ops-warden/intakes/intakes.md
tegwick 70d8b503f0
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assent to the NetKingdom security layer model (WARDEN-IN-0001)
gate-house asked ops-warden to assent to three boundary items ratified in
GH-DEC-2026-001. All three are assented in ADR-0010.

Staff: accepted. Grepping section 5 as it invites turned up a real
non-conformance — src/warden/vault.py is a direct OpenBao client performing a
write, and so is `warden desk`'s `bao kv put`. Section 5's only escape hatch is
read-only diagnostics, which does not cover a signing write, so both are
declared in INTENT.md as an engine gap with intended owner secrets-engine and
the blocker "no engine exposes an SSH-CA surface" — ADR-0003 turned inward
rather than an exemption argued for. taint.py is metadata-only and declared
under the read-only allowance; `warden access` proxies run under the caller's
identity and supply no authority of their own.

Doctrine versus runbook: accepted. NetKingdom Security Literacy becomes a lane
routing runbook that references gate-house doctrine instead of restating it. It
had also become a prose second source for registry/routing/catalog.yaml, which
ADR-0001 already rules against.

Lane versus rule: assented unconditionally, and the access-engine veto is not
exercised. One request on sequencing only — a window where both names resolve.

gate-house added to the routing tables in INTENT.md and SCOPE.md.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YWBMovyFoy9RRrfL7zKvPJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014535@bnt-lap001
Assistant-Session: d0036016-73e8-4da1-8e47-563e3ab39a3c
2026-08-28 21:47:44 +02:00

3.4 KiB

Intake records

WARDEN-IN-0001 — Assent requested: Staff layer, doctrine vs runbook, and the access lane/rule demarcation

id: WARDEN-IN-0001
kind: intake
title: 'Assent requested: Staff layer, doctrine vs runbook, and the access lane/rule
  demarcation'
status: closed
outcome: assented
origin: cross-repo
origin_ref: gate-house GH-DEC-2026-001
priority: medium
owner: ops-warden
requested_by: gate-house
standard: net-kingdom/canon/standards/security-layer-model_v0.1.md
description: 'gate-house asks ops-warden to assent to three boundary items. (1) ops-warden
  is Staff, bound by the rule that Staff acts only through Engine APIs and never touches
  Tooling directly (standard section 5). (2) Doctrine versus runbook: the NetKingdom
  Security Literacy section in ops-warden INTENT is evidence the security curriculum
  had no owner; it now has one in gate-house. Proposal is that doctrine and curriculum
  move to gate-house and that section becomes lane-specific runbooks referencing gate-house
  doctrine rather than restating it. ops-warden keeps the lanes it stewards and everything
  operational about them. (3) The access lane/rule demarcation, normative in standard
  section 8: ops-warden and ops-mason own access lanes — how a worker reaches a host;
  access-engine owns access rules — whether they may. This demarcation is the condition
  attached to renaming flex-auth to access-engine, so ops-warden effectively holds
  a veto on that name. Also requested: add gate-house to the Security Literacy and
  routing tables — currently every plane is listed and gate-house appears nowhere
  — routing doctrine and authority-model questions there while continuing to route
  policy decisions to access-engine. If moving the curriculum out leaves ops-warden
  unable to instruct its own workers, say so; the boundary is wrong if it does.'
notes: 'Assented to all three items in ADR-0010, with reasoning in
  history/2026-08-28-security-layer-model-assent.md. (1) Staff accepted; the section 5
  binding rule exposed a real non-conformance — src/warden/vault.py is a direct
  OpenBao client performing a write, as is warden desk''s bao kv put. Declared in
  INTENT.md as an engine gap with intended owner secrets-engine and blocker "no engine
  exposes an SSH-CA surface", not negotiated as an exemption; taint.py declared under
  the read-only allowance; warden access proxies run under the caller''s identity.
  An amendment is offered back to gate-house: a second sanctioned shape in section 5 for
  a declared engine gap carrying intended owner, blocker and review date, machine-readable
  so section 10 can tell a tracked gap from an undeclared violation. (2) Doctrine versus
  runbook accepted; the literacy section is now a lane routing runbook referencing
  gate-house doctrine. Answering gate-house''s test question: it does not leave ops-warden
  unable to instruct its workers, because what instructs them is warden plan / warden route
  and .claude/rules/credential-routing.md, which stays inline by design. (3) The lane/rule
  demarcation assented unconditionally and the access-engine veto not exercised — ops-warden
  already consumes decisions and renders none. One request on sequencing only: a deprecation
  window in which both names resolve (598 references across 82 files here). gate-house added
  to the routing tables in INTENT.md and SCOPE.md.'
created: '2026-08-28T19:30:28.087109Z'
updated: '2026-08-28T21:05:00Z'