2026-08-19 21:18:44 +02:00
|
|
|
---
|
|
|
|
|
repo: zone-engine
|
|
|
|
|
repo_flavor: project
|
|
|
|
|
project_status: draft
|
|
|
|
|
started: "2026-08-19"
|
|
|
|
|
---
|
|
|
|
|
|
|
|
|
|
# Goal — zone-engine
|
|
|
|
|
|
|
|
|
|
## Outcome
|
|
|
|
|
|
|
|
|
|
Enforcement rigidity is a declared, reviewable property of a named zone rather
|
|
|
|
|
than a boolean per repo. A control can be turned on for the band of the estate
|
|
|
|
|
that wants its failure mode, and left advisory where that failure mode would
|
|
|
|
|
stop the work. Deep refactors get relaxed rigidity through an exception that
|
|
|
|
|
expires on its own.
|
|
|
|
|
|
|
|
|
|
## Invariants
|
|
|
|
|
|
Refine SCOPE, add INTENT, fix the GOAL invariant flex-auth rejected
GOAL.md still carried the first-draft invariant — "nothing this repo builds sits
synchronously in a decision path" — after flex-auth's review had rejected it as
a latency guarantee wearing an authority guarantee's clothes. Under that wording
zone-engine could compile enforced: false for a lane, flip warden sign from deny
to allow with no flex-auth policy change, and be literally compliant. Replaced:
identity and membership here, effect in a flex-auth policy package. Compiled-not-
queried is demoted to a consequence of that, which is what it always was.
SCOPE now records what the two reviews settled rather than what was proposed:
separate standard (canon Decision 5.6), membership declared in tenancy.yaml's
reserved zones: key, stance out of scope for controls flex-auth decides, the
fail-open axis modelled PEP-side because a PDP structurally cannot express it,
organization_posture an input rather than a declaration field, and reefs not
ours. Plus the two inherited constraints: the dead trust_zone field already
sitting where membership would go, and flex-auth's lack of a reload path.
INTENT.md states the argument, including what would falsify the repo — the
exception lifecycle not needing a runtime is called out as a legitimate outcome
that should archive this repo rather than keep it for its own sake.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 22:20:13 +02:00
|
|
|
- **`flex-auth` remains the only policy decision point.** zone-engine is
|
|
|
|
|
authority over zone **identity and membership**; the **effect** of a zone on
|
|
|
|
|
any decision flex-auth renders is expressed in a flex-auth policy package.
|
|
|
|
|
|
|
|
|
|
The first draft of this invariant said "nothing this repo builds sits
|
|
|
|
|
synchronously in a decision path". flex-auth rejected that on review: it is a
|
|
|
|
|
*latency* guarantee, not an authority one. Compiled data that determines an
|
|
|
|
|
outcome is still deciding — it just decided earlier. Under the old wording
|
|
|
|
|
zone-engine could compile `enforced: false` for a lane, flip `warden sign`
|
|
|
|
|
from deny to allow with no flex-auth policy change, and be literally
|
|
|
|
|
compliant. Membership is ours; stance is theirs.
|
|
|
|
|
- **Compiled, not queried.** Membership reaches flex-auth by compilation into
|
|
|
|
|
the registry it already loads. This is a *consequence* of the invariant
|
|
|
|
|
above, not the invariant itself — flex-auth is `service_class:
|
|
|
|
|
latency-critical` and loads its registry once at process start.
|
2026-08-19 21:18:44 +02:00
|
|
|
- **A zone that can be quietly widened is not a boundary.** Every change of
|
|
|
|
|
stance is observable, and every exception has an enforced expiry.
|
|
|
|
|
- **Accuracy, not altitude** (`tenancy-posture_v0.1` §6). A repo declaring a
|
|
|
|
|
stricter zone than it can evidence is the failure to design against, because
|
|
|
|
|
it looks like progress.
|
|
|
|
|
- **Placement is not posture.** Reefs are a separate axis and stay separate.
|
|
|
|
|
- **The model precedes the schema.** No API, no storage, no wire format until
|
|
|
|
|
`ZONE-WP-0001` has partitioned the real estate.
|
|
|
|
|
|
|
|
|
|
## Success gates
|
|
|
|
|
|
|
|
|
|
1. The model partitions today's estate — the 27 ops-warden catalog lanes, the
|
|
|
|
|
actor inventory, the posture-carrying workloads — without a residue of
|
|
|
|
|
unexplained exceptions.
|
|
|
|
|
2. A canon standard is drafted and offered to `net-kingdom`, in the family of
|
|
|
|
|
`tenancy-posture_v0.1`.
|
|
|
|
|
3. At least two repos declare zones and are read by a third — a model only its
|
|
|
|
|
author honours is not adopted.
|
|
|
|
|
4. `ops-warden`'s `policy.enabled` is retired in favour of a zone-aware control,
|
|
|
|
|
closing `WARDEN-WP-0031-T05`.
|
|
|
|
|
5. Whether a runtime is needed is answered on evidence from the exception
|
|
|
|
|
lifecycle, not assumed.
|
|
|
|
|
|
|
|
|
|
## Project retirement
|
|
|
|
|
|
|
|
|
|
Archive when the standard is canon, the declarations are live, and either a
|
|
|
|
|
runtime exists with an owner or the decision that none is needed is recorded.
|