The agent responsible to create, change, maintain and tear down access routes with new credentials, tokens, policies, etc inside net-kingdom. Ops-mason is responsible to build the security infrastructure as required and defined by architecture documents as a base for ops-warden..
Find a file
tegwick 7bd230c06a feat(mason): operators/ custody mount and its access policy
operators/ enabled as KV v2; operator-custody grants read/write on it.

Kept separate from platform-admin rather than folded in, though that
would have been one stanza. platform-admin lists the mounts an
administrator operates *on*; operators/ is the one mount an
administrator keeps things *in*. Separating them lets custody move
independently of administration, which is what the S6 trust stage
(two-of-three independent recovery control) requires and which cannot be
retrofitted once the grant is buried inside platform-admin.

Delete is deliberately absent from the policy. A credential is retired
by writing its successor, and KV v2 keeps the prior version — the
history that did not exist when the LLDAP predecessor was overwritten in
a browser password manager on 2026-08-27 and lost for good.

ops-mason-build verified behaviourally, not just by capability strings:
metadata reads succeed, `kv get` on the forge token returns permission
denied, and enabling a mount returns permission denied.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 3377672@bnt-lap001
Assistant-Session: 15463ccf-238f-4e13-b163-93aa25c6d166
2026-08-28 11:18:06 +02:00
bundles build: add guarded Kubernetes plane executor 2026-08-22 11:23:38 +02:00
docs build: provision and verify Whitehat foundational plane 2026-08-22 11:26:49 +02:00
intakes Close legacy identifier intake 2026-08-22 23:21:23 +02:00
manifests/whitehat-plane build: add guarded Kubernetes plane executor 2026-08-22 11:23:38 +02:00
plans feat(mason): deliver and verify the forge read credential 2026-08-27 23:46:42 +02:00
policies feat(mason): operators/ custody mount and its access policy 2026-08-28 11:18:06 +02:00
scripts fix(bao-session): drop the TTY guard on login 2026-08-28 11:06:53 +02:00
src/ops_mason build: provision and verify Whitehat foundational plane 2026-08-22 11:26:49 +02:00
tests build: provision and verify Whitehat foundational plane 2026-08-22 11:26:49 +02:00
workplans feat(mason): deliver and verify the forge read credential 2026-08-27 23:46:42 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-08-27 22:49:39 +02:00
.gitignore intake: hand off legacy MASON identifier scheme 2026-08-22 11:33:34 +02:00
.repo-classification.yaml chore(registrar): bind MASON-IN-0001 residual 2026-08-22 11:34:25 +02:00
AGENTS.md feat(mason): scoped, named OpenBao sessions instead of borrowing yours 2026-08-28 11:04:26 +02:00
INTENT.md Real build executed for real (MASON-WP-0001-T05, MASON-WP-0001 done 5/5) 2026-07-27 01:25:14 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-30 00:42:40 +02:00
pyproject.toml build: add guarded Kubernetes plane executor 2026-08-22 11:23:38 +02:00
README.md build: add guarded Kubernetes plane executor 2026-08-22 11:23:38 +02:00
SCOPE.md Tighten the ops-warden boundary after reviewing its actual repo 2026-07-27 00:44:37 +02:00
WORK-RECORDS.md chore(work-records): regenerate after MASON-WP-0003-T02 2026-08-27 22:49:56 +02:00

ops-mason

The builder of NetKingdom security infrastructure — creates, changes, maintains, and tears down access routes, credentials, tokens, and policies so that ops-warden always has something real to route to.

The four-phase process

  1. Construction plan — given an access demand, draft what needs building, respecting/extending/compacting existing structure first.
  2. Review and optimize — self-review the plan against what already exists, for consistency and ease of use.
  3. Executive summary — the one mandatory human decision gate: render who gets what access, for how long, and what it costs to reverse.
  4. Build — once approved, execute the plan.

See INTENT.md for the full responsibility boundary against ops-warden, OpenBao, flex-auth, and key-cape.

Guarded Kubernetes planes

Small Kubernetes security foundations can use the fail-closed ops-mason plane workflow. It pins source manifests and object identities, validates cluster context/RBAC/dependencies/drift, requires an approved construction plan plus exact digest for apply, and produces metadata-only evidence and a non-executing rollback plan.

See docs/kubernetes-plane.md.