docs: declare Engine/PIP under security-layer-model v0.7
Assent to ZONE-IN-0001 in this repository's own voice: layer Engine, role PIP, offline reference remaining the catalogued surface. Align INTENT, SCOPE, and GOAL with accepted statute v0.7 and companion v0.2. Record the scope-against-intent review and open ZONE-WP-0003 for the mechanical remainder. Do not reopen the no-runtime decision. Assistant: grok Assistant-Session: 01a04ceb-0745-7ae1-9e26-0d10e5d52b8b
This commit is contained in:
parent
1b9a252fa3
commit
a34bc194dc
6 changed files with 704 additions and 88 deletions
250
workplans/ZONE-WP-0003-security-layer-model-alignment.md
Normal file
250
workplans/ZONE-WP-0003-security-layer-model-alignment.md
Normal file
|
|
@ -0,0 +1,250 @@
|
|||
---
|
||||
id: ZONE-WP-0003
|
||||
type: workplan
|
||||
title: "Declare Engine/PIP and freeze the offline zone-membership surface"
|
||||
domain: infotech
|
||||
repo: zone-engine
|
||||
status: ready
|
||||
owner: zone-engine
|
||||
assignee: grok
|
||||
lane: yellow
|
||||
topic_slug: netkingdom
|
||||
planning_priority: P1
|
||||
created: "2026-08-29"
|
||||
updated: "2026-08-29"
|
||||
origin: "history/2026-08-29-security-layer-model-scope-against-intent.md"
|
||||
context_paths:
|
||||
- "GOAL.md"
|
||||
- "INTENT.md"
|
||||
- "SCOPE.md"
|
||||
- "README.md"
|
||||
- "intakes/intakes.md"
|
||||
- "history/2026-08-23-retain-reference-decision.md"
|
||||
- "history/2026-08-29-security-layer-model-scope-against-intent.md"
|
||||
quality_dor: DoR-Ok
|
||||
quality_dor_at: "2026-08-29"
|
||||
quality_dor_by: grok
|
||||
quality_dor_note: "Gaps are evidenced against security-layer-model v0.7, companion v0.2, and the shipped offline resolver; owners, stop conditions, and the no-runtime freeze are explicit."
|
||||
---
|
||||
|
||||
# ZONE-WP-0003 — Declare Engine/PIP and freeze the offline zone-membership surface
|
||||
|
||||
## Goal
|
||||
|
||||
Make this repository a conforming Engine-layer PIP under NetKingdom Security
|
||||
Layer Model v0.7 without reversing the 2026-08-23 no-runtime decision. Declare
|
||||
the layer in a machine-readable form, close the declaration intake, record the
|
||||
already-completed layer cut, and map current membership output onto the facts
|
||||
a future request-claim must carry.
|
||||
|
||||
Source review: `history/2026-08-29-security-layer-model-scope-against-intent.md`.
|
||||
Statute: `net-kingdom/canon/standards/security-layer-model_v0.7.md`.
|
||||
Companion: `net-kingdom/SECURITY-COMPANION.md` v0.2.
|
||||
|
||||
`INTENT.md` already declares `layer: Engine` and `role: PIP` in this
|
||||
repository's own voice. This workplan makes that declaration checkable and
|
||||
closes the remaining documentary gaps. It does not add a live API.
|
||||
|
||||
## Why these gaps are the relevant ones
|
||||
|
||||
| Priority | Gap | Why address it here |
|
||||
| --- | --- | --- |
|
||||
| P0 | No `layer.yaml` or conformance check | Statute §11 is mechanical; a new Tooling client or decision surface would land as the small convenience §6 warns about |
|
||||
| P0 | `ZONE-IN-0001` still open after the declaration | gate-house asked for our voice; §14 still counts us among the silent nine |
|
||||
| P1 | Statute §10 artifacts for the 2026-08-23 cut are incomplete | The procedure was written from this case; the freeze is the checkable piece |
|
||||
| P1 | `README.md` still names only `flex-auth` | Consumer-facing docs must use the ruled PDP name |
|
||||
| P1 | Resolver output is membership, not a claim | Statute §18 wants claims; §17 forbids inventing the schema here |
|
||||
|
||||
A live Engine API, a PEP stance map, compiled stance, reef/zone composition,
|
||||
and the `flex-auth` repository rename are intentionally excluded.
|
||||
|
||||
## Authority and dependencies
|
||||
|
||||
- **gate-house / net-kingdom** own the statute and the §4 catalog. This plan
|
||||
declares into that catalog; it does not edit it.
|
||||
- **`access-engine` (currently `flex-auth`)** owns the PDP, policy packages,
|
||||
and the governed rename. This plan uses the ruled name in prose and leaves
|
||||
fixture owner identities as `flex-auth` until that rename lands.
|
||||
- **Taxonomy** owns the request-claim schema (statute §17, unassigned). This
|
||||
plan offers a field mapping, not a schema.
|
||||
- **zone-engine** owns the declaration, the conformance check, the freeze
|
||||
record, and the PIP mapping note.
|
||||
- **Operator action** is not required. No archive, rename, or service
|
||||
deployment is in this plan.
|
||||
|
||||
## Boundaries
|
||||
|
||||
- Do not add an API, daemon, database, controller, scheduler, or reload path.
|
||||
- Do not expose an authorization decision surface or cache a verdict.
|
||||
- Do not compile stance into membership or change a live effect from a local
|
||||
profile edit.
|
||||
- Do not publish a PEP stance map; this repository is not PEP-shaped.
|
||||
- Do not invent the estate request-claim schema.
|
||||
- Do not map `reef-*` onto security zones.
|
||||
- Do not treat observation-in-production or automatic containment as available.
|
||||
- Do not fold `ZONE-WP-0001` or `ZONE-WP-0002` back open.
|
||||
- Leave fixture `policy_owner` / source identities as the actual repository
|
||||
names they pin.
|
||||
|
||||
## T01 - Machine-readable layer declaration and conformance check
|
||||
|
||||
```task
|
||||
id: ZONE-WP-0003-T01
|
||||
status: todo
|
||||
priority: high
|
||||
```
|
||||
|
||||
Add `layer.yaml` in the kings-guard no-contact shape, pointing at security
|
||||
layer model v0.7:
|
||||
|
||||
- `layer: engine`
|
||||
- `role: pip`
|
||||
- `tooling_contacts: []`
|
||||
- `non_tooling_clients` lists any State Hub / work-record client, recorded
|
||||
as not-catalogued
|
||||
- no `pep_stance` path
|
||||
- catalog note: §4 Engine / PIP; offline reference conformance per the
|
||||
2026-08-23 disposition
|
||||
|
||||
Add `tools/check_layer_conformance.py` and a unit test. The check must fail
|
||||
if:
|
||||
|
||||
- `layer.yaml` is missing, unparseable, or disagrees with `INTENT.md`
|
||||
frontmatter;
|
||||
- a Tooling-layer client import appears under `tools/` (OpenBao/Vault,
|
||||
cluster, direct datastore);
|
||||
- a new HTTP authorization decision surface appears.
|
||||
|
||||
Wire it into `make check`. Review dates, if any, are reported, never used as
|
||||
a calendar-day build failure.
|
||||
|
||||
**Done when:** `layer.yaml` is committed, agrees with `INTENT.md`, `make check`
|
||||
covers it, and a reviewer can see there are no Tooling contacts, no PEP
|
||||
claim, and no decision surface.
|
||||
|
||||
## T02 - Close ZONE-IN-0001 and notify gate-house
|
||||
|
||||
```task
|
||||
id: ZONE-WP-0003-T02
|
||||
status: todo
|
||||
priority: high
|
||||
```
|
||||
|
||||
Close `ZONE-IN-0001` in `intakes/intakes.md` with outcome `absorbed` /
|
||||
promoted to this workplan, recording that the proposed Engine layer is
|
||||
assented in this repository's own voice and that the offline PIP form is the
|
||||
catalogued surface, not a contest.
|
||||
|
||||
Notify `gate-house` (State Hub message or equivalent durable notice) that
|
||||
zone-engine has declared Engine / PIP under v0.7 so statute §14 can stop
|
||||
counting this repository among the undeclared nine.
|
||||
|
||||
**Done when:** the intake file is closed with a resolution that points at
|
||||
`INTENT.md` and this workplan, and the notice to `gate-house` exists.
|
||||
|
||||
## T03 - Record the §10 artifacts for the 2026-08-23 layer cut
|
||||
|
||||
```task
|
||||
id: ZONE-WP-0003-T03
|
||||
status: todo
|
||||
priority: medium
|
||||
```
|
||||
|
||||
Write a short retrospective under `history/` (or a `docs/` note cited from
|
||||
`INTENT.md`) that gathers the six statute §10 artifacts for the already
|
||||
completed cut:
|
||||
|
||||
| Artifact | Source |
|
||||
| --- | --- |
|
||||
| before/after `INTENT.md` | 2026-08-23 retain text vs 2026-08-29 declaration |
|
||||
| client inventory | none against Tooling; offline Python tools only |
|
||||
| gap inventory | none as §5.3 contacts; live Engine API is not a gap this repo currently owes |
|
||||
| assent list | flex-auth / ops-warden adoption already evidenced; no new boundary moves |
|
||||
| state-migration decision | `history/2026-08-23-retain-reference-decision.md` |
|
||||
| permission freeze | no live API, no decision surface, no compiled stance until a later cut carries its own six artifacts |
|
||||
|
||||
**Done when:** a reviewer can find all six artifacts without reconstructing
|
||||
them from workplan history, and `INTENT.md` or `SCOPE.md` cites the note.
|
||||
|
||||
## T04 - Align remaining consumer-facing naming
|
||||
|
||||
```task
|
||||
id: ZONE-WP-0003-T04
|
||||
status: todo
|
||||
priority: medium
|
||||
```
|
||||
|
||||
Update `README.md` so a first-time reader sees Engine / PIP, offline
|
||||
reference, and `access-engine` as the ruled PDP name (currently `flex-auth`).
|
||||
Do not rewrite historical evidence, workplan files, or fixture owner
|
||||
identities.
|
||||
|
||||
Confirm `GOAL.md` invariants already match; only patch if T01–T03 drift them.
|
||||
|
||||
**Done when:** `README.md`, `INTENT.md`, `SCOPE.md`, and `GOAL.md` agree on
|
||||
layer, role, and PDP name, and `git grep access-engine README.md INTENT.md
|
||||
SCOPE.md GOAL.md` is the consumer-facing surface.
|
||||
|
||||
## T05 - PIP claim-boundary note, without a schema
|
||||
|
||||
```task
|
||||
id: ZONE-WP-0003-T05
|
||||
status: todo
|
||||
priority: medium
|
||||
```
|
||||
|
||||
Write `docs/pip-claim-boundary.md` that:
|
||||
|
||||
1. lists the facts this PIP owns today (authoritative identity, declared and
|
||||
effective zone, admission result and reason, membership revision, source
|
||||
and source revision);
|
||||
2. maps those fields onto what a future statute §17 request-claim must carry
|
||||
(issuer, freshness, zone membership — not stance, not failure mode);
|
||||
3. states that stance and failure mode remain owner policy and PEP
|
||||
configuration, consumed by `access-engine` as a claim or a versioned rule
|
||||
(statute §18);
|
||||
4. marks the mapping as a contribution to Taxonomy, not a published schema;
|
||||
5. forbids a competing claim dialect and forbids compiling those facts into
|
||||
registry content that determines an outcome.
|
||||
|
||||
Offer the note to `gate-house` / `net-kingdom` and to `access-engine`. Do not
|
||||
wait on their assent to keep the freeze.
|
||||
|
||||
**Done when:** the note is cited from `SCOPE.md`, tests still pass unchanged,
|
||||
and no new wire format has shipped.
|
||||
|
||||
## Acceptance criteria
|
||||
|
||||
- [ ] `layer.yaml` declares Engine / PIP, no Tooling contacts, no PEP map.
|
||||
- [ ] `make check` fails a new undeclared Tooling client or decision surface.
|
||||
- [ ] `ZONE-IN-0001` is closed on the own-voice declaration.
|
||||
- [ ] `gate-house` has been notified.
|
||||
- [ ] Statute §10 artifacts for the 2026-08-23 cut are gathered in one place.
|
||||
- [ ] Consumer-facing docs use `access-engine` as the ruled PDP name.
|
||||
- [ ] PIP facts are mapped for a future claim schema without shipping one.
|
||||
- [ ] No live API, daemon, decision surface, or compiled stance was added.
|
||||
|
||||
## Out of scope
|
||||
|
||||
- A zone-engine API, daemon, database, controller, scheduler, or synchronous
|
||||
lookup.
|
||||
- Publishing a PEP unreachable-engine stance map.
|
||||
- Compiling stance into registry content or changing owner policy.
|
||||
- Inventing or publishing the estate request-claim schema.
|
||||
- Mapping Railiance reefs onto security zones.
|
||||
- The `flex-auth` → `access-engine` repository rename.
|
||||
- Promoting `security-zones_v0.1` out of `proposed`.
|
||||
- Archiving or renaming this Forgejo repository.
|
||||
- Estate-wide reference migration of unresolved catalog entries.
|
||||
|
||||
## Stop conditions
|
||||
|
||||
Stop and return to the relevant owner if implementation would require any of
|
||||
the following:
|
||||
|
||||
- adding zone-engine to a live authorization or enforcement path;
|
||||
- making a local profile authoritative over an owner policy package;
|
||||
- inventing a claim schema and presenting it as estate canon;
|
||||
- cataloguing this repository as PEP-shaped;
|
||||
- reversing the 2026-08-23 retain / no-runtime decision without a new §10
|
||||
layer-change record and assent from the repositories whose boundaries move.
|
||||
Loading…
Add table
Add a link
Reference in a new issue