The agent responsible to create, change, maintain and tear down access routes with new credentials, tokens, policies, etc inside net-kingdom. Ops-mason is responsible to build the security infrastructure as required and defined by architecture documents as a base for ops-warden..
custody-inventory.py walks operators/ and platform/workloads/, prints each path's description, owner, consumers and recovery path, and marks any missing them. Metadata only, never a value, so it runs under ops-mason-build and can be handed to anyone orienting themselves. First run: 21 paths, 17 undescribed. Described the four this session touched, including on_loss — the field whose absence meant the LLDAP predecessor's recovery path had to be worked out from first principles while locked out. ops-mason-build gains create/update on */metadata/*, since a description is documentation rather than a value. delete stays absent: deleting a metadata entry destroys every version of the secret beneath it. It also now denies itself sys/policies/acl/ops-mason-build. Without that the policy was advisory — a token that can write policies can delete its own denials, so the claim that OpenBao enforces "never read a value" was not true as written. An exact path outranks the glob, so changing what ops-mason may do is now an operator act, visible as one in the audit log. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 3377672@bnt-lap001 Assistant-Session: 15463ccf-238f-4e13-b163-93aa25c6d166 |
||
|---|---|---|
| bundles | ||
| docs | ||
| intakes | ||
| manifests/whitehat-plane | ||
| plans | ||
| policies | ||
| scripts | ||
| src/ops_mason | ||
| tests | ||
| workplans | ||
| .custodian-brief.md | ||
| .gitignore | ||
| .repo-classification.yaml | ||
| AGENTS.md | ||
| INTENT.md | ||
| LICENSE | ||
| pyproject.toml | ||
| README.md | ||
| SCOPE.md | ||
| WORK-RECORDS.md | ||
ops-mason
The builder of NetKingdom security infrastructure — creates, changes, maintains, and tears down access routes, credentials, tokens, and policies so that ops-warden always has something real to route to.
- Why and boundaries: INTENT.md
- Current work: workplans/
The four-phase process
- Construction plan — given an access demand, draft what needs building, respecting/extending/compacting existing structure first.
- Review and optimize — self-review the plan against what already exists, for consistency and ease of use.
- Executive summary — the one mandatory human decision gate: render who gets what access, for how long, and what it costs to reverse.
- Build — once approved, execute the plan.
See INTENT.md for the full responsibility boundary against ops-warden,
OpenBao, flex-auth, and key-cape.
Guarded Kubernetes planes
Small Kubernetes security foundations can use the fail-closed ops-mason plane workflow. It pins source manifests and object identities, validates
cluster context/RBAC/dependencies/drift, requires an approved construction
plan plus exact digest for apply, and produces metadata-only evidence and a
non-executing rollback plan.