Reliable multi-tenant auto setup audit capability
Find a file
codex 40fc7d694c
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Answer flex-auth B3: the emitter is the section 4 source, not the archive
AUDIT-IN-0005. flex-auth produces the decision record, declares no §11
emission guarantee, and declined to take the reading that moves the
obligation to audit-core. audit-core declines it too, on its own authority:
class, cadence and detection surface are properties of emitting; audit-core
cannot detect non-production; the obligations already sit on each sender
registration; archive-as-source would make §11's check vacuous; and no
access-engine sender is registered at all.

Binds audit-core, does not rule §11 — gate-house still owns that, so
flex-auth's G2 stays open.

Reflexive half: audit-core's own chain-head attestation emission is now
declared in layer.yaml rather than only in docs/integrity.md prose, and
asserted against the CronJob and the contract by test.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
2026-09-21 02:09:47 +02:00
.claude/rules docs: workplan-first agent guidance prose (CUST-WP-0055 T04 batch 5) 2026-07-08 19:50:55 +02:00
.forgejo/workflows Add Forgejo CI smoke workflow (enablement template) 2026-07-08 12:28:40 +02:00
.repo-manager Track repo-manager index and the TAMQ introduction 2026-08-29 14:45:26 +02:00
audit_core Bound /readyz so kubelet probes cannot hang the Service 2026-09-14 22:13:55 +02:00
data/capability Implement AUDIT-WP-0007 hash-chain integrity. 2026-08-16 01:18:30 +02:00
deploy Operate scheduled chain-head attestation (AUDIT-WP-0009-T12) 2026-09-15 21:18:17 +02:00
docs Answer flex-auth B3: the emitter is the section 4 source, not the archive 2026-09-21 02:09:47 +02:00
evidence Make the failure matrix an executable harness 2026-08-10 17:49:32 +02:00
history Align to Security Layer Model v0.7; revise SCOPE; raise AUDIT-WP-0009 2026-08-29 14:42:51 +02:00
intakes Answer flex-auth B3: the emitter is the section 4 source, not the archive 2026-09-21 02:09:47 +02:00
registry Implement AUDIT-WP-0007 hash-chain integrity. 2026-08-16 01:18:30 +02:00
scripts Add attended overlap-then-drop bearer revocation proof 2026-09-15 22:27:01 +02:00
spec Added PRD for what we want to do 2026-06-01 23:38:26 +02:00
tests Answer flex-auth B3: the emitter is the section 4 source, not the archive 2026-09-21 02:09:47 +02:00
workplans Answer flex-auth B3: the emitter is the section 4 source, not the archive 2026-09-21 02:09:47 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-09-15 22:33:05 +02:00
.dockerignore Prepare railiance01 delivery: dynamic leases, migrate Job, operator runbook 2026-08-13 00:58:49 +02:00
.gitignore Make the failure matrix an executable harness 2026-08-10 17:49:32 +02:00
.repo-classification.yaml Human-review .repo-classification.yaml (CUST-WP-0050 follow-up) 2026-06-22 17:56:17 +02:00
AGENTS.md docs(agents): repoint remote State Hub URL to the in-cluster address 2026-08-25 00:20:39 +02:00
CLAUDE.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:24 +02:00
Containerfile Prepare compatible audit receiver with verified container lifecycle 2026-09-11 06:46:15 +02:00
INTENT.md Align to Security Layer Model v0.7; revise SCOPE; raise AUDIT-WP-0009 2026-08-29 14:42:51 +02:00
layer.yaml Answer flex-auth B3: the emitter is the section 4 source, not the archive 2026-09-21 02:09:47 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-29 23:53:10 +02:00
Makefile Implement AUDIT-WP-0006 honest operational custody. 2026-08-16 00:24:33 +02:00
pyproject.toml Add the PostgreSQL audit backend and a shared conformance suite 2026-08-10 17:09:46 +02:00
README.md Prepare railiance01 delivery: dynamic leases, migrate Job, operator runbook 2026-08-13 00:58:49 +02:00
requirements.lock Prepare compatible audit receiver with verified container lifecycle 2026-09-11 06:46:15 +02:00
SCOPE.md AUDIT-WP-0009-T03/T09 — evidence_kind, and approval-engine's registration inputs 2026-09-06 22:31:37 +02:00
TamqMessagingIntroduction.md Track repo-manager index and the TAMQ introduction 2026-08-29 14:45:26 +02:00
tenancy.yaml evidence(AUDIT-WP-0008): establish E2 target pass 2026-08-23 00:26:32 +02:00
WORK-RECORDS.md chore(consistency): write back T11 done and work-record index 2026-09-15 22:34:14 +02:00

Reliable multi-tenant auto setup audit capability

Production on railiance01 (AUDIT-WP-0005): PostgreSQL custody, digest-pinned image, operator procedures in docs/operator-runbook.md. Manifests live in deploy/.

Backend contract

The pluggable backend interface, event schema (audit-core.event.v1alpha1), retention policy, and migration path from the mock file backend are documented in docs/audit-backend-contract.md.

Development Mock Backend

The first implementation is intentionally tiny: a replaceable audit interface with a mock file backend.

By default it writes JSONL audit events to:

/tmp/audit-core/audit-YYYYMMDDTHH.jsonl

Files older than 7 days are removed when the backend writes or when cleanup is run explicitly. This backend is for local integration and bootstrap wiring. It is not durable audit custody.

Example:

python3 -m audit_core emit \
  --source openbao \
  --action openbao.authenticated_readiness_proof \
  --resource openbao/openbao-0 \
  --outcome success \
  --detail file_audit_visible=true \
  --detail backend=mock-file

Cleanup:

python3 -m audit_core cleanup

Make targets:

make test
make mock-audit-smoke
make mock-audit-cleanup

Environment:

  • AUDIT_CORE_MOCK_DIR: override the output directory.
  • AUDIT_CORE_MOCK_RETENTION_DAYS: override the default 7-day cleanup window.