Reliable multi-tenant auto setup audit capability
Find a file
tegwick 6eaa33699d
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Align to Security Layer Model v0.7; revise SCOPE; raise AUDIT-WP-0009
The standard is accepted at v0.7 and all three of audit-core's v0.6
findings landed in it (§9.6 threat decomposition, cadence MUST for
load-bearing sources with reconciliation/heartbeat for low-volume
classes, §3.3's Evidence row restated as an estate trade).

INTENT.md: layer/role declared in frontmatter as §11 and companion §2
require — layer.yaml alone did not discharge it. Layer section rewritten
for the Evidence role and its obligations. New Evidence Bound section
carrying the §9.6 sound/unsound forms and the three-row threat table,
including the residual nothing in the model prevents.

SCOPE.md: replaced the statehub register stub, which carried no boundary
at all. Statute-fixed prohibitions now live here, separated from the
merely-not-yet — §16 ruled the stronger-custody gap closed, so WORM and
data.archive are not ours rather than not yet.

Assessment found nine gaps. Headline: postgres_backend returns
tamper_evidence=True unconditionally while docs/integrity.md permits it
only against a live external attestation, and the one on record is
2026-08-16 with no job renewing it — audit-core overclaiming its own
bound, the §9.6 defect turned inward. Also: no cadence, heartbeat,
reconciliation, or load-bearing classification exists, so the obligation
audit-core argued up from SHOULD to MUST is not yet dischargeable
against audit-core.

AUDIT-WP-0009 raised, ten tasks.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WpeL68AWHqtqPQZEXY5kFe

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4040362@bnt-lap001
Assistant-Session: 4fd0fd24-2ee8-4413-bd67-43bd79ca73f1
2026-08-29 14:42:51 +02:00
.claude/rules docs: workplan-first agent guidance prose (CUST-WP-0055 T04 batch 5) 2026-07-08 19:50:55 +02:00
.forgejo/workflows Add Forgejo CI smoke workflow (enablement template) 2026-07-08 12:28:40 +02:00
audit_core feat(AUDIT-WP-0008): enforce temporary sender expiry 2026-08-22 11:59:26 +02:00
data/capability Implement AUDIT-WP-0007 hash-chain integrity. 2026-08-16 01:18:30 +02:00
deploy deploy(AUDIT-WP-0008): pin sender-expiry image 2026-08-22 12:01:08 +02:00
docs evidence(AUDIT-WP-0008): establish E2 target pass 2026-08-23 00:26:32 +02:00
evidence Make the failure matrix an executable harness 2026-08-10 17:49:32 +02:00
history Align to Security Layer Model v0.7; revise SCOPE; raise AUDIT-WP-0009 2026-08-29 14:42:51 +02:00
intakes Intake AUDIT-IN-0002: register tenant-engine as a sender 2026-08-29 13:02:59 +02:00
registry Implement AUDIT-WP-0007 hash-chain integrity. 2026-08-16 01:18:30 +02:00
scripts feat(AUDIT-WP-0008): add T02 synthetic load driver 2026-08-22 16:46:31 +02:00
spec Added PRD for what we want to do 2026-06-01 23:38:26 +02:00
tests test(AUDIT-WP-0008): exercise T02 driver over HTTP 2026-08-22 16:55:37 +02:00
workplans Align to Security Layer Model v0.7; revise SCOPE; raise AUDIT-WP-0009 2026-08-29 14:42:51 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-08-25 20:07:50 +02:00
.dockerignore Prepare railiance01 delivery: dynamic leases, migrate Job, operator runbook 2026-08-13 00:58:49 +02:00
.gitignore Make the failure matrix an executable harness 2026-08-10 17:49:32 +02:00
.repo-classification.yaml Human-review .repo-classification.yaml (CUST-WP-0050 follow-up) 2026-06-22 17:56:17 +02:00
AGENTS.md docs(agents): repoint remote State Hub URL to the in-cluster address 2026-08-25 00:20:39 +02:00
CLAUDE.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:24 +02:00
Containerfile Prepare railiance01 delivery: dynamic leases, migrate Job, operator runbook 2026-08-13 00:58:49 +02:00
INTENT.md Align to Security Layer Model v0.7; revise SCOPE; raise AUDIT-WP-0009 2026-08-29 14:42:51 +02:00
layer.yaml Align to Security Layer Model v0.7; revise SCOPE; raise AUDIT-WP-0009 2026-08-29 14:42:51 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-29 23:53:10 +02:00
Makefile Implement AUDIT-WP-0006 honest operational custody. 2026-08-16 00:24:33 +02:00
pyproject.toml Add the PostgreSQL audit backend and a shared conformance suite 2026-08-10 17:09:46 +02:00
README.md Prepare railiance01 delivery: dynamic leases, migrate Job, operator runbook 2026-08-13 00:58:49 +02:00
SCOPE.md Align to Security Layer Model v0.7; revise SCOPE; raise AUDIT-WP-0009 2026-08-29 14:42:51 +02:00
tenancy.yaml evidence(AUDIT-WP-0008): establish E2 target pass 2026-08-23 00:26:32 +02:00
WORK-RECORDS.md Refresh work-record index 2026-08-28 22:36:08 +02:00

Reliable multi-tenant auto setup audit capability

Production on railiance01 (AUDIT-WP-0005): PostgreSQL custody, digest-pinned image, operator procedures in docs/operator-runbook.md. Manifests live in deploy/.

Backend contract

The pluggable backend interface, event schema (audit-core.event.v1alpha1), retention policy, and migration path from the mock file backend are documented in docs/audit-backend-contract.md.

Development Mock Backend

The first implementation is intentionally tiny: a replaceable audit interface with a mock file backend.

By default it writes JSONL audit events to:

/tmp/audit-core/audit-YYYYMMDDTHH.jsonl

Files older than 7 days are removed when the backend writes or when cleanup is run explicitly. This backend is for local integration and bootstrap wiring. It is not durable audit custody.

Example:

python3 -m audit_core emit \
  --source openbao \
  --action openbao.authenticated_readiness_proof \
  --resource openbao/openbao-0 \
  --outcome success \
  --detail file_audit_visible=true \
  --detail backend=mock-file

Cleanup:

python3 -m audit_core cleanup

Make targets:

make test
make mock-audit-smoke
make mock-audit-cleanup

Environment:

  • AUDIT_CORE_MOCK_DIR: override the output directory.
  • AUDIT_CORE_MOCK_RETENTION_DAYS: override the default 7-day cleanup window.