# NetKingdom layer declaration route Date: 2026-09-04 Catalog: `netkingdom-layer-declaration` Doctrine owner: `gate-house` Path steward: `ops-warden` This page is a route from the accepted NetKingdom security companion to the reference declaration artifacts. It does not redefine the layer model. ## Worker checklist 1. Read `net-kingdom/SECURITY-COMPANION.md`, then use the accepted `net-kingdom/canon/standards/security-layer-model_v0.7.md` for the normative layer, Tooling-contact, and PEP obligations. `v0.8` is proposed, not accepted, and its acceptance flip is held on amendments A9–A13 (`GH-DEC-2026-019`) — but those amendments' substance **already governs** through the decision record that authorises each of them, so declare to the shape below now. 2. **Declare in your own `INTENT.md` frontmatter.** That is the declaration (`GH-DEC-2026-017` §1). Use ops-warden's `layer.yaml` as the machine-readable reference *form*, which is a **derived** artifact that must be marked derived, must name `INTENT.md` as its source, and must agree with it. Adapt its repository, layer, contacts, and ownership facts; do not copy ops-warden-specific claims as your own. 3. If the repository is PEP-shaped, use `pep-stance.yaml` as the stance-map reference and publish the resulting path in the repository's layer declaration. 4. Adapt `scripts/check_layer_conformance.py` and `tests/test_layer_conformance.py`, then run both checks in the declaring repo. 5. Send the declaration and any stance-map inventory pointer to `gate-house` for doctrine/register review. Route credential or operational-lane questions back through `warden route`; do not place doctrine in the routing catalog. Reference checks in this checkout: ```bash python3 scripts/check_layer_conformance.py pytest tests/test_layer_conformance.py ``` ## Reference-form change set — 2026-09-21 (`GH-DEC-2026-017`) **If you copied ops-warden's `layer.yaml` before 2026-09-21, it is now the wrong shape in three ways.** The change is to the reference form, which is why `gate-house` asked ops-warden to make it here rather than asking each adopter to work it out. Apply all three in your own repository; ops-warden does not edit anyone else's files. 1. **Remove `standard_version:` from the sidecar *and* from your `INTENT.md` frontmatter.** A layer declaration MUST NOT carry a standard version (`GH-DEC-2026-017` §5, amendment A12): the declared layer is a standing property that does not change when the standard is revised, and a version in the declaration makes every revision read as though it invalidated every declaration. Keeping it "for information" was declined explicitly — a field that is present will be branched on. Version-scoped state belongs in the derived conformance record. If your checker lists `standard_version` as a required key, or prints it in a report line, it will now **reject a conforming declaration** — fix the checker in the same commit. 2. **Add `derived: true` and `derived_from: INTENT.md`.** The sidecar is a derived artifact under §11's derived-artifact rule and does not govern (`GH-DEC-2026-017` §1, amendment A11). If your `INTENT.md` has no frontmatter `layer:` key, add one — that, not the sidecar and not a prose line, is your declaration. 3. **Fold ASCII case before comparing a layer value, and re-spell nothing.** §3's vocabulary is closed and has **four** tokens — `Taxonomy`, `Tooling`, `Engine`, `Staff` — and comparison is case-insensitive (`GH-DEC-2026-017` §2 and §3, amendment A9). `Staff` and `staff` are the same value; a lowercase declaration is conforming, not tolerated. Two traps: a validator that admits only three tokens and rejects `Taxonomy` carries a defect — the layer this standard itself occupies is in the vocabulary; and an equality assertion between your two forms silently performs the re-spelling the ruling declined to order. Assert the **fold**, so a real layer divergence still fails. A disagreement between the two forms, after folding, is a **finding in its own right** and must be reported rather than resolved away by precedence. Precedence says which value is your answer; it does not say the disagreement did not happen. `pep-stance.yaml` is **not** a layer declaration and is out of scope here: its `standard_version` / `standard_version_reviewed` pair is a stance map's record of what was reviewed, and stays. ops-warden's applied instance of this change set is commit-local: `INTENT.md`, `layer.yaml`, `scripts/check_layer_conformance.py`, `tests/test_layer_conformance.py`. Read those four together rather than the sidecar alone. ## Ownership boundary `gate-house` owns what the model requires. Each repository owns the truth of its own declaration. `ops-warden` owns only this discoverable path to those sources.