ops-mason/SCOPE.md
tegwick 0c39bbd1cc Register with State Hub, close bootstrap housekeeping (MASON-0001)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 00:22:58 +02:00

1.6 KiB

SCOPE

One-liner

Builder of NetKingdom security infrastructure — creates, changes, maintains, and tears down OpenBao AppRoles, policies, and KV secret paths so ops-warden always has something real to route to.

Core Idea

Four-phase process: (1) construction plan — respect/extend/compact existing structure before proposing new; (2) review/optimize against what already exists; (3) executive summary — the one mandatory human decision gate, in plain terms; (4) build, only after approval.

In Scope

  • Construction plans for new/changed/retired OpenBao AppRoles, policies, KV secret paths
  • Consistency review — reuse over duplication, compaction over sprawl
  • The executive-summary format that makes a plan decidable at a glance
  • Registering what it builds into ops-warden's routing catalog
  • Its own audit trail of what it built, under which approved plan

Out of Scope

  • Deciding whether access should exist — that's architecture/founder, ops-mason builds what's already decided
  • Runtime authorization decisions — flex-auth
  • Identity/MFA — key-cape/Keycloak
  • Routing consumers to lanes once built — ops-warden
  • SSH certificate issuance — ops-warden
  • OpenBao cluster init/unseal, platform deploy — railiance-platform
  • Holding or logging secret values, ever

Current State

Charter only (INTENT.md). MASON-WP-0001 scopes the four-phase pipeline and its first real exercise: the rein-openweights OpenBao AppRole that glas-harness/GLAS-WP-0002-T02 is blocked on. No code yet.

Getting Oriented

  • Start with: INTENT.md
  • Agent instructions: AGENTS.md
  • Workplans: workplans/