feat: complete local layer model v0.7 conformance work
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06eaf-3425-7f92-a0c2-bb4aa4faebe4
This commit is contained in:
tegwick 2026-09-05 01:19:48 +02:00
parent 89b117f640
commit 00145d705e
13 changed files with 279 additions and 27 deletions

View file

@ -40,6 +40,24 @@
version: 1
entries:
- id: netkingdom-layer-declaration
title: NetKingdom layer declaration and PEP stance-map route
risk: standard
workload_ref:
applicability: not-applicable
reason: "Repository conformance guidance, not a workload credential or runtime action."
need_keywords: [how, declare, layer, declaration, netkingdom, security, companion, pep, pep-shaped, stance, conformance, tooling, staff, engine]
owner_repo: ops-warden
subsystem: NetKingdom layer-conformance routing
warden_executes: false
wiki_ref: wiki/playbooks/netkingdom-layer-declaration.md#worker-checklist
canon_ref: net-kingdom/canon/standards/security-layer-model_v0.7.md
reviewed: "2026-09-04"
status: active
delegation:
mode: permanent
reviewed: "2026-09-04"
- id: ssh-cert-host-access
title: Short-lived SSH certificate for host / ops reachability
# Emits a signed certificate — a public artifact. The private key never leaves the caller (WARDEN-WP-0032-T05).