Declare the layer in layer.yaml, check it against INTENT.md, and fail make check on a new Tooling client or HTTP decision surface. Record the six statute §10 artifacts for the 2026-08-23 cut, name access-engine on the README, and offer a non-schema PIP field mapping to Taxonomy. Assistant: grok Assistant-Session: 01a04ceb-0745-7ae1-9e26-0d10e5d52b8b
38 lines
1.2 KiB
Markdown
38 lines
1.2 KiB
Markdown
# zone-engine
|
|
|
|
Engine-layer **PIP** for NetKingdom **security-zone** identity and membership,
|
|
retained as offline reference conformance. This repository validates workload
|
|
membership and admission, projects only explicit owner-versioned control
|
|
profiles, checks time-boxed exception fixtures, and verifies the lineage of
|
|
the canonical standard.
|
|
|
|
It is not a live engine, not a PEP, and not a policy decision point. Canon is
|
|
published by `net-kingdom`. `access-engine` (currently `flex-auth`) is the
|
|
only PDP; each enforcement-point owner retains live policy and failure-mode
|
|
authority. Layer declaration: `INTENT.md` frontmatter and `layer.yaml`.
|
|
|
|
## Checks
|
|
|
|
```bash
|
|
make check
|
|
make canon-lineage CANON_ROOT=/path/to/net-kingdom
|
|
```
|
|
|
|
Resolve the versioned reference manifest and optional owner profile:
|
|
|
|
```bash
|
|
python3 tools/resolve_zones.py \
|
|
--manifest fixtures/manifests/reference.yaml \
|
|
--control-profile profiles/netkingdom-build-v0.1.yaml
|
|
```
|
|
|
|
Evaluate exception conformance at an explicit instant:
|
|
|
|
```bash
|
|
python3 tools/check_zone_exceptions.py \
|
|
fixtures/exceptions/valid-active.yaml \
|
|
--policy fixtures/exceptions/policy.yaml \
|
|
--at 2026-08-23T10:00:00Z
|
|
```
|
|
|
|
Orient: `GOAL.md` → `SCOPE.md` → `workplans/`.
|