railiance-master/docs/adr/ADR-0009-netkingdom-security-layer-interaction.md
codex a0c35b7438 feat(RMASTER-WP-0026): declare Taxonomy layer and consume NetKingdom §20
Add layer.yaml, RMASTER-ADR-0009, the consumption contract, and a tracked
non-answer for the five §20.3 questions. Split admission, exposure, and
authorization without renaming schema fields. Finish the workplan.

Assistant: grok
Assistant-Session: 01a04c9f-cd6b-7741-bce0-f1d9d1b3c3bc
2026-08-29 12:52:35 +02:00

83 lines
3.5 KiB
Markdown

---
id: RMASTER-ADR-0009
title: "NetKingdom Security-Layer Interaction Boundary"
status: accepted
revision: "accepted-1"
owner: railiance-master
last_reviewed: "2026-08-29"
review_interval: 6m
---
# ADR-0009: NetKingdom Security-Layer Interaction Boundary
Date: 2026-08-29
Status: Accepted
## Context
NetKingdom Security Layer Model v0.7 is accepted. Section 20 restates
Railiance workload-operation definitions owned by this repository and
states consumption rules every Railiance consumer of NetKingdom security
owes. Companion v0.2 §9 is the operative form of the same boundary.
This repository had declared the four axes and the workload coverage rule
in its own voice, but had no machine-readable layer declaration, no
recorded assent to §20, and no framework contract that bound rails, rapps,
and reefs to those consumption rules. Admission (ADR-0006) and exposure
(ADR-0008) were live and were not demarcated from authorization.
Statute §20.4: an interaction boundary between two frameworks is owned by
neither alone. Changes to §20 require this repository's assent for the
axis definitions and `glas-harness` assent for the session and tool-policy
seam.
Ratified 2026-08-29 under `RMASTER-WP-0026`.
## Decision
1. **This repository is Taxonomy of Railiance workload operations.** The
machine-readable declaration is [`layer.yaml`](../../layer.yaml). It is
not a NetKingdom §4 catalog row. It is not PEP-shaped. It holds no
Tooling-layer client.
2. **Statute §20.1 restates our definitions and does not author them.**
Workload, the four axes, and the rule that `rein-*` is not a fifth axis
remain this repository's. NetKingdom may cite them; it may not redefine
them without our assent.
3. **Statute §20.2 is the consumption constitution** for every Railiance
consumer of NetKingdom security. The detailed contract is
[`docs/netkingdom-security-consumption-contract.md`](../netkingdom-security-consumption-contract.md).
4. **Statute §20.3 remains unset.** This repository will not imply a
mapping of rails, rapps, reefs, or ownership onto Taxonomy, Tooling,
Engine, or Staff. The five questions are tracked, unanswered, in
[`docs/netkingdom-axis-layer-open-questions.md`](../netkingdom-axis-layer-open-questions.md).
5. **Admission, exposure, and authorization stay three questions.**
ADR-0006 answers whether a binding may run in production. ADR-0008
answers who may reach a listener we control. `access-engine` answers
whether an actor may perform an action. `production-approved` and
`exposure: public` are not authorization decisions.
6. **Changes to this boundary** require this repository's assent for the
axis definitions. Changes that touch the glas-harness seam require
`glas-harness` assent as well.
## Consequences
- Rails, rapps, and reefs consume `access-engine`, `approval-engine`,
`secrets-engine`, and `audit-core`. They do not grow local substitutes.
- This repository does not host a PDP, an approval store, a credential
plane, an evidence archive, or an actuation surface.
- PEP stance maps belong in the repositories that cause protected side
effects, inventoried in statute §13.1, not here.
- Observation-in-production and automatic containment remain estate-wide
zeros. Framework plans must not assume they exist.
- `gate-house` can cite this ADR as this repository's own-voice
declaration and §20 assent, rather than a review note about us.
## Notes
This ADR does not amend ADR-0001 through ADR-0008. It adds the security
consumption axis those records did not have to name.