(orchestration): compose KeyCape C1 and C2b 2026-08-23 13:24:55 +02:00
WORK-RECORDS.md Refresh work-record index 2026-08-29 02:45:20 +02:00

NetKingdom

NetKingdom is the canonical security architecture, integration boundary, and bootstrap/reference implementation for NetKingdom environments. It defines identity, tenancy, credential, workload-zone, and security-composition contracts while leaving provider and Railiance execution in their owning repositories.

The dynamic, self-optimizing security platform is the long-term direction in INTENT.md, not a claim about current delivery.

Orientation

  • SCOPE.md — what this repo owns, current state, and when it is relevant
  • Security layer model — how the security estate is layered (Taxonomy / Tooling / Engines / Staff) and what each layer may own
  • Agent companion — the operative two-page form of that standard: what to declare, what binds you, what you may never claim
  • Security scenario composition — deterministic, plan-only capability and trust composition
  • Posture feedback — deterministic, proposal-only posture and evidence remediation findings

Security Infrastructure Documents

  • secrets-engine security infrastructure boundary defines how secrets-engine participates in the NetKingdom security infrastructure and how it interacts with OpenBao, flex-auth, user-engine, ops-warden, ops-bridge, info-tech-canon, State Hub, and agents.