Add layer.yaml, RMASTER-ADR-0009, the consumption contract, and a tracked non-answer for the five §20.3 questions. Split admission, exposure, and authorization without renaming schema fields. Finish the workplan. Assistant: grok Assistant-Session: 01a04c9f-cd6b-7741-bce0-f1d9d1b3c3bc
83 lines
3.5 KiB
Markdown
83 lines
3.5 KiB
Markdown
---
|
|
id: RMASTER-ADR-0009
|
|
title: "NetKingdom Security-Layer Interaction Boundary"
|
|
status: accepted
|
|
revision: "accepted-1"
|
|
owner: railiance-master
|
|
last_reviewed: "2026-08-29"
|
|
review_interval: 6m
|
|
---
|
|
|
|
# ADR-0009: NetKingdom Security-Layer Interaction Boundary
|
|
|
|
Date: 2026-08-29
|
|
Status: Accepted
|
|
|
|
## Context
|
|
|
|
NetKingdom Security Layer Model v0.7 is accepted. Section 20 restates
|
|
Railiance workload-operation definitions owned by this repository and
|
|
states consumption rules every Railiance consumer of NetKingdom security
|
|
owes. Companion v0.2 §9 is the operative form of the same boundary.
|
|
|
|
This repository had declared the four axes and the workload coverage rule
|
|
in its own voice, but had no machine-readable layer declaration, no
|
|
recorded assent to §20, and no framework contract that bound rails, rapps,
|
|
and reefs to those consumption rules. Admission (ADR-0006) and exposure
|
|
(ADR-0008) were live and were not demarcated from authorization.
|
|
|
|
Statute §20.4: an interaction boundary between two frameworks is owned by
|
|
neither alone. Changes to §20 require this repository's assent for the
|
|
axis definitions and `glas-harness` assent for the session and tool-policy
|
|
seam.
|
|
|
|
Ratified 2026-08-29 under `RMASTER-WP-0026`.
|
|
|
|
## Decision
|
|
|
|
1. **This repository is Taxonomy of Railiance workload operations.** The
|
|
machine-readable declaration is [`layer.yaml`](../../layer.yaml). It is
|
|
not a NetKingdom §4 catalog row. It is not PEP-shaped. It holds no
|
|
Tooling-layer client.
|
|
|
|
2. **Statute §20.1 restates our definitions and does not author them.**
|
|
Workload, the four axes, and the rule that `rein-*` is not a fifth axis
|
|
remain this repository's. NetKingdom may cite them; it may not redefine
|
|
them without our assent.
|
|
|
|
3. **Statute §20.2 is the consumption constitution** for every Railiance
|
|
consumer of NetKingdom security. The detailed contract is
|
|
[`docs/netkingdom-security-consumption-contract.md`](../netkingdom-security-consumption-contract.md).
|
|
|
|
4. **Statute §20.3 remains unset.** This repository will not imply a
|
|
mapping of rails, rapps, reefs, or ownership onto Taxonomy, Tooling,
|
|
Engine, or Staff. The five questions are tracked, unanswered, in
|
|
[`docs/netkingdom-axis-layer-open-questions.md`](../netkingdom-axis-layer-open-questions.md).
|
|
|
|
5. **Admission, exposure, and authorization stay three questions.**
|
|
ADR-0006 answers whether a binding may run in production. ADR-0008
|
|
answers who may reach a listener we control. `access-engine` answers
|
|
whether an actor may perform an action. `production-approved` and
|
|
`exposure: public` are not authorization decisions.
|
|
|
|
6. **Changes to this boundary** require this repository's assent for the
|
|
axis definitions. Changes that touch the glas-harness seam require
|
|
`glas-harness` assent as well.
|
|
|
|
## Consequences
|
|
|
|
- Rails, rapps, and reefs consume `access-engine`, `approval-engine`,
|
|
`secrets-engine`, and `audit-core`. They do not grow local substitutes.
|
|
- This repository does not host a PDP, an approval store, a credential
|
|
plane, an evidence archive, or an actuation surface.
|
|
- PEP stance maps belong in the repositories that cause protected side
|
|
effects, inventoried in statute §13.1, not here.
|
|
- Observation-in-production and automatic containment remain estate-wide
|
|
zeros. Framework plans must not assume they exist.
|
|
- `gate-house` can cite this ADR as this repository's own-voice
|
|
declaration and §20 assent, rather than a review note about us.
|
|
|
|
## Notes
|
|
|
|
This ADR does not amend ADR-0001 through ADR-0008. It adds the security
|
|
consumption axis those records did not have to name.
|