8.9 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | state_hub_workstream_id |
|---|---|---|---|---|---|---|---|---|---|---|
| SECRETS-WP-0005 | workplan | Close high-value SCOPE and INTENT gaps | infotech | secrets-engine | finished | codex | custodian | 2026-06-29 | 2026-06-29 | 262e8539-bfd9-435c-81fc-8148c9c5f744 |
SECRETS-WP-0005 - Close high-value SCOPE and INTENT gaps
Goal
Convert the SCOPE/INTENT gap analysis into concrete documentation and planning changes that improve day-to-day value for agents, operators, and cross-repo integrators.
The main value target is clarity: keep SCOPE.md useful as a stable operating
boundary, make the service/API direction visible, map the hardening trajectory,
and tighten language around OpenBao custody, ops-warden routing, and lifecycle
work.
Source Analysis
This workplan is based on:
history/2026-06-29-scope-intent-gap-analysis.mdSCOPE.mdINTENT.mddocs/netkingdom-security-infrastructure.md
The assessment found no major contradiction. The gap is that SCOPE.md is now
implementation-rich and current, while INTENT.md is stable and aspirational.
The best value comes from separating durable boundary language from volatile
status, then making future high-value surfaces explicit enough that agents do
not have to rediscover the direction.
Value Strategy
Prioritize changes that:
- reduce stale operational text in long-lived boundary docs;
- make future work easier to route without adding new authority;
- clarify custody and routing boundaries before live OpenBao handoffs;
- turn hardening goals into visible acceptance targets;
- preserve current useful context by moving it to
history/instead of deleting it.
Tasks
T01 - Separate durable scope from volatile status
id: SECRETS-WP-0005-T01
status: done
priority: high
state_hub_task_id: "37c72cb5-d3fa-42a7-a9a4-28712582539e"
2026-06-29: Refactored SCOPE.md current-state language to remove exact test counts, active workplan state, and pending live-gate detail. Durable status now points agents to workplans, .custodian-brief.md, and history/.
Refactor SCOPE.md so it remains a stable boundary document rather than a
second workplan ledger.
Keep the current maturity summary, but remove or generalize details that will
stale quickly: exact test counts, active workplan state, and pending live gates.
Move any useful historical detail into history/ if it is not already captured.
Acceptance:
SCOPE.mdstill tells agents what this repo owns and does not own.SCOPE.mdno longer depends on exact test counts or active workplan status to remain true.- Current-state details needed for continuity are preserved in
history/or the relevant workplan. git diff --checkis clean.
T02 - Add service/API direction to the boundary
id: SECRETS-WP-0005-T02
status: done
priority: high
state_hub_task_id: "8703854c-c722-45a9-ab93-1bd914ebd37f"
2026-06-29: Added future service/API mode to SCOPE.md as an in-bound surface over proven CLI semantics for plans, deliveries, handoffs, lifecycle actions, and evidence.
Represent the INTENT.md service-mode direction in SCOPE.md without
overcommitting implementation.
The service/API surface should be described as in scope for future work: a stable interface for ops-warden, agents, CI, workloads, and future UI surfaces to request approved plans, deliveries, handoffs, and non-secret evidence without knowing OpenBao internals.
Acceptance:
SCOPE.mdnames service/API mode as an in-bound future surface.- The boundary says service mode does not replace OpenBao, flex-auth, key-cape, user-engine, or ops-warden.
- No new API contract is promised beyond what this repo can plausibly own.
T03 - Add a hardening trajectory section
id: SECRETS-WP-0005-T03
status: done
priority: high
state_hub_task_id: "351eea5d-878b-4ddf-9d1f-6dd59929e3b0"
2026-06-29: Added a durable Hardening Trajectory section to SCOPE.md, linked to docs/hardening-backlog.md, covering scoped auth, wrapping/leases, dual control, lifecycle, and service/API maturation.
Add a short durable hardening section to SCOPE.md that mirrors the direction
in INTENT.md.
It should cover:
- replacing bootstrap token files with OIDC, service auth, or other scoped auth;
- response wrapping and short leases;
- dual control for production provisioning;
- routine rotation, revocation, and deactivation;
- evidence that proves delivery and lifecycle actions without exposing values.
Acceptance:
SCOPE.mdgives agents a clear next-hardening map.- The hardening section does not claim these items are already complete.
- The section references existing backlog or workplan locations when useful.
T04 - Tighten ops-warden and custody wording
id: SECRETS-WP-0005-T04
status: done
priority: high
state_hub_task_id: "9444e6ba-2853-42d4-a074-e21b350d5d8a"
2026-06-29: Tightened SCOPE.md and docs/ops-warden-routing-contract.md so OpenBao remains the custody backend, secrets-engine orchestrates approved OpenBao-backed flows, and ops-warden remains a conduit-not-broker SSH cert issuer.
Review SCOPE.md, INTENT.md, and routing docs for wording that could imply
secrets-engine stores raw secret values itself or that ops-warden vends
non-SSH secrets.
Preferred phrasing:
- OpenBao keeps custody, policy, lease, and audit.
- secrets-engine orchestrates cataloged OpenBao-backed issuance, delivery, handoff, verification, and revocation.
- ops-warden routes non-SSH credential needs here and issues SSH certificates itself.
Acceptance:
SCOPE.mdno longer says secrets-engine broadly "custodies tokens" without clarifying OpenBao custody.- Routing docs remain aligned with the conduit-not-broker model.
- No text suggests raw values may move through Git, State Hub, chat, prompts, workplans, or normal logs.
T05 - Make lifecycle capability first-class
id: SECRETS-WP-0005-T05
status: done
priority: medium
state_hub_task_id: "b259a499-a1aa-4b37-bf4d-bf19ed79eb99"
2026-06-29: Added a first-class Lifecycle and non-secret evidence capability block to SCOPE.md for provision, verify, deliver, rotate, revoke, deactivate, and audit workflows.
Add durable boundary language for rotation, revocation, deactivation, and non-secret lifecycle evidence.
This should not require implementing new lifecycle code immediately. The goal is to make lifecycle ownership and value clear enough that future implementation work can be routed cleanly.
Acceptance:
SCOPE.mdincludes lifecycle as a first-class capability or boundary concern, not only as a passing list item.- The text distinguishes one-off revoke support from routine lifecycle management.
- Any follow-up implementation gaps are linked to
docs/hardening-backlog.mdor a future workplan.
T06 - Bring INTENT vocabulary forward carefully
id: SECRETS-WP-0005-T06
status: done
priority: medium
state_hub_task_id: "cdd1c8a1-11ac-4d92-8d67-f239e62b0e62"
2026-06-29: Updated INTENT.md carefully to acknowledge scoped OpenBao capability grants and auth-capability lanes while keeping the file mission-level and implementation-light.
Consider a small INTENT.md update for concepts that have become important
without changing the mission: auth-capability lanes, scoped OpenBao
capabilities, and the distinction between KV secret lanes and non-KV capability
lanes.
This task is intentionally careful because INTENT.md should remain stable and
aspirational, not become implementation status.
Acceptance:
INTENT.mdacknowledges scoped OpenBao capabilities if the wording improves clarity.- The file remains stable, concise, and mission-oriented.
- Implementation-specific lane names stay in
SCOPE.md, workplans, or history unless they serve as examples.
T07 - Verify, sync, and record closeout
id: SECRETS-WP-0005-T07
status: done
priority: medium
state_hub_task_id: "5168182e-9fce-4bf4-8e6d-7c6e93cc8f71"
2026-06-29: Final documentation checks passed (git diff --check clean), docs were reviewed against docs/netkingdom-security-infrastructure.md, and State Hub consistency sync applied the SECRETS-WP-0005 task updates.
Run final documentation checks, preserve non-secret closeout evidence, and sync the workplan state.
Acceptance:
git diff --checkis clean.- The final changed docs are reviewed against
docs/netkingdom-security-infrastructure.md. - State Hub progress records the closeout.
- After workplan file changes, the custodian consistency sync is run or the
operator is asked to run
make fix-consistency REPO=secrets-engine.
Exit Criteria
SCOPE.mdis stable enough for agents to use without frequent status churn.INTENT.mdandSCOPE.mdagree on the expanded lane model without turning INTENT into an implementation ledger.- Service/API direction, hardening trajectory, custody boundaries, and lifecycle ownership are visible and actionable.
- No raw secret values, token material, or sensitive operational details are added to Git, State Hub, chat, prompts, workplans, or normal logs.