zone-engine/README.md
tegwick acfd93fc86 feat: finish ZONE-WP-0003 Engine/PIP freeze and claim mapping
Declare the layer in layer.yaml, check it against INTENT.md, and fail
make check on a new Tooling client or HTTP decision surface. Record the
six statute §10 artifacts for the 2026-08-23 cut, name access-engine on
the README, and offer a non-schema PIP field mapping to Taxonomy.

Assistant: grok
Assistant-Session: 01a04ceb-0745-7ae1-9e26-0d10e5d52b8b
2026-08-29 12:49:24 +02:00

1.2 KiB

zone-engine

Engine-layer PIP for NetKingdom security-zone identity and membership, retained as offline reference conformance. This repository validates workload membership and admission, projects only explicit owner-versioned control profiles, checks time-boxed exception fixtures, and verifies the lineage of the canonical standard.

It is not a live engine, not a PEP, and not a policy decision point. Canon is published by net-kingdom. access-engine (currently flex-auth) is the only PDP; each enforcement-point owner retains live policy and failure-mode authority. Layer declaration: INTENT.md frontmatter and layer.yaml.

Checks

make check
make canon-lineage CANON_ROOT=/path/to/net-kingdom

Resolve the versioned reference manifest and optional owner profile:

python3 tools/resolve_zones.py \
  --manifest fixtures/manifests/reference.yaml \
  --control-profile profiles/netkingdom-build-v0.1.yaml

Evaluate exception conformance at an explicit instant:

python3 tools/check_zone_exceptions.py \
  fixtures/exceptions/valid-active.yaml \
  --policy fixtures/exceptions/policy.yaml \
  --at 2026-08-23T10:00:00Z

Orient: GOAL.mdSCOPE.mdworkplans/.