Complete flex-auth PEP and document railiance packaging path

Local + HTTP POST /v1/check PEP with fail-closed transport errors;
shell:view enforced on /app/. Vocabulary docs for T07. Helm chart lives
in railiance-apps; Dockerfile already present for T08.
This commit is contained in:
tegwick 2026-08-09 02:00:12 +02:00
parent 0e973a91aa
commit 44439f8d8d
8 changed files with 273 additions and 20 deletions

View file

@ -0,0 +1,36 @@
# flex-auth vocabulary — coulomb.social
Protected system id: `coulomb-social` (`FLEX_AUTH_PROTECTED_SYSTEM_ID`).
## Actions (v0 shell)
| Action | Resource type | Resource id | Effect (local mode) |
|--------|---------------|-------------|---------------------|
| `shell:view` | `shell` | e.g. `app_home` | allow if authenticated |
| `member:self:read` | `member` | OIDC `sub` | allow if subject == resource id |
| `member:admin` | `member` | any | deny (until policy package) |
## Runtime modes
| `FLEX_AUTH_BASE_URL` | Behavior |
|----------------------|----------|
| empty | local vocabulary above |
| set | `POST {base}/v1/check` (schema: flex-auth `check_request.schema.json`); fail-closed on error |
## Cluster status (2026-08-09)
Only `flex-auth-tenant-engine` is running in-cluster; a general flex-auth
check Service for app PEPs is **not** yet the S5 default for coulomb.social.
Until that lands, leave `FLEX_AUTH_BASE_URL` empty (local mode) or point at a
dev PDP.
## Future policy package
When registering with flex-auth / Topaz:
- system: `coulomb-social`
- package: allow `shell:view` for principals with a valid platform session
- package: allow `member:self:read` when subject id matches resource id
- deny-by-default otherwise
See `flex-auth/schemas/protected_system_manifest.schema.json`.