Reliable multi-tenant auto setup audit capability
Find a file
tegwick 58a106aa4d
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
Implement AUDIT-WP-0008 T03, T06, T07, T08.
T08 fixes two defects in our own declaration. provider.R.available quoted a
30-day horizon audit-core does not solely control: at P1 the erasure horizon is
the instance maximum across co-residents, so a co-resident declaring longer
extends what a sender's records remain recoverable for, silently. Decision 4.5.4
names this for tiers; it applies to a provider quoting a number too, and the
provider block now says so. And user-engine, the only consumer, was notified
under Decision 6.1 -- what we declared, that E4 and R4 are unreachable here, and
that the retention number is a floor rather than a ceiling.

T03 writes docs/erasure-and-audit.md: the fact/payload split, why shreddability
is not retrofittable onto a chain committing to cleartext, and why the retained
hash is a confirmation oracle over low-entropy audit records. The framework half
was already resolved as Decision 4.5.3, so what remains is our own position. The
legal basis for retaining audit facts is routed to risk-nexus, open and visible.

T06 closes the review loop with net-kingdom: five findings adopted, declaration
validates clean, and the E line will go stale on an upgrade that Decision 6.1
deliberately does not require anyone to announce.

T07 enumerates the seven dependencies on the accept path and specifies five
recovery scenarios with integrity as a pass condition. It settled one thing: V2
is not reachable from P1 as built, since platform-pg runs instances 1 and
Decision 4.6.1 makes V the minimum across synchronous providers. V1 is the
ceiling here, not the next step. The exercise needs a live window.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 15:24:55 +02:00
.claude/rules docs: workplan-first agent guidance prose (CUST-WP-0055 T04 batch 5) 2026-07-08 19:50:55 +02:00
.forgejo/workflows Add Forgejo CI smoke workflow (enablement template) 2026-07-08 12:28:40 +02:00
audit_core Scope the read path by tenant (AUDIT-WP-0008-T04). 2026-08-17 22:05:52 +02:00
data/capability Implement AUDIT-WP-0007 hash-chain integrity. 2026-08-16 01:18:30 +02:00
deploy Close AUDIT-WP-0007 after live chain attestation. 2026-08-16 01:23:54 +02:00
docs Implement AUDIT-WP-0008 T03, T06, T07, T08. 2026-08-18 15:24:55 +02:00
evidence Make the failure matrix an executable harness 2026-08-10 17:49:32 +02:00
registry Implement AUDIT-WP-0007 hash-chain integrity. 2026-08-16 01:18:30 +02:00
scripts Implement AUDIT-WP-0006 honest operational custody. 2026-08-16 00:24:33 +02:00
spec Added PRD for what we want to do 2026-06-01 23:38:26 +02:00
tests Scope the read path by tenant (AUDIT-WP-0008-T04). 2026-08-17 22:05:52 +02:00
workplans Implement AUDIT-WP-0008 T03, T06, T07, T08. 2026-08-18 15:24:55 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-08-18 15:21:17 +02:00
.dockerignore Prepare railiance01 delivery: dynamic leases, migrate Job, operator runbook 2026-08-13 00:58:49 +02:00
.gitignore Make the failure matrix an executable harness 2026-08-10 17:49:32 +02:00
.repo-classification.yaml Human-review .repo-classification.yaml (CUST-WP-0050 follow-up) 2026-06-22 17:56:17 +02:00
AGENTS.md Regenerate agent instructions from state-hub templates (CUST-WP-0055 T01) 2026-07-08 14:50:17 +02:00
CLAUDE.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:24 +02:00
Containerfile Prepare railiance01 delivery: dynamic leases, migrate Job, operator runbook 2026-08-13 00:58:49 +02:00
INTENT.md Seeded repo with intent 2026-06-01 23:20:04 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-29 23:53:10 +02:00
Makefile Implement AUDIT-WP-0006 honest operational custody. 2026-08-16 00:24:33 +02:00
pyproject.toml Add the PostgreSQL audit backend and a shared conformance suite 2026-08-10 17:09:46 +02:00
README.md Prepare railiance01 delivery: dynamic leases, migrate Job, operator runbook 2026-08-13 00:58:49 +02:00
SCOPE.md Refine AUDIT-WP-0008 open tasks against draft-8. 2026-08-18 15:20:58 +02:00
tenancy.yaml Implement AUDIT-WP-0008 T03, T06, T07, T08. 2026-08-18 15:24:55 +02:00
WORK-RECORDS.md Implement AUDIT-WP-0008 T03, T06, T07, T08. 2026-08-18 15:24:55 +02:00

Reliable multi-tenant auto setup audit capability

Production on railiance01 (AUDIT-WP-0005): PostgreSQL custody, digest-pinned image, operator procedures in docs/operator-runbook.md. Manifests live in deploy/.

Backend contract

The pluggable backend interface, event schema (audit-core.event.v1alpha1), retention policy, and migration path from the mock file backend are documented in docs/audit-backend-contract.md.

Development Mock Backend

The first implementation is intentionally tiny: a replaceable audit interface with a mock file backend.

By default it writes JSONL audit events to:

/tmp/audit-core/audit-YYYYMMDDTHH.jsonl

Files older than 7 days are removed when the backend writes or when cleanup is run explicitly. This backend is for local integration and bootstrap wiring. It is not durable audit custody.

Example:

python3 -m audit_core emit \
  --source openbao \
  --action openbao.authenticated_readiness_proof \
  --resource openbao/openbao-0 \
  --outcome success \
  --detail file_audit_visible=true \
  --detail backend=mock-file

Cleanup:

python3 -m audit_core cleanup

Make targets:

make test
make mock-audit-smoke
make mock-audit-cleanup

Environment:

  • AUDIT_CORE_MOCK_DIR: override the output directory.
  • AUDIT_CORE_MOCK_RETENTION_DAYS: override the default 7-day cleanup window.