- repo-identity.md / repo-boundary.md: replace leftover repo-seed template text with secrets-engine identity and boundary (T01) - mark SECRETS-WP-0001 T01–T03 done (T02 dev-workflow commands and T03 first real workplan were completed during the MVP build); workplan status -> finished Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
516 B
516 B
Repo boundary
This repo owns the secrets-engine workflow/interaction layer only. It does not own:
- Secret custody, policy, lease, and audit backend → OpenBao / railiance-platform
- SSH certificate issuance → ops-warden (
warden sign) - Tunnels and remote transport → ops-bridge
- Authorization decisions → flex-auth
- Identity and claim lifecycle → user-engine / key-cape
- Cross-system security boundary doc → net-kingdom/docs/
- Request history and progress index → State Hub (read model)