--- id: ops-warden-adr-0005 type: adr title: "ADR-0005 — Implement one lane narrowly, route everything else" domain: infotech repo: ops-warden status: accepted version: "1.0" revision: "1" owner: ops-warden binds: "ops-warden" created: "2026-06-18" updated: "2026-08-18" last_reviewed: "2026-08-18" review_interval: 6m enforced_by: "SCOPE.md; registry/routing/catalog.yaml warden_executes" supersedes: "" successor: "" --- # ADR-0005 — Implement one lane narrowly, route everything else ## Status Accepted. The founding charter decision, taken 2026-06-18 (`history/2026-06-18-access-routing-intent-shift-assessment.md`). ## Context ops-warden began as an SSH certificate manager. It then became the place workers asked when they did not know where a credential came from — which is a real need, and the obvious way to serve it is to start fetching credentials. Down that path is a component that issues SSH certificates, vends API keys, brokers tokens, and holds authority over all of them: a single point whose compromise is total. NetKingdom's architecture deliberately separates identity (key-cape), authorization (flex-auth), and secrets (OpenBao). A helpful front door that absorbed all three would quietly undo that separation, one convenience at a time. ## Decision **ops-warden executes exactly one lane with its own authority: SSH certificate issuance for `adm`/`agt`/`atm` actors.** `warden_executes: true` appears on one catalog entry and is expected to stay that way. **For every other need it routes, and where the lane is `exec_capable` it may assist by proxying as the caller** under `ADR-0002`. Routing is not a lesser service — it is the service. Knowing which subsystem owns a need, and being right about it, is what this repo sells. **Scope growth is tested by ownership, not by usefulness.** "Would this be handy in ops-warden?" is the wrong question and almost always answers yes. The right question is "does ops-warden have the authority to own this, permanently?" If the answer is no, the correct outcome is a pointer, or an `interim` cover recorded under `ADR-0003`. ## Consequences **The blast radius stays bounded and known.** Compromising ops-warden yields the SSH signing lane. That is worth defending well precisely because it is the only thing here. **We say no to requests that would be easy to say yes to.** `warden secret`, `warden login`, `warden bao`, `warden tunnel` do not exist and must not be invented; the agent instructions name them as anti-patterns because agents keep reaching for them. Each would be a day's work and a permanent widening. **Being useful therefore depends on the pointers being right**, which is the whole weight behind `ADR-0001`'s anchor enforcement and the catalog's review dates. A router that routes wrongly is worse than no router. **It leaves real gaps visible rather than filled.** Six workload lanes and three tenant lanes are covered interim because secrets-engine and tenant-engine have not shipped front doors. Under this ADR that is the correct state, tracked under `ADR-0003`, and not a signal that ops-warden should absorb them. ## Related - `SCOPE.md` — the issue-vs-route table - `wiki/AccessRouting.md` — role and boundary - `ADR-0001`, `ADR-0002`, `ADR-0003` — the three rules that follow from this one