Offline steps exercised against the secrets-engine example; live caller-auth steps remain unexercised. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: sonnet Assistant-Process: 295952@bnt-lap001 Assistant-Session: e93f64ad-516c-46eb-9666-aad8d300c477
1.8 KiB
1.8 KiB
NetKingdom Security Pattern Tutorials
Hands-on paths for operating the canonical NetKingdom security patterns
(NK-WP-0009). Each tutorial is a file in this directory, written from
TEMPLATE.md and checked by make tutorials-verify.
Rules
- Exercise status is mandatory. Per
docs/attended-procedure-standard.md, a tutorial header saysexercised <date> by <operator>orunexercised. Nothing is labelled exercised until someone has run it. - Every concrete step names its owning repo. This repo owns canon and
reference tooling only (see
SCOPE.md); deployment belongs to owners. - Verification and rollback are required, not optional happy-path extras.
- No secrets, ever. Tutorials show paths and commands, never values.
- Consume, don't copy. Link owner runbooks; do not paste runtime
manifests. Use the named
openbao-ui-railiance01tunnel, never a public Bao URL (bao.coulomb.socialis retired).
Index
| Tutorial | Workplan task | Owners | Status |
|---|---|---|---|
| OpenBao: consume, attend, recover | T03 | railiance-platform, net-kingdom | unexercised |
| Short-lived SSH credentials | T04 | ops-warden, ops-bridge | unexercised |
| Add a protected system to flex-auth | T05 | flex-auth, package owner | unexercised (offline part run) |
Deferred (see NK-WP-0009): T02 object-storage STS (needs an owner-backed issuer and refusal/lease proof — ADR-0008 is architecture, not evidence).
Pattern mapping
NK-WP-0008 (the pattern library) has no file in this repo, so tutorials map to
the canonical documents directly: docs/platform-identity-security-architecture.md,
docs/responsibility-map.md, docs/platform-root-custody.md.