Headless multi-application, multi-tenant security zone mangement engine.
Find a file
codex 44cd1fc231 fix(workplans): adopt ADR-007 derived identifiers
Records absent from central carried random pre-ADR-007 identifiers minted by
the retired local hub, which C-06 refused as stale references. Deriving from
the canonical record id takes no identity from anything.

Refs CUST-WP-0068-T06

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-25 19:31:02 +02:00
docs docs: finish zone reference hardening workplan 2026-08-23 12:35:01 +02:00
fixtures feat: harden zone reference contracts 2026-08-23 12:27:13 +02:00
history docs: finish zone reference hardening workplan 2026-08-23 12:35:01 +02:00
profiles feat: harden zone reference contracts 2026-08-23 12:27:13 +02:00
tests feat: harden zone reference contracts 2026-08-23 12:27:13 +02:00
tools docs: finish zone reference hardening workplan 2026-08-23 12:35:01 +02:00
workplans fix(workplans): adopt ADR-007 derived identifiers 2026-08-25 19:31:02 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-08-23 12:32:50 +02:00
.gitignore feat: compile security zone declarations 2026-08-22 14:19:07 +02:00
.repo-classification.yaml Seed zone-engine — authority for security zones and exception lifecycle 2026-08-19 21:18:44 +02:00
AGENTS.md Seed zone-engine — authority for security zones and exception lifecycle 2026-08-19 21:18:44 +02:00
DECISIONS.md fix(workplans): adopt ADR-007 derived identifiers 2026-08-25 19:31:02 +02:00
GOAL.md docs: finish zone reference hardening workplan 2026-08-23 12:35:01 +02:00
INTENT.md docs: finish zone reference hardening workplan 2026-08-23 12:35:01 +02:00
Makefile feat: harden zone reference contracts 2026-08-23 12:27:13 +02:00
README.md docs: finish zone reference hardening workplan 2026-08-23 12:35:01 +02:00
SCOPE.md docs: finish zone reference hardening workplan 2026-08-23 12:35:01 +02:00
WORK-RECORDS.md docs: finish zone reference hardening workplan 2026-08-23 12:35:01 +02:00

zone-engine

Offline reference conformance for NetKingdom security zones. This repository validates workload membership and admission, projects only explicit owner-versioned control profiles, checks time-boxed exception fixtures, and verifies the lineage of the canonical standard.

It is not a service or policy decision point. Canon is published by net-kingdom; flex-auth and each enforcement-point owner retain live policy authority.

Checks

make check
make canon-lineage CANON_ROOT=/path/to/net-kingdom

Resolve the versioned reference manifest and optional owner profile:

python3 tools/resolve_zones.py \
  --manifest fixtures/manifests/reference.yaml \
  --control-profile profiles/netkingdom-build-v0.1.yaml

Evaluate exception conformance at an explicit instant:

python3 tools/check_zone_exceptions.py \
  fixtures/exceptions/valid-active.yaml \
  --policy fixtures/exceptions/policy.yaml \
  --at 2026-08-23T10:00:00Z

Orient: GOAL.mdSCOPE.mdworkplans/.