Reliable multi-tenant auto setup audit capability
Find a file
tegwick c4016a70d5
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
AUDIT-WP-0009-T11 — register informed-decision, and answer GH-DEC-2026-014
informed-decision is the browser-facing approver surface; GH-DEC-2026-012
limit 3 makes its evidence copy the one that must reach audit-core
independently of the emitter, because there the actor being audited and the
evidence source are the same component.

Registration accepted on every proposed field — exact source,
["tenant:platform"], write true, read false, load-bearing, secret_policy
redact. Prepared and inert: the scope overlay applies only to a sender the
Secret already carries, asserted by test rather than by reading. Ingress ANDs
namespace and pod label in one peer, following approval-engine rather than
user-engine's older breadth.

Gate House asked whether the record shape can carry a source-held-content
declaration with a retrieval expectation, and asked for a straight answer
rather than a rule the storage cannot meet. Both halves, which must travel
together:

  It CAN carry the declaration. data is stored verbatim into details.data and
  hash-chained, so content_exists and custody need no schema change and become
  as tamper-evident as the commitment they accompany.

  It CANNOT detect non-production. audit-core performs no retrieval and its
  egress permits Postgres and DNS only. Detection happens at retrieval, by the
  reviewer; the stored declaration is what turns a blank into a failure
  attributable to the named custodian.

Residual stated rather than left to be found: a custodian that never held the
content can emit a false content_exists. audit-core validates the declaration's
shape, never its truth — the same class as omission at source, and not closed
by the chain, by attestation, or by T04/T06. A test asserts no egress to the
emitter exists, because that claim silently stops being true if one appears.

Cadence: reconciliation plus heartbeat is right for a mixed-volume source, with
both scoped per class rather than per source — a per-source heartbeat is
satisfied by the high-volume presentation stream and says nothing about a quiet
month of dispositions. Bound: a compromised emitter suppresses the event and
its own count together.

Also recorded: commitment-only satisfies non-alteration and never
reconstructability, in this repo's documents as in theirs; and tenant
provenance under GH-DEC-2026-013 lands in the registration record, not the
envelope, since audit-core checks a value the credential may write rather than
resolving an identity claim.

No secret was created and no production manifest applied.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nb7Q6ZmXppNDkTWytfYqfv

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2069992@bnt-lap001
Assistant-Session: 167dd7f8-2a25-4be1-aa46-3b6f1a5f94c6
2026-09-10 15:15:35 +02:00
.claude/rules docs: workplan-first agent guidance prose (CUST-WP-0055 T04 batch 5) 2026-07-08 19:50:55 +02:00
.forgejo/workflows Add Forgejo CI smoke workflow (enablement template) 2026-07-08 12:28:40 +02:00
.repo-manager Track repo-manager index and the TAMQ introduction 2026-08-29 14:45:26 +02:00
audit_core AUDIT-WP-0009-T03/T09 — evidence_kind, and approval-engine's registration inputs 2026-09-06 22:31:37 +02:00
data/capability Implement AUDIT-WP-0007 hash-chain integrity. 2026-08-16 01:18:30 +02:00
deploy AUDIT-WP-0009-T11 — register informed-decision, and answer GH-DEC-2026-014 2026-09-10 15:15:35 +02:00
docs AUDIT-WP-0009-T11 — register informed-decision, and answer GH-DEC-2026-014 2026-09-10 15:15:35 +02:00
evidence Make the failure matrix an executable harness 2026-08-10 17:49:32 +02:00
history Align to Security Layer Model v0.7; revise SCOPE; raise AUDIT-WP-0009 2026-08-29 14:42:51 +02:00
intakes AUDIT-WP-0009-T11 — register informed-decision, and answer GH-DEC-2026-014 2026-09-10 15:15:35 +02:00
registry Implement AUDIT-WP-0007 hash-chain integrity. 2026-08-16 01:18:30 +02:00
scripts feat(AUDIT-WP-0008): add T02 synthetic load driver 2026-08-22 16:46:31 +02:00
spec Added PRD for what we want to do 2026-06-01 23:38:26 +02:00
tests AUDIT-WP-0009-T11 — register informed-decision, and answer GH-DEC-2026-014 2026-09-10 15:15:35 +02:00
workplans AUDIT-WP-0009-T11 — register informed-decision, and answer GH-DEC-2026-014 2026-09-10 15:15:35 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-09-08 20:34:53 +02:00
.dockerignore Prepare railiance01 delivery: dynamic leases, migrate Job, operator runbook 2026-08-13 00:58:49 +02:00
.gitignore Make the failure matrix an executable harness 2026-08-10 17:49:32 +02:00
.repo-classification.yaml Human-review .repo-classification.yaml (CUST-WP-0050 follow-up) 2026-06-22 17:56:17 +02:00
AGENTS.md docs(agents): repoint remote State Hub URL to the in-cluster address 2026-08-25 00:20:39 +02:00
CLAUDE.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:24 +02:00
Containerfile Prepare railiance01 delivery: dynamic leases, migrate Job, operator runbook 2026-08-13 00:58:49 +02:00
INTENT.md Align to Security Layer Model v0.7; revise SCOPE; raise AUDIT-WP-0009 2026-08-29 14:42:51 +02:00
layer.yaml Align to Security Layer Model v0.7; revise SCOPE; raise AUDIT-WP-0009 2026-08-29 14:42:51 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-29 23:53:10 +02:00
Makefile Implement AUDIT-WP-0006 honest operational custody. 2026-08-16 00:24:33 +02:00
pyproject.toml Add the PostgreSQL audit backend and a shared conformance suite 2026-08-10 17:09:46 +02:00
README.md Prepare railiance01 delivery: dynamic leases, migrate Job, operator runbook 2026-08-13 00:58:49 +02:00
SCOPE.md AUDIT-WP-0009-T03/T09 — evidence_kind, and approval-engine's registration inputs 2026-09-06 22:31:37 +02:00
TamqMessagingIntroduction.md Track repo-manager index and the TAMQ introduction 2026-08-29 14:45:26 +02:00
tenancy.yaml evidence(AUDIT-WP-0008): establish E2 target pass 2026-08-23 00:26:32 +02:00
WORK-RECORDS.md chore(records): refresh the work-records index for T03/T09 2026-09-06 22:32:55 +02:00

Reliable multi-tenant auto setup audit capability

Production on railiance01 (AUDIT-WP-0005): PostgreSQL custody, digest-pinned image, operator procedures in docs/operator-runbook.md. Manifests live in deploy/.

Backend contract

The pluggable backend interface, event schema (audit-core.event.v1alpha1), retention policy, and migration path from the mock file backend are documented in docs/audit-backend-contract.md.

Development Mock Backend

The first implementation is intentionally tiny: a replaceable audit interface with a mock file backend.

By default it writes JSONL audit events to:

/tmp/audit-core/audit-YYYYMMDDTHH.jsonl

Files older than 7 days are removed when the backend writes or when cleanup is run explicitly. This backend is for local integration and bootstrap wiring. It is not durable audit custody.

Example:

python3 -m audit_core emit \
  --source openbao \
  --action openbao.authenticated_readiness_proof \
  --resource openbao/openbao-0 \
  --outcome success \
  --detail file_audit_visible=true \
  --detail backend=mock-file

Cleanup:

python3 -m audit_core cleanup

Make targets:

make test
make mock-audit-smoke
make mock-audit-cleanup

Environment:

  • AUDIT_CORE_MOCK_DIR: override the output directory.
  • AUDIT_CORE_MOCK_RETENTION_DAYS: override the default 7-day cleanup window.