2026-08-19 21:18:44 +02:00
|
|
|
# SCOPE
|
|
|
|
|
|
2026-08-23 10:42:12 +02:00
|
|
|
> What this repository can do, when it is relevant, and when it is not.
|
2026-08-23 12:35:01 +02:00
|
|
|
> The historical argument is `INTENT.md`; completed gates and retirement are
|
|
|
|
|
> recorded in `GOAL.md`.
|
2026-08-19 21:18:44 +02:00
|
|
|
|
|
|
|
|
---
|
|
|
|
|
|
|
|
|
|
## One-liner
|
|
|
|
|
|
2026-08-29 11:57:25 +02:00
|
|
|
`zone-engine` is the Engine-layer **PIP** for NetKingdom zone identity and
|
|
|
|
|
membership, retained as an offline reference-conformance repository. It does
|
|
|
|
|
**not** run a live engine, render a policy decision, or cause a protected side
|
|
|
|
|
effect.
|
|
|
|
|
|
|
|
|
|
## Layer
|
|
|
|
|
|
|
|
|
|
Declared in `INTENT.md` frontmatter, in this repository's own voice:
|
|
|
|
|
|
|
|
|
|
| Key | Value |
|
|
|
|
|
| --- | --- |
|
|
|
|
|
| Layer | Engine |
|
|
|
|
|
| Role | PIP |
|
|
|
|
|
| Statute | `security-layer-model_v0.7` (accepted 2026-08-29) |
|
|
|
|
|
| Companion | `net-kingdom/SECURITY-COMPANION.md` v0.2 |
|
|
|
|
|
| Catalogued form | offline reference conformance (2026-08-23 disposition) |
|
|
|
|
|
| PEP-shaped | no |
|
|
|
|
|
| Tooling contacts | none |
|
|
|
|
|
| Conformance | conforming for Tooling contact; the live Engine API is not a missing capability this repository currently owes |
|
|
|
|
|
|
|
|
|
|
The machine-readable `layer.yaml` form and a conformance check that fails a
|
|
|
|
|
new Tooling client or a new decision surface are not yet evidenced here.
|
|
|
|
|
Until they are, the declaration is the `INTENT.md` frontmatter and the prose
|
|
|
|
|
in that file.
|
|
|
|
|
|
|
|
|
|
`access-engine` (currently `flex-auth`) is the only PDP. Zone stance and
|
|
|
|
|
failure mode remain owner policy and PEP configuration. This repository
|
|
|
|
|
projects only explicit versioned owner data and never changes a live effect.
|
2026-08-23 10:42:12 +02:00
|
|
|
|
2026-08-23 12:35:01 +02:00
|
|
|
## Lifecycle
|
2026-08-23 10:42:12 +02:00
|
|
|
|
2026-08-23 12:35:01 +02:00
|
|
|
`ZONE-WP-0001` delivered and proved the model. `ZONE-WP-0002` hardened the
|
|
|
|
|
retained reference boundary. Both are finished with `DoD-Ok`; no runtime is
|
2026-08-29 11:57:25 +02:00
|
|
|
needed.
|
2026-08-23 10:42:12 +02:00
|
|
|
|
2026-08-23 12:35:01 +02:00
|
|
|
The repository is retained while `security-zones_v0.1` remains `proposed` in
|
|
|
|
|
net-kingdom canon, with zone-engine as maintainer of fixtures and reference
|
2026-08-29 11:57:25 +02:00
|
|
|
tooling. Retention is not service ownership. Acceptance of the security layer
|
|
|
|
|
model does not reopen the no-runtime decision; it names the retained form as
|
|
|
|
|
the Engine/PIP this repository already is.
|
|
|
|
|
|
|
|
|
|
Normal change triggers remain: a canon lifecycle or content change, an
|
|
|
|
|
owner-requested conformance revision, or evidence that an adopting control
|
|
|
|
|
cannot enforce the contract at its existing point. The layer declaration and
|
|
|
|
|
the PIP claim-mapping work that follow from v0.7 are owner-driven revisions
|
|
|
|
|
of that kind. Archival remains an attended action once the reference
|
|
|
|
|
artifacts are durably handed off or no longer needed.
|
|
|
|
|
|
|
|
|
|
A live Engine API, a decision surface, or stance compiled into membership
|
|
|
|
|
would be a layer change and is out of present scope.
|
2026-08-23 11:29:20 +02:00
|
|
|
|
2026-08-23 10:42:12 +02:00
|
|
|
## Capability actually present
|
|
|
|
|
|
2026-08-23 12:35:01 +02:00
|
|
|
This repository provides:
|
|
|
|
|
|
|
|
|
|
- a non-authoritative pointer and machine-checked lineage record for the
|
|
|
|
|
canonical `net-kingdom/canon/standards/security-zones_v0.1.md`;
|
|
|
|
|
- an offline resolver for direct declarations and caller-supplied Repo Manager
|
|
|
|
|
v1 workload projections;
|
|
|
|
|
- explicit `applicable` and `not-applicable` handling, with unresolved facts
|
|
|
|
|
remaining `unknown` and no path, repo, reef, actor, or lane inference;
|
|
|
|
|
- validation of authoritative identity bindings, zone declarations, review
|
|
|
|
|
dates, context floors, and continuity evidence;
|
|
|
|
|
- canonical `satisfied`, `unsatisfied`, `unknown`, and `not-applicable` results
|
|
|
|
|
with workload references, identity bindings, guarantees, sources, and source
|
|
|
|
|
revisions;
|
|
|
|
|
- deterministic membership revisions bound to canonicalized identity,
|
|
|
|
|
membership, workload reference, and source revision;
|
|
|
|
|
- deterministic first/previous-snapshot addition, removal, and change reports;
|
|
|
|
|
- optional control projection from an explicit, total, versioned profile that
|
|
|
|
|
names policy owner, PEP owner, and policy reference for every row;
|
|
|
|
|
- an offline exception checker with an explicit evaluation instant, covering
|
|
|
|
|
grant authority, maximum duration, exclusive expiry, overlap, renewal,
|
|
|
|
|
wildcard rejection, and durable-authority bounds; and
|
|
|
|
|
- reusable manifests, profiles, exception fixtures, evidence, and 29 unit
|
|
|
|
|
tests.
|
|
|
|
|
|
|
|
|
|
The resolver consumes already-located declarations and already-resolved
|
|
|
|
|
workload-reference projections. It does not discover a fleet, repair an
|
|
|
|
|
ambiguous join, read a live clock, or publish a consumer registry. Its profile
|
|
|
|
|
fixture records owner-approved v0.1 behavior; only the referenced owner policy
|
|
|
|
|
and PEP configuration can change a live effect.
|
2026-08-23 10:42:12 +02:00
|
|
|
|
2026-08-29 11:57:25 +02:00
|
|
|
The resolver output is a reference membership/admission record. It is not yet
|
|
|
|
|
a statute §17 request-claim. Taxonomy owns that schema and has not published
|
|
|
|
|
it. This repository must not ship a competing dialect.
|
|
|
|
|
|
2026-08-23 10:42:12 +02:00
|
|
|
## Authority boundary
|
|
|
|
|
|
|
|
|
|
| Concern | Authority | This repository's role |
|
Refine SCOPE, add INTENT, fix the GOAL invariant flex-auth rejected
GOAL.md still carried the first-draft invariant — "nothing this repo builds sits
synchronously in a decision path" — after flex-auth's review had rejected it as
a latency guarantee wearing an authority guarantee's clothes. Under that wording
zone-engine could compile enforced: false for a lane, flip warden sign from deny
to allow with no flex-auth policy change, and be literally compliant. Replaced:
identity and membership here, effect in a flex-auth policy package. Compiled-not-
queried is demoted to a consequence of that, which is what it always was.
SCOPE now records what the two reviews settled rather than what was proposed:
separate standard (canon Decision 5.6), membership declared in tenancy.yaml's
reserved zones: key, stance out of scope for controls flex-auth decides, the
fail-open axis modelled PEP-side because a PDP structurally cannot express it,
organization_posture an input rather than a declaration field, and reefs not
ours. Plus the two inherited constraints: the dead trust_zone field already
sitting where membership would go, and flex-auth's lack of a reload path.
INTENT.md states the argument, including what would falsify the repo — the
exception lifecycle not needing a runtime is called out as a legitimate outcome
that should archive this repo rather than keep it for its own sake.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 22:20:13 +02:00
|
|
|
| --- | --- | --- |
|
2026-08-23 12:35:01 +02:00
|
|
|
| Workload identity and requested membership | Workload's responsible repo | Reference-validates supplied facts |
|
|
|
|
|
| Managed workload tuple and applicability | Repo Manager / owning catalog | Consumes the explicit projection |
|
|
|
|
|
| Zone ids and admission standard | zone-engine model, published by net-kingdom | Maintains conformance fixtures and lineage |
|
|
|
|
|
| Canon publication and lifecycle | net-kingdom | Detects change; never promotes by inference |
|
2026-08-29 11:57:25 +02:00
|
|
|
| Layer model and engine roles | gate-house / net-kingdom canon | Declares Engine/PIP; does not author the statute |
|
|
|
|
|
| Request-claim schema | Taxonomy (statute §17, unassigned) | Will consume, not invent |
|
|
|
|
|
| Control stance | Owner of the control; effect in `access-engine` policy | Projects only explicit versioned owner data |
|
2026-08-23 12:35:01 +02:00
|
|
|
| Failure behavior | Owner of the PEP | Records provenance and semantics only |
|
2026-08-29 11:57:25 +02:00
|
|
|
| Authorization effect | `access-engine` (currently `flex-auth`) | Makes no decision; supplies PIP facts |
|
2026-08-23 12:35:01 +02:00
|
|
|
| Exception grant and expiry | Designated control authority and enforcement point | Checks reusable fixtures offline |
|
2026-08-29 11:57:25 +02:00
|
|
|
| Reef placement vs zone floor | Railiance / canon composition (statute §20.3) | Keeps the axes separate; does not compose them |
|
2026-08-23 10:42:12 +02:00
|
|
|
|
|
|
|
|
The invariant remains: **membership is ours; stance is theirs; the decision
|
2026-08-29 11:57:25 +02:00
|
|
|
point is neither.** `access-engine` remains the only PDP for decisions it
|
|
|
|
|
renders.
|
2026-08-23 10:42:12 +02:00
|
|
|
|
|
|
|
|
## Deliberately absent
|
|
|
|
|
|
|
|
|
|
There is no:
|
|
|
|
|
|
|
|
|
|
- API, daemon, database, controller, scheduler, watch loop, or reload path;
|
2026-08-23 12:35:01 +02:00
|
|
|
- synchronous lookup in an authorization or enforcement path;
|
2026-08-29 11:57:25 +02:00
|
|
|
- authorization decision surface, cached verdict, or compiled stance;
|
|
|
|
|
- PEP, unreachable-engine stance map, or protected side effect;
|
|
|
|
|
- Tooling-layer client (OpenBao, key-cape, or a direct datastore);
|
2026-08-23 10:42:12 +02:00
|
|
|
- central exception store, grant workflow, clock, or expiry evaluator;
|
|
|
|
|
- live policy evaluation or implementation of another repository's control;
|
2026-08-23 12:35:01 +02:00
|
|
|
- fleet discovery, reference repair, registry publication, or workload
|
|
|
|
|
migration;
|
2026-08-23 10:42:12 +02:00
|
|
|
- network segmentation, reef placement, tenancy, identity, or secrets service;
|
2026-08-29 11:57:25 +02:00
|
|
|
- estate request-claim schema, or authority to publish one; or
|
2026-08-23 10:42:12 +02:00
|
|
|
- authority to publish canon or select a consumer's stance and failure mode.
|
|
|
|
|
|
2026-08-23 12:35:01 +02:00
|
|
|
Exception expiry remains enforced at decision or enforcement time by each
|
|
|
|
|
owning control. The offline checker is conformance evidence, not a live
|
|
|
|
|
decision point.
|
2026-08-19 21:18:44 +02:00
|
|
|
|
|
|
|
|
## Relevant when
|
|
|
|
|
|
2026-08-23 12:35:01 +02:00
|
|
|
- Reproducing or extending v0.1 conformance fixtures.
|
|
|
|
|
- Checking direct declarations or explicit Repo Manager projections offline.
|
|
|
|
|
- Verifying a versioned owner profile is total and fully attributed.
|
|
|
|
|
- Testing an owner exception implementation against the lifecycle boundaries.
|
2026-08-29 11:57:25 +02:00
|
|
|
- Reviewing a net-kingdom canon lifecycle/content change, including the
|
|
|
|
|
security-layer-model.
|
|
|
|
|
- Declaring or checking this repository's Engine/PIP conformance.
|
2026-08-23 12:35:01 +02:00
|
|
|
- Auditing why no zone-engine runtime exists.
|
2026-08-19 21:18:44 +02:00
|
|
|
|
|
|
|
|
## Not relevant when
|
|
|
|
|
|
2026-08-23 12:35:01 +02:00
|
|
|
- Determining the published rule: read net-kingdom canon.
|
2026-08-29 11:57:25 +02:00
|
|
|
- Asking whether a request is allowed: use `access-engine` or the owning
|
|
|
|
|
control.
|
2026-08-23 12:35:01 +02:00
|
|
|
- Discovering or repairing managed workloads: use Repo Manager and the owning
|
|
|
|
|
catalog.
|
|
|
|
|
- Granting, applying, or expiring a live exception: use the control owner's
|
2026-08-23 10:42:12 +02:00
|
|
|
versioned policy or PEP configuration.
|
2026-08-23 12:35:01 +02:00
|
|
|
- Placing a workload, routing a network, managing identity/tenancy, or handling
|
|
|
|
|
secrets.
|
2026-08-29 11:57:25 +02:00
|
|
|
- Publishing an unreachable-engine stance, containing a workload, or observing
|
|
|
|
|
production: those are PEP, actuation, and `kings-guard`, and the last two
|
|
|
|
|
are held at zero by the statute.
|
|
|
|
|
- Mapping Railiance `reef-*` onto security zones: statute §20.3 leaves that
|
|
|
|
|
composition unwritten; guessing it here is out of scope.
|