Open security core for dev sec ops on kubernetes
Question 12 asked whether to add a quality-of-service dimension. No - because we could not enforce it. Community PostgreSQL has no resource governor, so a declared priority would be an unenforced claim in a declaration, which is what retiring tenantIsolation was about. An axis implies graduation and enforcement and this has neither. Co-residents are equal, and a consumer whose latency cannot survive an unprioritised neighbour escalates to P2. Service class is still declared, as a category not a level: it informs placement, acts as a trigger, and gives "acceptable degradation" in the noisy-neighbour artifact something to be acceptable relative to - what batch tolerates is an outage for latency-critical. Class mixture must be visible, because an unenforceable risk nobody can see is worse than one that is stated. rapp-postgres now reports it and the live instance already flags latency-critical beside batch. Gateway-level prioritisation in a connection proxy is recorded as the known escalation short of P2 - real, and infrastructure we do not run. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> |
||
|---|---|---|
| .claude | ||
| .forgejo/workflows | ||
| .githooks | ||
| canon | ||
| docs | ||
| examples | ||
| history | ||
| identity-provisioner | ||
| keys | ||
| local-identity | ||
| registry | ||
| sso-mfa | ||
| tests | ||
| tools | ||
| wiki | ||
| workplans | ||
| .custodian-brief.md | ||
| .gitignore | ||
| .repo-classification.yaml | ||
| .sops.yaml | ||
| AGENTS.md | ||
| CLAUDE.md | ||
| CONFIG.md | ||
| DECISIONS.md | ||
| INTENT.md | ||
| LICENSE | ||
| Makefile | ||
| README.md | ||
| SCOPE.md | ||
| WORK-RECORDS.md | ||
NetKingdom
NetKingdom provides a dynamic self optimizing full circle security-platform for kubernetes deployed IT-infrastructures.
Orientation
- SCOPE.md — what this repo owns, current state, and when it is relevant
Security Infrastructure Documents
- secrets-engine security infrastructure boundary defines how secrets-engine participates in the NetKingdom security infrastructure and how it interacts with OpenBao, flex-auth, user-engine, ops-warden, ops-bridge, info-tech-canon, State Hub, and agents.