Written against draft-7, which landed after the task was drafted and moved the target. Decision 5.4 fixes the location at tenancy.yaml in the repo root rather than docs/, and fixes the schema: current, target, reviewed, gap, placement_exceptions, service_class, per-path detail, provider block. Declares I1 A2 E1 P1 R1. E is quoted at 1 although T04 put the E2 mechanism on both paths, because §13.2 states a passing CI run is not E2 evidence -- the artifact is adversarial, compares separate tenant contexts and carries a review date. Our cross-tenant tests are mechanical, so under §13.1 the level is not claimable until T05. The mechanism is recorded in paths.E and the reason in gap.E. Claiming E2 off unit tests would be the overclaim §6 prohibits, and refusing that reasoning is what found the read-path defect. R stays at 1: R2 needs backupRetentionDays in rapp-postgres's consumer file, requested in T02 and not ours to declare. Two additions draft-7 forced. A credentials gap under Decision 9.2 -- our own finding, adopted as a rule, and it binds us: ingest credentials are static long-lived bearer tokens, declared as a stated gap rather than a silent exclusion. And a provides block under Decision 5.5, declaring what a sender can reach through this service: E2 now, E3 pending ADR-0003, E4 and R4 unreachable. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> |
||
|---|---|---|
| .claude/rules | ||
| .forgejo/workflows | ||
| audit_core | ||
| data/capability | ||
| deploy | ||
| docs | ||
| evidence | ||
| registry | ||
| scripts | ||
| spec | ||
| tests | ||
| workplans | ||
| .custodian-brief.md | ||
| .dockerignore | ||
| .gitignore | ||
| .repo-classification.yaml | ||
| AGENTS.md | ||
| CLAUDE.md | ||
| Containerfile | ||
| INTENT.md | ||
| LICENSE | ||
| Makefile | ||
| pyproject.toml | ||
| README.md | ||
| SCOPE.md | ||
| tenancy.yaml | ||
| WORK-RECORDS.md | ||
Reliable multi-tenant auto setup audit capability
Production on railiance01 (AUDIT-WP-0005): PostgreSQL custody, digest-pinned
image, operator procedures in
docs/operator-runbook.md. Manifests live in
deploy/.
Backend contract
The pluggable backend interface, event schema (audit-core.event.v1alpha1),
retention policy, and migration path from the mock file backend are documented
in docs/audit-backend-contract.md.
Development Mock Backend
The first implementation is intentionally tiny: a replaceable audit interface with a mock file backend.
By default it writes JSONL audit events to:
/tmp/audit-core/audit-YYYYMMDDTHH.jsonl
Files older than 7 days are removed when the backend writes or when cleanup is run explicitly. This backend is for local integration and bootstrap wiring. It is not durable audit custody.
Example:
python3 -m audit_core emit \
--source openbao \
--action openbao.authenticated_readiness_proof \
--resource openbao/openbao-0 \
--outcome success \
--detail file_audit_visible=true \
--detail backend=mock-file
Cleanup:
python3 -m audit_core cleanup
Make targets:
make test
make mock-audit-smoke
make mock-audit-cleanup
Environment:
AUDIT_CORE_MOCK_DIR: override the output directory.AUDIT_CORE_MOCK_RETENTION_DAYS: override the default 7-day cleanup window.