docs: declare Engine/PIP under security-layer-model v0.7

Assent to ZONE-IN-0001 in this repository's own voice: layer Engine, role
PIP, offline reference remaining the catalogued surface. Align INTENT,
SCOPE, and GOAL with accepted statute v0.7 and companion v0.2. Record the
scope-against-intent review and open ZONE-WP-0003 for the mechanical
remainder. Do not reopen the no-runtime decision.

Assistant: grok
Assistant-Session: 01a04ceb-0745-7ae1-9e26-0d10e5d52b8b
This commit is contained in:
tegwick 2026-08-29 11:57:25 +02:00
parent 1b9a252fa3
commit a34bc194dc
6 changed files with 704 additions and 88 deletions

47
GOAL.md
View file

@ -17,21 +17,26 @@ expires on its own.
## Invariants
- **`flex-auth` remains the only policy decision point.** zone-engine is
authority over zone **identity and membership**; the **effect** of a zone on
any decision flex-auth renders is expressed in a flex-auth policy package.
- **`access-engine` remains the only policy decision point.** It is the ruled
name for the repository currently called `flex-auth`. zone-engine is the
Engine-layer **PIP** for zone **identity and membership**; the **effect** of
a zone on any decision `access-engine` renders is expressed in an
`access-engine` policy package or as a claim on the request (security layer
model v0.7 §6, §18).
The first draft of this invariant said "nothing this repo builds sits
synchronously in a decision path". flex-auth rejected that on review: it is a
*latency* guarantee, not an authority one. Compiled data that determines an
outcome is still deciding — it just decided earlier. Under the old wording
zone-engine could compile `enforced: false` for a lane, flip `warden sign`
from deny to allow with no flex-auth policy change, and be literally
compliant. Membership is ours; stance is theirs.
- **Compiled, not queried.** Membership reaches flex-auth by compilation into
the registry it already loads. This is a *consequence* of the invariant
above, not the invariant itself — flex-auth is `service_class:
latency-critical` and loads its registry once at process start.
from deny to allow with no policy-package change, and be literally
compliant. Membership is ours; stance is theirs; the decision point is
neither.
- **Compiled, not queried.** Membership reaches `access-engine` by compilation
into the registry it already loads, as a PIP fact, never as stance. This is
a *consequence* of the invariant above, not the invariant itself —
`access-engine` is `service_class: latency-critical` and loads its registry
once at process start.
- **A zone that can be quietly widened is not a boundary.** Every change of
stance is observable, and every exception has an enforced expiry.
- **Accuracy, not altitude** (`tenancy-posture_v0.1` §6). A repo declaring a
@ -64,15 +69,23 @@ runtime exists with an owner or the decision that none is needed is recorded.
It does not reopen the no-runtime decision; it makes the retained artifacts
truthful enough for an explicit archive-or-maintain decision.
`ZONE-WP-0003` is the owner-driven revision that follows from security layer
model v0.7 being accepted. It declares the Engine/PIP layer, records the
already-completed layer cut, and evolves the reference surface so zone facts
can be consumed as claims. It does not add a live API, a decision surface, or
a PEP.
## Retirement decision — 2026-08-23
Retain the repository as an offline reference-conformance repository while the
canonical v0.1 standard remains `proposed`. The maintainer is zone-engine; the
maintenance surface is limited to canon lineage, conformance fixtures, and
concrete owner-driven revisions. There is no service or routine delivery
backlog.
canonical `security-zones_v0.1` standard remains `proposed`. The maintainer is
zone-engine; the maintenance surface is limited to canon lineage, conformance
fixtures, and concrete owner-driven revisions. There is no service or routine
delivery backlog. The 2026-08-29 layer declaration is one such revision: the
security layer model is **accepted**; the zone standard is still **proposed**;
the catalogued form stays offline.
Reassess archival when net-kingdom accepts or supersedes v0.1, when the fixtures
are durably adopted by canon/control owners, or when no adopting control needs
the reference. An actual Forgejo archive or rename remains attended operator
work.
Reassess archival when net-kingdom accepts or supersedes `security-zones_v0.1`,
when the fixtures are durably adopted by canon/control owners, or when no
adopting control needs the reference. An actual Forgejo archive or rename
remains attended operator work.