Accept now extends a single-schema chain. Verify walks it; a rewritten payload_hash is a break. Tamper evidence is that detector plus an external chain-head attestation, not WORM.
126 lines
5.5 KiB
JSON
126 lines
5.5 KiB
JSON
{
|
|
"schema_version": "0.1",
|
|
"record_scope": "operational",
|
|
"canon": {
|
|
"model": "ITC-CAP",
|
|
"model_version": "0.4.0",
|
|
"canon_version": "0.6.0",
|
|
"status": "draft",
|
|
"catalog": "info-tech-canon/infospace/models/capability/capabilities.yaml",
|
|
"evidence_basis_catalog": "info-tech-canon/infospace/models/governance/evidence-basis.yaml"
|
|
},
|
|
"record_id": "capability-case:audit-core-operational:2026-08",
|
|
"created_at": "2026-08-16T00:00:00Z",
|
|
"subject": "Live audit-core receiver on railiance01, restated in canon terms",
|
|
"note": "Joins reuse-surface id capability.audit.event-retain to ITC-CAP operations.audit. Maturity attaches to this provision, not the abstract capability. data.backup is cited, not restated.",
|
|
"reuse_surface": {
|
|
"id": "capability.audit.event-retain",
|
|
"path": "registry/capabilities/capability.audit.event-retain.md"
|
|
},
|
|
"requires": [
|
|
{
|
|
"consumer": "audit-core.railiance01",
|
|
"capability": "operations.audit",
|
|
"profile": "administrative",
|
|
"minimum_maturity": "D4",
|
|
"requirement_note": "Production dependency for user-engine outbox delivery. D4 is the current ask; D5 would need measured integrity verification and actively controlled reliability."
|
|
},
|
|
{
|
|
"consumer": "audit-core.railiance01",
|
|
"capability": "data.archive",
|
|
"profile": "operational",
|
|
"requirement_note": "INTENT still wants unbounded WORM archive beyond the 30-day platform backup window. Unmet. Owner: audit-core to write a demand; resource-control to procure a different bucket/lifecycle than Barman. No provision is invented here."
|
|
}
|
|
],
|
|
"provisions": [
|
|
{
|
|
"provider": "audit-core.railiance01",
|
|
"capability": "operations.audit",
|
|
"profile": "administrative",
|
|
"environment": "production",
|
|
"maturity": "D4",
|
|
"implements": "HTTP POST /v1/events into append-only PostgreSQL on platform-pg, namespace audit-core, ClusterIP + default-deny",
|
|
"maturity_rationale": "Approved for production dependency since AUDIT-WP-0005. Not D5: one replica, reliability is not actively controlled. Integrity is measured (hash chain + verify + external head) but is not WORM.",
|
|
"uses_provisions": [
|
|
{
|
|
"capability": "data.transactional",
|
|
"provider": "rapp-postgres/platform-pg database audit_core",
|
|
"relation": "may_use",
|
|
"note": "operations.audit does not declare depends_on data.transactional in the catalog. The live store is Postgres; this names which provision satisfies it."
|
|
},
|
|
{
|
|
"capability": "data.backup",
|
|
"provider": "rapp-postgres/platform-pg CNPG barmanObjectStore",
|
|
"relation": "may_use",
|
|
"note": "Cite resource-control/data/capability/platform-audit-storage.json. Do not restate that case. Recoverable window 30 days, provision D4 against a D5 requirement.",
|
|
"evidence_basis": "measured",
|
|
"observed_at": "2026-08-14"
|
|
},
|
|
{
|
|
"capability": "security.secrets",
|
|
"provider": "OpenBao / external-secrets on reef-railiance",
|
|
"relation": "may_use",
|
|
"note": "ClusterSecretStore openbao-audit-core and openbao-audit-core-database. Never class P."
|
|
}
|
|
],
|
|
"consumes": [
|
|
{
|
|
"class": "S",
|
|
"name": "retained events",
|
|
"quantity": {
|
|
"value": null,
|
|
"unit": "GB"
|
|
},
|
|
"period": "month",
|
|
"basis": "unknown",
|
|
"gap": "pg_total_relation_size of audit_core has not been recorded against this provision (owner: audit-core)"
|
|
},
|
|
{
|
|
"class": "H",
|
|
"name": "receiver operation",
|
|
"quantity": {
|
|
"value": null,
|
|
"unit": "hour"
|
|
},
|
|
"period": "month",
|
|
"supply": "internal",
|
|
"basis": "unknown",
|
|
"gap": "operator hours are not recorded (owner: audit-core; start a time record later)"
|
|
},
|
|
{
|
|
"class": "I",
|
|
"name": "intelligence",
|
|
"quantity": {
|
|
"value": null,
|
|
"unit": "token"
|
|
},
|
|
"period": "month",
|
|
"basis": "unknown",
|
|
"gap": "audit-core does not meter token consumption against this provision (owner: audit-core)"
|
|
}
|
|
],
|
|
"evidence": [
|
|
{
|
|
"hook": "audit_records",
|
|
"basis": "measured",
|
|
"value": "in-pod remote failure matrix 12 pass / 0 fail / 3 skip; live accept 202 before and after lease rotation",
|
|
"observed_at": "2026-08-13",
|
|
"ref": "evidence/failure-matrix-20260813T103908Z.json"
|
|
},
|
|
{
|
|
"hook": "integrity_verification",
|
|
"basis": "measured",
|
|
"value": "hash chain on accept; verify fails after a superuser payload_hash rewrite; chain-head attestation stored outside platform-pg",
|
|
"observed_at": "2026-08-16",
|
|
"ref": "tests/test_integrity.py#test_rewritten_payload_fails_verify;docs/integrity.md;docs/evidence/chain-head-20260816.json"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"open_items": [
|
|
"data.archive is required by INTENT and unprovided. A founder decision is needed before resource-control procures a WORM/object-lock destination distinct from the 30-day Barman bucket.",
|
|
"integrity_verification is measured. A database owner who rewrites the suffix and the external attestation together can still lie; that is the stated proof bound.",
|
|
"Class S/H/I consumption is unknown on this provision.",
|
|
"Do not emit booked cost or a second usage stream for platform:audit-storage."
|
|
]
|
|
}
|