From af9f5996e2d0e1b626ca45078f12232cf09218bf Mon Sep 17 00:00:00 2001 From: tegwick Date: Tue, 18 Aug 2026 22:36:39 +0200 Subject: [PATCH] Deliver ADR cleanup packets and publish first-wave arc42 stubs Packets go to seven owning repos by inbox and checklist. Railiance, NetKingdom, and State Hub now have published architecture stubs. --- .../addressing-and-permanence/v1/index.html | 6 +- .../v1/index.html | 6 +- .../v1/index.html | 6 +- .../v1/index.html | 6 +- .../v1/index.html | 6 +- .../v1/index.html | 6 +- .../v1/index.html | 6 +- .../v1/index.html | 6 +- .../railiance-repository-prefix/v1/index.html | 6 +- .../architecture/net-kingdom/v0.1/index.html | 244 +++++++++++++++++ .../v0.1/revisions/draft-1/index.html | 244 +++++++++++++++++ .../architecture/policy-nexus/v0.1/index.html | 6 +- build/architecture/railiance/v0.1/index.html | 245 +++++++++++++++++ .../v0.1/revisions/draft-1/index.html | 245 +++++++++++++++++ build/architecture/state-hub/v0.1/index.html | 246 ++++++++++++++++++ .../v0.1/revisions/draft-1/index.html | 246 ++++++++++++++++++ build/index.html | 2 +- build/publication-manifest.json | 73 +++++- .../standards/tenancy-posture/v0.1/index.html | 6 +- docs/adr-review/SUMMARY.md | 6 +- docs/adr-review/ledger.json | 81 ++++++ docs/adr-review/packets/README.md | 10 + docs/adr-review/packets/activity-core.md | 23 ++ docs/adr-review/packets/coulomb-social.md | 18 ++ docs/adr-review/packets/net-kingdom.md | 24 ++ docs/adr-review/packets/railiance-hosts.md | 24 ++ docs/adr-review/packets/railiance-infra.md | 23 ++ docs/adr-review/packets/railiance-platform.md | 15 ++ docs/adr-review/packets/the-custodian.md | 38 +++ publication.json | 25 ++ source-inventory.config.json | 9 +- source-inventory.json | 18 ++ ...S-WP-0002-arc42-architecture-collection.md | 15 +- ...EXUS-WP-0003-adr-review-cleanup-publish.md | 7 +- 34 files changed, 1891 insertions(+), 56 deletions(-) create mode 100644 build/architecture/net-kingdom/v0.1/index.html create mode 100644 build/architecture/net-kingdom/v0.1/revisions/draft-1/index.html create mode 100644 build/architecture/railiance/v0.1/index.html create mode 100644 build/architecture/railiance/v0.1/revisions/draft-1/index.html create mode 100644 build/architecture/state-hub/v0.1/index.html create mode 100644 build/architecture/state-hub/v0.1/revisions/draft-1/index.html create mode 100644 docs/adr-review/packets/README.md create mode 100644 docs/adr-review/packets/activity-core.md create mode 100644 docs/adr-review/packets/coulomb-social.md create mode 100644 docs/adr-review/packets/net-kingdom.md create mode 100644 docs/adr-review/packets/railiance-hosts.md create mode 100644 docs/adr-review/packets/railiance-infra.md create mode 100644 docs/adr-review/packets/railiance-platform.md create mode 100644 docs/adr-review/packets/the-custodian.md diff --git a/build/adr/addressing-and-permanence/v1/index.html b/build/adr/addressing-and-permanence/v1/index.html index 027f6aa..0a096cc 100644 --- a/build/adr/addressing-and-permanence/v1/index.html +++ b/build/adr/addressing-and-permanence/v1/index.html @@ -1,6 +1,6 @@ - + Policy addressing and permanence -
policy-nexus-adr-0001 accepted · accepted-1 the-custodian reviewed 2026-08-18generated from canonical source — do not edit

Policy addressing and permanence

Source: policy-nexus · docs/adr/ADR-0001-addressing-and-permanence.md · 9c6a1d3ce0a76b3cbd342ab74d3914aa339fd4e0

Review due: 2027-02-18

  • Status: accepted
  • Date: 2026-08-18
  • Owner: the-custodian
+
policy-nexus-adr-0001 accepted · accepted-1 the-custodian reviewed 2026-08-18generated from canonical source — do not edit

Policy addressing and permanence

Source: policy-nexus · docs/adr/ADR-0001-addressing-and-permanence.md · b93928330ef7a76976fa62989bb54f47dbe04832

Review due: 2027-02-18

  • Status: accepted
  • Date: 2026-08-18
  • Owner: the-custodian

Decision

A document has one stable current address and immutable revision addresses:

/<kind>/<document>/<version>/
@@ -211,4 +211,4 @@ a:focus-visible,.rail a:focus-visible{outline:2px solid var(--brass);outline-off
 

Consequences

  • Builds fail if a source disappears, an id differs, a path collides, or an immutable revision would change; stale output is not silently called fresh.
  • Pages show status, revision, owner, last review and exact source revision.
  • Availability remains restart recovery on the single-node rail. This contract promises stable addressing, not a high-availability SLA.
-
policy-nexus-adr-0001 · accepted-1 · acceptedpolicy-nexus · docs/adr/ADR-0001-addressing-and-permanence.md · 9c6a1d3ce0a76b3cbd342ab74d3914aa339fd4e0
+
policy-nexus-adr-0001 · accepted-1 · acceptedpolicy-nexus · docs/adr/ADR-0001-addressing-and-permanence.md · b93928330ef7a76976fa62989bb54f47dbe04832
diff --git a/build/adr/railiance-derived-rail-composition/v1/index.html b/build/adr/railiance-derived-rail-composition/v1/index.html index 20dbc34..3a22536 100644 --- a/build/adr/railiance-derived-rail-composition/v1/index.html +++ b/build/adr/railiance-derived-rail-composition/v1/index.html @@ -1,6 +1,6 @@ - + Derived Rail Composition -
RMASTER-ADR-0005 accepted · accepted-1 railiance-master reviewed 2026-07-26generated from canonical source — do not edit

Derived Rail Composition

Source: railiance-master · docs/adr/ADR-0005-derived-rail-composition.md · debbc13b4018f20db0997516b99afc1cc21084d7

Review due: 2027-01-26

Date: 2026-07-26 Status: Accepted

+
RMASTER-ADR-0005 accepted · accepted-1 railiance-master reviewed 2026-07-26generated from canonical source — do not edit

Derived Rail Composition

Source: railiance-master · docs/adr/ADR-0005-derived-rail-composition.md · 883533ed8af1703cc9bb4a2b24137e325bbbda47

Review due: 2027-01-26

Date: 2026-07-26 Status: Accepted

Context

Knative provides distinct workload activation and revision semantics but runs on Kubernetes. Treating it as an unrelated peer rail would duplicate generic workload lifecycle and substrate assumptions.

@@ -202,4 +202,4 @@ a:focus-visible,.rail a:focus-visible{outline:2px solid var(--brass);outline-off

Consequences

  • New platform workloads continue to use rail-kubernetes unless a specialized rail is justified.
  • Derived rails declare base-rail compatibility rather than copying lifecycle contracts.
  • Fabric and conformance tooling must understand rail dependency and readiness.
  • Knative installation stays with the S2 substrate owner.
-
RMASTER-ADR-0005 · accepted-1 · acceptedrailiance-master · docs/adr/ADR-0005-derived-rail-composition.md · debbc13b4018f20db0997516b99afc1cc21084d7
+
RMASTER-ADR-0005 · accepted-1 · acceptedrailiance-master · docs/adr/ADR-0005-derived-rail-composition.md · 883533ed8af1703cc9bb4a2b24137e325bbbda47
diff --git a/build/adr/railiance-first-wave-reef-rollout/v1/index.html b/build/adr/railiance-first-wave-reef-rollout/v1/index.html index b3a8426..d0b58af 100644 --- a/build/adr/railiance-first-wave-reef-rollout/v1/index.html +++ b/build/adr/railiance-first-wave-reef-rollout/v1/index.html @@ -1,6 +1,6 @@ - + First-Wave reef Rollout -
RMASTER-ADR-0004 accepted · accepted-1 railiance-master reviewed 2026-07-26generated from canonical source — do not edit

First-Wave reef Rollout

Source: railiance-master · docs/adr/ADR-0004-first-wave-reef-rollout.md · debbc13b4018f20db0997516b99afc1cc21084d7

Review due: 2027-01-26

Date: 2026-07-25 Status: Accepted

+
RMASTER-ADR-0004 accepted · accepted-1 railiance-master reviewed 2026-07-26generated from canonical source — do not edit

First-Wave reef Rollout

Source: railiance-master · docs/adr/ADR-0004-first-wave-reef-rollout.md · 883533ed8af1703cc9bb4a2b24137e325bbbda47

Review due: 2027-01-26

Date: 2026-07-25 Status: Accepted

Context

Railiance now has a reef model, but it needs a concrete first rollout.

The current substrate reality is not uniform:

@@ -214,4 +214,4 @@ a:focus-visible,.rail a:focus-visible{outline:2px solid var(--brass);outline-off

Notes

This ADR chooses the first rollout set. It does not require that every future substrate be modeled the same way.

-
RMASTER-ADR-0004 · accepted-1 · acceptedrailiance-master · docs/adr/ADR-0004-first-wave-reef-rollout.md · debbc13b4018f20db0997516b99afc1cc21084d7
+
RMASTER-ADR-0004 · accepted-1 · acceptedrailiance-master · docs/adr/ADR-0004-first-wave-reef-rollout.md · 883533ed8af1703cc9bb4a2b24137e325bbbda47
diff --git a/build/adr/railiance-private-by-default-exposure/v1/index.html b/build/adr/railiance-private-by-default-exposure/v1/index.html index 4d38576..ca3d8bc 100644 --- a/build/adr/railiance-private-by-default-exposure/v1/index.html +++ b/build/adr/railiance-private-by-default-exposure/v1/index.html @@ -1,6 +1,6 @@ - + Private-by-default Exposure -
RMASTER-ADR-0008 accepted · accepted-1 railiance-master reviewed 2026-08-15generated from canonical source — do not edit

Private-by-default Exposure

Source: railiance-master · docs/adr/ADR-0008-private-by-default-exposure.md · debbc13b4018f20db0997516b99afc1cc21084d7

Review due: 2027-02-15

Date: 2026-08-15 Status: Accepted

+
RMASTER-ADR-0008 accepted · accepted-1 railiance-master reviewed 2026-08-15generated from canonical source — do not edit

Private-by-default Exposure

Source: railiance-master · docs/adr/ADR-0008-private-by-default-exposure.md · 883533ed8af1703cc9bb4a2b24137e325bbbda47

Review due: 2027-02-15

Date: 2026-08-15 Status: Accepted

Context

ADR-0006 says a topology binding is not permission to run a workload in production. It does not say who may reach a listener. A working deploy, a hosts_rail / binds_rapp line, or an Ingress object has been enough to put something on the public internet.

Family readiness vocabularies are deliberately not unified (schemas/README.md). Reef lifecycle_state has no production-approved. Rapp readiness_state has no production-approved either. Exposure cannot be derived from those enums.

@@ -215,4 +215,4 @@ a:focus-visible,.rail a:focus-visible{outline:2px solid var(--brass);outline-off

Consequences

  • ADR-0006 still answers "may this binding run in production?" This ADR answers "who may reach the listener?" Do not merge the axes.
  • The three readiness enums stay distinct on purpose.
  • Family schemas grow an additive exposure field. Rapp data_classification: public is a different field and must not be reused as the posture name.
  • Implementation stays in the owning repos. This ADR does not install NetworkPolicy, UFW, Ingress, or tunnels.
  • Existing public surfaces on reef-railiance remain up until named as grants. This ADR is not a shutdown plan.
  • CoulombCore host inventory and Q7 / Goss reaction stay outside this decision.
-
RMASTER-ADR-0008 · accepted-1 · acceptedrailiance-master · docs/adr/ADR-0008-private-by-default-exposure.md · debbc13b4018f20db0997516b99afc1cc21084d7
+
RMASTER-ADR-0008 · accepted-1 · acceptedrailiance-master · docs/adr/ADR-0008-private-by-default-exposure.md · 883533ed8af1703cc9bb4a2b24137e325bbbda47
diff --git a/build/adr/railiance-rail-kubernetes-wave-1-boundary/v1/index.html b/build/adr/railiance-rail-kubernetes-wave-1-boundary/v1/index.html index 1556574..424025b 100644 --- a/build/adr/railiance-rail-kubernetes-wave-1-boundary/v1/index.html +++ b/build/adr/railiance-rail-kubernetes-wave-1-boundary/v1/index.html @@ -1,6 +1,6 @@ - + Wave 1 rail-kubernetes Boundary -
RMASTER-ADR-0002 accepted · accepted-1 railiance-master reviewed 2026-07-25generated from canonical source — do not edit

Wave 1 rail-kubernetes Boundary

Source: railiance-master · docs/adr/ADR-0002-rail-kubernetes-wave-1-boundary.md · debbc13b4018f20db0997516b99afc1cc21084d7

Review due: 2027-01-25

Date: 2026-07-25 Status: Accepted

+
RMASTER-ADR-0002 accepted · accepted-1 railiance-master reviewed 2026-07-25generated from canonical source — do not edit

Wave 1 rail-kubernetes Boundary

Source: railiance-master · docs/adr/ADR-0002-rail-kubernetes-wave-1-boundary.md · 883533ed8af1703cc9bb4a2b24137e325bbbda47

Review due: 2027-01-25

Date: 2026-07-25 Status: Accepted

Context

Railiance wants rail-* repos to represent workload execution contracts rather than abstract naming ideas.

Today, the concrete Kubernetes workload contract already exists, but it is embedded in railiance-cluster. That repo currently owns both:

@@ -215,4 +215,4 @@ a:focus-visible,.rail a:focus-visible{outline:2px solid var(--brass);outline-off

Notes

This ADR does not require all current files to move immediately.

It requires the ownership line to be explicit now, so practical repo separation can proceed without ambiguity.

-
RMASTER-ADR-0002 · accepted-1 · acceptedrailiance-master · docs/adr/ADR-0002-rail-kubernetes-wave-1-boundary.md · debbc13b4018f20db0997516b99afc1cc21084d7
+
RMASTER-ADR-0002 · accepted-1 · acceptedrailiance-master · docs/adr/ADR-0002-rail-kubernetes-wave-1-boundary.md · 883533ed8af1703cc9bb4a2b24137e325bbbda47
diff --git a/build/adr/railiance-rapp-declaration-contract/v1/index.html b/build/adr/railiance-rapp-declaration-contract/v1/index.html index 7782392..e915aa4 100644 --- a/build/adr/railiance-rapp-declaration-contract/v1/index.html +++ b/build/adr/railiance-rapp-declaration-contract/v1/index.html @@ -1,6 +1,6 @@ - + Rapp Declaration Contract -
RMASTER-ADR-0007 accepted · accepted-1 railiance-master reviewed 2026-08-13generated from canonical source — do not edit

Rapp Declaration Contract

Source: railiance-master · docs/adr/ADR-0007-rapp-declaration-contract.md · debbc13b4018f20db0997516b99afc1cc21084d7

Review due: 2027-02-13

Date: 2026-08-13 Status: Accepted

+
RMASTER-ADR-0007 accepted · accepted-1 railiance-master reviewed 2026-08-13generated from canonical source — do not edit

Rapp Declaration Contract

Source: railiance-master · docs/adr/ADR-0007-rapp-declaration-contract.md · 883533ed8af1703cc9bb4a2b24137e325bbbda47

Review due: 2027-02-13

Date: 2026-08-13 Status: Accepted

Context

RMASTER-WP-0017 through RMASTER-WP-0019 established the four-axis model and materialized the first family repos. The model held up. Its enforcement did not.

A 2026-08-11 survey by railiance-platform found that the three live rapp.yaml files were mutually unreadable: rollout, smoke, and rollback contracts used different shapes; metadata that both rails carry consistently appeared in only one rapp; reef-railiance bound_rapps listed rapp-qonto only, while rapp-openbao and rapp-postgres were already live on the same reef. docs/repo-family-bootstrap-contract.md named fields in prose and could not catch any of this.

@@ -207,4 +207,4 @@ a:focus-visible,.rail a:focus-visible{outline:2px solid var(--brass);outline-off

Consequences

  • Drift across family declarations fails in tools/validate-family-declarations.py instead of accumulating in prose.
  • railiance-platform RAILIANCE-WP-0015-T02 can converge rapp-openbao and rapp-postgres onto one shape. Migration belongs to the owning repos; this ADR does not move any declaration.
  • reef-railiance must stop treating bound_rapps: [rapp-qonto] as source of truth. The list is already stale.
  • Three further rapp-* repos (rapp-secrets-engine, rapp-tenant-engine, rapp-user-engine) carry the family prefix and no declaration. They are visible to the validator as undeclared and must be declared, renamed, or retired by their owners.
  • Calling the validator from fix-consistency still waits on the-custodian admitting the family prefixes into the classification standard. That sequencing is not this repo's.
-
RMASTER-ADR-0007 · accepted-1 · acceptedrailiance-master · docs/adr/ADR-0007-rapp-declaration-contract.md · debbc13b4018f20db0997516b99afc1cc21084d7
+
RMASTER-ADR-0007 · accepted-1 · acceptedrailiance-master · docs/adr/ADR-0007-rapp-declaration-contract.md · 883533ed8af1703cc9bb4a2b24137e325bbbda47
diff --git a/build/adr/railiance-rapp-first-wave-selection/v1/index.html b/build/adr/railiance-rapp-first-wave-selection/v1/index.html index 893a6e0..4a91fb6 100644 --- a/build/adr/railiance-rapp-first-wave-selection/v1/index.html +++ b/build/adr/railiance-rapp-first-wave-selection/v1/index.html @@ -1,6 +1,6 @@ - + First-Wave rapp Selection -
RMASTER-ADR-0003 accepted · accepted-1 railiance-master reviewed 2026-07-25generated from canonical source — do not edit

First-Wave rapp Selection

Source: railiance-master · docs/adr/ADR-0003-rapp-first-wave-selection.md · debbc13b4018f20db0997516b99afc1cc21084d7

Review due: 2027-01-25

Date: 2026-07-25 Status: Accepted

+
RMASTER-ADR-0003 accepted · accepted-1 railiance-master reviewed 2026-07-25generated from canonical source — do not edit

First-Wave rapp Selection

Source: railiance-master · docs/adr/ADR-0003-rapp-first-wave-selection.md · 883533ed8af1703cc9bb4a2b24137e325bbbda47

Review due: 2027-01-25

Date: 2026-07-25 Status: Accepted

Context

Railiance wants rapp-* repos to represent managed workload packages rather than new ownership layers.

The current workload surfaces already suggest several candidates:

@@ -213,4 +213,4 @@ a:focus-visible,.rail a:focus-visible{outline:2px solid var(--brass);outline-off

Notes

This ADR chooses sequence, not a mandatory destination for every workload in the ecosystem.

-
RMASTER-ADR-0003 · accepted-1 · acceptedrailiance-master · docs/adr/ADR-0003-rapp-first-wave-selection.md · debbc13b4018f20db0997516b99afc1cc21084d7
+
RMASTER-ADR-0003 · accepted-1 · acceptedrailiance-master · docs/adr/ADR-0003-rapp-first-wave-selection.md · 883533ed8af1703cc9bb4a2b24137e325bbbda47
diff --git a/build/adr/railiance-reef-production-admission/v1/index.html b/build/adr/railiance-reef-production-admission/v1/index.html index b749c2f..1575326 100644 --- a/build/adr/railiance-reef-production-admission/v1/index.html +++ b/build/adr/railiance-reef-production-admission/v1/index.html @@ -1,6 +1,6 @@ - + Reef Production Admission -
RMASTER-ADR-0006 accepted · accepted-1 railiance-master reviewed 2026-08-15generated from canonical source — do not edit

Reef Production Admission

Source: railiance-master · docs/adr/ADR-0006-reef-production-admission.md · debbc13b4018f20db0997516b99afc1cc21084d7

Review due: 2027-02-15

Date: 2026-07-26 Status: Accepted

+
RMASTER-ADR-0006 accepted · accepted-1 railiance-master reviewed 2026-08-15generated from canonical source — do not edit

Reef Production Admission

Source: railiance-master · docs/adr/ADR-0006-reef-production-admission.md · 883533ed8af1703cc9bb4a2b24137e325bbbda47

Review due: 2027-02-15

Date: 2026-07-26 Status: Accepted

Context

Fabric topology can say that a reef hosts a rail or binds a workload, but that does not demonstrate capacity, isolation, recoverability, or approval for a critical internet-facing service.

@@ -203,4 +203,4 @@ a:focus-visible,.rail a:focus-visible{outline:2px solid var(--brass);outline-off

Consequences

  • hosts_rail and binds_rapp no longer imply deployability.
  • reef-railiance may host Knative in wave 2, but Qonto cannot be called production-approved solely from that declaration.
  • Repeated evidence collection should become functional automation.
  • production-approved is not permission to publish a listener. See ADR-0008.
-
RMASTER-ADR-0006 · accepted-1 · acceptedrailiance-master · docs/adr/ADR-0006-reef-production-admission.md · debbc13b4018f20db0997516b99afc1cc21084d7
+
RMASTER-ADR-0006 · accepted-1 · acceptedrailiance-master · docs/adr/ADR-0006-reef-production-admission.md · 883533ed8af1703cc9bb4a2b24137e325bbbda47
diff --git a/build/adr/railiance-repository-prefix/v1/index.html b/build/adr/railiance-repository-prefix/v1/index.html index 27f85e7..54c187a 100644 --- a/build/adr/railiance-repository-prefix/v1/index.html +++ b/build/adr/railiance-repository-prefix/v1/index.html @@ -1,6 +1,6 @@ - + Repository Prefix Architecture -
RMASTER-ADR-0001 accepted · accepted-1 railiance-master reviewed 2026-07-25generated from canonical source — do not edit

Repository Prefix Architecture

Source: railiance-master · docs/adr/ADR-0001-repository-prefix-architecture.md · debbc13b4018f20db0997516b99afc1cc21084d7

Review due: 2027-01-25

Date: 2026-07-25 Status: Accepted

+
RMASTER-ADR-0001 accepted · accepted-1 railiance-master reviewed 2026-07-25generated from canonical source — do not edit

Repository Prefix Architecture

Source: railiance-master · docs/adr/ADR-0001-repository-prefix-architecture.md · 883533ed8af1703cc9bb4a2b24137e325bbbda47

Review due: 2027-01-25

Date: 2026-07-25 Status: Accepted

Context

Railiance already has a meaningful set of ownership repos such as railiance-infra, railiance-cluster, railiance-platform, railiance-enablement, railiance-apps, railiance-forge, and railiance-fabric.

That structure is useful, but it does not by itself capture all of the dimensions Railiance now needs.

@@ -232,4 +232,4 @@ a:focus-visible,.rail a:focus-visible{outline:2px solid var(--brass);outline-off

Notes

This ADR defines the repository taxonomy. It does not yet mandate a full migration or rename of existing repos. Migration should happen when it produces clearer ownership and lower ambiguity, not merely for naming purity.

-
RMASTER-ADR-0001 · accepted-1 · acceptedrailiance-master · docs/adr/ADR-0001-repository-prefix-architecture.md · debbc13b4018f20db0997516b99afc1cc21084d7
+
RMASTER-ADR-0001 · accepted-1 · acceptedrailiance-master · docs/adr/ADR-0001-repository-prefix-architecture.md · 883533ed8af1703cc9bb4a2b24137e325bbbda47
diff --git a/build/architecture/net-kingdom/v0.1/index.html b/build/architecture/net-kingdom/v0.1/index.html new file mode 100644 index 0000000..ba8d65e --- /dev/null +++ b/build/architecture/net-kingdom/v0.1/index.html @@ -0,0 +1,244 @@ + + + + +NetKingdom architecture + +
net-kingdom-architecture proposed · draft-1 net-kingdom reviewed 2026-08-18generated from canonical source — do not edit

NetKingdom architecture

Source: net-kingdom · docs/architecture/net-kingdom_v0.1.md · ba5d8642e91a31055eafdaef6993d779f6af7e06

Review due: 2027-02-18

About this document

+

First-wave arc42 for NetKingdom: the estate's identity and tenancy security core. Chapter 9 lists governing ADRs and standards; it does not paste them.

+
+

01Introduction and Goals

+

NetKingdom is the open security core for DevSecOps on Kubernetes. It owns identity, tenancy posture, and the contracts that flex-auth, key-cape, tenant-engine, and railiance workloads implement.

+

1.1 Requirements Overview

+
  • One IAM profile, versioned, owned here.
  • Tenancy described as graduated axes, not a single on/off switch.
  • Workload packaging and credential vending have explicit boundaries.
+

1.2 Quality Goals

+
  1. Provider-neutral identity contract.
  2. Recursive multi-tenant authorization that implementers can declare.
  3. Honest about what is not there yet (Tenancy Posture).
+

1.3 Stakeholders

+
RoleConcern
net-kingdomCanon owner for identity and tenancy.
flex-auth / key-cape / tenant-engineImplementers of the contracts.
railiance-masterWorkload packaging on the rail.
the-custodianFederation; does not redefine these concepts.
+
+

02Architecture Constraints

+

N/A for this stub.

+
+

03System Scope and Context

+

In: IAM profile, tenancy posture, tenant/user-engine boundaries, credential management, playbook capability contract, NetKingdom ADRs. Out: publication (policy-nexus), rail runtime (railiance), estate work-factory (the-custodian).

+

3.1 Business Context

+

Security here is dynamic and adversarial. The system exists so implementers share one contract instead of copying a neighbour.

+

3.2 Technical Context

+

Consumers: flex-auth, key-cape, tenant-engine, audit-core, rApps. Published today: Tenancy Posture /standards/tenancy-posture/v0.1/.

+
+

04Solution Strategy

+

N/A for this stub — recursive multi-tenant identity (ADR-0006) and the IAM profile ownership rule (ADR-0011) are the spine.

+
+

05Building Block View

+

5.1 Level 1 – System/Top-Level

+

N/A for this stub.

+
+

06Runtime View

+

N/A for this stub.

+
+

07Deployment View

+

N/A for this stub.

+
+

08Cross-Cutting Concepts

+

N/A for this stub.

+
+

09Architecture Decisions

+
SourceStatusNotes
canon/standards/tenancy-posture_v0.1.mdproposedPublished. First publication of this site.
canon/standards/iam-profile_v0.3.mdacceptedCurrent profile. Needs a unique publication id (v0.2 still shares netkingdom-iam-profile).
canon/standards/iam-profile_v0.2.mdshould be supersededv0.3 supersedes it; front-matter still accepted.
docs/adr/ADR-0006ADR-0015see filesIdentity, orchestration, IAM ownership, tenant roles, packaging. Publish after NK-ADR-* prefix and review metadata.
+

Custodian ADR-008 is superseded by Tenancy Posture and is not current.

+
+

10Quality Requirements

+

N/A for this stub.

+
+

11Risks and Technical Debt

+

N/A for this stub. Residual: IAM Profile id collision (WP-0003 packet).

+
+

12Glossary

+
TermMeaning
IAM ProfileProvider-neutral OIDC contract owned here.
Tenancy PostureGraduated axes for describing multi-tenancy.
Tenant-engineLifecycle and capability roles for tenants.
+
net-kingdom-architecture · draft-1 · proposednet-kingdom · docs/architecture/net-kingdom_v0.1.md · ba5d8642e91a31055eafdaef6993d779f6af7e06
diff --git a/build/architecture/net-kingdom/v0.1/revisions/draft-1/index.html b/build/architecture/net-kingdom/v0.1/revisions/draft-1/index.html new file mode 100644 index 0000000..ba8d65e --- /dev/null +++ b/build/architecture/net-kingdom/v0.1/revisions/draft-1/index.html @@ -0,0 +1,244 @@ + + + + +NetKingdom architecture + +
net-kingdom-architecture proposed · draft-1 net-kingdom reviewed 2026-08-18generated from canonical source — do not edit

NetKingdom architecture

Source: net-kingdom · docs/architecture/net-kingdom_v0.1.md · ba5d8642e91a31055eafdaef6993d779f6af7e06

Review due: 2027-02-18

About this document

+

First-wave arc42 for NetKingdom: the estate's identity and tenancy security core. Chapter 9 lists governing ADRs and standards; it does not paste them.

+
+

01Introduction and Goals

+

NetKingdom is the open security core for DevSecOps on Kubernetes. It owns identity, tenancy posture, and the contracts that flex-auth, key-cape, tenant-engine, and railiance workloads implement.

+

1.1 Requirements Overview

+
  • One IAM profile, versioned, owned here.
  • Tenancy described as graduated axes, not a single on/off switch.
  • Workload packaging and credential vending have explicit boundaries.
+

1.2 Quality Goals

+
  1. Provider-neutral identity contract.
  2. Recursive multi-tenant authorization that implementers can declare.
  3. Honest about what is not there yet (Tenancy Posture).
+

1.3 Stakeholders

+
RoleConcern
net-kingdomCanon owner for identity and tenancy.
flex-auth / key-cape / tenant-engineImplementers of the contracts.
railiance-masterWorkload packaging on the rail.
the-custodianFederation; does not redefine these concepts.
+
+

02Architecture Constraints

+

N/A for this stub.

+
+

03System Scope and Context

+

In: IAM profile, tenancy posture, tenant/user-engine boundaries, credential management, playbook capability contract, NetKingdom ADRs. Out: publication (policy-nexus), rail runtime (railiance), estate work-factory (the-custodian).

+

3.1 Business Context

+

Security here is dynamic and adversarial. The system exists so implementers share one contract instead of copying a neighbour.

+

3.2 Technical Context

+

Consumers: flex-auth, key-cape, tenant-engine, audit-core, rApps. Published today: Tenancy Posture /standards/tenancy-posture/v0.1/.

+
+

04Solution Strategy

+

N/A for this stub — recursive multi-tenant identity (ADR-0006) and the IAM profile ownership rule (ADR-0011) are the spine.

+
+

05Building Block View

+

5.1 Level 1 – System/Top-Level

+

N/A for this stub.

+
+

06Runtime View

+

N/A for this stub.

+
+

07Deployment View

+

N/A for this stub.

+
+

08Cross-Cutting Concepts

+

N/A for this stub.

+
+

09Architecture Decisions

+
SourceStatusNotes
canon/standards/tenancy-posture_v0.1.mdproposedPublished. First publication of this site.
canon/standards/iam-profile_v0.3.mdacceptedCurrent profile. Needs a unique publication id (v0.2 still shares netkingdom-iam-profile).
canon/standards/iam-profile_v0.2.mdshould be supersededv0.3 supersedes it; front-matter still accepted.
docs/adr/ADR-0006ADR-0015see filesIdentity, orchestration, IAM ownership, tenant roles, packaging. Publish after NK-ADR-* prefix and review metadata.
+

Custodian ADR-008 is superseded by Tenancy Posture and is not current.

+
+

10Quality Requirements

+

N/A for this stub.

+
+

11Risks and Technical Debt

+

N/A for this stub. Residual: IAM Profile id collision (WP-0003 packet).

+
+

12Glossary

+
TermMeaning
IAM ProfileProvider-neutral OIDC contract owned here.
Tenancy PostureGraduated axes for describing multi-tenancy.
Tenant-engineLifecycle and capability roles for tenants.
+
net-kingdom-architecture · draft-1 · proposednet-kingdom · docs/architecture/net-kingdom_v0.1.md · ba5d8642e91a31055eafdaef6993d779f6af7e06
diff --git a/build/architecture/policy-nexus/v0.1/index.html b/build/architecture/policy-nexus/v0.1/index.html index b70ce49..1713475 100644 --- a/build/architecture/policy-nexus/v0.1/index.html +++ b/build/architecture/policy-nexus/v0.1/index.html @@ -1,6 +1,6 @@ - + Policy Nexus architecture -
policy-nexus-architecture proposed · draft-1 the-custodian reviewed 2026-08-18generated from canonical source — do not edit

Policy Nexus architecture

Source: policy-nexus · docs/architecture/policy-nexus_v0.1.md · 9c6a1d3ce0a76b3cbd342ab74d3914aa339fd4e0

Review due: 2027-02-18

About this document

+
policy-nexus-architecture proposed · draft-1 the-custodian reviewed 2026-08-18generated from canonical source — do not edit

Policy Nexus architecture

Source: policy-nexus · docs/architecture/policy-nexus_v0.1.md · b93928330ef7a76976fa62989bb54f47dbe04832

Review due: 2027-02-18

About this document

This document follows the arc42 template for the publication surface at policy.coulomb.social. It is the first-wave architecture document this repository is allowed to author. Other first-wave systems are written in their owning repos.

01Introduction and Goals

@@ -245,4 +245,4 @@ a:focus-visible,.rail a:focus-visible{outline:2px solid var(--brass);outline-off

12Glossary

TermMeaning
Current addressThe stable URL for the document as it now stands.
Revision addressWrite-once URL for one source digest.
Publication entryOne object in publication.json. Discovery is not publication.
First-wave completeChapters 1, 3, 4, 5.1, 9 and 12 are real; others real or N/A.
-
policy-nexus-architecture · draft-1 · proposedpolicy-nexus · docs/architecture/policy-nexus_v0.1.md · 9c6a1d3ce0a76b3cbd342ab74d3914aa339fd4e0
+
policy-nexus-architecture · draft-1 · proposedpolicy-nexus · docs/architecture/policy-nexus_v0.1.md · b93928330ef7a76976fa62989bb54f47dbe04832
diff --git a/build/architecture/railiance/v0.1/index.html b/build/architecture/railiance/v0.1/index.html new file mode 100644 index 0000000..7ea7fe8 --- /dev/null +++ b/build/architecture/railiance/v0.1/index.html @@ -0,0 +1,245 @@ + + + + +Railiance architecture + +
railiance-architecture proposed · draft-1 railiance-master reviewed 2026-08-18generated from canonical source — do not edit

Railiance architecture

Source: railiance-master · docs/architecture/railiance_v0.1.md · 883533ed8af1703cc9bb4a2b24137e325bbbda47

Review due: 2027-02-18

About this document

+

First-wave arc42 for the Railiance runtime substrate. Deeper chapters belong to follow-on work in this repo. Chapter 9 lists the ADRs this repo already publishes; it does not paste them.

+
+

01Introduction and Goals

+

Railiance-master is the authoritative source for Railiance framework architecture: repo families, workload models, and substrate boundaries that implementation repos must not invent locally.

+

1.1 Requirements Overview

+
  • Name the rails, reefs, and rApps and who owns each boundary.
  • Keep those decisions in docs/adr/ with publication-grade metadata.
  • Consume platform packages; do not fork identity or tenancy.
+

1.2 Quality Goals

+
  1. Reviewable boundary decisions.
  2. Private-by-default exposure until admission.
  3. Derived rails compose; they do not fork policy.
+

1.3 Stakeholders

+
RoleConcern
railiance-masterFramework language and first-wave rApp set.
railiance-platformS3, placement, substrate services.
railiance-appsProduction digest bindings.
NetKingdomIdentity and tenancy posture of workloads.
+
+

02Architecture Constraints

+

N/A for this stub.

+
+

03System Scope and Context

+

In: rails, reefs, rApp packaging, admission, exposure defaults. Out: tenant identity semantics (NetKingdom), publication of policy (policy-nexus), OS baseline (railiance-hosts).

+

3.1 Business Context

+

Implementation repos solve immediate cluster problems. This system holds the shared meaning so those repos do not drift.

+

3.2 Technical Context

+

Neighbours: railiance-platform, railiance-apps, rapp-* packages, the reef (Traefik, cert-manager), Forgejo, NetKingdom, policy-nexus.

+
+

04Solution Strategy

+

N/A for this stub — repository-prefix architecture and rapp-first wave are already in the ADRs in §9.

+
+

05Building Block View

+

5.1 Level 1 – System/Top-Level

+

N/A for this stub.

+
+

06Runtime View

+

N/A for this stub.

+
+

07Deployment View

+

N/A for this stub.

+
+

08Cross-Cutting Concepts

+

N/A for this stub.

+
+

09Architecture Decisions

+

Published on policy.coulomb.social from this repo:

+
IdStatusDecision
RMASTER-ADR-0001acceptedRepository prefix architecture
RMASTER-ADR-0002acceptedWave 1 rail-kubernetes boundary
RMASTER-ADR-0003acceptedFirst-wave rapp selection
RMASTER-ADR-0004acceptedFirst-wave reef rollout
RMASTER-ADR-0005acceptedDerived rail composition
RMASTER-ADR-0006acceptedReef production admission
RMASTER-ADR-0007acceptedRapp declaration contract
RMASTER-ADR-0008acceptedPrivate-by-default exposure
+

Unresolved: identical accepted ADR-003/004 copies in railiance-hosts and railiance-infra. Not listed as current here until those owners rule.

+
+

10Quality Requirements

+

N/A for this stub.

+
+

11Risks and Technical Debt

+

N/A for this stub.

+
+

12Glossary

+
TermMeaning
RailA composed runtime path.
ReefThe production admission environment.
rAppA packaged workload bound by a declaration contract.
+
railiance-architecture · draft-1 · proposedrailiance-master · docs/architecture/railiance_v0.1.md · 883533ed8af1703cc9bb4a2b24137e325bbbda47
diff --git a/build/architecture/railiance/v0.1/revisions/draft-1/index.html b/build/architecture/railiance/v0.1/revisions/draft-1/index.html new file mode 100644 index 0000000..7ea7fe8 --- /dev/null +++ b/build/architecture/railiance/v0.1/revisions/draft-1/index.html @@ -0,0 +1,245 @@ + + + + +Railiance architecture + +
railiance-architecture proposed · draft-1 railiance-master reviewed 2026-08-18generated from canonical source — do not edit

Railiance architecture

Source: railiance-master · docs/architecture/railiance_v0.1.md · 883533ed8af1703cc9bb4a2b24137e325bbbda47

Review due: 2027-02-18

About this document

+

First-wave arc42 for the Railiance runtime substrate. Deeper chapters belong to follow-on work in this repo. Chapter 9 lists the ADRs this repo already publishes; it does not paste them.

+
+

01Introduction and Goals

+

Railiance-master is the authoritative source for Railiance framework architecture: repo families, workload models, and substrate boundaries that implementation repos must not invent locally.

+

1.1 Requirements Overview

+
  • Name the rails, reefs, and rApps and who owns each boundary.
  • Keep those decisions in docs/adr/ with publication-grade metadata.
  • Consume platform packages; do not fork identity or tenancy.
+

1.2 Quality Goals

+
  1. Reviewable boundary decisions.
  2. Private-by-default exposure until admission.
  3. Derived rails compose; they do not fork policy.
+

1.3 Stakeholders

+
RoleConcern
railiance-masterFramework language and first-wave rApp set.
railiance-platformS3, placement, substrate services.
railiance-appsProduction digest bindings.
NetKingdomIdentity and tenancy posture of workloads.
+
+

02Architecture Constraints

+

N/A for this stub.

+
+

03System Scope and Context

+

In: rails, reefs, rApp packaging, admission, exposure defaults. Out: tenant identity semantics (NetKingdom), publication of policy (policy-nexus), OS baseline (railiance-hosts).

+

3.1 Business Context

+

Implementation repos solve immediate cluster problems. This system holds the shared meaning so those repos do not drift.

+

3.2 Technical Context

+

Neighbours: railiance-platform, railiance-apps, rapp-* packages, the reef (Traefik, cert-manager), Forgejo, NetKingdom, policy-nexus.

+
+

04Solution Strategy

+

N/A for this stub — repository-prefix architecture and rapp-first wave are already in the ADRs in §9.

+
+

05Building Block View

+

5.1 Level 1 – System/Top-Level

+

N/A for this stub.

+
+

06Runtime View

+

N/A for this stub.

+
+

07Deployment View

+

N/A for this stub.

+
+

08Cross-Cutting Concepts

+

N/A for this stub.

+
+

09Architecture Decisions

+

Published on policy.coulomb.social from this repo:

+
IdStatusDecision
RMASTER-ADR-0001acceptedRepository prefix architecture
RMASTER-ADR-0002acceptedWave 1 rail-kubernetes boundary
RMASTER-ADR-0003acceptedFirst-wave rapp selection
RMASTER-ADR-0004acceptedFirst-wave reef rollout
RMASTER-ADR-0005acceptedDerived rail composition
RMASTER-ADR-0006acceptedReef production admission
RMASTER-ADR-0007acceptedRapp declaration contract
RMASTER-ADR-0008acceptedPrivate-by-default exposure
+

Unresolved: identical accepted ADR-003/004 copies in railiance-hosts and railiance-infra. Not listed as current here until those owners rule.

+
+

10Quality Requirements

+

N/A for this stub.

+
+

11Risks and Technical Debt

+

N/A for this stub.

+
+

12Glossary

+
TermMeaning
RailA composed runtime path.
ReefThe production admission environment.
rAppA packaged workload bound by a declaration contract.
+
railiance-architecture · draft-1 · proposedrailiance-master · docs/architecture/railiance_v0.1.md · 883533ed8af1703cc9bb4a2b24137e325bbbda47
diff --git a/build/architecture/state-hub/v0.1/index.html b/build/architecture/state-hub/v0.1/index.html new file mode 100644 index 0000000..5ecbfe9 --- /dev/null +++ b/build/architecture/state-hub/v0.1/index.html @@ -0,0 +1,246 @@ + + + + +State Hub architecture + +
state-hub-architecture proposed · draft-1 state-hub reviewed 2026-08-18generated from canonical source — do not edit

State Hub architecture

Source: state-hub · docs/architecture/state-hub_v0.1.md · db89e5463fe8bb8bf6811cf839548244eab28c4b

Review due: 2027-02-18

About this document

+

First-wave arc42 for State Hub, the estate's live coordination read-model. This service is in active retirement planning; new permanent ownership should not land here. Chapter 9 points at the estate ADRs that still bind it.

+
+

01Introduction and Goals

+

State Hub is a queryable, auditable memory of work: domains, repos, workplans, tasks, decisions, progress. Files remain the origin. The hub is derived state (custodian ADR-001, ADR-003).

+

It remains operational until retirement gates in prj-state-hub-retirement are met. Replacement ownership is moving toward repo-manager and hub-core.

+

1.1 Requirements Overview

+
  • Rebuild coordination state from registered repository files.
  • One identifier registrar (ADR-007). This workstation is not it.
  • Preserve compatibility; do not take new permanent architectural ownership.
+

1.2 Quality Goals

+
  1. Rebuildability from git.
  2. Hub never becomes the origin of work.
  3. Extraction paths stay open.
+

1.3 Stakeholders

+
RoleConcern
state-hubLive read-model during retirement.
the-custodianEstate rules the hub must not invert.
repo-managerIncoming consistency / repo representation.
product reposWorkplan files the hub indexes.
+
+

02Architecture Constraints

+

N/A for this stub — retirement program is the binding constraint.

+
+

03System Scope and Context

+

In: indexing workplans/tasks/decisions, consistency rebuild, query API and dashboard used today. Out: being the source of work items; new cross-domain capabilities; publication of policy (policy-nexus).

+

3.1 Business Context

+

Files are excellent for canon and provenance. The estate still needs a live query surface while retirement proceeds.

+

3.2 Technical Context

+

Inputs: workplan markdown via fix-consistency. Outputs: HTTP/MCP APIs. Neighbours: every registered repo, activity-core (ops runs), policy-nexus (does not index the hub).

+
+

04Solution Strategy

+

N/A for this stub. The strategy is already in the estate ADRs: files first, materialized derived state, single registrar, local cache vs authority (ADR-010, proposed).

+
+

05Building Block View

+

5.1 Level 1 – System/Top-Level

+

N/A for this stub.

+
+

06Runtime View

+

N/A for this stub.

+
+

07Deployment View

+

N/A for this stub.

+
+

08Cross-Cutting Concepts

+

N/A for this stub.

+
+

09Architecture Decisions

+

This repo has no docs/adr/ corpus. Binding decisions live in the-custodian and are listed on the estate map:

+
Estate ADRStatusWhy it binds this system
CUST-ADR-001 (workplans as repo artefacts)acceptedHub is a read model.
CUST-ADR-003 (materialized derived state)acceptedHow the cache invalidates.
CUST-ADR-007 (identity and registrar)acceptedOne writer of workplan UUIDs.
CUST-ADR-010 (hub authority / local cache)proposedTwo kinds of hub data.
+

Do not treat a State Hub /decisions row as the published ADR.

+
+

10Quality Requirements

+

N/A for this stub.

+
+

11Risks and Technical Debt

+

N/A for this stub. Residual: this workstation cannot mint registrar UUIDs.

+
+

12Glossary

+
TermMeaning
Read modelDerived index; never the origin.
RegistrarThe single instance allowed to mint workplan UUIDs.
RetirementCoordinated move of capabilities out of this repo.
+
state-hub-architecture · draft-1 · proposedstate-hub · docs/architecture/state-hub_v0.1.md · db89e5463fe8bb8bf6811cf839548244eab28c4b
diff --git a/build/architecture/state-hub/v0.1/revisions/draft-1/index.html b/build/architecture/state-hub/v0.1/revisions/draft-1/index.html new file mode 100644 index 0000000..5ecbfe9 --- /dev/null +++ b/build/architecture/state-hub/v0.1/revisions/draft-1/index.html @@ -0,0 +1,246 @@ + + + + +State Hub architecture + +
state-hub-architecture proposed · draft-1 state-hub reviewed 2026-08-18generated from canonical source — do not edit

State Hub architecture

Source: state-hub · docs/architecture/state-hub_v0.1.md · db89e5463fe8bb8bf6811cf839548244eab28c4b

Review due: 2027-02-18

About this document

+

First-wave arc42 for State Hub, the estate's live coordination read-model. This service is in active retirement planning; new permanent ownership should not land here. Chapter 9 points at the estate ADRs that still bind it.

+
+

01Introduction and Goals

+

State Hub is a queryable, auditable memory of work: domains, repos, workplans, tasks, decisions, progress. Files remain the origin. The hub is derived state (custodian ADR-001, ADR-003).

+

It remains operational until retirement gates in prj-state-hub-retirement are met. Replacement ownership is moving toward repo-manager and hub-core.

+

1.1 Requirements Overview

+
  • Rebuild coordination state from registered repository files.
  • One identifier registrar (ADR-007). This workstation is not it.
  • Preserve compatibility; do not take new permanent architectural ownership.
+

1.2 Quality Goals

+
  1. Rebuildability from git.
  2. Hub never becomes the origin of work.
  3. Extraction paths stay open.
+

1.3 Stakeholders

+
RoleConcern
state-hubLive read-model during retirement.
the-custodianEstate rules the hub must not invert.
repo-managerIncoming consistency / repo representation.
product reposWorkplan files the hub indexes.
+
+

02Architecture Constraints

+

N/A for this stub — retirement program is the binding constraint.

+
+

03System Scope and Context

+

In: indexing workplans/tasks/decisions, consistency rebuild, query API and dashboard used today. Out: being the source of work items; new cross-domain capabilities; publication of policy (policy-nexus).

+

3.1 Business Context

+

Files are excellent for canon and provenance. The estate still needs a live query surface while retirement proceeds.

+

3.2 Technical Context

+

Inputs: workplan markdown via fix-consistency. Outputs: HTTP/MCP APIs. Neighbours: every registered repo, activity-core (ops runs), policy-nexus (does not index the hub).

+
+

04Solution Strategy

+

N/A for this stub. The strategy is already in the estate ADRs: files first, materialized derived state, single registrar, local cache vs authority (ADR-010, proposed).

+
+

05Building Block View

+

5.1 Level 1 – System/Top-Level

+

N/A for this stub.

+
+

06Runtime View

+

N/A for this stub.

+
+

07Deployment View

+

N/A for this stub.

+
+

08Cross-Cutting Concepts

+

N/A for this stub.

+
+

09Architecture Decisions

+

This repo has no docs/adr/ corpus. Binding decisions live in the-custodian and are listed on the estate map:

+
Estate ADRStatusWhy it binds this system
CUST-ADR-001 (workplans as repo artefacts)acceptedHub is a read model.
CUST-ADR-003 (materialized derived state)acceptedHow the cache invalidates.
CUST-ADR-007 (identity and registrar)acceptedOne writer of workplan UUIDs.
CUST-ADR-010 (hub authority / local cache)proposedTwo kinds of hub data.
+

Do not treat a State Hub /decisions row as the published ADR.

+
+

10Quality Requirements

+

N/A for this stub.

+
+

11Risks and Technical Debt

+

N/A for this stub. Residual: this workstation cannot mint registrar UUIDs.

+
+

12Glossary

+
TermMeaning
Read modelDerived index; never the origin.
RegistrarThe single instance allowed to mint workplan UUIDs.
RetirementCoordinated move of capabilities out of this repo.
+
state-hub-architecture · draft-1 · proposedstate-hub · docs/architecture/state-hub_v0.1.md · db89e5463fe8bb8bf6811cf839548244eab28c4b
diff --git a/build/index.html b/build/index.html index dba736f..db6e448 100644 --- a/build/index.html +++ b/build/index.html @@ -183,4 +183,4 @@ footer{border-top:2px solid var(--ink);margin-top:20px;padding-top:22px;font-fam .route .tag{font-family:var(--font-mono);font-size:9px;letter-spacing:.1em;text-transform:uppercase;color:var(--brass);display:block;margin-bottom:8px} a:focus-visible,.rail a:focus-visible{outline:2px solid var(--brass);outline-offset:3px} @media (prefers-reduced-motion:reduce){*{animation:none!important;transition:none!important}} -
policy surfacegenerated from canonical sources — do not edit

Coulomb Policy Nexus

Canon and architecture decisions at stable addresses, with visible currency.

DocumentStatusLifecycleRevisionOwnerReviewedReview dueCurrency
NetKingdom Tenancy Posture v0.1proposedactivedraft-8net-kingdom2026-08-172027-02-17current
Coulomb estate architectureproposedactivedraft-1the-custodian2026-08-182027-02-18current
Policy Nexus architectureproposedactivedraft-1the-custodian2026-08-182027-02-18current
Policy addressing and permanenceacceptedactiveaccepted-1the-custodian2026-08-182027-02-18current
Repository Prefix Architectureacceptedactiveaccepted-1railiance-master2026-07-252027-01-25current
Wave 1 rail-kubernetes Boundaryacceptedactiveaccepted-1railiance-master2026-07-252027-01-25current
First-Wave rapp Selectionacceptedactiveaccepted-1railiance-master2026-07-252027-01-25current
First-Wave reef Rolloutacceptedactiveaccepted-1railiance-master2026-07-262027-01-26current
Derived Rail Compositionacceptedactiveaccepted-1railiance-master2026-07-262027-01-26current
Reef Production Admissionacceptedactiveaccepted-1railiance-master2026-08-152027-02-15current
Rapp Declaration Contractacceptedactiveaccepted-1railiance-master2026-08-132027-02-13current
Private-by-default Exposureacceptedactiveaccepted-1railiance-master2026-08-152027-02-15current
+
policy surfacegenerated from canonical sources — do not edit

Coulomb Policy Nexus

Canon and architecture decisions at stable addresses, with visible currency.

DocumentStatusLifecycleRevisionOwnerReviewedReview dueCurrency
NetKingdom Tenancy Posture v0.1proposedactivedraft-8net-kingdom2026-08-172027-02-17current
Coulomb estate architectureproposedactivedraft-1the-custodian2026-08-182027-02-18current
Railiance architectureproposedactivedraft-1railiance-master2026-08-182027-02-18current
NetKingdom architectureproposedactivedraft-1net-kingdom2026-08-182027-02-18current
State Hub architectureproposedactivedraft-1state-hub2026-08-182027-02-18current
Policy Nexus architectureproposedactivedraft-1the-custodian2026-08-182027-02-18current
Policy addressing and permanenceacceptedactiveaccepted-1the-custodian2026-08-182027-02-18current
Repository Prefix Architectureacceptedactiveaccepted-1railiance-master2026-07-252027-01-25current
Wave 1 rail-kubernetes Boundaryacceptedactiveaccepted-1railiance-master2026-07-252027-01-25current
First-Wave rapp Selectionacceptedactiveaccepted-1railiance-master2026-07-252027-01-25current
First-Wave reef Rolloutacceptedactiveaccepted-1railiance-master2026-07-262027-01-26current
Derived Rail Compositionacceptedactiveaccepted-1railiance-master2026-07-262027-01-26current
Reef Production Admissionacceptedactiveaccepted-1railiance-master2026-08-152027-02-15current
Rapp Declaration Contractacceptedactiveaccepted-1railiance-master2026-08-132027-02-13current
Private-by-default Exposureacceptedactiveaccepted-1railiance-master2026-08-152027-02-15current
diff --git a/build/publication-manifest.json b/build/publication-manifest.json index 0bd7c0f..62aee24 100644 --- a/build/publication-manifest.json +++ b/build/publication-manifest.json @@ -13,7 +13,7 @@ "source_digest": "99f802d91a0b3a65f0dac58230d8904f7c61cf3f81eff072fbbc59b634612a8a", "source_path": "canon/standards/tenancy-posture_v0.1.md", "source_repo": "net-kingdom", - "source_revision": "f4f885289e196b6770fea5d509959e3031fd9295", + "source_revision": "ba5d8642e91a31055eafdaef6993d779f6af7e06", "status": "proposed", "title": "NetKingdom Tenancy Posture v0.1" }, @@ -34,6 +34,57 @@ "status": "proposed", "title": "Coulomb estate architecture" }, + { + "canonical_path": "architecture/railiance/v0.1/index.html", + "currency": "current", + "id": "railiance-architecture", + "last_reviewed": "2026-08-18", + "lifecycle": "active", + "owner": "railiance-master", + "review_due": "2027-02-18", + "revision": "draft-1", + "revision_path": "architecture/railiance/v0.1/revisions/draft-1/index.html", + "source_digest": "1cc0af5cdb6cae771bc134722672385b8e71df1a778adc3358862a1d8f5d7217", + "source_path": "docs/architecture/railiance_v0.1.md", + "source_repo": "railiance-master", + "source_revision": "883533ed8af1703cc9bb4a2b24137e325bbbda47", + "status": "proposed", + "title": "Railiance architecture" + }, + { + "canonical_path": "architecture/net-kingdom/v0.1/index.html", + "currency": "current", + "id": "net-kingdom-architecture", + "last_reviewed": "2026-08-18", + "lifecycle": "active", + "owner": "net-kingdom", + "review_due": "2027-02-18", + "revision": "draft-1", + "revision_path": "architecture/net-kingdom/v0.1/revisions/draft-1/index.html", + "source_digest": "dd42250edcc444fa9a5007c3f9d561984840af2b19a07cf2916cbcc8434df0f7", + "source_path": "docs/architecture/net-kingdom_v0.1.md", + "source_repo": "net-kingdom", + "source_revision": "ba5d8642e91a31055eafdaef6993d779f6af7e06", + "status": "proposed", + "title": "NetKingdom architecture" + }, + { + "canonical_path": "architecture/state-hub/v0.1/index.html", + "currency": "current", + "id": "state-hub-architecture", + "last_reviewed": "2026-08-18", + "lifecycle": "active", + "owner": "state-hub", + "review_due": "2027-02-18", + "revision": "draft-1", + "revision_path": "architecture/state-hub/v0.1/revisions/draft-1/index.html", + "source_digest": "f65748fa3c861a6f399365ee5315af4e47ec91823837e3d7d89c17d4b385f2aa", + "source_path": "docs/architecture/state-hub_v0.1.md", + "source_repo": "state-hub", + "source_revision": "db89e5463fe8bb8bf6811cf839548244eab28c4b", + "status": "proposed", + "title": "State Hub architecture" + }, { "canonical_path": "architecture/policy-nexus/v0.1/index.html", "currency": "current", @@ -47,7 +98,7 @@ "source_digest": "179cbb86bca95f71f46f51ca1971ff1c274eed7d900adf0672b537d4bcc5b480", "source_path": "docs/architecture/policy-nexus_v0.1.md", "source_repo": "policy-nexus", - "source_revision": "9c6a1d3ce0a76b3cbd342ab74d3914aa339fd4e0", + "source_revision": "b93928330ef7a76976fa62989bb54f47dbe04832", "status": "proposed", "title": "Policy Nexus architecture" }, @@ -64,7 +115,7 @@ "source_digest": "a28668fb4b8b6c5ec8c94baac000061276d85ef1849ec7ab8d132b913dbfe3be", "source_path": "docs/adr/ADR-0001-addressing-and-permanence.md", "source_repo": "policy-nexus", - "source_revision": "9c6a1d3ce0a76b3cbd342ab74d3914aa339fd4e0", + "source_revision": "b93928330ef7a76976fa62989bb54f47dbe04832", "status": "accepted", "title": "Policy addressing and permanence" }, @@ -81,7 +132,7 @@ "source_digest": "b9c993ded8d79d6f871dba9cf08a320b2d619609a448ad3d02b632f5b6f76497", "source_path": "docs/adr/ADR-0001-repository-prefix-architecture.md", "source_repo": "railiance-master", - "source_revision": "debbc13b4018f20db0997516b99afc1cc21084d7", + "source_revision": "883533ed8af1703cc9bb4a2b24137e325bbbda47", "status": "accepted", "title": "Repository Prefix Architecture" }, @@ -98,7 +149,7 @@ "source_digest": "7e1fc5aedd7294192d8702a22b9f205e5bae20793836fdc48c0c071d10d7ab9d", "source_path": "docs/adr/ADR-0002-rail-kubernetes-wave-1-boundary.md", "source_repo": "railiance-master", - "source_revision": "debbc13b4018f20db0997516b99afc1cc21084d7", + "source_revision": "883533ed8af1703cc9bb4a2b24137e325bbbda47", "status": "accepted", "title": "Wave 1 rail-kubernetes Boundary" }, @@ -115,7 +166,7 @@ "source_digest": "28135e94758b6935518d2e83458c1e607deeabb341879b605eef6529b3168cbc", "source_path": "docs/adr/ADR-0003-rapp-first-wave-selection.md", "source_repo": "railiance-master", - "source_revision": "debbc13b4018f20db0997516b99afc1cc21084d7", + "source_revision": "883533ed8af1703cc9bb4a2b24137e325bbbda47", "status": "accepted", "title": "First-Wave rapp Selection" }, @@ -132,7 +183,7 @@ "source_digest": "36ec3aad5082ceff685d66e091c0a24b52abfc65b36595d00dce2b52a7250f4e", "source_path": "docs/adr/ADR-0004-first-wave-reef-rollout.md", "source_repo": "railiance-master", - "source_revision": "debbc13b4018f20db0997516b99afc1cc21084d7", + "source_revision": "883533ed8af1703cc9bb4a2b24137e325bbbda47", "status": "accepted", "title": "First-Wave reef Rollout" }, @@ -149,7 +200,7 @@ "source_digest": "e02982ce54691cf1589ac3d04012b9b9282f9eb54ed4b8f2f0544371f9b87f3e", "source_path": "docs/adr/ADR-0005-derived-rail-composition.md", "source_repo": "railiance-master", - "source_revision": "debbc13b4018f20db0997516b99afc1cc21084d7", + "source_revision": "883533ed8af1703cc9bb4a2b24137e325bbbda47", "status": "accepted", "title": "Derived Rail Composition" }, @@ -166,7 +217,7 @@ "source_digest": "d9fbd9d21d86e461334abc24060c39127f2158ba25317b3d3dc326c4f7eaf08c", "source_path": "docs/adr/ADR-0006-reef-production-admission.md", "source_repo": "railiance-master", - "source_revision": "debbc13b4018f20db0997516b99afc1cc21084d7", + "source_revision": "883533ed8af1703cc9bb4a2b24137e325bbbda47", "status": "accepted", "title": "Reef Production Admission" }, @@ -183,7 +234,7 @@ "source_digest": "263431f88ba04d6ab9ab3b6c0d6a2bb08634bfe83dc0719350f0855d399c18b2", "source_path": "docs/adr/ADR-0007-rapp-declaration-contract.md", "source_repo": "railiance-master", - "source_revision": "debbc13b4018f20db0997516b99afc1cc21084d7", + "source_revision": "883533ed8af1703cc9bb4a2b24137e325bbbda47", "status": "accepted", "title": "Rapp Declaration Contract" }, @@ -200,7 +251,7 @@ "source_digest": "276ea38233413f1e23670bbf57c486abc361b0a275ca67efea7d677103713b32", "source_path": "docs/adr/ADR-0008-private-by-default-exposure.md", "source_repo": "railiance-master", - "source_revision": "debbc13b4018f20db0997516b99afc1cc21084d7", + "source_revision": "883533ed8af1703cc9bb4a2b24137e325bbbda47", "status": "accepted", "title": "Private-by-default Exposure" } diff --git a/build/standards/tenancy-posture/v0.1/index.html b/build/standards/tenancy-posture/v0.1/index.html index 9dc8a63..5866b32 100644 --- a/build/standards/tenancy-posture/v0.1/index.html +++ b/build/standards/tenancy-posture/v0.1/index.html @@ -1,6 +1,6 @@ - + NetKingdom Tenancy Posture v0.1 -
netkingdom-tenancy-posture proposed · draft-8 net-kingdom reviewed 2026-08-17generated from canonical source — do not edit

NetKingdom Tenancy Posture v0.1

A framework for describing, holding and improving multi-tenancy — including where we are not there yet.

Source: net-kingdom · canon/standards/tenancy-posture_v0.1.md · f4f885289e196b6770fea5d509959e3031fd9295

Review due: 2027-02-17

Status

+
netkingdom-tenancy-posture proposed · draft-8 net-kingdom reviewed 2026-08-17generated from canonical source — do not edit

NetKingdom Tenancy Posture v0.1

A framework for describing, holding and improving multi-tenancy — including where we are not there yet.

Source: net-kingdom · canon/standards/tenancy-posture_v0.1.md · ba5d8642e91a31055eafdaef6993d779f6af7e06

Review due: 2027-02-17

Status

Proposed, draft-8; ratification-ready. Relocated from the-custodian/canon/architecture on 2026-08-17: multi-tenancy is part of the IT-security framework NetKingdom provides, so this framework belongs in NetKingdom canon beside the IAM Profile and the tenant-engine boundary contract, not in the work-factory canon.

  • draft-1 proposed a single model with fixed characteristics. Rejected: it could not describe a repo that is not there yet.
  • draft-2 reframed to graduated levels per axis. Externally corroborated (§16), but four of its statements were wrong and one thing it needed was missing.
  • draft-3 applied those corrections, added the retention axis, and recorded an adoption stance.
  • draft-4 closed the two gaps draft-3 left open: R4 had no mechanism beyond waiting, and the noisy-neighbour evidence artifact asserted something shared infrastructure cannot provide.
  • draft-5 relocated to NetKingdom and renamed the dimensions from planes to axes, because the word was already taken (§0).
  • draft-6 applied tenant-engine's review: five changes, including an axis that did not fit its data shape.
  • draft-7 applies audit-core, railiance-platform and flex-auth. Eleven further changes, two of them corrections to statements this document made as fact about other repos. Every posture I guessed was too generous, on every repo that has now self-reported.
  • draft-8 applies adaptive-pricing's review, the last of the six, and the consistency review across all declarations. It adds the missing availability axis, a canonical declaration schema, explicit authority for tier assurance, retention/placement coupling, downgrade propagation, and honest sanctioned customer language. It also corrects the distinction between an implemented control and an evidenced current level.

Reviewed by all six. The score: six repos found three live defects in their own code by reading the ladders — tenant-engine's unfiltered event accessor, audit-core's unfiltered read path, flex-auth's unauthenticated /v1/check — and railiance-platform found apps-pg running with no backup configured at all while writing its §10.2 disclosure. The framework changed to fit the repos; no repo was told to fabricate a posture.

@@ -441,4 +441,4 @@ per consumer: 14 connections (12 runtime + 2 migration)

20Ratification path

  1. Reviewed by tenant-engine, flex-auth, audit-core, rapp-postgres, railiance-platform and adaptive-pricing against §19. Complete in draft-8.
  2. Each publishes its own posture vector (§5) as part of review. The framework is validated by whether it can describe them accurately — if a repo cannot express itself in these six ladders, the ladders are wrong and this document changes, not the repo. Complete in draft-8; all six root declarations validate against the canonical schema.
  3. On acceptance, supersedes the routing of rapp-postgres/docs/canon-drafts/shared-platform-relational-storage_v0.1-draft.md, whose §§3–8 are absorbed here. That draft is withdrawn rather than left pending.
  4. On acceptance, rapp-postgres ADR-0001 through ADR-0004 move to accepted and are annotated as the PostgreSQL implementation of the E, P, R and shared-capacity rules.
-
netkingdom-tenancy-posture · draft-8 · proposednet-kingdom · canon/standards/tenancy-posture_v0.1.md · f4f885289e196b6770fea5d509959e3031fd9295
+
netkingdom-tenancy-posture · draft-8 · proposednet-kingdom · canon/standards/tenancy-posture_v0.1.md · ba5d8642e91a31055eafdaef6993d779f6af7e06
diff --git a/docs/adr-review/SUMMARY.md b/docs/adr-review/SUMMARY.md index fc67f55..1770c33 100644 --- a/docs/adr-review/SUMMARY.md +++ b/docs/adr-review/SUMMARY.md @@ -1,12 +1,12 @@ # ADR review ledger summary -Rows: 127 +Rows: 130 ## Inventory dispositions - `excluded`: 2 - `metadata-pending`: 105 -- `published`: 12 +- `published`: 15 - `unsupported-format`: 8 ## Proposed dispositions @@ -14,7 +14,7 @@ Rows: 127 - `conflict`: 5 - `publish`: 27 - `superseded`: 5 -- `unreviewed`: 90 +- `unreviewed`: 93 ## Front-matter `id` collisions diff --git a/docs/adr-review/ledger.json b/docs/adr-review/ledger.json index ebce131..b05df45 100644 --- a/docs/adr-review/ledger.json +++ b/docs/adr-review/ledger.json @@ -2229,6 +2229,33 @@ "source_repo": "net-kingdom", "successor": "" }, + { + "bare_adr": "", + "bare_adr_collisions": [], + "conflict_kinds": [], + "file_present": true, + "frontmatter": { + "id": "net-kingdom-architecture", + "last_reviewed": "2026-08-18", + "owner": "net-kingdom", + "review_interval": "6m", + "revision": "draft-1", + "status": "proposed", + "title": "NetKingdom architecture", + "updated": "", + "version": "0.1" + }, + "id_collisions": [], + "inventory_disposition": "published", + "inventory_reason": "Published through an explicit publication.json document entry.", + "missing_fields": [], + "notes": "", + "proposed_disposition": "unreviewed", + "review_notes": "", + "source_path": "docs/architecture/net-kingdom_v0.1.md", + "source_repo": "net-kingdom", + "successor": "" + }, { "bare_adr": "ADR-0001", "bare_adr_collisions": [ @@ -2904,6 +2931,33 @@ "source_repo": "railiance-master", "successor": "" }, + { + "bare_adr": "", + "bare_adr_collisions": [], + "conflict_kinds": [], + "file_present": true, + "frontmatter": { + "id": "railiance-architecture", + "last_reviewed": "2026-08-18", + "owner": "railiance-master", + "review_interval": "6m", + "revision": "draft-1", + "status": "proposed", + "title": "Railiance architecture", + "updated": "", + "version": "0.1" + }, + "id_collisions": [], + "inventory_disposition": "published", + "inventory_reason": "Published through an explicit publication.json document entry.", + "missing_fields": [], + "notes": "", + "proposed_disposition": "unreviewed", + "review_notes": "", + "source_path": "docs/architecture/railiance_v0.1.md", + "source_repo": "railiance-master", + "successor": "" + }, { "bare_adr": "ADR-0001", "bare_adr_collisions": [ @@ -3296,6 +3350,33 @@ "source_repo": "rein-aharness", "successor": "" }, + { + "bare_adr": "", + "bare_adr_collisions": [], + "conflict_kinds": [], + "file_present": true, + "frontmatter": { + "id": "state-hub-architecture", + "last_reviewed": "2026-08-18", + "owner": "state-hub", + "review_interval": "6m", + "revision": "draft-1", + "status": "proposed", + "title": "State Hub architecture", + "updated": "", + "version": "0.1" + }, + "id_collisions": [], + "inventory_disposition": "published", + "inventory_reason": "Published through an explicit publication.json document entry.", + "missing_fields": [], + "notes": "", + "proposed_disposition": "unreviewed", + "review_notes": "", + "source_path": "docs/architecture/state-hub_v0.1.md", + "source_repo": "state-hub", + "successor": "" + }, { "bare_adr": "ADR-0001", "bare_adr_collisions": [ diff --git a/docs/adr-review/packets/README.md b/docs/adr-review/packets/README.md new file mode 100644 index 0000000..c833cf2 --- /dev/null +++ b/docs/adr-review/packets/README.md @@ -0,0 +1,10 @@ +# Cleanup packets + +Per-repo checklists from POLICY-NEXUS-WP-0003-T05. They are work +artefacts, not published policy. + +`policy-nexus` will not edit your ADR bodies. Apply the checklist in +your repo, then tell this repo the publication `id` is ready. + +Contract: `docs/publication-contract.md`. +Conflicts: `docs/adr-review/conflicts.md`. diff --git a/docs/adr-review/packets/activity-core.md b/docs/adr-review/packets/activity-core.md new file mode 100644 index 0000000..eb47974 --- /dev/null +++ b/docs/adr-review/packets/activity-core.md @@ -0,0 +1,23 @@ +# Cleanup packet — activity-core + +From POLICY-NEXUS-WP-0003-T05. + +Ids `ACT-ADR-001`–`005` are already unique. This site is ready to +publish all five once each file has: + +```yaml +owner: activity-core +revision: "accepted-1" +last_reviewed: "YYYY-MM-DD" +review_interval: 6m +``` + +| File | Why it publishes | +| --- | --- | +| `adr-001-event-bridge-architecture.md` | Cross-repo event bridge | +| `adr-002-definition-format.md` | Definition format others consume | +| `adr-003-rule-instruction-model.md` | Rule vs instruction | +| `adr-004-producer-trust-boundary.md` | Producer trust boundary | +| `adr-005-ops-runs-vs-dev-work-records.md` | Ops-run vs work-record split | + +No body rewrite required. diff --git a/docs/adr-review/packets/coulomb-social.md b/docs/adr-review/packets/coulomb-social.md new file mode 100644 index 0000000..f993b8e --- /dev/null +++ b/docs/adr-review/packets/coulomb-social.md @@ -0,0 +1,18 @@ +# Cleanup packet — coulomb-social + +From POLICY-NEXUS-WP-0003-T05. + +## Conflict + +- `docs/adr/ADR-0002-space-content-forgejo-markdown.md` — status is + **superseded in part** by ADR-0003 / ADR-0004. Choose one: + 1. `status: superseded` with those two as successors, or + 2. keep a narrowed `accepted` decision and say which clause survived. + +Until that is one status, this site will not publish ADR-0002. + +## Also needed before any publish + +Prefix publication ids (`CSOC-ADR-0001` …). `ADR-0001` collides with +key-cape and target-revenue. Add `owner`, `revision`, `last_reviewed`, +`review_interval` to 0001, 0003, 0004. diff --git a/docs/adr-review/packets/net-kingdom.md b/docs/adr-review/packets/net-kingdom.md new file mode 100644 index 0000000..161f635 --- /dev/null +++ b/docs/adr-review/packets/net-kingdom.md @@ -0,0 +1,24 @@ +# Cleanup packet — net-kingdom + +From POLICY-NEXUS-WP-0003-T05. Do not apply in policy-nexus. + +## Blocking + +| File | Action | +| --- | --- | +| `canon/standards/iam-profile_v0.2.md` | Set `status: superseded`. Successor is v0.3. Id `netkingdom-iam-profile` is shared. | +| `canon/standards/iam-profile_v0.3.md` | Change `id` to `netkingdom-iam-profile-v0.3` (or similar unique id). Then it can be published. | + +## Ready to publish after prefix + review metadata + +`docs/adr/ADR-0006` through `ADR-0015`. Suggested ids `NK-ADR-0006` … +`NK-ADR-0015`. Add `owner`, `revision`, `last_reviewed` / +`review_interval`. + +These are unreviewed for relevance except as NetKingdom chapter 9 +candidates. Default if they only bind NetKingdom implementers: still +`publish` — they constrain flex-auth, key-cape, tenant-engine. + +## Already published + +- Tenancy Posture at `/standards/tenancy-posture/v0.1/`. diff --git a/docs/adr-review/packets/railiance-hosts.md b/docs/adr-review/packets/railiance-hosts.md new file mode 100644 index 0000000..f554fa2 --- /dev/null +++ b/docs/adr-review/packets/railiance-hosts.md @@ -0,0 +1,24 @@ +# Cleanup packet — railiance-hosts + +From POLICY-NEXUS-WP-0003-T05. Shared with `railiance-infra`. + +## Already ruled + +- `docs/adr/ADR-002-repo-boundary-hosts-vs-bootstrap.md` — superseded by + ADR-003. Add YAML `status: superseded` so the body and metadata agree. + Byte-identical copy exists in railiance-infra. + +## Conflict — do not publish both + +These files are **byte-identical** and **accepted** in both +`railiance-hosts` and `railiance-infra`: + +- `ADR-003-railiance-5repo-stack-architecture.md` +- `ADR-004-forgejo-in-cluster-actions-runner.md` + +Pick one publication source. The other becomes `superseded` or a +pointer, not a second current document. If the stack story moved to +`railiance-master`, say so. + +Who rules: railiance-hosts, railiance-infra, or railiance-master. +Nothing is published from these two ADRs until that ruling lands. diff --git a/docs/adr-review/packets/railiance-infra.md b/docs/adr-review/packets/railiance-infra.md new file mode 100644 index 0000000..967d5df --- /dev/null +++ b/docs/adr-review/packets/railiance-infra.md @@ -0,0 +1,23 @@ +# Cleanup packet — railiance-infra + +From POLICY-NEXUS-WP-0003-T05. Shared with `railiance-hosts`. + +## Already ruled + +- `docs/adr/ADR-002-repo-boundary-hosts-vs-bootstrap.md` — superseded by + ADR-003. Add YAML `status: superseded`. Identical hosts copy exists. + +## Conflict — do not publish both + +Byte-identical accepted copies also live in `railiance-hosts`: + +- `ADR-003-railiance-5repo-stack-architecture.md` +- `ADR-004-forgejo-in-cluster-actions-runner.md` + +One current publication source, not two. See the hosts packet. + +## Still unreviewed here + +- `docs/adr/ADR-005-k3s-api-tunnel-only.md` — relevance not ruled. If it + still binds cluster access, add publication front-matter and a unique + id (`RINFRA-ADR-0005`). diff --git a/docs/adr-review/packets/railiance-platform.md b/docs/adr-review/packets/railiance-platform.md new file mode 100644 index 0000000..3067614 --- /dev/null +++ b/docs/adr-review/packets/railiance-platform.md @@ -0,0 +1,15 @@ +# Cleanup packet — railiance-platform + +From POLICY-NEXUS-WP-0003-T05. + +These bind other repos. Add a unique `id` (suggested +`RPLAT-ADR-0001` … `0003`). 0002 and 0003 already have most other +publication fields; 0001 needs `id`. + +| File | Disposition | +| --- | --- | +| `ADR-0001-s3-platform-service-boundary.md` | publish | +| `ADR-0002-placement-policy-ownership.md` | publish (proposed is fine) | +| `ADR-0003-decisions-live-in-the-repo.md` | publish | + +`docs/adr/README.md` stays excluded (directory index). diff --git a/docs/adr-review/packets/the-custodian.md b/docs/adr-review/packets/the-custodian.md new file mode 100644 index 0000000..d49c403 --- /dev/null +++ b/docs/adr-review/packets/the-custodian.md @@ -0,0 +1,38 @@ +# Cleanup packet — the-custodian + +From POLICY-NEXUS-WP-0003-T05. Do not apply in policy-nexus. + +## Ready to publish after this packet + +Estate architecture ADRs in `canon/architecture/`. Suggested +publication ids (filename can stay): + +| File | Suggested `id` | +| --- | --- | +| `adr-001-workplans-as-repo-artefacts.md` | `CUST-ADR-001` | +| `adr-002-custodian-agent-runtime-design.md` | `CUST-ADR-002` | +| `adr-003-materialized-derived-state.md` | `CUST-ADR-003` | +| `adr-004-connectivity-first-network-posture.md` | `CUST-ADR-004` | +| `adr-005-cross-repo-workplans-project-repos.md` | `CUST-ADR-005` | +| `adr-006-canon-federation-concept-ownership.md` | `CUST-ADR-006` | +| `adr-007-workplan-identity-and-repo-worker-topology.md` | `CUST-ADR-007` | +| `adr-010-hub-authority-and-local-cache-model.md` | `CUST-ADR-010` | +| `adr-011-federated-namespaces-and-reconciliation-limits.md` | `CUST-ADR-011` | + +Add to each: `owner`, `revision` (or `version`), `last_reviewed` or +`updated`, `review_interval` (`6m` unless you declare otherwise). + +Bare `ADR-001`–`ADR-005` collide with coulomb-loop and kaizen-agentic. +A prefix is required before this site can register them. + +## Already ruled, small fix + +- `adr-008-multi-tenancy-model.md` — superseded, successor Tenancy + Posture. No body rewrite. +- `canon/standards/iam-profile_v0.1.md` — already superseded; point + `superseded_by` at `iam-profile_v0.3.md`, not v0.2. + +## Already published from this repo + +- `canon/architecture/coulomb-estate_v0.1.md` at + `/architecture/coulomb-estate/v0.1/`. diff --git a/publication.json b/publication.json index 536dd53..f87077e 100644 --- a/publication.json +++ b/publication.json @@ -16,6 +16,7 @@ "net-kingdom": {"path": "../net-kingdom"}, "policy-nexus": {"path": "."}, "railiance-master": {"path": "../railiance-master"}, + "state-hub": {"path": "../state-hub"}, "the-custodian": {"path": "../the-custodian"} }, "documents": [ @@ -37,6 +38,30 @@ "revision_path": "architecture/coulomb-estate/v0.1/revisions/{revision}/index.html", "review_interval": "6m" }, + { + "id": "railiance-architecture", + "source_repo": "railiance-master", + "source_path": "docs/architecture/railiance_v0.1.md", + "canonical_path": "architecture/railiance/v0.1/index.html", + "revision_path": "architecture/railiance/v0.1/revisions/{revision}/index.html", + "review_interval": "6m" + }, + { + "id": "net-kingdom-architecture", + "source_repo": "net-kingdom", + "source_path": "docs/architecture/net-kingdom_v0.1.md", + "canonical_path": "architecture/net-kingdom/v0.1/index.html", + "revision_path": "architecture/net-kingdom/v0.1/revisions/{revision}/index.html", + "review_interval": "6m" + }, + { + "id": "state-hub-architecture", + "source_repo": "state-hub", + "source_path": "docs/architecture/state-hub_v0.1.md", + "canonical_path": "architecture/state-hub/v0.1/index.html", + "revision_path": "architecture/state-hub/v0.1/revisions/{revision}/index.html", + "review_interval": "6m" + }, { "id": "policy-nexus-architecture", "source_repo": "policy-nexus", diff --git a/source-inventory.config.json b/source-inventory.config.json index 4d56706..fc03ddd 100644 --- a/source-inventory.config.json +++ b/source-inventory.config.json @@ -59,7 +59,7 @@ "net-kingdom": { "branch": "main", "remote": "https://forgejo.coulomb.social/coulomb/net-kingdom.git", - "selectors": ["canon/standards/**", "docs/adr/*.md"] + "selectors": ["canon/standards/**", "docs/adr/*.md", "docs/architecture/*.md"] }, "policy-nexus": { "local": true, @@ -78,7 +78,7 @@ "railiance-master": { "branch": "main", "remote": "https://forgejo.coulomb.social/coulomb/railiance-master.git", - "selectors": ["docs/adr/*.md"] + "selectors": ["docs/adr/*.md", "docs/architecture/*.md"] }, "railiance-platform": { "branch": "main", @@ -95,6 +95,11 @@ "remote": "https://forgejo.coulomb.social/coulomb/rein-aharness.git", "selectors": ["docs/adr/*.md"] }, + "state-hub": { + "branch": "main", + "remote": "https://forgejo.coulomb.social/coulomb/state-hub.git", + "selectors": ["docs/architecture/*.md"] + }, "target-revenue": { "branch": "main", "remote": "https://forgejo.coulomb.social/coulomb/target-revenue.git", diff --git a/source-inventory.json b/source-inventory.json index a2c4d83..fdba889 100644 --- a/source-inventory.json +++ b/source-inventory.json @@ -337,6 +337,12 @@ "source_path": "docs/adr/ADR-0015-netkingdom-railiance-workload-packaging-and-relational-platform.md", "source_repo": "net-kingdom" }, + { + "disposition": "published", + "reason": "Published through an explicit publication.json document entry.", + "source_path": "docs/architecture/net-kingdom_v0.1.md", + "source_repo": "net-kingdom" + }, { "disposition": "published", "reason": "Published through an explicit publication.json document entry.", @@ -439,6 +445,12 @@ "source_path": "docs/adr/ADR-0008-private-by-default-exposure.md", "source_repo": "railiance-master" }, + { + "disposition": "published", + "reason": "Published through an explicit publication.json document entry.", + "source_path": "docs/architecture/railiance_v0.1.md", + "source_repo": "railiance-master" + }, { "disposition": "metadata-pending", "reason": "In scope; awaits explicit publication addressing and owner/revision/review metadata.", @@ -493,6 +505,12 @@ "source_path": "docs/adr/ADR-001-agent-harness-architecture.md", "source_repo": "rein-aharness" }, + { + "disposition": "published", + "reason": "Published through an explicit publication.json document entry.", + "source_path": "docs/architecture/state-hub_v0.1.md", + "source_repo": "state-hub" + }, { "disposition": "metadata-pending", "reason": "In scope; awaits explicit publication addressing and owner/revision/review metadata.", diff --git a/workplans/POLICY-NEXUS-WP-0002-arc42-architecture-collection.md b/workplans/POLICY-NEXUS-WP-0002-arc42-architecture-collection.md index 897eef0..07a486a 100644 --- a/workplans/POLICY-NEXUS-WP-0002-arc42-architecture-collection.md +++ b/workplans/POLICY-NEXUS-WP-0002-arc42-architecture-collection.md @@ -220,7 +220,7 @@ unresolved WP-0003 conflicts. ```task id: POLICY-NEXUS-WP-0002-T05 -status: progress +status: done priority: medium ``` @@ -234,8 +234,12 @@ publish. Deeper chapters are the owning repo's follow-on, not a gate here. This repo authors only `docs/architecture/policy-nexus_v0.1.md`. 2026-08-18: policy-nexus stub exists with real chapters 1, 3 and 9. It is -published at `/architecture/policy-nexus/v0.1/`. The other four -documents remain owning-repo work. +published at `/architecture/policy-nexus/v0.1/`. + +Completed 2026-08-18. Stubs now exist in `railiance-master`, +`net-kingdom`, and `state-hub` (`docs/architecture/_v0.1.md`) +with real chapters 1, 3 and 9. Estate map was T04. First wave is +open. ### T06 — Register and publish @@ -260,8 +264,9 @@ publication stays explicit. 2026-08-18: `docs/architecture/*.md` is a policy-nexus selector. `policy-nexus-architecture` is published at `/architecture/policy-nexus/v0.1/`. Estate map is published at -`/architecture/coulomb-estate/v0.1/`. Other first-wave documents still -need owning-repo files. +`/architecture/coulomb-estate/v0.1/`. First-wave stubs for Railiance, +NetKingdom and State Hub are published at +`/architecture//v0.1/`. ### T07 — Smoke the published collection diff --git a/workplans/POLICY-NEXUS-WP-0003-adr-review-cleanup-publish.md b/workplans/POLICY-NEXUS-WP-0003-adr-review-cleanup-publish.md index e7a64b4..aaf3481 100644 --- a/workplans/POLICY-NEXUS-WP-0003-adr-review-cleanup-publish.md +++ b/workplans/POLICY-NEXUS-WP-0003-adr-review-cleanup-publish.md @@ -224,7 +224,7 @@ chapter 9: the listed estate ADRs match; no miss on that document. ```task id: POLICY-NEXUS-WP-0003-T05 -status: todo +status: done priority: high ``` @@ -237,6 +237,11 @@ Deliver the packet as a message or a PR *checklist* in the owning repo, not as an edit of the ADR bodies. This repo applies the packet only for `policy-nexus` itself. +Completed 2026-08-18. Checklists in `docs/adr-review/packets/` and +inbox messages from `policy-nexus` to the-custodian, net-kingdom, +railiance-hosts, railiance-infra, coulomb-social, activity-core, and +railiance-platform. No foreign ADR bodies were edited. + ### T06 — Register the ready set ```task