2026-06-28 09:03:37 +00:00
|
|
|
## Repo boundary
|
|
|
|
|
|
2026-08-29 11:57:47 +02:00
|
|
|
This repo owns the **secrets-engine** Lifecycle engine only (NetKingdom
|
|
|
|
|
security layer model v0.7: Engine / Lifecycle). It does not own:
|
2026-06-28 09:03:37 +00:00
|
|
|
|
2026-06-29 12:14:00 +02:00
|
|
|
- Secret custody, policy, lease, and audit backend → OpenBao / railiance-platform
|
2026-08-29 11:57:47 +02:00
|
|
|
- SSH certificate issuance (Staff PEP) → ops-warden (`warden sign`)
|
2026-06-29 12:14:00 +02:00
|
|
|
- Tunnels and remote transport → ops-bridge
|
2026-08-29 11:57:47 +02:00
|
|
|
- Authorization decisions → access-engine (`flex-auth`)
|
|
|
|
|
- Approval objects → approval-engine
|
|
|
|
|
- Evidence custody and integrity → audit-core
|
2026-06-29 12:14:00 +02:00
|
|
|
- Identity and claim lifecycle → user-engine / key-cape
|
2026-08-29 11:57:47 +02:00
|
|
|
- Security doctrine and the layer model → gate-house / net-kingdom canon
|
2026-06-29 12:14:00 +02:00
|
|
|
- Cross-system security boundary doc → net-kingdom/docs/
|
|
|
|
|
- Request history and progress index → State Hub (read model)
|