ops-warden/wiki
tegwick a70f559d40
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Apply GH-DEC-2026-017: INTENT.md governs, the sidecar is derived, no version
Verified against gate-house's own committed files before editing, not the inbox
message: GH-DEC-2026-017 in decisions/decisions.md at gate-house@def0af2,
amendments A9-A13 in docs/amendments/v0.8-section-11-declaration-amendments.md,
and sections 3, 4 and 11 of net-kingdom's security-layer-model_v0.8.md. The
ruling and docs/layer-declaration-precedence.md's secondary account agreed.

INTENT.md's frontmatter is the declaration; layer.yaml is a derived artifact,
now marked derived: true / derived_from: INTENT.md, and it does not govern.

standard_version is removed from BOTH forms. The ruling's general form is that a
layer declaration must not carry a standard version, and INTENT.md is the
declaration, so removing it from the sidecar alone would have left the field in
the only file that actually declares. INTENT.md's version-pinned `standard:`
path is de-versioned for the same reason: a pinned path reads as a validity
condition. The version ops-warden assented at stays with the assent, ADR-0010.

NO LAYER VALUE IS CHANGED. INTENT.md still says Staff and layer.yaml still says
staff. Section 3's vocabulary is closed, four tokens, and case-insensitive: the
two forms were never in disagreement about a layer, and the ruling asked nobody
to re-spell anything. The comment marking the divergence is rewritten from
"unruled, do not touch" to "ruled, folding case is the checker's job".

check_layer_conformance.py would have rejected the conforming declaration this
ruling produces -- it listed standard_version as a required key. It now reads
INTENT.md as the governing form, ASCII-folds before comparing, validates both
values against the closed four-token vocabulary (Taxonomy included; omitting it
is the defect A9 records against the estate's other validator), requires the
derived marking, rejects a returning standard_version in either file, and
reports a post-fold disagreement between the forms as a finding rather than
resolving it away by precedence.

The test asserts the fold, not equality. An equality assertion here would be
this repository quietly performing the re-spelling the ruling declined to order;
the fold still fails on a real layer divergence.

pep-stance.yaml is untouched. A stance map is not a layer declaration, and the
sidecar schema beyond the derived marking and the version is explicitly not
ruled.

layer.yaml is the form seven repositories copied, so the adopter change set is
written out in wiki/playbooks/netkingdom-layer-declaration.md -- including the
trap that an adopter which also copied the checker turns a conforming
declaration into MALFORMED exit 2 by removing the field alone. No other
repository is edited here.

Still open: where the removed version lives. A12 says the derived conformance
record "already MUST" carry it; ops-warden has a re-runnable checker that emits
nothing durable. Asked of gate-house in message 4220413a, unanswered, and left
open rather than answered by choosing. Nothing above depends on it.

Carries WARDEN-WP-0034-T06 to done.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
2026-09-21 02:38:55 +02:00
..
playbooks Apply GH-DEC-2026-017: INTENT.md governs, the sidecar is derived, no version 2026-09-21 02:38:55 +02:00
AccessManagementDirective.md Initial Commit 2026-03-28 00:45:43 +00:00
AccessRouting.md Scale the blocker window by lane risk, converging with risk-nexus 2026-08-21 13:29:29 +02:00
ActorInventoryPatterns.md WARDEN-WP-0006: NetKingdom stewardship docs and alignment 2026-06-17 08:22:45 +02:00
ApprovalConsumption.md Record GH-DEC-2026-015's narrow R3 permission on the approval page 2026-09-21 02:21:31 +02:00
AuditTrail.md Review layer model v0.6; publish the PEP stance map §6.4 requires 2026-08-29 10:20:49 +02:00
CertCommandInterface.md Retire CoulombCore references; correct the 16443 diagnosis 2026-08-19 19:31:41 +02:00
CredentialRouting.md Add NetKingdom SSO credential routing lanes 2026-08-23 21:43:12 +02:00
InterHubBootstrapAccessLane.md feat(WP-0012): add inter-hub-bootstrap-ssh catalog entry and align wiki 2026-06-24 12:45:23 +02:00
NetKingdomSecurityMap.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
OpenBaoSshEngineChecklist.md WARDEN-WP-0006: NetKingdom stewardship docs and alignment 2026-06-17 08:22:45 +02:00
OperatorAccessAssist.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
OpsWardenConfig.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
OpsWardenMemory.md Enable implicit phase-memory activation on every warden command. 2026-07-03 00:49:36 +02:00
PolicyGatedSigning.md docs: mark the unknown cell, measure the coverage we asked to publish 2026-09-10 08:02:10 +02:00
WorkloadSecurityPosture.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00