railiance-master/docs/adr/ADR-0009-netkingdom-security-layer-interaction.md
codex a0c35b7438 feat(RMASTER-WP-0026): declare Taxonomy layer and consume NetKingdom §20
Add layer.yaml, RMASTER-ADR-0009, the consumption contract, and a tracked
non-answer for the five §20.3 questions. Split admission, exposure, and
authorization without renaming schema fields. Finish the workplan.

Assistant: grok
Assistant-Session: 01a04c9f-cd6b-7741-bce0-f1d9d1b3c3bc
2026-08-29 12:52:35 +02:00

3.5 KiB

id title status revision owner last_reviewed review_interval
RMASTER-ADR-0009 NetKingdom Security-Layer Interaction Boundary accepted accepted-1 railiance-master 2026-08-29 6m

ADR-0009: NetKingdom Security-Layer Interaction Boundary

Date: 2026-08-29 Status: Accepted

Context

NetKingdom Security Layer Model v0.7 is accepted. Section 20 restates Railiance workload-operation definitions owned by this repository and states consumption rules every Railiance consumer of NetKingdom security owes. Companion v0.2 §9 is the operative form of the same boundary.

This repository had declared the four axes and the workload coverage rule in its own voice, but had no machine-readable layer declaration, no recorded assent to §20, and no framework contract that bound rails, rapps, and reefs to those consumption rules. Admission (ADR-0006) and exposure (ADR-0008) were live and were not demarcated from authorization.

Statute §20.4: an interaction boundary between two frameworks is owned by neither alone. Changes to §20 require this repository's assent for the axis definitions and glas-harness assent for the session and tool-policy seam.

Ratified 2026-08-29 under RMASTER-WP-0026.

Decision

  1. This repository is Taxonomy of Railiance workload operations. The machine-readable declaration is layer.yaml. It is not a NetKingdom §4 catalog row. It is not PEP-shaped. It holds no Tooling-layer client.

  2. Statute §20.1 restates our definitions and does not author them. Workload, the four axes, and the rule that rein-* is not a fifth axis remain this repository's. NetKingdom may cite them; it may not redefine them without our assent.

  3. Statute §20.2 is the consumption constitution for every Railiance consumer of NetKingdom security. The detailed contract is docs/netkingdom-security-consumption-contract.md.

  4. Statute §20.3 remains unset. This repository will not imply a mapping of rails, rapps, reefs, or ownership onto Taxonomy, Tooling, Engine, or Staff. The five questions are tracked, unanswered, in docs/netkingdom-axis-layer-open-questions.md.

  5. Admission, exposure, and authorization stay three questions. ADR-0006 answers whether a binding may run in production. ADR-0008 answers who may reach a listener we control. access-engine answers whether an actor may perform an action. production-approved and exposure: public are not authorization decisions.

  6. Changes to this boundary require this repository's assent for the axis definitions. Changes that touch the glas-harness seam require glas-harness assent as well.

Consequences

  • Rails, rapps, and reefs consume access-engine, approval-engine, secrets-engine, and audit-core. They do not grow local substitutes.
  • This repository does not host a PDP, an approval store, a credential plane, an evidence archive, or an actuation surface.
  • PEP stance maps belong in the repositories that cause protected side effects, inventoried in statute §13.1, not here.
  • Observation-in-production and automatic containment remain estate-wide zeros. Framework plans must not assume they exist.
  • gate-house can cite this ADR as this repository's own-voice declaration and §20 assent, rather than a review note about us.

Notes

This ADR does not amend ADR-0001 through ADR-0008. It adds the security consumption axis those records did not have to name.