RMASTER-ADR-0009 accepted · accepted-1 railiance-master reviewed 2026-08-29generated from canonical source — do not edit

NetKingdom Security-Layer Interaction Boundary

Source: railiance-master · docs/adr/ADR-0009-netkingdom-security-layer-interaction.md · 5ffd7d1b40d56249f490a318e728047fd3517c4c

Review due: 2027-02-28

Date: 2026-08-29 Status: Accepted

Context

NetKingdom Security Layer Model v0.7 is accepted. Section 20 restates Railiance workload-operation definitions owned by this repository and states consumption rules every Railiance consumer of NetKingdom security owes. Companion v0.2 §9 is the operative form of the same boundary.

This repository had declared the four axes and the workload coverage rule in its own voice, but had no machine-readable layer declaration, no recorded assent to §20, and no framework contract that bound rails, rapps, and reefs to those consumption rules. Admission (ADR-0006) and exposure (ADR-0008) were live and were not demarcated from authorization.

Statute §20.4: an interaction boundary between two frameworks is owned by neither alone. Changes to §20 require this repository's assent for the axis definitions and glas-harness assent for the session and tool-policy seam.

Ratified 2026-08-29 under RMASTER-WP-0026.

Decision

  1. This repository is Taxonomy of Railiance workload operations. The machine-readable declaration is layer.yaml. It is not a NetKingdom §4 catalog row. It is not PEP-shaped. It holds no Tooling-layer client.
  1. Statute §20.1 restates our definitions and does not author them. Workload, the four axes, and the rule that rein-* is not a fifth axis remain this repository's. NetKingdom may cite them; it may not redefine them without our assent.
  1. Statute §20.2 is the consumption constitution for every Railiance consumer of NetKingdom security. The detailed contract is docs/netkingdom-security-consumption-contract.md.
  1. Statute §20.3 remains unset. This repository will not imply a mapping of rails, rapps, reefs, or ownership onto Taxonomy, Tooling, Engine, or Staff. The five questions are tracked, unanswered, in docs/netkingdom-axis-layer-open-questions.md.
  1. Admission, exposure, and authorization stay three questions. ADR-0006 answers whether a binding may run in production. ADR-0008 answers who may reach a listener we control. access-engine answers whether an actor may perform an action. production-approved and exposure: public are not authorization decisions.
  1. Changes to this boundary require this repository's assent for the axis definitions. Changes that touch the glas-harness seam require glas-harness assent as well.

Consequences

  • Rails, rapps, and reefs consume access-engine, approval-engine, secrets-engine, and audit-core. They do not grow local substitutes.
  • This repository does not host a PDP, an approval store, a credential plane, an evidence archive, or an actuation surface.
  • PEP stance maps belong in the repositories that cause protected side effects, inventoried in statute §13.1, not here.
  • Observation-in-production and automatic containment remain estate-wide zeros. Framework plans must not assume they exist.
  • gate-house can cite this ADR as this repository's own-voice declaration and §20 assent, rather than a review note about us.

Notes

This ADR does not amend ADR-0001 through ADR-0008. It adds the security consumption axis those records did not have to name.