Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

1.6 KiB

API Reference: HashiCorp Boundary

Boundary CLI (JSON output)

Core Commands

boundary scopes list -scope-id=global -format=json
boundary targets list -scope-id=<id> -format=json
boundary host-catalogs list -scope-id=<id> -format=json
boundary credential-stores list -scope-id=<id> -format=json
boundary sessions list -scope-id=<id> -format=json
boundary auth-methods list -scope-id=global -format=json

Environment Variables

Variable Description
BOUNDARY_ADDR Controller address (e.g., http://127.0.0.1:9200)
BOUNDARY_TOKEN Authentication token

Target Fields

Field Description
name Target display name
type tcp or ssh
session_max_seconds Maximum session duration
session_connection_limit Max concurrent connections (-1 = unlimited)

Credential Store Types

Type Description
vault Vault-brokered dynamic credentials (recommended)
static Static credentials stored in Boundary

Auth Method Types

Type Zero Trust Suitability
oidc Recommended (SSO, MFA support)
ldap Acceptable with MFA
password Not recommended for zero trust

Session Recording

boundary targets update tcp -id=<id> -enable-session-recording=true \
  -storage-bucket-id=<bucket-id>

References