Enforcement controls in this estate have been repo-wide booleans. ops-warden's flex-auth pre-sign gate was the first to become flippable, and flipping it would have made flex-auth a hard dependency of every warden sign — including the SSH certs the ops-bridge tunnels depend on, one of which carries the policy call. Uniform enforcement across an estate under deep refactor hardens exactly the access needed to perform the refactor. Deferred under ops-warden ADR-0006; this repo is what that ADR defers to. Seeded deliberately without a schema. ZONE-WP-0001 produces a model and a canon draft, not an API: an engine that ships a wire format before it has partitioned the real estate defines the model by accident. Whether a runtime is warranted is an output of the exception-lifecycle task, not an assumption. Invariants set now, because they are the ones easy to lose later: flex-auth stays the only PDP and receives membership by compilation, not a synchronous lookup in a latency-critical decision path; placement (reefs) is not posture; accuracy not altitude, per tenancy-posture v0.1 §6. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
101 lines
4.5 KiB
Markdown
101 lines
4.5 KiB
Markdown
# SCOPE
|
||
|
||
> What this repository is about, when it is relevant, and when it is not.
|
||
> Direction lives in `GOAL.md`.
|
||
|
||
---
|
||
|
||
## One-liner
|
||
|
||
Authority for security zones — the bands of enforcement rigidity that scope
|
||
*where* a control is enforced, and the lifecycle of time-boxed exceptions that
|
||
relax them during deep refactors without leaving a permanent hole.
|
||
|
||
---
|
||
|
||
## Why this exists
|
||
|
||
Enforcement controls in this estate have been repo-wide booleans. ops-warden's
|
||
flex-auth pre-sign gate (`policy.enabled` with `fail_closed: true`) was the
|
||
first to become flippable, and flipping it would have made flex-auth a hard
|
||
dependency of every `warden sign` — including the SSH certificates the
|
||
ops-bridge tunnels depend on, one of which carries the policy call itself.
|
||
|
||
Across an estate under continuous deep refactor, uniform enforcement hardens
|
||
exactly the access needed to perform the refactor. That is not security; it is
|
||
an outage with good intentions. The flip was deferred under ops-warden's
|
||
`ADR-0006` — *enforcement is zone-scoped, never a global flag* — and this repo
|
||
is what that ADR defers to.
|
||
|
||
---
|
||
|
||
## In scope
|
||
|
||
- **Zone identity and membership.** What zones exist, and what puts a lane,
|
||
actor, or workload in one. Derived from declared posture where possible
|
||
rather than a fourth hand-maintained list.
|
||
- **Enforcement stance per control per zone** — enforced / advisory / exempt,
|
||
and the failure mode (fail-closed or fail-open) that goes with it. The failure
|
||
mode is the part with teeth.
|
||
- **Time-boxed exception lifecycle** — a relaxation with an expiry that is
|
||
enforced by something rather than intended, plus the record of who widened
|
||
what, when, and until when.
|
||
- **The declaration format** repos use to state their zones, following
|
||
`tenancy.yaml` and its rule: *accuracy, not altitude*.
|
||
- **Drafting the canon standard** for the model, offered to `net-kingdom` for
|
||
publication the way `tenant-engine` and `user-engine` have boundary contracts
|
||
in canon.
|
||
|
||
## Out of scope
|
||
|
||
- **Authorization decisions.** `flex-auth` is the PDP and stays the only one.
|
||
A second decision point is the split-brain this repo must not create.
|
||
- **Network segmentation.** "Zone" is overloaded; this is about enforcement
|
||
rigidity, not routing or NetworkPolicy. The two must not be conflated.
|
||
- **Substrate placement.** Reefs (`reef-railiance`, `reef-storage`) answer
|
||
*where does it run*; a zone answers *how rigidly is it governed*. Correlated,
|
||
not the same axis — and per repo-manager's rule, topology is not readiness.
|
||
- **Identity, secrets, tenancy.** `key-cape`, OpenBao / `secrets-engine`,
|
||
`tenant-engine`.
|
||
- **Implementing any specific control.** Owners keep their own controls; this
|
||
repo says where they bite.
|
||
- **Publishing canon.** `net-kingdom` owns canon; `policy-nexus` publishes.
|
||
|
||
---
|
||
|
||
## Relationship to what already exists
|
||
|
||
| Mechanism | Owner | Relationship |
|
||
| --- | --- | --- |
|
||
| `tenancy-posture_v0.1` (six axes, per-repo `tenancy.yaml`) | net-kingdom canon | **Structural model to follow** — graduated levels, declared conformance, review dates, "accuracy not altitude". Its §14 stance is *structure, not tooling*, which is why this repo starts as a model and not an API |
|
||
| Environment posture + workload maturity `M0`–`M3` | ops-warden (WP-0015) | Inputs a zone may derive membership from |
|
||
| `organization_posture: build` | ops-warden (WP-0029) | Candidate to fold in rather than run alongside |
|
||
| Reefs / `bound_reefs` | repo-manager | Correlated substrate axis; must be reconciled, not duplicated |
|
||
| Compiled registry snapshot | flex-auth | **How zone membership reaches the PDP.** flex-auth is latency-critical; compilation, not runtime lookup |
|
||
| `warden plan` verdicts + `reasons` | ops-warden (WP-0029) | Existing verdict machinery to extend, not parallel |
|
||
|
||
---
|
||
|
||
## Current state (2026-08-19)
|
||
|
||
Seeded. No model, no schema, no runtime. `ZONE-WP-0001` derives the model from
|
||
the real estate and drafts the canon standard; a runtime is earned only if the
|
||
exception lifecycle proves to need one.
|
||
|
||
Deliberately empty of schema — an empty engine that ships a schema first ends up
|
||
defining the model by accident.
|
||
|
||
---
|
||
|
||
## Relevant when
|
||
|
||
- A control is about to be enabled and the question "enforced *where*?" has no
|
||
answer
|
||
- A deep refactor needs relaxed rigidity in a band of the estate, with an expiry
|
||
- A repo needs to declare which zone its lanes sit in
|
||
|
||
## Not relevant when
|
||
|
||
- Asking whether a specific request is allowed (→ `flex-auth`)
|
||
- Placing a workload on a substrate (→ `repo-manager` reefs)
|
||
- Anything about network reachability
|