ops-warden/SCOPE.md
tegwick fd08950231
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Align INTENT and SCOPE to layer model v0.7; assess gaps; open WARDEN-WP-0034
The standard is accepted at v0.7, with SECURITY-COMPANION.md v0.2 as its
operative form. Four ops-warden findings were adopted between v0.4 and v0.7 —
§9.1's two marks, §5's Tooling scope rule, §6.4 obligation 1's second limb, and
§13.1's existence — and both ops-warden declaration artifacts are now cited in
the text as the estate's reference forms.

INTENT.md gains frontmatter (layer: Staff, pep_shaped: true) because §11 requires
a machine-readable declaration and prose cannot distinguish a declaration from a
transcribed review. The note now covers the agent principal (§3.4), the PEP
shape, the attributive evidence position, and the role the companion assigns:
the estate is told to ask ops-warden which lane, which credential, which route.

SCOPE.md records what is actually shipped against v0.7 and the honest conformance
state — declared gap, which is tracked non-conformance, not conformance.

The assessment checked every obligation against shipped code rather than intent.
Three gaps survive:

- §9.7.2 requires a PEP to state one revocation visibility deadline. Ours is
  unstated, and the honest value is uncomfortable: the cert TTL, up to 48h. A
  cert outlives revocation of the decision that authorized it — no CRL, no KRL
  distribution. That is a design property never written down, which is exactly
  what §9.7.2 exists to force into the open.
- §3.4 rule 1 forbids standing credentials and requires issued, attributable
  authority. ADR-0004's boundary keys on WARDEN_AGENT_ID, which an agent sets
  about itself. key-cape now issues a real coding-agent identity, so the
  ops-warden half can stop being advisory.
- §9.6 cadence remains undeclared. Attributive, so SHOULD not MUST, but silence
  through two reviews is the one outcome that is not defensible.

WARDEN-WP-0034 addresses all three, plus the discoverability gap the companion
creates and two items to route rather than absorb.

402 tests pass, ruff clean.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YWBMovyFoy9RRrfL7zKvPJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014535@bnt-lap001
Assistant-Session: d0036016-73e8-4da1-8e47-563e3ab39a3c
2026-08-29 14:50:55 +02:00

32 KiB
Raw Permalink Blame History

SCOPE

This file helps you quickly understand what this repository is about, when it is relevant, and when it is not. Aspirational direction lives in INTENT.md.


One-liner

Operational access steward and front door for the NetKingdom security model — issues short-lived SSH certificates for adm/agt/atm actors, and for every other credential need is the operator front door (warden access): routes to the owning subsystem and, for exec_capable lanes (OpenBao reads, key-cape login), proxies the fetch as the caller without taking custody. Also stewards workload security posture conformance and keeps ops access guidance aligned with NetKingdom canon.


Where we are (2026-08-22)

ops-warden issues short-lived SSH certificates and routes every other credential need to the subsystem that owns it. SSH signing is production-verified on Railiance OpenBao (warden sign against https://bao.coulomb.social, host CA trust deployed).

Access routing is shipped: wiki/AccessRouting.md, credential routing wiki, NetKingdom security map, machine-readable pointer catalog (registry/routing/catalog.yaml, WP-0010), and warden route lookup CLI (list/show/find, --json, WP-0011).

Operator access assist is shipped (WP-0014): warden access gives advisory handoffs for every catalog need and can proxy exec_capable lanes as the caller, without taking custody of values.

Owner-native exec lanes are documented in the catalog (WP-00170019 plus cross-repo stewardship): provisioned secret-exec routes to secrets-engine (whynot-design-npm-publish, production-exercised); scoped OpenBao tokens for ops-warden signing route to the railiance-platform credential broker (ops-warden-warden-sign-token, RAILIANCE-WP-0005 T08, live 2026-07-01). ops-warden points at the owner's front door — it does not mint OpenBao tokens or run credential.py itself.

Workload security posture is shipped (WP-0015, all tasks done): dev/test/prod environment posture, M0-M3 workload maturity, the secret-flow lattice, and blocker triage language (T1); machine-readable descriptors + warden policy list|show (T2); the read-only conformance checker scripts/check_secret_posture_conformance.py (T3); and the dev-tier contract-double library warden.doubles (T4). Canon landing in net-kingdom / info-tech-canon is owner-driven (tracked via coordination messages, T5).

The policy gate is zone-aware. The caller-identity path is production proven and the flex-auth pin enforces caller authentication. WP-0032 adopted security-zones_v0.1: the repo-wide policy.enabled and policy.fail_closed settings are retired, target workload membership compiles into flex-auth resource attributes, and ops-warden selects dependency failure behavior from the target zone. Unknown membership is explicit and uses the versioned build profile. Ops-warden itself declares z1-operational in tenancy.yaml.

ops-bridge cert_command pilot is shipped to pilot-ready (WP-0016): a read-only readiness gate (scripts/check_tunnel_cert_readiness.py) plus an opt-in offline contract smoke (--sign-smoke); the playbook leads with the gate and the pilot (agt-state-hub-bridge) is handed to ops-bridge. The live tunnel cutover is ops-bridge's to execute.

Credential hygiene and the policy front door shipped through July 2026: disclosure hygiene and rotation guidance (WP-0026 — warden taint, warden rotate-guide, agent read-boundary on high-risk lanes), the tenant secret custody pattern (WP-0028, first lane binky company email IMAP), experiential memory across worker/agent sessions (WP-0024), the Forgejo admin PAT lane (WP-0025), and the posture-aware policy front door (WP-0029 — warden plan, warden desk, declared organization_posture: build as a third axis). WP-0027 (tamper-resistant governance, mass rotation/lockdown) is drafted and sits in backlog.

Delegation register is the open question (WP-0030, proposed). ops-warden fronts 11 catalog lanes as a caller-identity proxy with no record of which component should own that front door. The primitive to delegate exists and is proven (exec_owner/exec_command — secrets-engine for npm publish, the credential broker for warden-sign) but is used by 2 of 24 lanes. See history/2026-08-11-delegation-surface-assessment.md.

INTENT alignment: SSH issuance mission met in production. All ops-warden workplans through WP-0029 are finished except WP-0027 (backlog) and WP-0030 (proposed). Remaining distance is in other repos' lanes: ops-bridge running the cert_command pilot cutover, flex-auth publishing the zone-aware pre-sign stance package, the owner-driven WP-0015 canon landing, and — newly named — the missing owner front doors that keep ops-warden holding interim lanes (secrets-engine, tenant-engine).

Layer-model conformance (v0.7, accepted)

ops-warden declares Staff, PEP-shaped, in INTENT.md frontmatter and in its own voice — security-layer-model_v0.7 §11. Shipped declaration artifacts, both cited in the standard as the estate's reference forms:

Artifact Declares Status
layer.yaml 5 Tooling contacts mapped to §5.1/§5.2/§5.3 shapes + non-Tooling clients so the check is total shipped; named reference form (§11)
pep-stance.yaml unreachable-engine stance map, total per zone shipped; registered in statute §13.1 (§6.4 obl. 3)
scripts/check_layer_conformance.py every direct Tooling client maps to a declared shape shipped; CI-enforced
tests/test_layer_conformance.py the §5.2 no-authority property, and published stance map equals shipped default shipped, 11 tests

Conformance state under §11: declared gap — tracked non-conformance, not conformance. Two §5.3 contacts (VaultCA signing write, warden desk bao kv put), intended owner secrets-engine, registered in statute §13.

Four ops-warden findings have been adopted into the standard: §9.1's two marks (pending vs declared-gap), §5's Tooling scope rule, §6.4 obligation 1's second limb, and §13.1's existence. Reviews: history/2026-08-29-layer-model-v04-review.md, -v06-review.md, -v07-scope-intent-assessment.md.

Issue vs route

ops-warden executes exactly one lane with its own authority and routes/assists the rest.

Need Subsystem ops-warden role
SSH cert for host/ops access (adm/agt/atm) ops-warden Issue (warden sign)
Scoped VAULT_TOKEN for warden-sign / policy-gate smoke railiance-platform credential broker Route — owner-native credential exec; ops-warden does not mint
API key / DB cred / dynamic lease OpenBao Assist — route; proxy as caller only for exec_capable lanes
Provisioned secret-exec (e.g. npm publish) secrets-engine (+ OpenBao custody) Route — primary secrets-engine exec; warden access as fallback
"May I perform action X?" flex-auth Route — point at policy; consume decisions where configured
Login / OIDC / MFA key-cape / Keycloak Assist — route; proxy login lane when exec_capable
SSH tunnel / port forward ops-bridge Route — supply cert_command
Host principal deployment railiance-infra Route — point at Ansible

Full role and boundary: wiki/AccessRouting.md. The catalog is a pointer layer — it never restates an owner's procedure (authored steps exist only for the SSH lane).

Interim by default. SSH issuance is the only lane ops-warden owns permanently. Where it proxies or assists, it is covering a need no component fronts yet — a legitimate service, but a tracked gap, retired to the owner once their front door exists (INTENT §9). Recording that intent per lane is WP-0030; today only whynot-design-npm-publish and ops-warden-warden-sign-token carry it.

Gap analysis: history/2026-07-01-intent-scope-gap-analysis.md (current); history/2026-06-24-intent-scope-gap-analysis.md (prior); history/2026-06-18-post-wp0008-intent-scope-reassessment.md (SSH lane); history/2026-06-18-access-routing-intent-shift-assessment.md (routing charter).


INTENT gap snapshot

INTENT success criterion Status
Worker knows which subsystem for each credential type Met
SSH short-lived, inventoried, audited Met (production)
ops-bridge integrates via stable cert_command Pilot-ready — contract + readiness gate (check_tunnel_cert_readiness.py, WP-0016) shipped; live cutover handed to ops-bridge
NetKingdom evolution reflected in docs Met
Non-SSH secrets stay out of ops-warden Met
Workload posture / maturity model for secret-flow blockers Met — two-axis standard + descriptors + conformance checker + dev doubles (WP-0015)
Every execution position explicitly permanent or interim with a named owner Met — every catalog entry carries delegation:; warden route gaps lists the interim set (WP-0030)

Maturity vector: D5 / A5 / C5 / R4 (Discovery / Availability / Completeness / Reliability)

Dimension Level Meaning today
D5 Discovery Routing wiki + security map + pointer catalog + NK canon cross-links
A5 Availability CLI + warden route + warden access advisory & proxy front door + warden policy + opt-in policy gate + agent --json
C5 Completeness All ops-warden lanes shipped — SSH (prod), routing, access assist, posture conformance, cert_command pilot gate, disclosure hygiene, tenant custody, policy front door, delegation register (WP-0030)
R4 Reliability Live OpenBao sign + credential-broker policy-gate smoke evidence on Railiance (2026-07-01)

Governing rules (ours)

The decisions that bind this repo are ADRs in docs/adr/, each owner: ops-warden — meaning we follow them and we are the ones who may change them. Changing one is a superseding ADR, never an in-place edit.

ADR Rule
ADR-0001 The routing catalog is a pointer layer, never a second copy of an owner's procedure (CI-enforced)
ADR-0002 ops-warden is a transparent conduit, never a secret broker
ADR-0003 Cover gaps, but never silently own them
ADR-0004 High-risk lanes refuse raw value streaming to agent sessions
ADR-0005 Implement one lane narrowly, route everything else
ADR-0006 Superseded: enforcement is zone-scoped, never a global flag
ADR-0007 Build-stage permissiveness stops at credential disclosure; every lane carries an explicit risk grade
ADR-0008 A lane's risk grade covers every field its path discloses, not just the field it is named after
ADR-0009 Adopt security-zones v0.1 and compile explicit workload membership; PEP failure mode is per zone
ADR-0010 ops-warden is Staff and PEP-shaped — it owns access lanes, never access rules; the direct OpenBao client is a declared engine gap, not an exemption

Rules we follow but do not own — NetKingdom canon, the IAM profile, the credential-management standard, the-custodian's ADR-001 workplan convention — are cited, never copied here. Publishable through policy-nexus, which carries owner into the published page and index.


Core Idea

Today: implements the SSH certificate lane from wiki/AccessManagementDirective.md §§15 — CA signing, actor inventory, TTL policy, cert-side scorecard, optional flex-auth pre-sign gate, and the cert_command interface for ops-bridge. Production path uses OpenBao SSH engine (backend: vault).

Direction (INTENT): issue short-lived SSH certificates and route dev workers to key-cape, flex-auth, OpenBao, ops-bridge, and railiance components for everything else — implementing only the SSH certificate lane directly, pointing at the owner for the rest.


In Scope

Implemented (SSH lane)

  • Local CA backend (ssh-keygen -s)
  • OpenBao / Vault-compatible SSH engine backend (production-verified)
  • Actor identity registry (inventory.yaml)
  • cert_command: warden sign <actor> --pubkey <path> → cert on stdout
  • TTL enforcement per ActorType (adm 48 h, agt 24 h, atm 8 h)
  • warden status, cleanup, scorecard, signatures log
  • Zone-aware flex-auth policy gate (policy_decision_id, zone, failure mode, and outcome in the signing audit; no repo-wide enable switch)
  • Production flex-auth registry builder (scripts/build_flex_auth_registry.py, registry/flex-auth/production_registry_snapshot.json)
  • Policy gate smoke runner (scripts/policy_gate_production_smoke.sh)
  • warden route lookup CLI (list/show/find, --json) over the pointer catalog
  • warden access operator front door (WP-0014): advisory handoff for any need, and a transparent, policy-gated, audited proxy (--fetch/--exec) for exec_capable lanes (OpenBao secret reads, key-cape login) — caller identity, value never held
  • warden issue and ops-ssh-wrapper (local backend; vault uses sign-only)
  • ops-bridge cert_command readiness gate (scripts/check_tunnel_cert_readiness.py, WP-0016) — read-only preflight + opt-in offline contract smoke
  • Coordination worker (warden worker, WP-0020) — autonomous triage of ops-warden's State Hub inbox via llm-connect. Conservative by default (triage + drafted replies, sends nothing); --full-auto opt-in. Four guardrails (fixed charter, action allowlist, no-secret invariant, dry-run/audit) enforced regardless of the brain. Scheduled (WP-0021) via a systemd --user timer (scripts/install-worker-timer.sh); review loop warden worker drafts | approve <id> + worker status; one-command kill switch (wiki/playbooks/scheduled-worker.md)
  • Runbooks for OpenBao config and Inter-Hub bootstrap SSH envelope
  • warden-sign token routing (RAILIANCE-WP-0005 T08): catalog id ops-warden-warden-sign-token and playbook wiki/playbooks/ops-warden-warden-sign-token.md — routes VAULT_TOKEN needs to railiance-platform/scripts/credential.py exec --grant ops-warden/warden-sign (preferred over manual export VAULT_TOKEN); warden sign emits broker hint when token env is unset (WP-0023)
  • Unified audit trail (WP-0022): append-only audit.jsonl, secret-material guard, instrumentation on sign/access/worker paths, warden activity CLI merging legacy logs + optional State Hub notes (wiki/AuditTrail.md)
  • Experiential memory (WP-0024, src/warden/memory.py) — recorded outcomes feed routing and coordination; no secret values, guardrail allowlist unchanged
  • Disclosure hygiene (WP-0026): warden taint <catalog-id> (KV custom_metadata, no data read), warden rotate-guide, safe fetch transports (--out / --exec / --wrap) with refusal to stream to non-terminal stdout, and the agent read-boundary on risk: high lanes (exit 7 when WARDEN_AGENT_ID is set)
  • Tenant secret custody (WP-0028): tenant vs platform/workloads/... path convention, policy/CCR/catalog ownership, first lane binky-company-email-imap
  • Policy front door (WP-0029): warden plan "<need>" [--json] returning autonomous / founder_required (typed act) / unroutable (CCR stub); warden desk loopback founder surface (approve, OIDC login, paste-once provision straight into OpenBao); organization_posture: build as posture axis C; catalog freshness reporting on warden route list and in plan JSON

Stewardship (documentation and alignment)

  • NetKingdom security routing guidance — which subsystem owns which credential type
  • Wiki and config references aligned with OpenBao-first platform standard
  • Capability registry entry for SSH certificate issuance
  • Routing pointer catalog (registry/routing/catalog.yaml)
  • Keeping ops access patterns consistent with net-kingdom platform architecture
  • Workload Security Posture standard (wiki/WorkloadSecurityPosture.md), machine-readable posture descriptors (registry/policy/security-posture.yaml), the read-only conformance checker, and the dev-tier contract-double library

Shipped workplans (archived)

WP Focus
WP-00010005 Initial CLI, quality, hygiene, OpenBao docs, hub sync
WP-0006 Credential routing, security map, inventory patterns, OpenBao checklist
WP-0007 Original opt-in flex-auth policy gate (global switch retired by WP-0032)
WP-0008 Production sign verification, stewardship closeout, archive hygiene
WP-0009 flex-auth registry + policy smoke; pickup brief for FLEX-WP-0007
WP-0010 Access routing charter + pointer catalog
WP-0011 warden route lookup CLI
WP-0012 Routing scenario playbooks (catalog + wiki expansion)
WP-0013 Production integration closeout — cert_command playbook, token hygiene, principals drift
WP-0014 Operator access assist — warden access advisory + proxy front door
WP-0015 Workload security posture — two-axis standard, descriptors, conformance checker, dev doubles
WP-0016 ops-bridge cert_command pilot — readiness gate (check_tunnel_cert_readiness.py) + handoff

Recently shipped (July 2026)

WP Focus
WP-0017 Access front-door discoverability
WP-0018 whynot-design-npm-publish — first concrete secret lane (production-exercised)
WP-0019 Route provisioned secret-exec lanes to secrets-engine (exec_owner pattern)
WP-0020 Coordination worker (warden worker)
WP-0021 Scheduled worker tick (systemd --user timer, kill switch)
WP-0022 Unified audit trail + warden activity
WP-0023 INTENTSCOPE alignment closeout
WP-0024 Experiential memory across worker/agent sessions (src/warden/memory.py)
WP-0025 Forgejo admin PAT OpenBao lane (CCR-2026-0006)
WP-0026 Credential disclosure hygiene — warden taint, warden rotate-guide, agent read-boundary, safe fetch transports
WP-0028 Tenant secret custody pattern — tenant vs platform paths; first lane binky company email IMAP
WP-0029 Policy front door — warden plan, warden desk, organization_posture: build third axis

Open ops-warden work

WP Status Focus
WP-0027 active Break-glass design/rehearsal activated narrowly on T02; mass rotation and policy-manifest reconcile remain deferred
WP-0032 finished Security zones adopted — global switch retired, explicit workload references compiled, and owner policy live
WP-0030 proposed Delegation register — record intended owner + blocker on every interim lane, warden route gaps, promotion gate

Remaining production distance is also in other repos' lanes (see Known gaps).

Known gaps (not ops-warden workplans)

Gap Owner Notes
ops-bridge cert_command on live tunnels ops-bridge Playbook + readiness gate shipped (WP-0016); pilot cutover handed off, awaiting ops-bridge
Principals sync warden ↔ railiance-infra ops-warden + infra scripts/check_principals_drift.py — operator runs periodically
NK-WP-0009 joint SSH tutorial net-kingdom Parallel coordination track
WP-0015 canon landing (generic WorkloadMaturityLevel + M0-M3 requirements) net-kingdom + info-tech-canon ops-warden drafted + offered (coordination msgs); owner-driven landing
Owner front doors for workload secret lanes secrets-engine 6 lanes proxied by ops-warden that secrets-engine exec could front, as WP-0019 did for npm publish
Owner front door for tenant secret lanes tenant-engine WP-0028 defined the custody pattern; 3 tenant lanes still fronted by ops-warden proxy

Out of Scope

  • Issuing or custodying non-SSH secrets (API keys, DB creds, OpenBao tokens, S3 STS, Inter-Hub keys) → OpenBao / railiance-platform credential broker / secrets-engine with flex-auth policy where required; ops-warden documents paths, routes to owner-native exec front doors, and may proxy caller-authenticated exec_capable lanes only
  • Identity / OIDC / MFA → key-cape, Keycloak
  • Authorization policy decisions → flex-auth
  • flex-auth runtime deployment and secret-flow lattice enforcement → flex-auth (FLEX-WP-0007 and follow-ups)
  • Tunnel lifecycle → ops-bridge
  • Host principal deployment → railiance-infra
  • OpenBao / Vault cluster deployment → railiance-platform
  • Human admin SSH key generation (self-service ssh-keygen)
  • Session recording, SIEM, SSO / Teleport at scale
  • Permanently owning another component's lane. Covering an unfilled gap is in scope and expected; keeping it once secrets-engine / tenant-engine / user-engine can front it — or holding it without recording that it is interim — is not (INTENT §9)

Relevant When

  • Issuing or refreshing an SSH cert for adm/agt/atm
  • A worker needs a scoped VAULT_TOKEN for production warden sign or the flex-auth policy-gate smoke — route to ops-warden-warden-sign-token, then run credential exec in railiance-platform (no manual token paste)
  • A dev worker needs to know where to get credentials in the NetKingdom stack
  • An agent needs warden route find instead of re-deriving routing from wiki prose
  • ops-bridge needs a cert_command for a tunnel
  • Adding actors to the principals inventory (regenerate flex-auth registry snapshot)
  • Inter-Hub or bootstrap tasks need a short-lived agent SSH envelope
  • Checking cert-side compliance (scorecard)
  • Enabling or testing the opt-in flex-auth policy gate
  • Classifying whether a credential blocker is a dev/test double, owner-routed prod gate, or maturity/posture violation

Not Relevant When

  • Storing or vending API keys, OpenBao tokens, or runtime secrets (→ OpenBao / railiance-platform broker / secrets-engine)
  • Policy decisions on resource access (→ flex-auth)
  • Managing tunnels without SSH cert issuance (→ ops-bridge)
  • Static-key-only legacy access (ops-bridge static key mode)

Current State

  • SSH CLI: v0.1.0 — local + OpenBao backends
  • Production sign: verified 2026-06-18 (history/2026-06-17-openbao-production-verify.md)
  • Access routing: WP-0010 + WP-0011 shipped (warden route, pointer catalog)
  • Policy gate: caller shipped (WP-0007); registry + smoke complete (WP-0009 archived). WP-0031 shipped the calling identity and flex-auth's pin now runs callerAuth.mode: enforce (FLEX-WP-0016) — the gate is ready and verified (decision:f3f7c88f9585582a, anonymous /v1/check -> 401). WP-0032 and ADR-0009 retired the global switch: the compiled target workload selects the zone, flex-auth owns stance, and ops-warden applies the zone's PEP failure mode. Re-check caller identity with scripts/check_policy_caller_identity.py.
  • Workload posture: WP-0015 shipped (standard, descriptors, warden policy, conformance checker, dev doubles); canon landing owner-driven
  • ops-bridge cert_command: WP-0016 shipped to pilot-ready (readiness gate + offline contract smoke + handoff); live cutover is ops-bridge's
  • Access front door: WP-0017 discoverability + WP-0018 first concrete secret lane (whynot-design-npm-publish), production-exercised — whynot-design published @whynot/design@0.4.0 through the conduit. WP-0019 routes provisioned secret-exec lanes to secrets-engine (secrets-engine exec), proxy as transparent fallback
  • warden-sign broker routing: catalog ops-warden-warden-sign-token + wiki/playbooks/ops-warden-warden-sign-token.md (RAILIANCE-WP-0005 T08) — live make credential-exec-ops-warden-smoke proven 2026-07-01; manual export VAULT_TOKEN documented as fallback only
  • Audit + activity: WP-0022 shipped — warden activity, wiki/AuditTrail.md
  • INTENT closeout: WP-0023 shipped — INTENT refresh, production flip/cutover checklists, catalog promotion cadence, broker hint on missing VAULT_TOKEN
  • Disclosure hygiene: WP-0026 shipped — warden taint, warden rotate-guide, safe fetch transports (--out/--exec/--wrap), agent read-boundary on risk: high lanes (wiki/playbooks/agent-read-boundary.md)
  • Tenant custody: WP-0028 shipped — tenant vs platform path convention; first lane binky-company-email-imap. Front door is still an ops-warden proxy (tenant-engine gap)
  • Policy front door: WP-0029 shipped — warden plan "<need>" (autonomous / founder_required / unroutable), warden desk founder interaction surface, declared organization_posture: build as a third posture axis, catalog freshness reporting
  • Delegation: 27 catalog lanes carry delegation: (WP-0030). SSH is permanent; owner-fronted lanes are native; interim proxies name intended_owner + blocked_on. Query: warden route gaps.
  • Active work: WP-0027 (backlog); remaining production distance is other repos' lanes (and retiring interim covers as those owners ship front doors)
  • Integration docs: cert_command migration, token hygiene (broker-first), principals drift (wiki/playbooks/)
  • Latest assessment: history/2026-08-11-delegation-surface-assessment.md
  • Latest workplans: WP-0029 (policy front door) shipped July 2026; WP-0030 (delegation register) shipped August 2026

How It Fits (NetKingdom)

key-cape / Keycloak     identity claims
        → flex-auth     authorization decisions
        → OpenBao       runtime secrets & dynamic credentials
        → ops-warden    SSH certs + operational access guidance
        → ops-bridge    tunnel transport (cert_command consumer)
        → railiance-*   deployment and host enforcement

Upstream: OpenBao SSH engine (production) or local CA (labs). Actor inventory in operator config or Git-tracked patterns. flex-auth registry snapshot derived from inventory when policy gate is enabled.

Downstream: ops-bridge (primary), kaizen agents, CI automations, human operators.


Terminology

  • ActorType: adm | agt | atm
  • cert_command: shell command returning a cert on stdout
  • inventory.yaml: actor → principals + TTL registry
  • LocalCA / VaultCA: signing backends (backend: local | vault)
  • Pointer catalog: registry/routing/catalog.yaml — subsystem ownership lookup plus secret-free warden access handoff metadata
  • Workload Security Posture: env posture (dev/test/prod) plus maturity (M0-M3) used to decide whether a secret may flow to a workload

Repo Relationship
gate-house Owns the security layer model, doctrine, invariants, authority context, and conformance review. ops-warden routes doctrine questions there, and the companion routes the estate's path questions back to ops-warden (ADR-0010)
net-kingdom Canonical security architecture; ops-warden aligns to it
ops-bridge Primary cert_command consumer
railiance-infra Host-side SSH principals and hardening
railiance-platform OpenBao deployment and platform secrets
flex-auth Authorization — ruled name access-engine; the only policy decision point. Policy package shipped (FLEX-WP-0006); runtime deploy FLEX-WP-0007
key-cape Identity / IAM Profile lightweight mode
secrets-engine Owner-native secret-exec front door (secrets-engine exec/route); ops-warden routes provisioned secret lanes to it (WP-0019) and holds 6 more as interim proxies pending its front doors
tenant-engine Intended owner of tenant/client secret front doors; ops-warden holds 3 tenant lanes as interim proxies (WP-0028 pattern, WP-0030 register)
user-engine End-user identity/account lifecycle; no ops-warden lane today — route rather than absorb
zone-engine Owns the security zone model and exception lifecycle (ADR-0006); ops-warden is its first consumer
state-hub Workplan registry

Provided Capabilities

type: security
title: SSH certificate issuance
description: Issues short-lived CA-signed SSH certificates for adm/agt/atm actors via a
  pluggable cert_command interface; documents NetKingdom operational access routing;
  supports local CA and OpenBao/Vault-compatible SSH engine backends.
keywords: [ssh, certificate, ca, credential, warden, ops-warden, pki, openbao, vault, netkingdom]
type: security
title: Operator access front door (caller-identity fetch proxy)
description: warden access is the operator front door for any NetKingdom credential need.
  It renders the owner, auth method, path, and policy status, and for exec_capable lanes
  (OpenBao secret reads, key-cape OIDC login) proxies the fetch as the caller — running
  the owner's tool with the caller's identity and streaming the value to them. For
  owner-native lanes (secrets-engine exec, railiance-platform credential broker) it routes
  to the owner's front door instead of proxying. ops-warden takes no custody — transparent
  conduit, not a broker. Use this to discover how to obtain an API key, DB credential,
  npm token, warden-sign lease, or login — not a State Hub message.
keywords: [access, credential, secret, npm, token, api-key, openbao, key-cape, login, proxy, fetch, exec, warden-access, front-door, routing, warden-sign, vault_token, credential-broker]

Getting Oriented

Read first Purpose
INTENT.md Why ops-warden exists and where it is going
SCOPE.md What is implemented today (this file)
docs/adr/README.md The rules ops-warden owns — and how to tell ours from inherited canon
wiki/AccessRouting.md What ops-warden issues vs routes vs assists (role and boundary)
wiki/OperatorAccessAssist.md warden access front door + conduit-vs-broker boundary + guardrails
wiki/CredentialRouting.md Which subsystem for each credential need
wiki/WorkloadSecurityPosture.md Secret-store posture, workload maturity, and blocker triage
registry/routing/catalog.yaml Machine-readable routing pointer catalog
net-kingdom/SECURITY-COMPANION.md The estate's operative security rules — start here
layer.yaml Layer declaration: every Tooling contact and its §5 shape
pep-stance.yaml Unreachable-engine stance map (§6.4); equals shipped behaviour by test
tenancy.yaml Declared tenancy posture (I1 A1 E0 P n/a R n/a V0) and why each axis sits where it does
wiki/NetKingdomSecurityMap.md Platform security component map
examples/warden.production.example.yaml Production warden.yaml template
wiki/PolicyGatedSigning.md flex-auth opt-in gate + registry rollout
wiki/AccessManagementDirective.md SSH actor model
wiki/OpsWardenConfig.md warden.yaml and OpenBao
wiki/playbooks/ops-warden-warden-sign-token.md Scoped VAULT_TOKEN via credential broker (preferred path)
wiki/playbooks/operator-openbao-token-hygiene.md Manual token fallback and hygiene rules
wiki/AuditTrail.md Unified metadata-only audit + warden activity
wiki/playbooks/catalog-lane-promotion.md draft → active catalog promotion checklist
wiki/CertCommandInterface.md cert_command contract
history/2026-08-11-delegation-surface-assessment.md Current assessment — where ops-warden covers gaps and who should own them
workplans/WARDEN-WP-0030-delegation-register.md Delegation register plan (proposed)
history/2026-07-01-intent-scope-gap-analysis.md Prior INTENT↔SCOPE gap analysis
workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md Alignment closeout plan
history/2026-06-24-intent-scope-gap-analysis.md Prior gap analysis
history/2026-06-27-workload-security-posture-charter.md WP-0015 posture/conformance charter
history/2026-06-18-post-wp0008-intent-scope-reassessment.md SSH lane gap analysis
history/2026-06-18-access-routing-intent-shift-assessment.md Routing charter decision
history/2026-06-23-flex-auth-policy-gate-production-smoke.md Policy gate smoke evidence
net-kingdom/docs/platform-identity-security-architecture.md Platform security canon