Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ scripts/sync-mcp.sh --dry-run # then without --dry-run
scripts/codex-mcp-readiness.sh --source
scripts/onepassword-capability-doctor.sh
scripts/audit-agent-config.sh --source # --live reads host metadata
scripts/validate_public_privacy.py
scripts/sync-vscode.sh --check # then --apply
```

Expand Down
4 changes: 2 additions & 2 deletions docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -72,8 +72,8 @@ explicitly says otherwise.**
- [`git-identity.md`](git-identity.md) — GitHub identity across authorship,
transport and API. system-config is the read-only **consumer/enforcer** of a
registry produced elsewhere. **The identity matrix is never copied into this
repo — it is public.** Covers the gate mechanism and the read-only
`ng-doctor identity` checks.
repo — it is public.** Covers the commit gate, the value-blind public-source
privacy gate, and the read-only `ng-doctor identity` checks.
- [`agentic-hook-enforcement.md`](agentic-hook-enforcement.md) — per-runtime
hook surfaces (Claude, Codex, Copilot, Cursor, Devin) that carry the
git-identity gate, the adapter model, verified local state, and unresolved
Expand Down
9 changes: 5 additions & 4 deletions docs/agentic-tooling.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ title: Agentic Tooling
category: reference
component: agentic_tooling
status: active
version: 1.9.0
version: 1.9.1
last_updated: 2026-08-28
tags: [agentic, mcp, zsh, claude, codex, cursor, devin, copilot, gemini, workspace, substrate, tailscale, mercurial, huggingface, infisical, vscode]
priority: high
Expand Down Expand Up @@ -201,9 +201,10 @@ There are two lanes:

Project agents stop before direct host mutation, Proxmox console drift,
unscoped machine identities, secret material in files or state, and workloads
without a reviewed substrate contract. The contract shape comes from Citadel's
example at
`/Users/verlyn13/Organizations/the-nash-group/the-citadel/docs/reference/project-substrate-contract.example.yaml`.
without a reviewed substrate contract. The public contract projection is
[`policies/host-capability-substrate/project-substrate-admission.yaml`](../policies/host-capability-substrate/project-substrate-admission.yaml).
Resolve any external owner source through the private workspace registry; do
not embed a parent checkout path in project guidance.

## MCP Configuration

Expand Down
16 changes: 9 additions & 7 deletions docs/cloudflare-one-terminology.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,8 @@ title: Cloudflare One Terminology Reference
category: reference
component: cloudflare
status: active
version: 1.1.0
last_updated: 2026-05-27
version: 1.2.0
last_updated: 2026-08-28
tags: [cloudflare, cloudflare-one, sase, zero-trust, devices, access, traffic-policies, family-cloudflare, terminology]
priority: high
---
Expand All @@ -21,8 +21,10 @@ Cloudflare, device, DNS, Tunnel, Access, Traffic policy, or 1Password change.

## Current Cloudflare Authority

As of 2026-05-27, the active family-home Cloudflare control-plane repo is
`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`.
As of 2026-05-27, the active family-home Cloudflare control-plane is the
owner-scoped `family-cloudflare` repository. Resolve its checkout through the
private workspace registry rather than copying its parent path into this
public repository.

That repo is the migration target from the older
`/Users/verlyn13/Repos/local/cloudflare-dns` clone. Dated `cloudflare-dns`
Expand Down Expand Up @@ -125,9 +127,9 @@ Use this mapping when writing parent/suborg handbacks:

| Governance pillar | Cloudflare One surfaces |
|---|---|
| Covenant | Access controls, Identity providers, Users, enrollment identities, service credentials. |
| Citadel | Traffic policies, DLP, Remote Browser Isolation, Email security, Posture checks, hardening controls. |
| Nexus | Networks, Devices, Application Library, Tunnel, WAN, Mesh, Routes, Resolvers. |
| Identity and access | Access controls, Identity providers, Users, enrollment identities, service credentials. |
| Security policy | Traffic policies, DLP, Remote Browser Isolation, Email security, Posture checks, hardening controls. |
| Network control plane | Networks, Devices, Application Library, Tunnel, WAN, Mesh, Routes, Resolvers. |
| Meta / observability | Insights, Analytics, DEX, Logs, Roles and permissions, Reusable components. |

## Writing Rules
Expand Down
11 changes: 6 additions & 5 deletions docs/device-admin/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,8 @@ title: Device Admin — Status and Orientation
category: index
component: device_admin
status: active
version: 1.1.0
last_updated: 2026-05-28
version: 1.2.0
last_updated: 2026-08-28
tags: [device-admin, fleet, windows, linux, ssh, cloudflare-one, index]
priority: high
---
Expand All @@ -23,9 +23,10 @@ device-admin prose should say Cloudflare One Client, device profile, and Traffic
policies; older dated evidence may still say WARP, Zero Trust profile, or
Gateway policy where that was the source-era wording.

Current Cloudflare control-plane authority is
`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`, migrated from
the older `/Users/verlyn13/Repos/local/cloudflare-dns` repo. Dated
Current Cloudflare control-plane authority is the owner-scoped
`family-cloudflare` repository, migrated from the older
`/Users/verlyn13/Repos/local/cloudflare-dns` repo. Locate current owner source
through the private workspace registry rather than a parent path. Dated
`cloudflare-dns` handbacks remain historical evidence; new Cloudflare blockers
and proof requests should route to `family-cloudflare`.

Expand Down
4 changes: 2 additions & 2 deletions docs/device-admin/current-status.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -51,7 +51,7 @@ last_updated: 2026-05-28T07:23:14Z
cloudflare_control_plane_current_state:
verified_at: 2026-05-27T19:28:29Z
active_repo: family-cloudflare
active_repo_path: /Users/verlyn13/Organizations/the-nash-group/family-cloudflare
active_repo_ref: owner-scoped:family-cloudflare
active_repo_head: 8bc7f11
active_repo_branch: docs/fu-23-warp-overlay-coexistence-2026-05-27
active_repo_upstream_state: "no upstream tracking branch; main and origin/main both at 8bc7f11"
Expand Down Expand Up @@ -845,7 +845,7 @@ cross_cutting_tbd_items:

advisory_ingests:
- source_repo: hetzner
source_path: /Users/verlyn13/Organizations/the-nash-group/hetzner
source_repo_ref: owner-scoped:hetzner
source_doc: docs/reports/cloudflare-management-status-for-system-config-2026-05-14.md
source_commit: 009c091bc63556e6fb43503bf70aee97a269ea82
ingested_at: 2026-05-14T17:30:00Z
Expand Down
34 changes: 32 additions & 2 deletions docs/git-identity.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,8 @@ title: Git Identity Coherence (consumer of the meta-inventory registry)
category: reference
component: git_identity
status: active
version: 0.11.0
last_updated: 2026-08-13
version: 0.12.0
last_updated: 2026-08-28
tags: [git, github, identity, ssh, signing, gh, ng-doctor, meta-inventory, consumer]
priority: high
---
Expand Down Expand Up @@ -86,6 +86,36 @@ handoff in full before changing any Phase 1+ behavior:
`includeIf` lane yet — it inherits the personal lane. Do not invent a lane
without the operator.)

## Public-source privacy gate

[`scripts/validate_public_privacy.py`](../scripts/validate_public_privacy.py)
enforces the public side of this boundary. It scans tracked and untracked
nonignored text, staged content when it differs from the worktree, and symlink
targets for external organization checkout paths, common personal-mail domains,
and academic-mail suffixes. CI runs these public-safe heuristics without needing
the private registry.

The stronger local lane accepts an operator-owned literal dictionary:

```bash
scripts/validate_public_privacy.py \
--private-dictionary /absolute/path/outside/this/repo/private-identifiers.txt
```

The dictionary must be outside the repository, mode `0600`, and contain one
case-insensitive literal per line. Set
`SYSTEM_CONFIG_PUBLIC_PRIVACY_DICTIONARY` to that path to include the stronger
lane automatically in `scripts/validate-repo.sh`. The dictionary and its terms
remain private operator state; `system-config` does not own or reproduce them.

Failure receipts contain only a repository-relative path and rule identifier.
If the identifier occurs in the path itself, the path is redacted. No matched
text, identity, hash, or length is emitted. Narrow, rule-specific exceptions
live in [`policies/public-privacy.json`](../policies/public-privacy.json) for
truthful historical evidence, byte-pinned sources, and coordinated runtime
identifiers. An exception is classification, not permission to add new active
authority or executable use.

## Enforcement model

Read the registry, then per cloned repo join `repos[]` (expected) with
Expand Down
117 changes: 45 additions & 72 deletions docs/google-admin-tooling.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,58 +3,36 @@ title: Google Admin Tooling
category: reference
component: google_admin_tooling
status: active
version: 0.1.0
last_updated: 2026-05-17
version: 0.2.0
last_updated: 2026-08-28
tags: [google, gcloud, gam, workspace, guardian, cli]
priority: medium
---

# Google Admin Tooling

This document records the local, non-secret Google CLI shape on this
workstation. It is a host-state reference, not a provider-state authority
record. Do not commit Google OAuth tokens, service-account keys, refresh tokens,
or downloaded client-secret JSON.
This document records the public, non-secret Google CLI contract for this
workstation. It is a tool-shape reference, not an account, tenant, domain,
project, provider-state, or reauthentication authority. Resolve those bindings
through the private workspace registry and an explicit operator decision.

## Current Snapshot
Do not commit configuration names, account addresses, domain names, project
identifiers, OAuth tokens, service-account keys, refresh tokens, downloaded
client-secret JSON, or output that reveals those values.

Verified on 2026-05-17 from this repo on `main`.
## Tool Shape

The following installation shape was verified on 2026-05-17. Re-read the host
before relying on a version or path.

### Google Cloud CLI

- Install owner: Homebrew cask `gcloud-cli`
- Binary: `/opt/homebrew/bin/gcloud`
- SDK root: `/opt/homebrew/share/google-cloud-sdk`
- Installed version: `Google Cloud SDK 568.0.0`
- Component status: `gcloud components update --quiet` reported all components
up to date.
- Homebrew status: `brew outdated --cask gcloud-cli` returned no outdated cask.

The active local configuration is intentionally neutral:

| Config | Active | Account | Project |
|--------|--------|---------|---------|
| `thenash-guardian` | yes | `guardian@thenash.group` | unset |
| `default` | no | `jeffrey@happy-patterns.com` | `happy-playground-463417` |
| `scopecam-production` | no | `REDACTED-operator-google-account` | `scopecam-qa` |
| `scopecam-qa` | no | `REDACTED-operator-google-account` | `scopecam-qa` |

The Guardian config must not be bound to `scopecam-qa` or any Happy
Patterns-owned project unless the operator explicitly asks for that project
relationship.

Current auth state:

- `gcloud auth list` shows `guardian@thenash.group` as active.
- Application Default Credentials file shape is `authorized_user`, account
`guardian@thenash.group`, with no `quota_project_id`.
- Token refresh currently requires a human Google reauthentication flow. A
non-interactive check with
`gcloud auth print-access-token --account=guardian@thenash.group --quiet`
failed with "Reauthentication failed. cannot prompt during non-interactive
execution." The same class of failure applies to
`gcloud auth application-default print-access-token --quiet` until the
browser reauth is completed.
- Update owner: Homebrew; `system-config` reports cask staleness but does not
select an account or project.

### GAM7

Expand All @@ -63,66 +41,58 @@ Current auth state:
- Installed package: `gam7 7.43.5`
- `gam version` reports `GAM 7.43.05`
- Config file: `/Users/verlyn13/.gam/gam.cfg`
- Active GAM section: `thenash.group`
- Domain: `thenash.group`
- Admin email: `guardian@thenash.group`
- Workspace-specific config dir: `/Users/verlyn13/.gam/thenash.group`
- Configuration root: `~/.gam/`

The legacy binary `/Users/verlyn13/bin/gam7/gam` still exists but is not the
primary PATH binary. Prefer the `pipx` managed `gam` shim unless a task is
explicitly about legacy cleanup.

## Verification Commands
## Value-Blind Verification

Use these commands for a no-secret status check:
Use status-only commands that discard account and project values:

```bash
gcloud version
gcloud components update --quiet
brew list --cask --versions gcloud-cli
brew outdated --cask gcloud-cli
gcloud config configurations list --format='table(name,is_active,properties.core.account,properties.core.project)'
gcloud auth list --format='table(account,status)'
jq -r '"type=" + (.type // ""), "account=" + (.account // ""), "quota_project_id=" + (.quota_project_id // ""), "keys=" + (keys_unsorted | sort | join(","))' "$HOME/.config/gcloud/application_default_credentials.json"
gcloud config configurations list --filter=is_active:true --format='value(is_active)'
gcloud config get-value account >/dev/null 2>&1
gcloud config get-value project >/dev/null 2>&1
gcloud auth list --filter=status:ACTIVE --format='value(status)'
jq -e 'type == "object" and (.type | type == "string")' \
"$HOME/.config/gcloud/application_default_credentials.json" >/dev/null
gam version
```

Token refresh checks do not print token values:
An operator-authorized token readiness probe must discard the token and avoid
putting an account identifier in argv:

```bash
gcloud auth print-access-token --account=guardian@thenash.group --quiet >/dev/null
gcloud auth application-default print-access-token --quiet >/dev/null
gcloud auth print-access-token --quiet >/dev/null 2>&1
gcloud auth application-default print-access-token --quiet >/dev/null 2>&1
```

If those fail with a reauthentication prompt error, complete the human browser
steps below.

## Guardian Reauthentication
steps below. A successful refresh is not provider inventory or mutation
authority.

The preferred Guardian shape is:
## Operator-Gated Reauthentication

- active config: `thenash-guardian`
- active account: `guardian@thenash.group`
- project: unset
- ADC account: `guardian@thenash.group`
- ADC quota project: unset
Reauthentication is live account state. Before running it, the operator must
select the intended private-registry account/configuration and confirm whether
Application Default Credentials should be changed.

Repair commands:
Generic browser-flow commands are:

```bash
gcloud config configurations activate thenash-guardian
gcloud config set account guardian@thenash.group
gcloud config unset project --quiet
gcloud config set disable_usage_reporting true

gcloud auth login guardian@thenash.group --force
gcloud auth application-default login guardian@thenash.group --disable-quota-project
gcloud auth login --force
gcloud auth application-default login --disable-quota-project
```

Complete both browser flows as `guardian@thenash.group`. Do not use
`--update-adc` if it would copy an unrelated project binding into ADC.

After login, rerun the token refresh checks above.
The browser-selected identity must match the operator-approved private binding.
Do not infer it from this public repo. Do not use `--update-adc` if it would copy
an unrelated project binding into ADC. After login, rerun only the value-blind
readiness checks above.

## Update Policy

Expand All @@ -145,7 +115,10 @@ for the run.

## Stop Rules

- Do not bind Guardian gcloud config or ADC to `scopecam-qa`.
- Do not copy account, domain, configuration, or project identifiers into this
public document or command receipts.
- Do not change a gcloud configuration, account, project, or ADC binding without
the operator-selected private target.
- Do not inspect or print OAuth token contents.
- Do not commit files from `~/.config/gcloud`, `~/.gam`, or downloaded Google
credential JSON.
Expand Down
14 changes: 7 additions & 7 deletions docs/homebrew-tap-trust.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,8 @@ title: Homebrew Tap Trust
category: reference
component: homebrew
status: active
version: 1.2.1
last_updated: 2026-07-19
version: 1.2.2
last_updated: 2026-08-28
tags: [homebrew, tap-trust, supply-chain, system-update]
priority: high
---
Expand Down Expand Up @@ -74,12 +74,12 @@ batch on 2026-07-18 resolved that state without widening trust to any full tap.

| Item | Ownership decision | Applied state |
| --- | --- | --- |
| `cloudflare/cloudflare/cf-terraforming` | Required by the Citadel Cloudflare break-glass reconciliation lane; external-repo dependency, not system-config-owned | Kept and trusted as one formula |
| `cloudflare/cloudflare/cf-terraforming` | Required by an external Cloudflare break-glass reconciliation lane; external-repo dependency, not system-config-owned | Kept and trusted as one formula |
| `runpod/runpodctl/runpodctl` | Required by Hetzner RunPod stage-2 scripts; external-repo dependency, not system-config-owned | Kept and trusted as one formula |
| `hashicorp/tap/terraform` | No Nash dependency, but retained as this workstation's documented system-config Terraform baseline | Kept and trusted as one formula; stale inactive mise Terraform removed |
| `ascii-image-converter` | No system-config or relayed Nash requirement | Formula and tap removed |
| `turso` / `sqld` | No system-config or relayed Nash requirement | Formulae and tap removed |
| `pants` | No system-config or relayed Nash requirement | Cask and tap removed |
| `hashicorp/tap/terraform` | No external project dependency, but retained as this workstation's documented system-config Terraform baseline | Kept and trusted as one formula; stale inactive mise Terraform removed |
| `ascii-image-converter` | No system-config or relayed external requirement | Formula and tap removed |
| `turso` / `sqld` | No system-config or relayed external requirement | Formulae and tap removed |
| `pants` | No system-config or relayed external requirement | Cask and tap removed |
| `doppler` | Core formula retained an old third-party receipt | Reinstalled from `homebrew/core`; obsolete Doppler tap removed |

Unused `supabase/tap` and `1password/tap` were also removed. The 1Password tap
Expand Down
Loading
Loading