Register with State Hub, close bootstrap housekeeping (MASON-0001)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
parent
dff106073b
commit
0c39bbd1cc
5 changed files with 340 additions and 0 deletions
46
SCOPE.md
Normal file
46
SCOPE.md
Normal file
|
|
@ -0,0 +1,46 @@
|
|||
# SCOPE
|
||||
|
||||
## One-liner
|
||||
|
||||
Builder of NetKingdom security infrastructure — creates, changes,
|
||||
maintains, and tears down OpenBao AppRoles, policies, and KV secret paths
|
||||
so ops-warden always has something real to route to.
|
||||
|
||||
## Core Idea
|
||||
|
||||
Four-phase process: (1) construction plan — respect/extend/compact
|
||||
existing structure before proposing new; (2) review/optimize against
|
||||
what already exists; (3) executive summary — the one mandatory human
|
||||
decision gate, in plain terms; (4) build, only after approval.
|
||||
|
||||
## In Scope
|
||||
|
||||
- Construction plans for new/changed/retired OpenBao AppRoles, policies,
|
||||
KV secret paths
|
||||
- Consistency review — reuse over duplication, compaction over sprawl
|
||||
- The executive-summary format that makes a plan decidable at a glance
|
||||
- Registering what it builds into ops-warden's routing catalog
|
||||
- Its own audit trail of what it built, under which approved plan
|
||||
|
||||
## Out of Scope
|
||||
|
||||
- Deciding *whether* access should exist — that's architecture/founder,
|
||||
ops-mason builds what's already decided
|
||||
- Runtime authorization decisions — flex-auth
|
||||
- Identity/MFA — key-cape/Keycloak
|
||||
- Routing consumers to lanes once built — ops-warden
|
||||
- SSH certificate issuance — ops-warden
|
||||
- OpenBao cluster init/unseal, platform deploy — railiance-platform
|
||||
- Holding or logging secret values, ever
|
||||
|
||||
## Current State
|
||||
|
||||
Charter only (`INTENT.md`). `MASON-WP-0001` scopes the four-phase
|
||||
pipeline and its first real exercise: the `rein-openweights` OpenBao
|
||||
AppRole that `glas-harness/GLAS-WP-0002-T02` is blocked on. No code yet.
|
||||
|
||||
## Getting Oriented
|
||||
|
||||
- Start with: `INTENT.md`
|
||||
- Agent instructions: `AGENTS.md`
|
||||
- Workplans: `workplans/`
|
||||
Loading…
Add table
Add a link
Reference in a new issue