diff --git a/docs/agentic-tooling.md b/docs/agentic-tooling.md index 1bbedc1..7ca9c78 100644 --- a/docs/agentic-tooling.md +++ b/docs/agentic-tooling.md @@ -194,7 +194,7 @@ Project agents stop before direct host mutation, Proxmox console drift, unscoped machine identities, secret material in files or state, and workloads without a reviewed substrate contract. The contract shape comes from Citadel's example at -`/Users/verlyn13/Organizations/the-nash-group/the-citadel/docs/reference/project-substrate-contract.example.yaml`. +`/Users/verlyn13/Organizations//the-citadel/docs/reference/project-substrate-contract.example.yaml`. ## MCP Configuration diff --git a/docs/cloudflare-mcp.md b/docs/cloudflare-mcp.md index 24ea0d3..fbcc5de 100644 --- a/docs/cloudflare-mcp.md +++ b/docs/cloudflare-mcp.md @@ -81,7 +81,7 @@ instead of being preserved as user-added servers. Interim OAuth identity is `REDACTED-operator-google-account` (Option B) per the operator Cloudflare admin identity decision. The target identity is -`guardian@thenash.group` (Option C) after the Phase 2 Cloudflare account email +`@` (Option C) after the Phase 2 Cloudflare account email migration lands. The interim OAuth grant is read-mostly per the parent OAuth pilot findings: diff --git a/docs/cloudflare-one-terminology.md b/docs/cloudflare-one-terminology.md index 273efcb..421fe5d 100644 --- a/docs/cloudflare-one-terminology.md +++ b/docs/cloudflare-one-terminology.md @@ -22,7 +22,7 @@ Cloudflare, device, DNS, Tunnel, Access, Traffic policy, or 1Password change. ## Current Cloudflare Authority As of 2026-05-27, the active family-home Cloudflare control-plane repo is -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. +`/Users/verlyn13/Organizations//family-cloudflare`. That repo is the migration target from the older `/Users/verlyn13/Repos/local/cloudflare-dns` clone. Dated `cloudflare-dns` diff --git a/docs/codex-cli-setup.md b/docs/codex-cli-setup.md index 72fb6c0..e6236fc 100644 --- a/docs/codex-cli-setup.md +++ b/docs/codex-cli-setup.md @@ -62,7 +62,7 @@ boundary: | Full access | **OFF** (standing) | "Full access ON" is capability-availability, not a proven runtime grant — effective enforcement is `config.toml` Sandbox + Approval. Leaving it ON while relying on the sandbox to neutralize it is fragile and conflicts with the approval-gated posture: Full access = no-approval edits to *any* file, which can reach outside the workspace. | | Sandbox | **Read only** (default); `workspace-write` per-task only | Default-deny writes; widen only for a specific task. | | Approval | **On request** | Keep a human in the loop for actions outside the read-only sandbox. | -| Config selection | **jefahnierocks (entity) scope**, not `the-nash-group` | `the-nash-group` points the active config at **parent** scope while the work tree is the jefahnierocks **entity** — a boundary mismatch. Alternatively adopt a jefahnierocks-rooted project `.codex/config.toml` with `trust_level` opt-in. | +| Config selection | **jefahnierocks (entity) scope**, not `` | `` points the active config at **parent** scope while the work tree is the jefahnierocks **entity** — a boundary mismatch. Alternatively adopt a jefahnierocks-rooted project `.codex/config.toml` with `trust_level` opt-in. | Posture model: **HCS ADR 0017** (cited by identifier) — *UI labels are not runtime receipts*. The app's GUI permission rows are SOURCE/posture evidence, not diff --git a/docs/device-admin/README.md b/docs/device-admin/README.md index b8f3fc5..d507a7f 100644 --- a/docs/device-admin/README.md +++ b/docs/device-admin/README.md @@ -24,7 +24,7 @@ policies; older dated evidence may still say WARP, Zero Trust profile, or Gateway policy where that was the source-era wording. Current Cloudflare control-plane authority is -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`, migrated from +`/Users/verlyn13/Organizations//family-cloudflare`, migrated from the older `/Users/verlyn13/Repos/local/cloudflare-dns` repo. Dated `cloudflare-dns` handbacks remain historical evidence; new Cloudflare blockers and proof requests should route to `family-cloudflare`. diff --git a/docs/device-admin/cloudflare-dns-handback-ingest-2026-05-14.md b/docs/device-admin/cloudflare-dns-handback-ingest-2026-05-14.md index 8554f45..aedfab1 100644 --- a/docs/device-admin/cloudflare-dns-handback-ingest-2026-05-14.md +++ b/docs/device-admin/cloudflare-dns-handback-ingest-2026-05-14.md @@ -24,7 +24,7 @@ was changed by this ingest. Current-state note, added 2026-05-27: this remains the historical ingest from the former `cloudflare-dns` repo. Active family-home Cloudflare control-plane work has migrated to -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. Use this +`/Users/verlyn13/Organizations//family-cloudflare`. Use this document for provenance, but refresh new Cloudflare One Client, device-profile, Gateway, Access, Tunnel, DNS, Worker, or Pulumi/IaC claims against `family-cloudflare` or live provider proof. @@ -39,7 +39,7 @@ Traffic policies for Gateway policies. | Field | Value | |---|---| -| Source repo | `/Users/verlyn13/Repos/local/cloudflare-dns` (historical; migrated to `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare` as of 2026-05-27) | +| Source repo | `/Users/verlyn13/Repos/local/cloudflare-dns` (historical; migrated to `/Users/verlyn13/Organizations//family-cloudflare` as of 2026-05-27) | | Source doc | `docs/handback-system-config-2026-05-13.md` | | Source commit | `b5b9460` (file introduction) | | Parent context commit | `9e4458a` (`fix(state): correct stale enabled flag for 05-adult-identity-bypass`) | diff --git a/docs/device-admin/cloudflare-windows-multi-user-ingest-2026-05-15.md b/docs/device-admin/cloudflare-windows-multi-user-ingest-2026-05-15.md index 0eb7d5a..e98136c 100644 --- a/docs/device-admin/cloudflare-windows-multi-user-ingest-2026-05-15.md +++ b/docs/device-admin/cloudflare-windows-multi-user-ingest-2026-05-15.md @@ -24,7 +24,7 @@ package, or CLI surface. Current-state note, added 2026-05-27: the original follow-up was aimed at the pre-migration `cloudflare-dns` repo. Active Cloudflare control-plane work now -belongs in `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`, so +belongs in `/Users/verlyn13/Organizations//family-cloudflare`, so that repo must answer or supersede this rebaseline before any Windows cutover. ## Source diff --git a/docs/device-admin/current-status.yaml b/docs/device-admin/current-status.yaml index bc1594f..4323a71 100644 --- a/docs/device-admin/current-status.yaml +++ b/docs/device-admin/current-status.yaml @@ -51,7 +51,7 @@ last_updated: 2026-05-28T07:23:14Z cloudflare_control_plane_current_state: verified_at: 2026-05-27T19:28:29Z active_repo: family-cloudflare - active_repo_path: /Users/verlyn13/Organizations/the-nash-group/family-cloudflare + active_repo_path: /Users/verlyn13/Organizations//family-cloudflare active_repo_head: 8bc7f11 active_repo_branch: docs/fu-23-warp-overlay-coexistence-2026-05-27 active_repo_upstream_state: "no upstream tracking branch; main and origin/main both at 8bc7f11" @@ -845,7 +845,7 @@ cross_cutting_tbd_items: advisory_ingests: - source_repo: hetzner - source_path: /Users/verlyn13/Organizations/the-nash-group/hetzner + source_path: /Users/verlyn13/Organizations//hetzner source_doc: docs/reports/cloudflare-management-status-for-system-config-2026-05-14.md source_commit: 009c091bc63556e6fb43503bf70aee97a269ea82 ingested_at: 2026-05-14T17:30:00Z diff --git a/docs/device-admin/device-overlay-posture-cloudflare-tailscale-2026-05-18.md b/docs/device-admin/device-overlay-posture-cloudflare-tailscale-2026-05-18.md index 1a033e1..2d7e05a 100644 --- a/docs/device-admin/device-overlay-posture-cloudflare-tailscale-2026-05-18.md +++ b/docs/device-admin/device-overlay-posture-cloudflare-tailscale-2026-05-18.md @@ -28,7 +28,7 @@ term. Current-state note, added 2026-05-27: Cloudflare authority has migrated from the historical `cloudflare-dns` repo to -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. Use the old +`/Users/verlyn13/Organizations//family-cloudflare`. Use the old handbacks below for provenance only; current Cloudflare One Client, Access, Tunnel, and profile claims need `family-cloudflare` or live provider proof. diff --git a/docs/device-admin/fedora-top-remote-admin-routing-design-2026-05-13.md b/docs/device-admin/fedora-top-remote-admin-routing-design-2026-05-13.md index 8e11d34..4d2d083 100644 --- a/docs/device-admin/fedora-top-remote-admin-routing-design-2026-05-13.md +++ b/docs/device-admin/fedora-top-remote-admin-routing-design-2026-05-13.md @@ -37,7 +37,7 @@ the `cloudflare-warp` package name remain literal. Current-state note, added 2026-05-27: this design predates the migration from `/Users/verlyn13/Repos/local/cloudflare-dns` to -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. Keep the +`/Users/verlyn13/Organizations//family-cloudflare`. Keep the design conclusions, but refresh Cloudflare-side evidence in `family-cloudflare` before authoring or applying any cutover packet. @@ -80,7 +80,7 @@ This design crosses three repos. The boundary is strict: |---|---|---|---| | Host hardening, host firewall, host package state, host SSH config, host daemon state | `system-config` (this repo) | All of it. | This document, packets, apply records. | | LAN routing, OPNsense rules, ISC DHCP, Unbound DNS, NAT, HAProxy frontends, WoL | HomeNetOps (`~/Repos/verlyn13/HomeNetOps`) | All LAN-layer state. | "We need " requests via the handback-format pattern; never reach in. | -| Cloudflare DNS records, Cloudflare Tunnel, Access policies, Traffic policies, Cloudflare One Client device enrollment, device profiles, account-level tokens | `family-cloudflare` (`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`) | All Cloudflare-side state, including current device-profile assignments and adult-vs-kids profile membership. | "We need " requests; never claim live Cloudflare state unless current `family-cloudflare` proof or provider evidence supplies it. | +| Cloudflare DNS records, Cloudflare Tunnel, Access policies, Traffic policies, Cloudflare One Client device enrollment, device profiles, account-level tokens | `family-cloudflare` (`/Users/verlyn13/Organizations//family-cloudflare`) | All Cloudflare-side state, including current device-profile assignments and adult-vs-kids profile membership. | "We need " requests; never claim live Cloudflare state unless current `family-cloudflare` proof or provider evidence supplies it. | Implication: any statement in any subsequent packet of the form "the Cloudflare Access policy for `fedora-top` is N" must cite a @@ -527,4 +527,4 @@ boundaries, nothing more. - [../secrets.md](../secrets.md) - HomeNetOps repo (external authority): `~/Repos/verlyn13/HomeNetOps` - `family-cloudflare` repo (external authority): - `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare` + `/Users/verlyn13/Organizations//family-cloudflare` diff --git a/docs/device-admin/fu-23-operator-device-access-proof-input-2026-05-18.md b/docs/device-admin/fu-23-operator-device-access-proof-input-2026-05-18.md index 1c1ab23..c11ce53 100644 --- a/docs/device-admin/fu-23-operator-device-access-proof-input-2026-05-18.md +++ b/docs/device-admin/fu-23-operator-device-access-proof-input-2026-05-18.md @@ -50,8 +50,8 @@ device profile, and Traffic policies. Operator-relayed parent packets: -- `/Users/verlyn13/Organizations/the-nash-group/.claude/orchestration/cloudflare-resource-management/MINIMUM-NAMED-CLOUDFLARE-ACCESS-DESIGN-2026-05-18.md` -- `/Users/verlyn13/Organizations/the-nash-group/.claude/orchestration/cloudflare-resource-management/FU-23-SUBORG-AGENT-ORCHESTRATION-2026-05-18.md` +- `/Users/verlyn13/Organizations//.claude/orchestration/cloudflare-resource-management/MINIMUM-NAMED-CLOUDFLARE-ACCESS-DESIGN-2026-05-18.md` +- `/Users/verlyn13/Organizations//.claude/orchestration/cloudflare-resource-management/FU-23-SUBORG-AGENT-ORCHESTRATION-2026-05-18.md` System-config sources: @@ -215,7 +215,7 @@ Record PASS/FAIL/date only. Do not commit screenshots. 1. From the travel MacBook's normal operator browser profile, open the Cloudflare dashboard. -2. Confirm the Nash Group / expected Cloudflare parent account is selectable. +2. Confirm the parent organization / expected Cloudflare parent account is selectable. 3. Confirm the Cloudflare One dashboard / `homezerotrust` context can be reached without changing any settings. 4. Record: diff --git a/docs/device-admin/handback-request-cloudflare-dns-2026-05-13.md b/docs/device-admin/handback-request-cloudflare-dns-2026-05-13.md index 94c1a68..c7e3fd8 100644 --- a/docs/device-admin/handback-request-cloudflare-dns-2026-05-13.md +++ b/docs/device-admin/handback-request-cloudflare-dns-2026-05-13.md @@ -20,7 +20,7 @@ Cloudflare One Client + `cloudflared` cutover packets for the household fleet. Current-state note, added 2026-05-27: this request was answered by the pre-migration `cloudflare-dns` repo and remains historical provenance. Active Cloudflare control-plane work has migrated to -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`; new packets +`/Users/verlyn13/Organizations//family-cloudflare`; new packets must refresh current claims there or against live provider proof. `family-cloudflare` is now the active authority for Cloudflare account and team diff --git a/docs/device-admin/handback-request-cloudflare-dns-windows-multi-user-2026-05-15.md b/docs/device-admin/handback-request-cloudflare-dns-windows-multi-user-2026-05-15.md index cf9a3f7..bcbcba1 100644 --- a/docs/device-admin/handback-request-cloudflare-dns-windows-multi-user-2026-05-15.md +++ b/docs/device-admin/handback-request-cloudflare-dns-windows-multi-user-2026-05-15.md @@ -24,7 +24,7 @@ unless the operator separately authorizes that work in the Current-state note, added 2026-05-27: this request was originally addressed to the pre-migration `cloudflare-dns` repo. Active Cloudflare control-plane work has migrated to -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`; that repo +`/Users/verlyn13/Organizations//family-cloudflare`; that repo must answer or supersede this request before any Windows multi-user cutover. ## Why This Exists diff --git a/docs/device-admin/handback-request-cloudflare-zero-trust-full-context-2026-05-16.md b/docs/device-admin/handback-request-cloudflare-zero-trust-full-context-2026-05-16.md index 52e3447..7fbc4de 100644 --- a/docs/device-admin/handback-request-cloudflare-zero-trust-full-context-2026-05-16.md +++ b/docs/device-admin/handback-request-cloudflare-zero-trust-full-context-2026-05-16.md @@ -170,12 +170,12 @@ state (current-status.yaml, system-wide section - **Identity providers configured in Cloudflare One:** Google OAuth + email OTP. -- **Cloudflare account name:** `The Nash Group`. +- **Cloudflare account name:** `the parent organization`. - **Cloudflare account ID:** `13eb584192d9cefb730fde0cfd271328`. - **Team name:** `homezerotrust` (team domain `homezerotrust.cloudflareaccess.com`). - **Account ownership scope (important):** the Cloudflare - account is at the **Nash Group parent level**, not the + account is at the **parent organization parent level**, not the jefahnierocks-entity level. jefahnierocks devices, identities, and zones (including `jefahnierocks.com`) are tenants under this parent account. See §6 Scope Boundaries below. @@ -200,11 +200,11 @@ This means: - For the device-level cutovers this handback unblocks (Cloudflare One Client enrollment for fedora-top / MAMAWORK / DSJ; SSH Tunnel + Access for off-LAN admin), the design should work with - whatever operator identity Nash-Group IAM eventually settles + whatever operator identity parent-organization IAM eventually settles on, and not bake assumptions in. - Recommendation either way: design **as if** there will be a separate operator-tier profile (call it `Operator` for now) - distinct from `Adults`. If Nash-Group IAM later resolves + distinct from `Adults`. If parent-organization IAM later resolves Jeff's identity to plain `Adults`, the Operator profile can be merged or aliased. The reverse (designing only for Adults then having to split out later) is worse. @@ -606,11 +606,11 @@ clarification 2026-05-16: ### Account / ownership -- **Cloudflare account name:** `The Nash Group`. +- **Cloudflare account name:** `the parent organization`. - **Cloudflare account ID:** `13eb584192d9cefb730fde0cfd271328`. - **Team name:** `homezerotrust`. - **Team domain:** `homezerotrust.cloudflareaccess.com`. -- **Account scope:** Nash Group (parent). jefahnierocks devices +- **Account scope:** parent organization (parent). jefahnierocks devices + zones (including `jefahnierocks.com`) are tenants under this parent account. See §6 Scope Boundaries. - **IaC:** Pulumi TypeScript in the `family-cloudflare` repo @@ -661,7 +661,7 @@ operator clarifications above, system-config recommends the designer evaluate **at least these candidate additions**: - **`Operator`** profile for Jeff (distinct from `Adults`). - Even if Nash-Group IAM eventually resolves Jeff's identity + Even if parent-organization IAM eventually resolves Jeff's identity to plain Adults, designing as if Operator-tier exists is cheaper than retrofitting. - **`Adults-Ahnie`** profile (kid-coexistence-aware adult, @@ -688,10 +688,10 @@ Cloudflare design touches: | Scope | Owner repo / entity | What it owns | What it does NOT own | |---|---|---|---| -| Parent governance | `the-nash-group` (parent entity) | Cloudflare account `The Nash Group` (`13eb584192d9cefb730fde0cfd271328`); cross-entity IAM and identity planning; standards; audit | Day-to-day device admin; per-family-member identity assignment; entity branding | -| Cloudflare IaC | `family-cloudflare` (managed by parent for all entities) | Pulumi TypeScript for the Nash Group Cloudflare account - Cloudflare One Client device profiles, Traffic policies, Access apps, Tunnels, DNS, managed networks, beacon registration | jefahnierocks-side device packets; operator-side Cloudflare One Client enrollment; identity-source decisions (those are IAM-planning scope) | -| Family device admin (this entity) | `jefahnierocks` (entity, `~/Organizations/jefahnierocks/`) | Device inventory and admin packets for family devices; per-device 1Password admin SSH keys; family identity-to-device mapping (Jeff / Ahnie / Axel / Wyn / Ila); fleet lifecycle | Cloudflare account or Pulumi state; Litecky-business resources; HomeNetOps LAN config; The Nash Group standards | -| Operator workspace + chezmoi orchestration | `system-config` (under jefahnierocks, this repo) | The operator MacBook config (chezmoi, mise, direnv, MCP, SSH client conf.d, 1P SSH agent integration); the device-admin packet ceremony (windows-terminal-admin-spec, packet-defect halt rule, etc.); operator-side Cloudflare One Client enrollment procedure | Cloudflare server-side; Pulumi state; Nash-Group IAM; what identities exist; LAN infrastructure | +| Parent governance | `` (parent entity) | Cloudflare account `the parent organization` (`13eb584192d9cefb730fde0cfd271328`); cross-entity IAM and identity planning; standards; audit | Day-to-day device admin; per-family-member identity assignment; entity branding | +| Cloudflare IaC | `family-cloudflare` (managed by parent for all entities) | Pulumi TypeScript for the parent organization Cloudflare account - Cloudflare One Client device profiles, Traffic policies, Access apps, Tunnels, DNS, managed networks, beacon registration | jefahnierocks-side device packets; operator-side Cloudflare One Client enrollment; identity-source decisions (those are IAM-planning scope) | +| Family device admin (this entity) | `jefahnierocks` (entity, `~/Organizations/jefahnierocks/`) | Device inventory and admin packets for family devices; per-device 1Password admin SSH keys; family identity-to-device mapping (Jeff / Ahnie / Axel / Wyn / Ila); fleet lifecycle | Cloudflare account or Pulumi state; Litecky-business resources; HomeNetOps LAN config; the parent organization standards | +| Operator workspace + chezmoi orchestration | `system-config` (under jefahnierocks, this repo) | The operator MacBook config (chezmoi, mise, direnv, MCP, SSH client conf.d, 1P SSH agent integration); the device-admin packet ceremony (windows-terminal-admin-spec, packet-defect halt rule, etc.); operator-side Cloudflare One Client enrollment procedure | Cloudflare server-side; Pulumi state; parent-organization IAM; what identities exist; LAN infrastructure | **Implications for the Cloudflare designer:** @@ -704,11 +704,11 @@ Cloudflare design touches: `desktop-2jj3187-warp-enrollment-cutover-packet`, `fedora-top-warp-enrollment-cutover-packet`), each gated on family-cloudflare answering this handback. -- Operator Cloudflare admin identity is a Nash-Group IAM +- Operator Cloudflare admin identity is a parent-organization IAM decision (not jefahnierocks scope). Design with that separation in mind. - Litecky Editing Services (Ahnie's business) is a separate - entity under Nash Group with its own repo + entity under parent organization with its own repo (`~/Organizations/litecky-editing/`). For now, Ahnie's Cloudflare identity is jefahnierocks-managed (`ahnielitecky@gmail.com`) because device management is routed through jefahnierocks. @@ -793,7 +793,7 @@ that answers, at minimum: policy each, what's the assignment rule. 2. **Jeff's profile placement** — Adults or a new `Operator` / `Admin` profile? Note that the actual Cloudflare admin - identity for Jeff is a **Nash-Group IAM decision** (not + identity for Jeff is a **parent-organization IAM decision** (not jefahnierocks); recommend designing as if a separate Operator tier exists, then aliasing if IAM-planning collapses it back to Adults. @@ -847,16 +847,16 @@ that answers, at minimum: - Wyn: `wynrjohnson@gmail.com`. - Ila: `ilagenevievemary@gmail.com`. - **Outstanding identity decision is Nash-Group scope, not + **Outstanding identity decision is parent-organization scope, not jefahnierocks:** Jeff's actual Cloudflare admin identity (Happy Patterns work email vs. personal Gmail vs. some - other) is part of broader IAM planning at the Nash Group - parent. family-cloudflare can either (a) wait for Nash-Group + other) is part of broader IAM planning at the parent organization + parent. family-cloudflare can either (a) wait for parent-organization IAM to resolve before finalizing operator-tier Access policies, or (b) design with a placeholder operator identity that can be re-mapped when IAM-planning lands. Operator preference: do not block jefahnierocks device - cutovers on Nash-Group IAM planning; design with a + cutovers on parent-organization IAM planning; design with a placeholder. ### Operator-roaming policy @@ -953,7 +953,7 @@ operator's admin capability — fully or partially. | **MacBook physical loss / theft (non-compromise)** | Same as death; but with credential rotation as precaution | Same as death; plus pre-emptive 1P session invalidation + GitHub token rotation + Cloudflare session invalidation | | **MacBook stolen, awake, unlocked, 1P agent unlocked** | Catastrophic: everything reachable from MacBook is in adversarial hands until the operator-side blast radius is contained | Emergency session-invalidation from any other 1P-capable device; rotate every per-device admin SSH key (the agent could still be unlocked); rotate every API token in 1P that was last used recently | | **1Password account compromised (separate from MacBook)** | Every per-device admin SSH key is exposed; every API token in `Dev` vault is exposed | Full 1P recovery flow + Cloudflare/GitHub/Hetzner/every-provider rotation. Worse than MacBook theft. | -| **Cloudflare account compromised** | device profiles can be re-pointed; Access policies can be modified; Gateway can be turned off; Tunnels can be created against any host; `jefahnierocks.com` DNS can be rewritten | Nash-Group escalation; Cloudflare support recovery; potentially zone re-transfer | +| **Cloudflare account compromised** | device profiles can be re-pointed; Access policies can be modified; Gateway can be turned off; Tunnels can be created against any host; `jefahnierocks.com` DNS can be rewritten | parent-organization escalation; Cloudflare support recovery; potentially zone re-transfer | | **Cloudflare account suspended (billing/TOS)** | All Cloudflare One Client + Access + Tunnel + Gateway features stop. `jefahnierocks.com` DNS stops. Family internet may stop (depending on DNS dependency). | Resolve with Cloudflare; meanwhile fall back to LAN-direct admin (no off-LAN admin available) | | **Google account suspended / lost (jeffrey@happy-patterns.com)** | Loss of Cloudflare OAuth login (sign in as that identity). Loss of Workspace email. Possible cascade to GitHub if linked. | Google recovery flow. Email OTP fallback for Cloudflare (if configured per-profile). | | **GitHub access lost (token rotation, account lock)** | system-config repo + every other repo become inaccessible from operator | GitHub recovery flow; 1P-stored GitHub PAT recovery | @@ -961,7 +961,7 @@ operator's admin capability — fully or partially. | **Hetzner outage** | If cloudflared is on Hetzner only, all off-LAN admin breaks. If LAN connector exists too, off-LAN admin still works. | Wait for Hetzner. | | **Home LAN power outage** | All on-LAN admin targets unreachable; Synology beacon down (no managed-network detection). WoL on UPS-fed devices could still wake them. | UPS for critical gear (Synology, OPNsense). Off-LAN admin not helpful unless devices come up on a battery-backed switch. | | **Synology beacon cert/disk failure** | Cloudflare managed-network detection fails (devices think they're off-LAN even when home) | Re-deploy beacon (10-year cert is static; can be copied from backup). family-cloudflare Pulumi state should carry the fingerprint pin. | -| **Operator (Jeff) incapacitated / unreachable** | No admin can happen until Jeff recovers or successor is empowered. No documented successor today (see §8.5). | Nash-Group governance; needs pre-planning. | +| **Operator (Jeff) incapacitated / unreachable** | No admin can happen until Jeff recovers or successor is empowered. No documented successor today (see §8.5). | parent-organization governance; needs pre-planning. | ### 8.3 MacBook loss / theft / death scenarios (three flavors) @@ -1040,7 +1040,7 @@ Inputs the operator needs **to even start that flow**: | 1Password Secret Key (account-bind) | 1P emergency kit PDF | Must be stored offline (printed in safe, encrypted USB, etc.) | | Apple ID password | Operator brain / iCloud Keychain | If iCloud Keychain was on the lost MacBook, Apple recovery flow | | GitHub recovery codes / 2FA backup | Should be in 1P (loop) and ALSO printed offline | Currently: TBD-operator | -| Cloudflare account recovery / 2FA backup | Should be in 1P (loop) and ALSO printed offline | Currently: TBD-operator. Note Nash-Group scope. | +| Cloudflare account recovery / 2FA backup | Should be in 1P (loop) and ALSO printed offline | Currently: TBD-operator. Note parent-organization scope. | | Hetzner account recovery / 2FA backup | Should be in 1P (loop) and ALSO printed offline | Currently: TBD-operator | | Domain registrar (where `jefahnierocks.com` and `happy-patterns.com` are registered) recovery | Should be in 1P + offline | Currently: TBD-operator | @@ -1064,13 +1064,13 @@ enrollment + 2FA), not require persistent device fingerprinting. Jeff is sole admin. If Jeff is unavailable (vacation off-grid, incapacitated, unreachable for weeks, deceased), no one can -currently administer the family fleet. The Nash Group parent +currently administer the family fleet. the parent organization parent scope owns this concern (it's an IAM-succession question beyond jefahnierocks), but jefahnierocks records it here so the Cloudflare design accounts for it: - **Who is Jeff's emergency successor?** TBD-operator. Likely - a Nash-Group-trusted party. + a parent-organization-trusted party. - **What does the successor need access to?** At minimum: - 1P vault `Dev` (read access; admin would need write). - Cloudflare account (admin tier). @@ -1181,7 +1181,7 @@ architect them out: should encourage automated `cloudflared` updates on whichever host runs it. system-config can package this. - **Operator forgets which Cloudflare account is which.** When - Nash-Group manages multiple entities' Cloudflare resources, + parent-organization manages multiple entities' Cloudflare resources, the operator working on jefahnierocks devices can't accidentally mutate happy-patterns / litecky resources. family-cloudflare Pulumi state per-entity scoping helps; @@ -1302,9 +1302,9 @@ but family-cloudflare will need these to finalize) - [ ] **Jeff's Cloudflare admin identity** — Happy Patterns email, personal Gmail, or something else. **This is a - Nash-Group IAM-planning decision, not a jefahnierocks + parent-organization IAM-planning decision, not a jefahnierocks decision.** family-cloudflare should design with a placeholder - operator identity and re-map when Nash-Group IAM-planning + operator identity and re-map when parent-organization IAM-planning resolves. - [ ] **Hetzner inventory** — count of servers, role(s), public IP(s). Needed only if the designer wants to recommend Option diff --git a/docs/device-admin/hetzner-cloudflare-management-status-ingest-2026-05-14.md b/docs/device-admin/hetzner-cloudflare-management-status-ingest-2026-05-14.md index 89f0ab9..ff42763 100644 --- a/docs/device-admin/hetzner-cloudflare-management-status-ingest-2026-05-14.md +++ b/docs/device-admin/hetzner-cloudflare-management-status-ingest-2026-05-14.md @@ -24,7 +24,7 @@ this ingest. Current-state note, added 2026-05-27: this ingest predates the migration from `/Users/verlyn13/Repos/local/cloudflare-dns` to -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. Treat +`/Users/verlyn13/Organizations//family-cloudflare`. Treat Cloudflare facts here as historical/advisory only; current Cloudflare authority is `family-cloudflare` or live provider proof. @@ -32,7 +32,7 @@ is `family-cloudflare` or live provider proof. | Field | Value | |---|---| -| Source repo | `/Users/verlyn13/Organizations/the-nash-group/hetzner` | +| Source repo | `/Users/verlyn13/Organizations//hetzner` | | Source report | `docs/reports/cloudflare-management-status-for-system-config-2026-05-14.md` | | Source commit cited | `009c091bc63556e6fb43503bf70aee97a269ea82` (`docs: leave-clean status refresh post Phase 2 and post-transfer truth alignment (#23)`) | | Source inspection mode | repo-only at Hetzner-repo authoring time; no live server, dashboard, Cloudflare API, or 1Password read was performed for that report | @@ -160,7 +160,7 @@ repos. ## Related -- Hetzner repo source report (`/Users/verlyn13/Organizations/the-nash-group/hetzner/docs/reports/cloudflare-management-status-for-system-config-2026-05-14.md`) +- Hetzner repo source report (`/Users/verlyn13/Organizations//hetzner/docs/reports/cloudflare-management-status-for-system-config-2026-05-14.md`) - [handback-request-cloudflare-dns-2026-05-13.md](./handback-request-cloudflare-dns-2026-05-13.md) - the historical outbound request. - [fedora-top-remote-admin-routing-design-2026-05-13.md](./fedora-top-remote-admin-routing-design-2026-05-13.md) - diff --git a/docs/device-admin/homenetops-opnsense-tailscale-roaming-admin-report-2026-05-27.md b/docs/device-admin/homenetops-opnsense-tailscale-roaming-admin-report-2026-05-27.md index 02aa2c1..9f9b5bb 100644 --- a/docs/device-admin/homenetops-opnsense-tailscale-roaming-admin-report-2026-05-27.md +++ b/docs/device-admin/homenetops-opnsense-tailscale-roaming-admin-report-2026-05-27.md @@ -99,11 +99,11 @@ HomeNetOps sources: Family-cloudflare sources: -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/docs/warp-overlay-coexistence.md` -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/docs/design-surfaces.md` -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/docs/managed-network-tls-beacon.md` -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/docs/architecture.md` -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/infrastructure/pulumi/policy-inputs.yaml` +- `/Users/verlyn13/Organizations//family-cloudflare/docs/warp-overlay-coexistence.md` +- `/Users/verlyn13/Organizations//family-cloudflare/docs/design-surfaces.md` +- `/Users/verlyn13/Organizations//family-cloudflare/docs/managed-network-tls-beacon.md` +- `/Users/verlyn13/Organizations//family-cloudflare/docs/architecture.md` +- `/Users/verlyn13/Organizations//family-cloudflare/infrastructure/pulumi/policy-inputs.yaml` HomeNetOps stand-down sources: diff --git a/docs/device-admin/onboarding-2026-05-12.md b/docs/device-admin/onboarding-2026-05-12.md index f16cb07..4faeaf4 100644 --- a/docs/device-admin/onboarding-2026-05-12.md +++ b/docs/device-admin/onboarding-2026-05-12.md @@ -29,7 +29,7 @@ those to Cloudflare One Client, device profile, and Traffic policies. Current-state note, added 2026-05-27: Cloudflare control-plane authority has migrated from `/Users/verlyn13/Repos/local/cloudflare-dns` to -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. Historical +`/Users/verlyn13/Organizations//family-cloudflare`. Historical `cloudflare-dns` requests and ingests remain provenance; current Cloudflare blockers and proof requests should route to `family-cloudflare`. @@ -201,7 +201,7 @@ Use these documents when starting an agent directly on the target device: | Outbound to cloudflare-dns | [handback-request-cloudflare-dns-2026-05-13.md](./handback-request-cloudflare-dns-2026-05-13.md) | Historical request to `/Users/verlyn13/Repos/local/cloudflare-dns` for org-wide Cloudflare One / Cloudflare One Client / Access / Tunnel posture and per-device profile recommendations. Current claims must be refreshed in `family-cloudflare`. Non-secret only; no live Cloudflare change requested. | | Outbound to HomeNetOps | [handback-request-homenetops-2026-05-13.md](./handback-request-homenetops-2026-05-13.md) | Two-item request to `~/Repos/verlyn13/HomeNetOps`: (1) posture confirmation for fedora-top (no new rule requested); (2) static-DHCP reservation for MAMAWORK Ethernet MAC `B0-41-6F-0E-B7-B6` -> `192.168.0.101` plus Unbound host override `mamawork.home.arpa`. Mirrors the 2026-05-13 fedora-top pattern. Non-secret only. **Answered 2026-05-14** - see [mamawork-homenetops-lan-identity-2026-05-14.md](./mamawork-homenetops-lan-identity-2026-05-14.md). | | MAMAWORK mini-PC | [mamawork-homenetops-lan-identity-2026-05-14.md](./mamawork-homenetops-lan-identity-2026-05-14.md) | Ingest of the HomeNetOps PASS hand-back for MAMAWORK. OPNsense static DHCP reservation bound, Unbound override `mamawork.home.arpa -> 192.168.0.101`, LAN/igc1 ARP confirms IP-to-MAC, `dig` PASS from LAN resolver. The earlier TCP/22 timeout was Windows-side and has since been resolved for the MacBook admin lane. ARP `permanent=false` because MAMAWORK is host-static; switching to DHCP would activate ISC static-ARP defense (optional follow-up packet). | -| Hetzner (advisory) | [hetzner-cloudflare-management-status-ingest-2026-05-14.md](./hetzner-cloudflare-management-status-ingest-2026-05-14.md) | Advisory-only ingest of `/Users/verlyn13/Organizations/the-nash-group/hetzner` commit `009c091`. Hetzner brokers Cloudflare Tunnel ingress for hosted apps (Infisical, Postal Web, runpod-review-webui); it is NOT a household device control plane. Encodes the decision to NOT route household device admin through Hetzner; preferred target remains Cloudflare One Client / Access via `family-cloudflare`; Tailscale stays transition/break-glass. Does not satisfy current `family-cloudflare` proof needs. | +| Hetzner (advisory) | [hetzner-cloudflare-management-status-ingest-2026-05-14.md](./hetzner-cloudflare-management-status-ingest-2026-05-14.md) | Advisory-only ingest of `/Users/verlyn13/Organizations//hetzner` commit `009c091`. Hetzner brokers Cloudflare Tunnel ingress for hosted apps (Infisical, Postal Web, runpod-review-webui); it is NOT a household device control plane. Encodes the decision to NOT route household device admin through Hetzner; preferred target remains Cloudflare One Client / Access via `family-cloudflare`; Tailscale stays transition/break-glass. Does not satisfy current `family-cloudflare` proof needs. | | Fedora 44 laptop | [fedora-top-admin-backup-ssh-key-strategy-packet-2026-05-14.md](./fedora-top-admin-backup-ssh-key-strategy-packet-2026-05-14.md) | Prepared. Adds one additional `verlyn13` ED25519 admin public key to `fedora-top` `/home/verlyn13/.ssh/authorized_keys`, with the private half held only in 1Password (Dev vault on my.1password.com) and served via the 1Password SSH agent on a backup operator device. Keeps `AllowUsers verlyn13`. Keeps `PasswordAuthentication no`. Does not add any other admin user. Does not reuse the legacy MAMAWORK `DadAdmin_WinNet` key. Snapshot-backed rollback. Closes the single-MacBook dependency for fedora-top remote administration. | | MAMAWORK mini-PC | [mamawork-ssh-investigation-packet-2026-05-14.md](./mamawork-ssh-investigation-packet-2026-05-14.md), [mamawork-inbound-tcp-blackhole-remediation-apply-2026-05-14.md](./mamawork-inbound-tcp-blackhole-remediation-apply-2026-05-14.md), [mamawork-sshd-admin-match-block-apply-2026-05-14.md](./mamawork-sshd-admin-match-block-apply-2026-05-14.md) | SSH investigation/remediation chain. Scoped investigation found Windows network-identity drift; remediation restored LAN TCP/22 and TCP/3389 reachability from the MacBook. Admin auth still failed until the sshd admin Match block packet restored `AuthorizedKeysFile __PROGRAMDATA__/ssh/administrators_authorized_keys` for local Administrators. MacBook real-auth proof now returns `MamaWork` / `mamawork\jeffr`. | | MAMAWORK mini-PC | [mamawork-switch-to-dhcp-source-of-truth-packet-2026-05-14.md](./mamawork-switch-to-dhcp-source-of-truth-packet-2026-05-14.md) | Prepared, optional. Switches the MAMAWORK wired adapter from host-side static IP (`192.168.0.101` manual) to DHCP so the existing OPNsense reservation owns the address and ISC static-ARP defense can activate (currently `permanent=false`). Brief 2-10 second reconnect window. Intentionally separate from the SSH investigation packet so connectivity changes are not bundled with debugging. | diff --git a/docs/google-admin-tooling.md b/docs/google-admin-tooling.md index 04e8d17..86e0932 100644 --- a/docs/google-admin-tooling.md +++ b/docs/google-admin-tooling.md @@ -34,7 +34,7 @@ The active local configuration is intentionally neutral: | Config | Active | Account | Project | |--------|--------|---------|---------| -| `thenash-guardian` | yes | `guardian@thenash.group` | unset | +| `thenash-guardian` | yes | `@` | unset | | `default` | no | `jeffrey@happy-patterns.com` | `happy-playground-463417` | | `scopecam-production` | no | `REDACTED-operator-google-account` | `scopecam-qa` | | `scopecam-qa` | no | `REDACTED-operator-google-account` | `scopecam-qa` | @@ -45,12 +45,12 @@ relationship. Current auth state: -- `gcloud auth list` shows `guardian@thenash.group` as active. +- `gcloud auth list` shows `@` as active. - Application Default Credentials file shape is `authorized_user`, account - `guardian@thenash.group`, with no `quota_project_id`. + `@`, with no `quota_project_id`. - Token refresh currently requires a human Google reauthentication flow. A non-interactive check with - `gcloud auth print-access-token --account=guardian@thenash.group --quiet` + `gcloud auth print-access-token --account=@ --quiet` failed with "Reauthentication failed. cannot prompt during non-interactive execution." The same class of failure applies to `gcloud auth application-default print-access-token --quiet` until the @@ -63,10 +63,10 @@ Current auth state: - Installed package: `gam7 7.43.5` - `gam version` reports `GAM 7.43.05` - Config file: `/Users/verlyn13/.gam/gam.cfg` -- Active GAM section: `thenash.group` -- Domain: `thenash.group` -- Admin email: `guardian@thenash.group` -- Workspace-specific config dir: `/Users/verlyn13/.gam/thenash.group` +- Active GAM section: `` +- Domain: `` +- Admin email: `@` +- Workspace-specific config dir: `/Users/verlyn13/.gam/` The legacy binary `/Users/verlyn13/bin/gam7/gam` still exists but is not the primary PATH binary. Prefer the `pipx` managed `gam` shim unless a task is @@ -90,7 +90,7 @@ gam version Token refresh checks do not print token values: ```bash -gcloud auth print-access-token --account=guardian@thenash.group --quiet >/dev/null +gcloud auth print-access-token --account=@ --quiet >/dev/null gcloud auth application-default print-access-token --quiet >/dev/null ``` @@ -102,24 +102,24 @@ steps below. The preferred Guardian shape is: - active config: `thenash-guardian` -- active account: `guardian@thenash.group` +- active account: `@` - project: unset -- ADC account: `guardian@thenash.group` +- ADC account: `@` - ADC quota project: unset Repair commands: ```bash gcloud config configurations activate thenash-guardian -gcloud config set account guardian@thenash.group +gcloud config set account @ gcloud config unset project --quiet gcloud config set disable_usage_reporting true -gcloud auth login guardian@thenash.group --force -gcloud auth application-default login guardian@thenash.group --disable-quota-project +gcloud auth login @ --force +gcloud auth application-default login @ --disable-quota-project ``` -Complete both browser flows as `guardian@thenash.group`. Do not use +Complete both browser flows as `@`. Do not use `--update-adc` if it would copy an unrelated project binding into ADC. After login, rerun the token refresh checks above. diff --git a/docs/host-capability-substrate/0001-repo-boundary-decision.md b/docs/host-capability-substrate/0001-repo-boundary-decision.md index 4e715ec..c000f53 100644 --- a/docs/host-capability-substrate/0001-repo-boundary-decision.md +++ b/docs/host-capability-substrate/0001-repo-boundary-decision.md @@ -39,7 +39,7 @@ Parent research plan: [`../host-capability-substrate-research-plan.md`](../host- ### 1.1 Nash Covenant principles (cited as planning input) -From `~/Organizations/the-nash-group/the-covenant/PRINCIPLES.md`: +From `~/Organizations//the-covenant/PRINCIPLES.md`: 1. The Sacred Timeline is Linear and Clean 2. Every Commit Shall Speak Its Purpose @@ -777,7 +777,7 @@ Gated on: approval grants + audit hash chain + dashboard review + lease manager - [Tooling surface matrix](./tooling-surface-matrix.md) (v1.0.0+) - [Project substrate adoption](./project-substrate-adoption.md) (v0.1.0+) - [Target-repo templates](./templates/) -- `~/Organizations/the-nash-group/the-covenant/PRINCIPLES.md` — 16 principles +- `~/Organizations//the-covenant/PRINCIPLES.md` — 16 principles - [`docs/project-conventions.md`](../project-conventions.md) - [`docs/mcp-config.md`](../mcp-config.md) - [`docs/secrets.md`](../secrets.md) diff --git a/docs/host-capability-substrate/2026-04-24-control-plane-broker-design.md b/docs/host-capability-substrate/2026-04-24-control-plane-broker-design.md index 2cc4092..29cec02 100644 --- a/docs/host-capability-substrate/2026-04-24-control-plane-broker-design.md +++ b/docs/host-capability-substrate/2026-04-24-control-plane-broker-design.md @@ -207,7 +207,7 @@ not change the broker's other contracts: The identity transition is also part of the baseline. The interim operator OAuth identity is `REDACTED-operator-google-account` (Option B); the Phase C -target identity is `guardian@thenash.group`, with the Cloudflare account email +target identity is `@`, with the Cloudflare account email migration target date of 2026-07-15, per parent identifier `OPERATOR-CLOUDFLARE-ADMIN-IDENTITY-DECISION-2026-05-16.md`. The broker's typed-operation and lease-and-ledger contract is identity-agnostic, but a diff --git a/docs/host-capability-substrate/project-substrate-adoption.md b/docs/host-capability-substrate/project-substrate-adoption.md index aeb0c5a..fc4f64b 100644 --- a/docs/host-capability-substrate/project-substrate-adoption.md +++ b/docs/host-capability-substrate/project-substrate-adoption.md @@ -15,15 +15,15 @@ Host-local adoption guidance for project use of the shared substrate until HCS is primary for typed evidence and operation gating. Source authority: Citadel PR #37, merged to -`The-Nash-Group/citadel-config` at +`The-parent-organization/citadel-config` at `46c55857427af4b887194277bac2218c20b595b6`. Read with: - Citadel standard: - `/Users/verlyn13/Organizations/the-nash-group/the-citadel/docs/project-substrate-control-plane-standard.md` + `/Users/verlyn13/Organizations//the-citadel/docs/project-substrate-control-plane-standard.md` - Citadel example contract: - `/Users/verlyn13/Organizations/the-nash-group/the-citadel/docs/reference/project-substrate-contract.example.yaml` + `/Users/verlyn13/Organizations//the-citadel/docs/reference/project-substrate-contract.example.yaml` - Host-local policy snapshot: [`../../policies/host-capability-substrate/project-substrate-admission.yaml`](../../policies/host-capability-substrate/project-substrate-admission.yaml) @@ -63,7 +63,7 @@ docs/infrastructure/project-substrate-contract.yaml Use the Citadel example contract shape at: ```text -/Users/verlyn13/Organizations/the-nash-group/the-citadel/docs/reference/project-substrate-contract.example.yaml +/Users/verlyn13/Organizations//the-citadel/docs/reference/project-substrate-contract.example.yaml ``` The contract declares the workload lanes, owner, authority repo, resource diff --git a/docs/iterm2-profile-redesign.md b/docs/iterm2-profile-redesign.md index 665d70a..2835459 100644 --- a/docs/iterm2-profile-redesign.md +++ b/docs/iterm2-profile-redesign.md @@ -458,7 +458,7 @@ B6. **Current verification.** The installer passes with one managed profile and one managed color preset. `ng-doctor`'s iTerm2 category passes its current checks. It does not yet prove color import or badge behavior. B7. **Done.** `Guardian L0` and `Nash Repo` profiles add path-scoped visual -signaling for `/Users/verlyn13/Organizations/the-nash-group`. This is a +signaling for `/Users/verlyn13/Organizations/`. This is a documented exception to default project-path independence because the profile's purpose is to distinguish Parent L0 context from nested repo context. See `docs/iterm2-guardian-profiles.md`. @@ -539,7 +539,7 @@ be updated, ask for that explicitly after the repo work lands. | Default Bookmark | Installer sets it deterministically | Consistent setup across machines; matches "deterministic" goal. | | Shell-integration scope | Interactive only (skipped in agentic) | Preserves agentic startup budget. | | Clipboard write (`Allow Clipboard Access From Terminal`) | `false` on Dev (and inherited by SSH variant in Phase C) | Closes OSC 52 / OSC 1337 SetClipboard injection vector. This workstation runs agentic tools (Claude Code, Codex, MCP) that pipe untrusted remote text through the terminal — any such text containing a clipboard-write escape would silently overwrite the system clipboard. Industry default for hardened multi-host setups. Read access (paste) unaffected. Escape hatch: edit the field to `true` in `iterm2/profiles/00-dev.json` and re-run `scripts/install-iterm2-profiles.sh`; iTerm2 reloads dynamically. Add a sibling "Dev (clipboard)" profile only if friction emerges in practice — do not pre-build. Decided 2026-05-08. | -| Nash Guardian profiles | Path-scoped visual exception | The user explicitly wants Parent L0 and nested-repo visual separation for `~/Organizations/the-nash-group`; the exception is documented and does not set commands, env, working directories, or secrets. | +| Nash Guardian profiles | Path-scoped visual exception | The user explicitly wants Parent L0 and nested-repo visual separation for `~/Organizations/`; the exception is documented and does not set commands, env, working directories, or secrets. | | Jefahnierocks Explorer profiles | Path-scoped visual exception | The user explicitly wants personal Explorer and nested-repo visual separation for `~/Organizations/jefahnierocks`; the exception is documented and keeps clipboard/triggers/global preferences under existing policy. | | Happy Patterns Professional profiles | Path-scoped visual exception | The user explicitly wants professional org and nested-repo visual separation for `~/Organizations/happy-patterns`; the exception is documented and keeps clipboard/triggers/global preferences under existing policy. | diff --git a/docs/project-conventions.md b/docs/project-conventions.md index f840df6..671b050 100644 --- a/docs/project-conventions.md +++ b/docs/project-conventions.md @@ -502,7 +502,7 @@ docs/infrastructure/project-substrate-contract.yaml Use the Citadel example shape at: ```text -/Users/verlyn13/Organizations/the-nash-group/the-citadel/docs/reference/project-substrate-contract.example.yaml +/Users/verlyn13/Organizations//the-citadel/docs/reference/project-substrate-contract.example.yaml ``` The live host-local adoption policy is diff --git a/docs/restart-handoff-2026-08-08.md b/docs/restart-handoff-2026-08-08.md index b00b211..8755e3a 100644 --- a/docs/restart-handoff-2026-08-08.md +++ b/docs/restart-handoff-2026-08-08.md @@ -113,7 +113,7 @@ three real clones: | Clone path | Verified live fact | | --- | --- | -| `/Users/verlyn13/Organizations/the-nash-group-github-profile` | Origin uses `github.com`, while the registry expects `github.com-nash-group`; local status already had 3 entries. The doctor prints this same clone as `parent-org/.github` in the remote check and `The-Nash-Group/.github` in the config-drift check. | +| `/Users/verlyn13/Organizations/-github-profile` | Origin uses `github.com`, while the registry expects `github.com-nash-group`; local status already had 3 entries. The doctor prints this same clone as `parent-org/.github` in the remote check and `The-parent-organization/.github` in the config-drift check. | | `/Users/verlyn13/Organizations/happy-patterns/apps/happy-patterns-org.github.io` | Clean worktree; origin uses `github.com`, while the registry expects `github.com-happy-patterns`; email/signing/host configuration also differs from the registered lane. | | `/Users/verlyn13/Organizations/happy-patterns/apps/scopecam` | Clean worktree on `development`; origin uses `github.com`, while the registry expects `github.com-happy-patterns`; email/signing/host configuration also differs from the registered lane. | diff --git a/docs/secret-records.md b/docs/secret-records.md index 7c23d0e..8b6cfb0 100644 --- a/docs/secret-records.md +++ b/docs/secret-records.md @@ -45,7 +45,7 @@ Allowed statuses: `planned`, `issued`, `active`, `transitional`, `retired`, ## Known Cross-Boundary Tokens `TF_VAR_github_token` observed in the Happy Patterns GitHub UI is a separate -Happy Patterns to The-Nash-Group provider credential. It is not a +Happy Patterns to parent-organization provider credential. It is not a `system-config` MCP token and should not be stored under the `github-mcp`, `github-happy-patterns`, or `github-dev-tools` aliases. Treat it as cross-entity and transitional until the owning project records its logical diff --git a/docs/secrets.md b/docs/secrets.md index 7a05da8..ac8fa98 100644 --- a/docs/secrets.md +++ b/docs/secrets.md @@ -21,7 +21,7 @@ The structural shape of every 1Password item referenced from this repo (field names, label-uniqueness rules, `op://` URI semantics, the cleanup recipe for duplicate-label drift) is governed by Nash's **1Password Item Shape Standard** at -`~/Organizations/the-nash-group/.org/standards/op-item-shape.md`. +`~/Organizations//.org/standards/op-item-shape.md`. This file restates the *jefahnierocks-side* policy (which references are live, which agent operations are authorized) and inherits the structural diff --git a/docs/security-hardening-implementation-plan.md b/docs/security-hardening-implementation-plan.md index 59f48c7..d87b63e 100644 --- a/docs/security-hardening-implementation-plan.md +++ b/docs/security-hardening-implementation-plan.md @@ -34,7 +34,7 @@ new implementation language should use Cloudflare One Client, Cloudflare One dashboard, device profiles, and Traffic policies. Current Cloudflare control-plane authority, verified 2026-05-27, is -`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. It is the +`/Users/verlyn13/Organizations//family-cloudflare`. It is the migration target from the old `/Users/verlyn13/Repos/local/cloudflare-dns` clone. This plan keeps older `cloudflare-dns` references only as audit provenance; new P9 decisions, provider proofs, and IaC references should route @@ -146,7 +146,7 @@ to entries under `~/Library/Logs/security-audit/2026-05-02-ua-wired/`. org-level Secure Web Gateway proxy toggle (TCP) is not enabled in Traffic Settings. - Adult-profile contract values per the current migration target - `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/infrastructure/pulumi/policy-inputs.yaml` + `/Users/verlyn13/Organizations//family-cloudflare/infrastructure/pulumi/policy-inputs.yaml` (the original audit cited the older `cloudflare-dns` path): `serviceModeV2.mode = "warp"`, `tunnelProtocol = "wireguard"`, `switchLocked = false`, `allowedToLeave = true`. Profile id matches the @@ -214,7 +214,7 @@ boundaries during normal operation. | P6 LaunchAgents | Host (`launchctl unload`) plus the originating project repo for any source fix | Agents whose origin tree is gone get unloaded and the plist removed; agents whose origin still exists get fixed in that repo. | | P7 MCP profiles | `system-config` (`scripts/sync-mcp.sh`, `scripts/mcp-servers.json`, `home/dot_local/bin/`) | Pure user-level baseline work. | | P8 agent memory | `~/.codex/memories/`, `~/.claude/` (host) | Personal review. The codex memory is the heavy carrier. | -| P9 Cloudflare One Client / Traffic policy enforcement | `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/` (Pulumi TypeScript transition repo covering Gateway DNS / Traffic policies, lists, device profiles, Cloudflare One Client enrollment Access app, Gateway DNS location); Cloudflare One dashboard (org admin only) for the Secure Web Gateway proxy toggle and 2 legacy unmanaged policies | Two distinct external surfaces. system-config does not own either. family-cloudflare/AGENTS.md is authoritative for the current Pulumi-side contracts. | +| P9 Cloudflare One Client / Traffic policy enforcement | `/Users/verlyn13/Organizations//family-cloudflare/` (Pulumi TypeScript transition repo covering Gateway DNS / Traffic policies, lists, device profiles, Cloudflare One Client enrollment Access app, Gateway DNS location); Cloudflare One dashboard (org admin only) for the Secure Web Gateway proxy toggle and 2 legacy unmanaged policies | Two distinct external surfaces. system-config does not own either. family-cloudflare/AGENTS.md is authoritative for the current Pulumi-side contracts. | | P10 ng-doctor posture | `system-config` (`home/dot_local/bin/executable_ng-doctor.tmpl`) | Pure repo work; designed to land last. | ## 1Password Context @@ -843,7 +843,7 @@ Preserve (do not touch during P5 cleanup): toggled off and back on, or the allowlist is reset as part of P5, the daemon must be re-added explicitly. Verify after any ALF change: `warp-cli status` should report `Connected`. Cross-check with - `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/docs/warp-client.md` + `/Users/verlyn13/Organizations//family-cloudflare/docs/warp-client.md` (current runbook for the Cloudflare One Client CLI-side contracts). Acceptance gates: @@ -1100,7 +1100,7 @@ Cloudflare One Client / Traffic policy state. system-config does not own either. | Surface | Scope | Owner of record | |---|---|---| -| `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/` (Pulumi TypeScript transition repo) | Gateway DNS / Traffic policies, custom-block / custom-block-content / custom-block-ads / custom-allow / custom-breakglass lists, three custom Cloudflare One Client device profiles (kids, adults, headless), default device profile (singleton import), managed networks / TLS beacon, Cloudflare One Client enrollment Access app, Gateway DNS location | family-cloudflare repo | +| `/Users/verlyn13/Organizations//family-cloudflare/` (Pulumi TypeScript transition repo) | Gateway DNS / Traffic policies, custom-block / custom-block-content / custom-block-ads / custom-allow / custom-breakglass lists, three custom Cloudflare One Client device profiles (kids, adults, headless), default device profile (singleton import), managed networks / TLS beacon, Cloudflare One Client enrollment Access app, Gateway DNS location | family-cloudflare repo | | Cloudflare One dashboard, NOT in Pulumi | Secure Web Gateway proxy toggle (Traffic Settings -> Network); two legacy unmanaged policies "Cert Pinning" (precedence 0) and "Block Malware" (precedence 9000) | org admin only | The system-config plan does **not** flip the Secure Web Gateway proxy @@ -1132,9 +1132,9 @@ Tasks before any policy decision: - Read the family-cloudflare architecture and posture docs first; they are the rationale source for both Pulumi-managed state and the dashboard toggle decision: - - `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/docs/architecture.md` - - `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/docs/warp-client.md` - - `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/infrastructure/pulumi/policy-inputs.yaml` + - `/Users/verlyn13/Organizations//family-cloudflare/docs/architecture.md` + - `/Users/verlyn13/Organizations//family-cloudflare/docs/warp-client.md` + - `/Users/verlyn13/Organizations//family-cloudflare/infrastructure/pulumi/policy-inputs.yaml` - historical import source, only if needed for provenance: `~/Repos/local/cloudflare-dns/state.json` - Verify or decide org-admin state in the Cloudflare One dashboard @@ -1216,7 +1216,7 @@ Proposed checks: - `launchagents_all_loaded_or_disabled` - `wireshark_chmodbpf_present_only_if_used` - `warp_connected_and_dns_gateway_enforced` — adults-profile expectations - per `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/infrastructure/pulumi/policy-inputs.yaml`: + per `/Users/verlyn13/Organizations//family-cloudflare/infrastructure/pulumi/policy-inputs.yaml`: - `serviceModeV2.mode == "warp"` (display string `WarpWithDnsOverHttps`) - `tunnelProtocol == "wireguard"` - `switchLocked == false` @@ -1490,13 +1490,13 @@ External research consulted while drafting this plan (URLs as of 2026-05-02): ### Internal cross-repo references -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/AGENTS.md` — +- `/Users/verlyn13/Organizations//family-cloudflare/AGENTS.md` — current guardrails for the family-home Cloudflare overlay control plane -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/docs/architecture.md` — +- `/Users/verlyn13/Organizations//family-cloudflare/docs/architecture.md` — system architecture, profile contracts, list contents, free-tier limits -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/docs/warp-client.md` — +- `/Users/verlyn13/Organizations//family-cloudflare/docs/warp-client.md` — Cloudflare One Client enrollment + diagnostic runbook -- `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare/infrastructure/pulumi/policy-inputs.yaml` — +- `/Users/verlyn13/Organizations//family-cloudflare/infrastructure/pulumi/policy-inputs.yaml` — op:// template for current policy inputs - `~/Repos/local/cloudflare-dns/state.json` — historical machine-readable Pulumi state from the pre-migration repo; use only for provenance/import diff --git a/docs/sentry-cli-setup.md b/docs/sentry-cli-setup.md index 228daa8..3f6bbb9 100644 --- a/docs/sentry-cli-setup.md +++ b/docs/sentry-cli-setup.md @@ -49,4 +49,4 @@ purpose-named, kebab-case item title (for example, For the live system-wide secret-handling rules, see [`docs/secrets.md`](./secrets.md). For item-shape rules (naming, field uniqueness, label collisions), see the Nash 1Password Item Shape Standard at -`~/Organizations/the-nash-group/.org/standards/op-item-shape.md`. +`~/Organizations//.org/standards/op-item-shape.md`. diff --git a/home/private_dot_ssh/private_conf.d/tng-openbao.conf.tmpl b/home/private_dot_ssh/private_conf.d/tng-openbao.conf.tmpl index 5a28c2c..6c70f2d 100644 --- a/home/private_dot_ssh/private_conf.d/tng-openbao.conf.tmpl +++ b/home/private_dot_ssh/private_conf.d/tng-openbao.conf.tmpl @@ -1,14 +1,34 @@ {{- $identityAgent := .ssh.identity_agent | default "~/Library/Group Containers/2BUA8C4S2C.com.1password/t/agent.sock" -}} -# The Nash Group OpenBao host +# Parent-organization OpenBao host # Managed by chezmoi # +# Host identity for this entry lives in MACHINE DATA +# (~/.config/chezmoi/chezmoi.toml), never in this repo. system-config is a +# PUBLIC repository: a reachable address plus a login user for a no-link +# entity's secrets manager must not be committed here. +# # Host-specific SSH policy belongs in ~/.ssh/conf.d modules so the generated # top-level ~/.ssh/config can stay small and reproducible. - -Host tng-openbao-1 46.225.220.249 - HostName 46.225.220.249 - User root +{{ if hasKey .ssh "parent_org_openbao" -}} +{{- $bao := .ssh.parent_org_openbao -}} +Host {{ $bao.alias }} {{ $bao.host }} + HostName {{ $bao.host }} + User {{ $bao.user }} IdentityAgent "{{ $identityAgent }}" IdentitiesOnly yes - IdentityFile ~/.ssh/tng-openbao-operator.pub + IdentityFile {{ $bao.identity_file }} PubkeyAuthentication unbound +{{- else -}} +# NOT CONFIGURED on this machine. +# +# To restore this host entry, add to ~/.config/chezmoi/chezmoi.toml under the +# existing [data.ssh] table (values are examples -- use the real ones): +# +# [data.ssh.parent_org_openbao] +# alias = "tng-openbao-1" +# host = "203.0.113.10" +# user = "root" +# identity_file = "~/.ssh/tng-openbao-operator.pub" +# +# Then re-run: chezmoi apply --dry-run --force (then without --dry-run) +{{- end }} diff --git a/policies/host-capability-substrate/project-substrate-admission.yaml b/policies/host-capability-substrate/project-substrate-admission.yaml index 996435b..142eabc 100644 --- a/policies/host-capability-substrate/project-substrate-admission.yaml +++ b/policies/host-capability-substrate/project-substrate-admission.yaml @@ -6,11 +6,11 @@ last_updated: "2026-05-06" source_authority: owner: the-citadel - repository: The-Nash-Group/citadel-config + repository: The-parent-organization/citadel-config pull_request: 37 merged_commit: 46c55857427af4b887194277bac2218c20b595b6 - standard_path: /Users/verlyn13/Organizations/the-nash-group/the-citadel/docs/project-substrate-control-plane-standard.md - example_contract_path: /Users/verlyn13/Organizations/the-nash-group/the-citadel/docs/reference/project-substrate-contract.example.yaml + standard_path: /Users/verlyn13/Organizations//the-citadel/docs/project-substrate-control-plane-standard.md + example_contract_path: /Users/verlyn13/Organizations//the-citadel/docs/reference/project-substrate-contract.example.yaml adoption_boundary: current_policy_owner: system-config @@ -61,7 +61,7 @@ ownership: contract: required_before_use: true recommended_project_path: docs/infrastructure/project-substrate-contract.yaml - example_shape_path: /Users/verlyn13/Organizations/the-nash-group/the-citadel/docs/reference/project-substrate-contract.example.yaml + example_shape_path: /Users/verlyn13/Organizations//the-citadel/docs/reference/project-substrate-contract.example.yaml allowed_statuses: - draft - accepted diff --git a/scripts/import-ssh-keys.zsh b/scripts/import-ssh-keys.zsh index 139db3c..d26732d 100755 --- a/scripts/import-ssh-keys.zsh +++ b/scripts/import-ssh-keys.zsh @@ -51,7 +51,7 @@ write_manifest() { /Users/verlyn13/.ssh/id_ed25519_business_org ssh/workstation/business_org/github ssh,interactive,github,workstation,business_org GitHub identity for business-org variant. De-duplicate with business-org. /Users/verlyn13/.ssh/id_ed25519_hubofaxel ssh/workstation/hubofaxel/github ssh,interactive,github,workstation,hubofaxel Git SSH key for hubofaxel. /Users/verlyn13/.ssh/id_ed25519_hubofwyn ssh/workstation/hubofwyn/github ssh,interactive,github,workstation,hubofwyn Git SSH key for hubofwyn. -/Users/verlyn13/.ssh/id_ed25519_nash-group ssh/workstation/nash-group/github ssh,interactive,github,workstation,nash-group Git SSH key for Nash Group. +/Users/verlyn13/.ssh/id_ed25519_nash-group ssh/workstation/nash-group/github ssh,interactive,github,workstation,nash-group Git SSH key for the parent organization. /Users/verlyn13/.ssh/id_ed25519_documentation ssh/workstation/documentation/container ssh,workstation,documentation,container laptop-to-documentation-container access key. Provenance review; archive if unused. /Users/verlyn13/.ssh/id_ed25519_mac ssh/workstation/mac/cross-machine ssh,workstation,mac,cross-machine verlyn13@fedora-top cross-machine identity. Provenance review. /Users/verlyn13/.ssh/id_ed25519_scope ssh/workstation/scope/unknown ssh,workstation,scope,unknown Provenance unclear. Review before action. diff --git a/scripts/validate-repo.sh b/scripts/validate-repo.sh index 91dae32..70f8abb 100755 --- a/scripts/validate-repo.sh +++ b/scripts/validate-repo.sh @@ -81,4 +81,72 @@ if rg -n --hidden --glob '!.git' --glob '!scripts/validate-repo.sh' \ exit 1 fi +# Identity content scan. THIS REPO IS PUBLIC. +# +# The consumer contract in docs/git-identity.md forbids committing registry.json +# "or any value from it" -- author emails, key paths, the parent-org real name. +# Only the first half was ever enforced: ng-doctor's +# identity_no_registry_file_committed greps git ls-files for a file NAMED +# registry.json and runs check-ignore. It performs no content inspection, and it +# reported green while 142 parent-org occurrences and 32 third-party personal +# email addresses sat in the tree. This step is the missing half. +# +# Exclusions are structural, not cosmetic -- each is a value something resolves +# against at runtime, where changing it would break a mechanism or (for the +# byte-pinned file) require a coordinated re-vendor: +# iterm2/** profile filenames + APS "Bound Hosts" globs +# docs/iterm2-*.md document those globs; must stay accurate +# zz-iterm2.zsh $PWD equality test against the org path +# tiers.yaml byte-pinned by a sibling repo's vendored snapshot +# tests/policies/** negative fixtures; the values are the test input +# home/.chezmoidata.yaml allowed_signers principals must byte-match the +# signing identity or verification stops +identity_excludes=( + --glob '!.git' --glob '!scripts/validate-repo.sh' + --glob '!iterm2/**' --glob '!docs/iterm2-*.md' + --glob '!home/dot_config/zshrc.d/zz-iterm2.zsh' + --glob '!policies/host-capability-substrate/tiers.yaml' + --glob '!tests/policies/**' --glob '!home/.chezmoidata.yaml' +) + +# Parent-org real name. Deliberately does NOT match a bare "nash-group", which +# only ever occurs inside identifiers that are excluded above or are themselves +# the thing being resolved (github.com-nash-group, id_ed25519_nash-group, +# ssh/workstation/nash-group/github). +if rg -n --hidden "${identity_excludes[@]}" \ + 'the-nash-group|thenash\.group|Nash[- ]Group' \ + .; then + echo "Error: parent-organization real name found in this PUBLIC repo" >&2 + echo " The parent org is no-link / publicAlias 'parent organization'." >&2 + echo " Use , , or 'the parent organization'." >&2 + exit 1 +fi + +# Email addresses outside the allowlist. The allowlist is what makes this +# runnable: it passes vendor/docs/RFC-reserved addresses and the operator's own +# entity domains, and fails personal and third-party addresses. +email_allow='@(example\.[a-z]+|[a-z0-9.-]+\.example\.com|internal\.company\.com' +email_allow+='|[a-z0-9.-]+\.(home\.arpa|hq|invalid|local)' +email_allow+='|github\.com|users\.noreply\.github\.com|openssh\.com|libssh\.org' +email_allow+='|anthropic\.com|tailscale\.com|cloudflare\.com|sentry\.io' +email_allow+='|happy-patterns\.com|jefahnierocks\.com|hubofwyn\.com|hubofaxel\.com)' +# +# The failure output is MASKED. CI logs for a public repo are themselves +# public, so echoing a matched address here would publish the exact value this +# step exists to keep out -- and would do it on every failing run, in a +# durable, indexable place. Report file and localpart shape only. +email_hits=$(rg -o --hidden "${identity_excludes[@]}" \ + '[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,}' \ + . | grep -vE "$email_allow" || true) +if [[ -n "$email_hits" ]]; then + echo "Error: non-allowlisted email address found in this PUBLIC repo" >&2 + echo "$email_hits" \ + | sed -E 's/:([A-Za-z0-9._%+-])[A-Za-z0-9._%+-]*@/:\1***@/' \ + | sort -u | sed 's/^/ /' >&2 + echo " Personal and third-party addresses must not be committed here." >&2 + echo " Use a REDACTED--google-account style placeholder." >&2 + echo " If the domain is legitimately public, add it to email_allow above." >&2 + exit 1 +fi + echo "system-config validation: PASS" diff --git a/scripts/write-1p-ssh-import-manifest.zsh b/scripts/write-1p-ssh-import-manifest.zsh index 48215ed..6bc7406 100755 --- a/scripts/write-1p-ssh-import-manifest.zsh +++ b/scripts/write-1p-ssh-import-manifest.zsh @@ -14,7 +14,7 @@ cat > "$MANIFEST_PATH" <<'EOF' /Users/verlyn13/.ssh/id_ed25519_business_org ssh/workstation/business_org/github ssh,interactive,github,workstation,business_org GitHub identity for business-org variant. De-duplicate with business-org. /Users/verlyn13/.ssh/id_ed25519_hubofaxel ssh/workstation/hubofaxel/github ssh,interactive,github,workstation,hubofaxel Git SSH key for hubofaxel. /Users/verlyn13/.ssh/id_ed25519_hubofwyn ssh/workstation/hubofwyn/github ssh,interactive,github,workstation,hubofwyn Git SSH key for hubofwyn. -/Users/verlyn13/.ssh/id_ed25519_nash-group ssh/workstation/nash-group/github ssh,interactive,github,workstation,nash-group Git SSH key for Nash Group. +/Users/verlyn13/.ssh/id_ed25519_nash-group ssh/workstation/nash-group/github ssh,interactive,github,workstation,nash-group Git SSH key for the parent organization. /Users/verlyn13/.ssh/id_ed25519_documentation ssh/workstation/documentation/container ssh,workstation,documentation,container laptop-to-documentation-container access key. Provenance review; archive if unused. /Users/verlyn13/.ssh/id_ed25519_mac ssh/workstation/mac/cross-machine ssh,workstation,mac,cross-machine verlyn13@fedora-top cross-machine identity. Provenance review. /Users/verlyn13/.ssh/id_ed25519_scope ssh/workstation/scope/unknown ssh,workstation,scope,unknown Provenance unclear. Review before action.