Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion docs/agentic-tooling.md
Original file line number Diff line number Diff line change
Expand Up @@ -194,7 +194,7 @@ Project agents stop before direct host mutation, Proxmox console drift,
unscoped machine identities, secret material in files or state, and workloads
without a reviewed substrate contract. The contract shape comes from Citadel's
example at
`/Users/verlyn13/Organizations/the-nash-group/the-citadel/docs/reference/project-substrate-contract.example.yaml`.
`/Users/verlyn13/Organizations/<parent-org>/the-citadel/docs/reference/project-substrate-contract.example.yaml`.

## MCP Configuration

Expand Down
2 changes: 1 addition & 1 deletion docs/cloudflare-mcp.md
Original file line number Diff line number Diff line change
Expand Up @@ -81,7 +81,7 @@ instead of being preserved as user-added servers.

Interim OAuth identity is `REDACTED-operator-google-account` (Option B) per the
operator Cloudflare admin identity decision. The target identity is
`guardian@thenash.group` (Option C) after the Phase 2 Cloudflare account email
`<parent-org-admin>@<parent-org-domain>` (Option C) after the Phase 2 Cloudflare account email
migration lands.

The interim OAuth grant is read-mostly per the parent OAuth pilot findings:
Expand Down
2 changes: 1 addition & 1 deletion docs/cloudflare-one-terminology.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ Cloudflare, device, DNS, Tunnel, Access, Traffic policy, or 1Password change.
## Current Cloudflare Authority

As of 2026-05-27, the active family-home Cloudflare control-plane repo is
`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`.
`/Users/verlyn13/Organizations/<parent-org>/family-cloudflare`.

That repo is the migration target from the older
`/Users/verlyn13/Repos/local/cloudflare-dns` clone. Dated `cloudflare-dns`
Expand Down
2 changes: 1 addition & 1 deletion docs/codex-cli-setup.md
Original file line number Diff line number Diff line change
Expand Up @@ -62,7 +62,7 @@ boundary:
| Full access | **OFF** (standing) | "Full access ON" is capability-availability, not a proven runtime grant — effective enforcement is `config.toml` Sandbox + Approval. Leaving it ON while relying on the sandbox to neutralize it is fragile and conflicts with the approval-gated posture: Full access = no-approval edits to *any* file, which can reach outside the workspace. |
| Sandbox | **Read only** (default); `workspace-write` per-task only | Default-deny writes; widen only for a specific task. |
| Approval | **On request** | Keep a human in the loop for actions outside the read-only sandbox. |
| Config selection | **jefahnierocks (entity) scope**, not `the-nash-group` | `the-nash-group` points the active config at **parent** scope while the work tree is the jefahnierocks **entity** — a boundary mismatch. Alternatively adopt a jefahnierocks-rooted project `.codex/config.toml` with `trust_level` opt-in. |
| Config selection | **jefahnierocks (entity) scope**, not `<parent-org>` | `<parent-org>` points the active config at **parent** scope while the work tree is the jefahnierocks **entity** — a boundary mismatch. Alternatively adopt a jefahnierocks-rooted project `.codex/config.toml` with `trust_level` opt-in. |

Posture model: **HCS ADR 0017** (cited by identifier) — *UI labels are not
runtime receipts*. The app's GUI permission rows are SOURCE/posture evidence, not
Expand Down
2 changes: 1 addition & 1 deletion docs/device-admin/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ policies; older dated evidence may still say WARP, Zero Trust profile, or
Gateway policy where that was the source-era wording.

Current Cloudflare control-plane authority is
`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`, migrated from
`/Users/verlyn13/Organizations/<parent-org>/family-cloudflare`, migrated from
the older `/Users/verlyn13/Repos/local/cloudflare-dns` repo. Dated
`cloudflare-dns` handbacks remain historical evidence; new Cloudflare blockers
and proof requests should route to `family-cloudflare`.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ was changed by this ingest.
Current-state note, added 2026-05-27: this remains the historical ingest from
the former `cloudflare-dns` repo. Active family-home Cloudflare control-plane
work has migrated to
`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. Use this
`/Users/verlyn13/Organizations/<parent-org>/family-cloudflare`. Use this
document for provenance, but refresh new Cloudflare One Client, device-profile,
Gateway, Access, Tunnel, DNS, Worker, or Pulumi/IaC claims against
`family-cloudflare` or live provider proof.
Expand All @@ -39,7 +39,7 @@ Traffic policies for Gateway policies.

| Field | Value |
|---|---|
| Source repo | `/Users/verlyn13/Repos/local/cloudflare-dns` (historical; migrated to `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare` as of 2026-05-27) |
| Source repo | `/Users/verlyn13/Repos/local/cloudflare-dns` (historical; migrated to `/Users/verlyn13/Organizations/<parent-org>/family-cloudflare` as of 2026-05-27) |
| Source doc | `docs/handback-system-config-2026-05-13.md` |
| Source commit | `b5b9460` (file introduction) |
| Parent context commit | `9e4458a` (`fix(state): correct stale enabled flag for 05-adult-identity-bypass`) |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ package, or CLI surface.

Current-state note, added 2026-05-27: the original follow-up was aimed at the
pre-migration `cloudflare-dns` repo. Active Cloudflare control-plane work now
belongs in `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`, so
belongs in `/Users/verlyn13/Organizations/<parent-org>/family-cloudflare`, so
that repo must answer or supersede this rebaseline before any Windows cutover.

## Source
Expand Down
4 changes: 2 additions & 2 deletions docs/device-admin/current-status.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -51,7 +51,7 @@ last_updated: 2026-05-28T07:23:14Z
cloudflare_control_plane_current_state:
verified_at: 2026-05-27T19:28:29Z
active_repo: family-cloudflare
active_repo_path: /Users/verlyn13/Organizations/the-nash-group/family-cloudflare
active_repo_path: /Users/verlyn13/Organizations/<parent-org>/family-cloudflare
active_repo_head: 8bc7f11
active_repo_branch: docs/fu-23-warp-overlay-coexistence-2026-05-27
active_repo_upstream_state: "no upstream tracking branch; main and origin/main both at 8bc7f11"
Expand Down Expand Up @@ -845,7 +845,7 @@ cross_cutting_tbd_items:

advisory_ingests:
- source_repo: hetzner
source_path: /Users/verlyn13/Organizations/the-nash-group/hetzner
source_path: /Users/verlyn13/Organizations/<parent-org>/hetzner
source_doc: docs/reports/cloudflare-management-status-for-system-config-2026-05-14.md
source_commit: 009c091bc63556e6fb43503bf70aee97a269ea82
ingested_at: 2026-05-14T17:30:00Z
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ term.

Current-state note, added 2026-05-27: Cloudflare authority has migrated from
the historical `cloudflare-dns` repo to
`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. Use the old
`/Users/verlyn13/Organizations/<parent-org>/family-cloudflare`. Use the old
handbacks below for provenance only; current Cloudflare One Client, Access,
Tunnel, and profile claims need `family-cloudflare` or live provider proof.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ the `cloudflare-warp` package name remain literal.

Current-state note, added 2026-05-27: this design predates the migration from
`/Users/verlyn13/Repos/local/cloudflare-dns` to
`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. Keep the
`/Users/verlyn13/Organizations/<parent-org>/family-cloudflare`. Keep the
design conclusions, but refresh Cloudflare-side evidence in `family-cloudflare`
before authoring or applying any cutover packet.

Expand Down Expand Up @@ -80,7 +80,7 @@ This design crosses three repos. The boundary is strict:
|---|---|---|---|
| Host hardening, host firewall, host package state, host SSH config, host daemon state | `system-config` (this repo) | All of it. | This document, packets, apply records. |
| LAN routing, OPNsense rules, ISC DHCP, Unbound DNS, NAT, HAProxy frontends, WoL | HomeNetOps (`~/Repos/verlyn13/HomeNetOps`) | All LAN-layer state. | "We need <X>" requests via the handback-format pattern; never reach in. |
| Cloudflare DNS records, Cloudflare Tunnel, Access policies, Traffic policies, Cloudflare One Client device enrollment, device profiles, account-level tokens | `family-cloudflare` (`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`) | All Cloudflare-side state, including current device-profile assignments and adult-vs-kids profile membership. | "We need <X>" requests; never claim live Cloudflare state unless current `family-cloudflare` proof or provider evidence supplies it. |
| Cloudflare DNS records, Cloudflare Tunnel, Access policies, Traffic policies, Cloudflare One Client device enrollment, device profiles, account-level tokens | `family-cloudflare` (`/Users/verlyn13/Organizations/<parent-org>/family-cloudflare`) | All Cloudflare-side state, including current device-profile assignments and adult-vs-kids profile membership. | "We need <X>" requests; never claim live Cloudflare state unless current `family-cloudflare` proof or provider evidence supplies it. |

Implication: any statement in any subsequent packet of the form
"the Cloudflare Access policy for `fedora-top` is N" must cite a
Expand Down Expand Up @@ -527,4 +527,4 @@ boundaries, nothing more.
- [../secrets.md](../secrets.md)
- HomeNetOps repo (external authority): `~/Repos/verlyn13/HomeNetOps`
- `family-cloudflare` repo (external authority):
`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`
`/Users/verlyn13/Organizations/<parent-org>/family-cloudflare`
Original file line number Diff line number Diff line change
Expand Up @@ -50,8 +50,8 @@ device profile, and Traffic policies.

Operator-relayed parent packets:

- `/Users/verlyn13/Organizations/the-nash-group/.claude/orchestration/cloudflare-resource-management/MINIMUM-NAMED-CLOUDFLARE-ACCESS-DESIGN-2026-05-18.md`
- `/Users/verlyn13/Organizations/the-nash-group/.claude/orchestration/cloudflare-resource-management/FU-23-SUBORG-AGENT-ORCHESTRATION-2026-05-18.md`
- `/Users/verlyn13/Organizations/<parent-org>/.claude/orchestration/cloudflare-resource-management/MINIMUM-NAMED-CLOUDFLARE-ACCESS-DESIGN-2026-05-18.md`
- `/Users/verlyn13/Organizations/<parent-org>/.claude/orchestration/cloudflare-resource-management/FU-23-SUBORG-AGENT-ORCHESTRATION-2026-05-18.md`

System-config sources:

Expand Down Expand Up @@ -215,7 +215,7 @@ Record PASS/FAIL/date only. Do not commit screenshots.

1. From the travel MacBook's normal operator browser profile, open the
Cloudflare dashboard.
2. Confirm the Nash Group / expected Cloudflare parent account is selectable.
2. Confirm the parent organization / expected Cloudflare parent account is selectable.
3. Confirm the Cloudflare One dashboard / `homezerotrust` context can be
reached without changing any settings.
4. Record:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ Cloudflare One Client + `cloudflared` cutover packets for the household fleet.
Current-state note, added 2026-05-27: this request was answered by the
pre-migration `cloudflare-dns` repo and remains historical provenance. Active
Cloudflare control-plane work has migrated to
`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`; new packets
`/Users/verlyn13/Organizations/<parent-org>/family-cloudflare`; new packets
must refresh current claims there or against live provider proof.

`family-cloudflare` is now the active authority for Cloudflare account and team
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ unless the operator separately authorizes that work in the
Current-state note, added 2026-05-27: this request was originally addressed to
the pre-migration `cloudflare-dns` repo. Active Cloudflare control-plane work
has migrated to
`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`; that repo
`/Users/verlyn13/Organizations/<parent-org>/family-cloudflare`; that repo
must answer or supersede this request before any Windows multi-user cutover.

## Why This Exists
Expand Down
Loading
Loading