Headless multi-application, multi-tenant security zone mangement engine.
Find a file
repo-manager 5177435060 repo.work.create_intake ZONE-IN-0001
correlation_id: 8050104b-0bd5-42b9-adbb-f167e369509e
reason: Request own-voice layer declaration under §11
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 23:02:14 +02:00
docs docs: finish zone reference hardening workplan 2026-08-23 12:35:01 +02:00
fixtures feat: harden zone reference contracts 2026-08-23 12:27:13 +02:00
history docs: finish zone reference hardening workplan 2026-08-23 12:35:01 +02:00
intakes repo.work.create_intake ZONE-IN-0001 2026-08-28 23:02:14 +02:00
profiles feat: harden zone reference contracts 2026-08-23 12:27:13 +02:00
tests feat: harden zone reference contracts 2026-08-23 12:27:13 +02:00
tools docs: finish zone reference hardening workplan 2026-08-23 12:35:01 +02:00
workplans fix(workplans): adopt ADR-007 derived identifiers 2026-08-25 19:31:02 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-08-23 12:32:50 +02:00
.gitignore feat: compile security zone declarations 2026-08-22 14:19:07 +02:00
.repo-classification.yaml Seed zone-engine — authority for security zones and exception lifecycle 2026-08-19 21:18:44 +02:00
AGENTS.md Seed zone-engine — authority for security zones and exception lifecycle 2026-08-19 21:18:44 +02:00
DECISIONS.md fix(workplans): adopt ADR-007 derived identifiers 2026-08-25 19:31:02 +02:00
GOAL.md docs: finish zone reference hardening workplan 2026-08-23 12:35:01 +02:00
INTENT.md Point layering note at the published standard 2026-08-28 21:21:08 +02:00
Makefile feat: harden zone reference contracts 2026-08-23 12:27:13 +02:00
README.md docs: finish zone reference hardening workplan 2026-08-23 12:35:01 +02:00
SCOPE.md docs: finish zone reference hardening workplan 2026-08-23 12:35:01 +02:00
WORK-RECORDS.md docs: finish zone reference hardening workplan 2026-08-23 12:35:01 +02:00

zone-engine

Offline reference conformance for NetKingdom security zones. This repository validates workload membership and admission, projects only explicit owner-versioned control profiles, checks time-boxed exception fixtures, and verifies the lineage of the canonical standard.

It is not a service or policy decision point. Canon is published by net-kingdom; flex-auth and each enforcement-point owner retain live policy authority.

Checks

make check
make canon-lineage CANON_ROOT=/path/to/net-kingdom

Resolve the versioned reference manifest and optional owner profile:

python3 tools/resolve_zones.py \
  --manifest fixtures/manifests/reference.yaml \
  --control-profile profiles/netkingdom-build-v0.1.yaml

Evaluate exception conformance at an explicit instant:

python3 tools/check_zone_exceptions.py \
  fixtures/exceptions/valid-active.yaml \
  --policy fixtures/exceptions/policy.yaml \
  --at 2026-08-23T10:00:00Z

Orient: GOAL.mdSCOPE.mdworkplans/.