The standard is accepted at v0.7, with SECURITY-COMPANION.md v0.2 as its operative form. Four ops-warden findings were adopted between v0.4 and v0.7 — §9.1's two marks, §5's Tooling scope rule, §6.4 obligation 1's second limb, and §13.1's existence — and both ops-warden declaration artifacts are now cited in the text as the estate's reference forms. INTENT.md gains frontmatter (layer: Staff, pep_shaped: true) because §11 requires a machine-readable declaration and prose cannot distinguish a declaration from a transcribed review. The note now covers the agent principal (§3.4), the PEP shape, the attributive evidence position, and the role the companion assigns: the estate is told to ask ops-warden which lane, which credential, which route. SCOPE.md records what is actually shipped against v0.7 and the honest conformance state — declared gap, which is tracked non-conformance, not conformance. The assessment checked every obligation against shipped code rather than intent. Three gaps survive: - §9.7.2 requires a PEP to state one revocation visibility deadline. Ours is unstated, and the honest value is uncomfortable: the cert TTL, up to 48h. A cert outlives revocation of the decision that authorized it — no CRL, no KRL distribution. That is a design property never written down, which is exactly what §9.7.2 exists to force into the open. - §3.4 rule 1 forbids standing credentials and requires issued, attributable authority. ADR-0004's boundary keys on WARDEN_AGENT_ID, which an agent sets about itself. key-cape now issues a real coding-agent identity, so the ops-warden half can stop being advisory. - §9.6 cadence remains undeclared. Attributive, so SHOULD not MUST, but silence through two reviews is the one outcome that is not defensible. WARDEN-WP-0034 addresses all three, plus the discoverability gap the companion creates and two items to route rather than absorb. 402 tests pass, ruff clean. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YWBMovyFoy9RRrfL7zKvPJ Assistant: claude-code Assistant-Model: opus Assistant-Process: 4014535@bnt-lap001 Assistant-Session: d0036016-73e8-4da1-8e47-563e3ab39a3c
32 KiB
SCOPE
This file helps you quickly understand what this repository is about, when it is relevant, and when it is not. Aspirational direction lives in
INTENT.md.
One-liner
Operational access steward and front door for the NetKingdom security model — issues
short-lived SSH certificates for adm/agt/atm actors, and for every other credential
need is the operator front door (warden access): routes to the owning subsystem and, for
exec_capable lanes (OpenBao reads, key-cape login), proxies the fetch as the caller
without taking custody. Also stewards workload security posture conformance and keeps ops
access guidance aligned with NetKingdom canon.
Where we are (2026-08-22)
ops-warden issues short-lived SSH certificates and routes every other credential
need to the subsystem that owns it. SSH signing is production-verified on
Railiance OpenBao (warden sign against https://bao.coulomb.social, host CA trust
deployed).
Access routing is shipped: wiki/AccessRouting.md, credential routing wiki,
NetKingdom security map, machine-readable pointer catalog
(registry/routing/catalog.yaml, WP-0010), and warden route lookup CLI
(list/show/find, --json, WP-0011).
Operator access assist is shipped (WP-0014): warden access gives advisory
handoffs for every catalog need and can proxy exec_capable lanes as the caller,
without taking custody of values.
Owner-native exec lanes are documented in the catalog (WP-0017–0019 plus
cross-repo stewardship): provisioned secret-exec routes to secrets-engine
(whynot-design-npm-publish, production-exercised); scoped OpenBao tokens for
ops-warden signing route to the railiance-platform credential broker
(ops-warden-warden-sign-token, RAILIANCE-WP-0005 T08, live 2026-07-01). ops-warden
points at the owner's front door — it does not mint OpenBao tokens or run
credential.py itself.
Workload security posture is shipped (WP-0015, all tasks done): dev/test/prod
environment posture, M0-M3 workload maturity, the secret-flow lattice, and blocker
triage language (T1); machine-readable descriptors + warden policy list|show (T2);
the read-only conformance checker scripts/check_secret_posture_conformance.py (T3);
and the dev-tier contract-double library warden.doubles (T4). Canon landing in
net-kingdom / info-tech-canon is owner-driven (tracked via coordination messages, T5).
The policy gate is zone-aware. The caller-identity path is production proven
and the flex-auth pin enforces caller authentication. WP-0032 adopted
security-zones_v0.1: the repo-wide policy.enabled and policy.fail_closed
settings are retired, target workload membership compiles into flex-auth resource
attributes, and ops-warden selects dependency failure behavior from the target
zone. Unknown membership is explicit and uses the versioned build profile.
Ops-warden itself declares z1-operational in tenancy.yaml.
ops-bridge cert_command pilot is shipped to pilot-ready (WP-0016): a read-only
readiness gate (scripts/check_tunnel_cert_readiness.py) plus an opt-in offline
contract smoke (--sign-smoke); the playbook leads with the gate and the pilot
(agt-state-hub-bridge) is handed to ops-bridge. The live tunnel cutover is
ops-bridge's to execute.
Credential hygiene and the policy front door shipped through July 2026:
disclosure hygiene and rotation guidance (WP-0026 — warden taint,
warden rotate-guide, agent read-boundary on high-risk lanes), the tenant secret
custody pattern (WP-0028, first lane binky company email IMAP), experiential memory
across worker/agent sessions (WP-0024), the Forgejo admin PAT lane (WP-0025), and the
posture-aware policy front door (WP-0029 — warden plan, warden desk, declared
organization_posture: build as a third axis). WP-0027 (tamper-resistant governance,
mass rotation/lockdown) is drafted and sits in backlog.
Delegation register is the open question (WP-0030, proposed). ops-warden fronts
11 catalog lanes as a caller-identity proxy with no record of which component should
own that front door. The primitive to delegate exists and is proven
(exec_owner/exec_command — secrets-engine for npm publish, the credential broker
for warden-sign) but is used by 2 of 24 lanes. See
history/2026-08-11-delegation-surface-assessment.md.
INTENT alignment: SSH issuance mission met in production. All ops-warden workplans
through WP-0029 are finished except WP-0027 (backlog) and WP-0030 (proposed).
Remaining distance is in other repos' lanes: ops-bridge running the cert_command pilot
cutover, flex-auth publishing the zone-aware pre-sign stance package,
the owner-driven WP-0015 canon landing, and — newly named — the missing owner front
doors that keep ops-warden holding interim lanes (secrets-engine, tenant-engine).
Layer-model conformance (v0.7, accepted)
ops-warden declares Staff, PEP-shaped, in INTENT.md frontmatter and in its
own voice — security-layer-model_v0.7 §11. Shipped declaration artifacts, both
cited in the standard as the estate's reference forms:
| Artifact | Declares | Status |
|---|---|---|
layer.yaml |
5 Tooling contacts mapped to §5.1/§5.2/§5.3 shapes + non-Tooling clients so the check is total | shipped; named reference form (§11) |
pep-stance.yaml |
unreachable-engine stance map, total per zone | shipped; registered in statute §13.1 (§6.4 obl. 3) |
scripts/check_layer_conformance.py |
every direct Tooling client maps to a declared shape | shipped; CI-enforced |
tests/test_layer_conformance.py |
the §5.2 no-authority property, and published stance map equals shipped default | shipped, 11 tests |
Conformance state under §11: declared gap — tracked non-conformance, not
conformance. Two §5.3 contacts (VaultCA signing write, warden desk bao kv put),
intended owner secrets-engine, registered in statute §13.
Four ops-warden findings have been adopted into the standard: §9.1's two marks
(pending vs declared-gap), §5's Tooling scope rule, §6.4 obligation 1's second
limb, and §13.1's existence. Reviews: history/2026-08-29-layer-model-v04-review.md,
-v06-review.md, -v07-scope-intent-assessment.md.
Issue vs route
ops-warden executes exactly one lane with its own authority and routes/assists the rest.
| Need | Subsystem | ops-warden role |
|---|---|---|
SSH cert for host/ops access (adm/agt/atm) |
ops-warden | Issue (warden sign) |
Scoped VAULT_TOKEN for warden-sign / policy-gate smoke |
railiance-platform credential broker | Route — owner-native credential exec; ops-warden does not mint |
| API key / DB cred / dynamic lease | OpenBao | Assist — route; proxy as caller only for exec_capable lanes |
| Provisioned secret-exec (e.g. npm publish) | secrets-engine (+ OpenBao custody) | Route — primary secrets-engine exec; warden access as fallback |
| "May I perform action X?" | flex-auth | Route — point at policy; consume decisions where configured |
| Login / OIDC / MFA | key-cape / Keycloak | Assist — route; proxy login lane when exec_capable |
| SSH tunnel / port forward | ops-bridge | Route — supply cert_command |
| Host principal deployment | railiance-infra | Route — point at Ansible |
Full role and boundary: wiki/AccessRouting.md. The catalog is a pointer layer —
it never restates an owner's procedure (authored steps exist only for the SSH lane).
Interim by default. SSH issuance is the only lane ops-warden owns permanently.
Where it proxies or assists, it is covering a need no component fronts yet — a
legitimate service, but a tracked gap, retired to the owner once their front door
exists (INTENT §9). Recording that intent per lane is WP-0030; today only
whynot-design-npm-publish and ops-warden-warden-sign-token carry it.
Gap analysis: history/2026-07-01-intent-scope-gap-analysis.md (current);
history/2026-06-24-intent-scope-gap-analysis.md (prior);
history/2026-06-18-post-wp0008-intent-scope-reassessment.md (SSH lane);
history/2026-06-18-access-routing-intent-shift-assessment.md (routing charter).
INTENT gap snapshot
| INTENT success criterion | Status |
|---|---|
| Worker knows which subsystem for each credential type | Met |
| SSH short-lived, inventoried, audited | Met (production) |
ops-bridge integrates via stable cert_command |
Pilot-ready — contract + readiness gate (check_tunnel_cert_readiness.py, WP-0016) shipped; live cutover handed to ops-bridge |
| NetKingdom evolution reflected in docs | Met |
| Non-SSH secrets stay out of ops-warden | Met |
| Workload posture / maturity model for secret-flow blockers | Met — two-axis standard + descriptors + conformance checker + dev doubles (WP-0015) |
| Every execution position explicitly permanent or interim with a named owner | Met — every catalog entry carries delegation:; warden route gaps lists the interim set (WP-0030) |
Maturity vector: D5 / A5 / C5 / R4 (Discovery / Availability / Completeness / Reliability)
| Dimension | Level | Meaning today |
|---|---|---|
| D5 | Discovery | Routing wiki + security map + pointer catalog + NK canon cross-links |
| A5 | Availability | CLI + warden route + warden access advisory & proxy front door + warden policy + opt-in policy gate + agent --json |
| C5 | Completeness | All ops-warden lanes shipped — SSH (prod), routing, access assist, posture conformance, cert_command pilot gate, disclosure hygiene, tenant custody, policy front door, delegation register (WP-0030) |
| R4 | Reliability | Live OpenBao sign + credential-broker policy-gate smoke evidence on Railiance (2026-07-01) |
Governing rules (ours)
The decisions that bind this repo are ADRs in docs/adr/, each owner: ops-warden —
meaning we follow them and we are the ones who may change them. Changing one is a
superseding ADR, never an in-place edit.
| ADR | Rule |
|---|---|
ADR-0001 |
The routing catalog is a pointer layer, never a second copy of an owner's procedure (CI-enforced) |
ADR-0002 |
ops-warden is a transparent conduit, never a secret broker |
ADR-0003 |
Cover gaps, but never silently own them |
ADR-0004 |
High-risk lanes refuse raw value streaming to agent sessions |
ADR-0005 |
Implement one lane narrowly, route everything else |
ADR-0006 |
Superseded: enforcement is zone-scoped, never a global flag |
ADR-0007 |
Build-stage permissiveness stops at credential disclosure; every lane carries an explicit risk grade |
ADR-0008 |
A lane's risk grade covers every field its path discloses, not just the field it is named after |
ADR-0009 |
Adopt security-zones v0.1 and compile explicit workload membership; PEP failure mode is per zone |
ADR-0010 |
ops-warden is Staff and PEP-shaped — it owns access lanes, never access rules; the direct OpenBao client is a declared engine gap, not an exemption |
Rules we follow but do not own — NetKingdom canon, the IAM profile, the
credential-management standard, the-custodian's ADR-001 workplan convention — are
cited, never copied here. Publishable through policy-nexus, which carries owner
into the published page and index.
Core Idea
Today: implements the SSH certificate lane from wiki/AccessManagementDirective.md
§§1–5 — CA signing, actor inventory, TTL policy, cert-side scorecard, optional
flex-auth pre-sign gate, and the cert_command interface for ops-bridge. Production
path uses OpenBao SSH engine (backend: vault).
Direction (INTENT): issue short-lived SSH certificates and route dev workers to key-cape, flex-auth, OpenBao, ops-bridge, and railiance components for everything else — implementing only the SSH certificate lane directly, pointing at the owner for the rest.
In Scope
Implemented (SSH lane)
- Local CA backend (
ssh-keygen -s) - OpenBao / Vault-compatible SSH engine backend (production-verified)
- Actor identity registry (
inventory.yaml) cert_command:warden sign <actor> --pubkey <path>→ cert on stdout- TTL enforcement per
ActorType(adm48 h,agt24 h,atm8 h) warden status, cleanup, scorecard, signatures log- Zone-aware flex-auth policy gate (
policy_decision_id, zone, failure mode, and outcome in the signing audit; no repo-wide enable switch) - Production flex-auth registry builder (
scripts/build_flex_auth_registry.py,registry/flex-auth/production_registry_snapshot.json) - Policy gate smoke runner (
scripts/policy_gate_production_smoke.sh) warden routelookup CLI (list/show/find,--json) over the pointer catalogwarden accessoperator front door (WP-0014): advisory handoff for any need, and a transparent, policy-gated, audited proxy (--fetch/--exec) forexec_capablelanes (OpenBao secret reads, key-cape login) — caller identity, value never heldwarden issueandops-ssh-wrapper(local backend; vault uses sign-only)- ops-bridge cert_command readiness gate (
scripts/check_tunnel_cert_readiness.py, WP-0016) — read-only preflight + opt-in offline contract smoke - Coordination worker (
warden worker, WP-0020) — autonomous triage of ops-warden's State Hub inbox via llm-connect. Conservative by default (triage + drafted replies, sends nothing);--full-autoopt-in. Four guardrails (fixed charter, action allowlist, no-secret invariant, dry-run/audit) enforced regardless of the brain. Scheduled (WP-0021) via asystemd --usertimer (scripts/install-worker-timer.sh); review loopwarden worker drafts | approve <id>+worker status; one-command kill switch (wiki/playbooks/scheduled-worker.md) - Runbooks for OpenBao config and Inter-Hub bootstrap SSH envelope
- warden-sign token routing (RAILIANCE-WP-0005 T08): catalog id
ops-warden-warden-sign-tokenand playbookwiki/playbooks/ops-warden-warden-sign-token.md— routesVAULT_TOKENneeds torailiance-platform/scripts/credential.py exec --grant ops-warden/warden-sign(preferred over manualexport VAULT_TOKEN);warden signemits broker hint when token env is unset (WP-0023) - Unified audit trail (WP-0022): append-only
audit.jsonl, secret-material guard, instrumentation on sign/access/worker paths,warden activityCLI merging legacy logs + optional State Hub notes (wiki/AuditTrail.md) - Experiential memory (WP-0024,
src/warden/memory.py) — recorded outcomes feed routing and coordination; no secret values, guardrail allowlist unchanged - Disclosure hygiene (WP-0026):
warden taint <catalog-id>(KVcustom_metadata, no data read),warden rotate-guide, safe fetch transports (--out/--exec/--wrap) with refusal to stream to non-terminal stdout, and the agent read-boundary onrisk: highlanes (exit 7 whenWARDEN_AGENT_IDis set) - Tenant secret custody (WP-0028): tenant vs
platform/workloads/...path convention, policy/CCR/catalog ownership, first lanebinky-company-email-imap - Policy front door (WP-0029):
warden plan "<need>" [--json]returningautonomous/founder_required(typed act) /unroutable(CCR stub);warden deskloopback founder surface (approve, OIDC login, paste-once provision straight into OpenBao);organization_posture: buildas posture axis C; catalog freshness reporting onwarden route listand in plan JSON
Stewardship (documentation and alignment)
- NetKingdom security routing guidance — which subsystem owns which credential type
- Wiki and config references aligned with OpenBao-first platform standard
- Capability registry entry for SSH certificate issuance
- Routing pointer catalog (
registry/routing/catalog.yaml) - Keeping ops access patterns consistent with
net-kingdomplatform architecture - Workload Security Posture standard (
wiki/WorkloadSecurityPosture.md), machine-readable posture descriptors (registry/policy/security-posture.yaml), the read-only conformance checker, and the dev-tier contract-double library
Shipped workplans (archived)
| WP | Focus |
|---|---|
| WP-0001–0005 | Initial CLI, quality, hygiene, OpenBao docs, hub sync |
| WP-0006 | Credential routing, security map, inventory patterns, OpenBao checklist |
| WP-0007 | Original opt-in flex-auth policy gate (global switch retired by WP-0032) |
| WP-0008 | Production sign verification, stewardship closeout, archive hygiene |
| WP-0009 | flex-auth registry + policy smoke; pickup brief for FLEX-WP-0007 |
| WP-0010 | Access routing charter + pointer catalog |
| WP-0011 | warden route lookup CLI |
| WP-0012 | Routing scenario playbooks (catalog + wiki expansion) |
| WP-0013 | Production integration closeout — cert_command playbook, token hygiene, principals drift |
| WP-0014 | Operator access assist — warden access advisory + proxy front door |
| WP-0015 | Workload security posture — two-axis standard, descriptors, conformance checker, dev doubles |
| WP-0016 | ops-bridge cert_command pilot — readiness gate (check_tunnel_cert_readiness.py) + handoff |
Recently shipped (July 2026)
| WP | Focus |
|---|---|
| WP-0017 | Access front-door discoverability |
| WP-0018 | whynot-design-npm-publish — first concrete secret lane (production-exercised) |
| WP-0019 | Route provisioned secret-exec lanes to secrets-engine (exec_owner pattern) |
| WP-0020 | Coordination worker (warden worker) |
| WP-0021 | Scheduled worker tick (systemd --user timer, kill switch) |
| WP-0022 | Unified audit trail + warden activity |
| WP-0023 | INTENT–SCOPE alignment closeout |
| WP-0024 | Experiential memory across worker/agent sessions (src/warden/memory.py) |
| WP-0025 | Forgejo admin PAT OpenBao lane (CCR-2026-0006) |
| WP-0026 | Credential disclosure hygiene — warden taint, warden rotate-guide, agent read-boundary, safe fetch transports |
| WP-0028 | Tenant secret custody pattern — tenant vs platform paths; first lane binky company email IMAP |
| WP-0029 | Policy front door — warden plan, warden desk, organization_posture: build third axis |
Open ops-warden work
| WP | Status | Focus |
|---|---|---|
| WP-0027 | active |
Break-glass design/rehearsal activated narrowly on T02; mass rotation and policy-manifest reconcile remain deferred |
| WP-0032 | finished |
Security zones adopted — global switch retired, explicit workload references compiled, and owner policy live |
| WP-0030 | proposed |
Delegation register — record intended owner + blocker on every interim lane, warden route gaps, promotion gate |
Remaining production distance is also in other repos' lanes (see Known gaps).
Known gaps (not ops-warden workplans)
| Gap | Owner | Notes |
|---|---|---|
ops-bridge cert_command on live tunnels |
ops-bridge | Playbook + readiness gate shipped (WP-0016); pilot cutover handed off, awaiting ops-bridge |
| Principals sync warden ↔ railiance-infra | ops-warden + infra | scripts/check_principals_drift.py — operator runs periodically |
| NK-WP-0009 joint SSH tutorial | net-kingdom | Parallel coordination track |
WP-0015 canon landing (generic WorkloadMaturityLevel + M0-M3 requirements) |
net-kingdom + info-tech-canon | ops-warden drafted + offered (coordination msgs); owner-driven landing |
| Owner front doors for workload secret lanes | secrets-engine | 6 lanes proxied by ops-warden that secrets-engine exec could front, as WP-0019 did for npm publish |
| Owner front door for tenant secret lanes | tenant-engine | WP-0028 defined the custody pattern; 3 tenant lanes still fronted by ops-warden proxy |
Out of Scope
- Issuing or custodying non-SSH secrets (API keys, DB creds, OpenBao tokens,
S3 STS, Inter-Hub keys) → OpenBao / railiance-platform credential broker /
secrets-engine with flex-auth policy where required; ops-warden documents paths,
routes to owner-native exec front doors, and may proxy caller-authenticated
exec_capablelanes only - Identity / OIDC / MFA → key-cape, Keycloak
- Authorization policy decisions → flex-auth
- flex-auth runtime deployment and secret-flow lattice enforcement → flex-auth
(
FLEX-WP-0007and follow-ups) - Tunnel lifecycle →
ops-bridge - Host principal deployment →
railiance-infra - OpenBao / Vault cluster deployment →
railiance-platform - Human admin SSH key generation (self-service
ssh-keygen) - Session recording, SIEM, SSO / Teleport at scale
- Permanently owning another component's lane. Covering an unfilled gap is in scope and expected; keeping it once secrets-engine / tenant-engine / user-engine can front it — or holding it without recording that it is interim — is not (INTENT §9)
Relevant When
- Issuing or refreshing an SSH cert for
adm/agt/atm - A worker needs a scoped
VAULT_TOKENfor productionwarden signor the flex-auth policy-gate smoke — route toops-warden-warden-sign-token, then runcredential execinrailiance-platform(no manual token paste) - A dev worker needs to know where to get credentials in the NetKingdom stack
- An agent needs
warden route findinstead of re-deriving routing from wiki prose ops-bridgeneeds acert_commandfor a tunnel- Adding actors to the principals inventory (regenerate flex-auth registry snapshot)
- Inter-Hub or bootstrap tasks need a short-lived agent SSH envelope
- Checking cert-side compliance (scorecard)
- Enabling or testing the opt-in flex-auth policy gate
- Classifying whether a credential blocker is a dev/test double, owner-routed prod gate, or maturity/posture violation
Not Relevant When
- Storing or vending API keys, OpenBao tokens, or runtime secrets (→ OpenBao / railiance-platform broker / secrets-engine)
- Policy decisions on resource access (→ flex-auth)
- Managing tunnels without SSH cert issuance (→ ops-bridge)
- Static-key-only legacy access (ops-bridge static key mode)
Current State
- SSH CLI: v0.1.0 — local + OpenBao backends
- Production sign: verified 2026-06-18 (
history/2026-06-17-openbao-production-verify.md) - Access routing: WP-0010 + WP-0011 shipped (
warden route, pointer catalog) - Policy gate: caller shipped (WP-0007); registry + smoke complete (WP-0009 archived).
WP-0031 shipped the calling identity and flex-auth's pin now runs
callerAuth.mode: enforce(FLEX-WP-0016) — the gate is ready and verified (decision:f3f7c88f9585582a, anonymous/v1/check-> 401). WP-0032 andADR-0009retired the global switch: the compiled target workload selects the zone, flex-auth owns stance, and ops-warden applies the zone's PEP failure mode. Re-check caller identity withscripts/check_policy_caller_identity.py. - Workload posture: WP-0015 shipped (standard, descriptors,
warden policy, conformance checker, dev doubles); canon landing owner-driven - ops-bridge cert_command: WP-0016 shipped to pilot-ready (readiness gate + offline contract smoke + handoff); live cutover is ops-bridge's
- Access front door: WP-0017 discoverability + WP-0018 first concrete secret lane
(
whynot-design-npm-publish), production-exercised — whynot-design published@whynot/design@0.4.0through the conduit. WP-0019 routes provisioned secret-exec lanes to secrets-engine (secrets-engine exec), proxy as transparent fallback - warden-sign broker routing: catalog
ops-warden-warden-sign-token+wiki/playbooks/ops-warden-warden-sign-token.md(RAILIANCE-WP-0005 T08) — livemake credential-exec-ops-warden-smokeproven 2026-07-01; manualexport VAULT_TOKENdocumented as fallback only - Audit + activity: WP-0022 shipped —
warden activity,wiki/AuditTrail.md - INTENT closeout: WP-0023 shipped — INTENT refresh, production flip/cutover
checklists, catalog promotion cadence, broker hint on missing
VAULT_TOKEN - Disclosure hygiene: WP-0026 shipped —
warden taint,warden rotate-guide, safe fetch transports (--out/--exec/--wrap), agent read-boundary onrisk: highlanes (wiki/playbooks/agent-read-boundary.md) - Tenant custody: WP-0028 shipped — tenant vs platform path convention; first lane
binky-company-email-imap. Front door is still an ops-warden proxy (tenant-engine gap) - Policy front door: WP-0029 shipped —
warden plan "<need>"(autonomous / founder_required / unroutable),warden deskfounder interaction surface, declaredorganization_posture: buildas a third posture axis, catalog freshness reporting - Delegation: 27 catalog lanes carry
delegation:(WP-0030). SSH ispermanent; owner-fronted lanes arenative; interim proxies nameintended_owner+blocked_on. Query:warden route gaps. - Active work: WP-0027 (
backlog); remaining production distance is other repos' lanes (and retiring interim covers as those owners ship front doors) - Integration docs: cert_command migration, token hygiene (broker-first), principals
drift (
wiki/playbooks/) - Latest assessment:
history/2026-08-11-delegation-surface-assessment.md - Latest workplans: WP-0029 (policy front door) shipped July 2026; WP-0030 (delegation register) shipped August 2026
How It Fits (NetKingdom)
key-cape / Keycloak identity claims
→ flex-auth authorization decisions
→ OpenBao runtime secrets & dynamic credentials
→ ops-warden SSH certs + operational access guidance
→ ops-bridge tunnel transport (cert_command consumer)
→ railiance-* deployment and host enforcement
Upstream: OpenBao SSH engine (production) or local CA (labs). Actor inventory in operator config or Git-tracked patterns. flex-auth registry snapshot derived from inventory when policy gate is enabled.
Downstream: ops-bridge (primary), kaizen agents, CI automations, human operators.
Terminology
ActorType:adm|agt|atmcert_command: shell command returning a cert on stdoutinventory.yaml: actor → principals + TTL registryLocalCA/VaultCA: signing backends (backend: local|vault)- Pointer catalog:
registry/routing/catalog.yaml— subsystem ownership lookup plus secret-freewarden accesshandoff metadata - Workload Security Posture: env posture (
dev/test/prod) plus maturity (M0-M3) used to decide whether a secret may flow to a workload
Related Repositories
| Repo | Relationship |
|---|---|
gate-house |
Owns the security layer model, doctrine, invariants, authority context, and conformance review. ops-warden routes doctrine questions there, and the companion routes the estate's path questions back to ops-warden (ADR-0010) |
net-kingdom |
Canonical security architecture; ops-warden aligns to it |
ops-bridge |
Primary cert_command consumer |
railiance-infra |
Host-side SSH principals and hardening |
railiance-platform |
OpenBao deployment and platform secrets |
flex-auth |
Authorization — ruled name access-engine; the only policy decision point. Policy package shipped (FLEX-WP-0006); runtime deploy FLEX-WP-0007 |
key-cape |
Identity / IAM Profile lightweight mode |
secrets-engine |
Owner-native secret-exec front door (secrets-engine exec/route); ops-warden routes provisioned secret lanes to it (WP-0019) and holds 6 more as interim proxies pending its front doors |
tenant-engine |
Intended owner of tenant/client secret front doors; ops-warden holds 3 tenant lanes as interim proxies (WP-0028 pattern, WP-0030 register) |
user-engine |
End-user identity/account lifecycle; no ops-warden lane today — route rather than absorb |
zone-engine |
Owns the security zone model and exception lifecycle (ADR-0006); ops-warden is its first consumer |
state-hub |
Workplan registry |
Provided Capabilities
type: security
title: SSH certificate issuance
description: Issues short-lived CA-signed SSH certificates for adm/agt/atm actors via a
pluggable cert_command interface; documents NetKingdom operational access routing;
supports local CA and OpenBao/Vault-compatible SSH engine backends.
keywords: [ssh, certificate, ca, credential, warden, ops-warden, pki, openbao, vault, netkingdom]
type: security
title: Operator access front door (caller-identity fetch proxy)
description: warden access is the operator front door for any NetKingdom credential need.
It renders the owner, auth method, path, and policy status, and for exec_capable lanes
(OpenBao secret reads, key-cape OIDC login) proxies the fetch as the caller — running
the owner's tool with the caller's identity and streaming the value to them. For
owner-native lanes (secrets-engine exec, railiance-platform credential broker) it routes
to the owner's front door instead of proxying. ops-warden takes no custody — transparent
conduit, not a broker. Use this to discover how to obtain an API key, DB credential,
npm token, warden-sign lease, or login — not a State Hub message.
keywords: [access, credential, secret, npm, token, api-key, openbao, key-cape, login, proxy, fetch, exec, warden-access, front-door, routing, warden-sign, vault_token, credential-broker]
Getting Oriented
| Read first | Purpose |
|---|---|
INTENT.md |
Why ops-warden exists and where it is going |
SCOPE.md |
What is implemented today (this file) |
docs/adr/README.md |
The rules ops-warden owns — and how to tell ours from inherited canon |
wiki/AccessRouting.md |
What ops-warden issues vs routes vs assists (role and boundary) |
wiki/OperatorAccessAssist.md |
warden access front door + conduit-vs-broker boundary + guardrails |
wiki/CredentialRouting.md |
Which subsystem for each credential need |
wiki/WorkloadSecurityPosture.md |
Secret-store posture, workload maturity, and blocker triage |
registry/routing/catalog.yaml |
Machine-readable routing pointer catalog |
net-kingdom/SECURITY-COMPANION.md |
The estate's operative security rules — start here |
layer.yaml |
Layer declaration: every Tooling contact and its §5 shape |
pep-stance.yaml |
Unreachable-engine stance map (§6.4); equals shipped behaviour by test |
tenancy.yaml |
Declared tenancy posture (I1 A1 E0 P n/a R n/a V0) and why each axis sits where it does |
wiki/NetKingdomSecurityMap.md |
Platform security component map |
examples/warden.production.example.yaml |
Production warden.yaml template |
wiki/PolicyGatedSigning.md |
flex-auth opt-in gate + registry rollout |
wiki/AccessManagementDirective.md |
SSH actor model |
wiki/OpsWardenConfig.md |
warden.yaml and OpenBao |
wiki/playbooks/ops-warden-warden-sign-token.md |
Scoped VAULT_TOKEN via credential broker (preferred path) |
wiki/playbooks/operator-openbao-token-hygiene.md |
Manual token fallback and hygiene rules |
wiki/AuditTrail.md |
Unified metadata-only audit + warden activity |
wiki/playbooks/catalog-lane-promotion.md |
draft → active catalog promotion checklist |
wiki/CertCommandInterface.md |
cert_command contract |
history/2026-08-11-delegation-surface-assessment.md |
Current assessment — where ops-warden covers gaps and who should own them |
workplans/WARDEN-WP-0030-delegation-register.md |
Delegation register plan (proposed) |
history/2026-07-01-intent-scope-gap-analysis.md |
Prior INTENT↔SCOPE gap analysis |
workplans/WARDEN-WP-0023-intent-scope-alignment-closeout.md |
Alignment closeout plan |
history/2026-06-24-intent-scope-gap-analysis.md |
Prior gap analysis |
history/2026-06-27-workload-security-posture-charter.md |
WP-0015 posture/conformance charter |
history/2026-06-18-post-wp0008-intent-scope-reassessment.md |
SSH lane gap analysis |
history/2026-06-18-access-routing-intent-shift-assessment.md |
Routing charter decision |
history/2026-06-23-flex-auth-policy-gate-production-smoke.md |
Policy gate smoke evidence |
net-kingdom/docs/platform-identity-security-architecture.md |
Platform security canon |