2026-08-19 19:15:55 +00:00
|
|
|
# zone-engine
|
|
|
|
|
|
2026-08-23 12:35:01 +02:00
|
|
|
Offline reference conformance for NetKingdom **security zones**. This repository
|
|
|
|
|
validates workload membership and admission, projects only explicit
|
|
|
|
|
owner-versioned control profiles, checks time-boxed exception fixtures, and
|
|
|
|
|
verifies the lineage of the canonical standard.
|
|
|
|
|
|
|
|
|
|
It is not a service or policy decision point. Canon is published by
|
|
|
|
|
`net-kingdom`; flex-auth and each enforcement-point owner retain live policy
|
|
|
|
|
authority.
|
|
|
|
|
|
|
|
|
|
## Checks
|
|
|
|
|
|
|
|
|
|
```bash
|
|
|
|
|
make check
|
|
|
|
|
make canon-lineage CANON_ROOT=/path/to/net-kingdom
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Resolve the versioned reference manifest and optional owner profile:
|
|
|
|
|
|
|
|
|
|
```bash
|
|
|
|
|
python3 tools/resolve_zones.py \
|
|
|
|
|
--manifest fixtures/manifests/reference.yaml \
|
|
|
|
|
--control-profile profiles/netkingdom-build-v0.1.yaml
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Evaluate exception conformance at an explicit instant:
|
|
|
|
|
|
|
|
|
|
```bash
|
|
|
|
|
python3 tools/check_zone_exceptions.py \
|
|
|
|
|
fixtures/exceptions/valid-active.yaml \
|
|
|
|
|
--policy fixtures/exceptions/policy.yaml \
|
|
|
|
|
--at 2026-08-23T10:00:00Z
|
|
|
|
|
```
|
2026-08-19 21:18:44 +02:00
|
|
|
|
|
|
|
|
Orient: `GOAL.md` → `SCOPE.md` → `workplans/`.
|