secrets-engine/docs/netkingdom-security-infrastructure.md
tegwick 1945e16685
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Declare Engine/Lifecycle against security layer model v0.7
Replace the gate-house review note with this repository's own declaration:
INTENT.md frontmatter, layer.yaml, and a published PEP stance map. SCOPE.md
and agent boundary docs now match that layer. The review under history/
identifies the implementation remainder; SECRETS-WP-0008 is the follow-on
workplan. SECRETS-IN-0001 is closed.

The layer is not contested. Catalog "custody" is a finding: OpenBao owns
custody, this engine owns the lifecycle API over it. SSH-CA signing is
accepted as a proposed engine API and declined as a Staff lane.

Assistant: grok
Assistant-Session: 01a04cea-cb33-7c63-bad7-c1b0f9f0076b
2026-08-29 11:57:47 +02:00

1 KiB

NetKingdom Security Infrastructure Boundary

The canonical document lives in the NetKingdom repository:

net-kingdom/docs/secrets-engine-security-infrastructure-boundary.md

Local checkout path:

/home/worsch/net-kingdom/docs/secrets-engine-security-infrastructure-boundary.md

This secrets-engine file is intentionally only a pointer. The canonical document belongs to NetKingdom because it defines cross-system security infrastructure responsibilities and boundaries across OpenBao, flex-auth, user-engine/key-cape, ops-warden, ops-bridge, info-tech-canon, State Hub, and agents.

The accepted layer model and working companion, which this repository now declares against as Engine / Lifecycle, live at:

net-kingdom/canon/standards/security-layer-model_v0.7.md
net-kingdom/SECURITY-COMPANION.md

secrets-engine consumes that boundary and implements the secrets workflow, catalog, stage policies, OpenBao apply/delivery mechanics, and evidence model that the canonical document assigns to it.