Compare commits
2 commits
3f62e59a8d
...
6d82ef7f14
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
6d82ef7f14 | ||
|
|
ff87f32ef4 |
2 changed files with 29 additions and 8 deletions
|
|
@ -2,19 +2,17 @@
|
||||||
# Custodian Brief — flex-auth
|
# Custodian Brief — flex-auth
|
||||||
|
|
||||||
**Domain:** infotech
|
**Domain:** infotech
|
||||||
**Last synced:** 2026-08-17 20:04 UTC
|
**Last synced:** 2026-08-18 05:28 UTC
|
||||||
**State Hub:** http://127.0.0.1:8000 *(adjust if running on a remote machine)*
|
**State Hub:** http://127.0.0.1:8000 *(adjust if running on a remote machine)*
|
||||||
|
|
||||||
## Active Workstreams
|
## Active Workstreams
|
||||||
|
|
||||||
### Tenancy posture declaration and inbound caller authentication
|
### Tenancy posture declaration and inbound caller authentication
|
||||||
Progress: 1/5 done | workplan_id: `31846b19-c2a3-428e-950b-5985bc9146eb`
|
Progress: 3/5 done | workplan_id: `31846b19-c2a3-428e-950b-5985bc9146eb`
|
||||||
|
|
||||||
**Open tasks:**
|
**Open tasks:**
|
||||||
- ! Tasks `b2e87a81`
|
- ! Tasks `b2e87a81`
|
||||||
- ! Tasks `06432560`
|
- ! Tasks `06432560`
|
||||||
- · Tasks `64eb7652`
|
|
||||||
- · Tasks `9195ba20`
|
|
||||||
|
|
||||||
---
|
---
|
||||||
## MCP Orientation (when available)
|
## MCP Orientation (when available)
|
||||||
|
|
|
||||||
|
|
@ -14,7 +14,7 @@ related_workplans:
|
||||||
- FLEX-WP-0004
|
- FLEX-WP-0004
|
||||||
- FLEX-WP-0011
|
- FLEX-WP-0011
|
||||||
created: "2026-08-17"
|
created: "2026-08-17"
|
||||||
updated: "2026-08-17"
|
updated: "2026-08-18"
|
||||||
state_hub_workstream_id: "31846b19-c2a3-428e-950b-5985bc9146eb"
|
state_hub_workstream_id: "31846b19-c2a3-428e-950b-5985bc9146eb"
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|
@ -29,7 +29,9 @@ real defect the review surfaced.
|
||||||
|
|
||||||
## Why this workplan exists
|
## Why this workplan exists
|
||||||
|
|
||||||
Three of the framework's five axes describe flex-auth cleanly. Assessing
|
The original five axes described flex-auth unevenly; draft-8's sixth
|
||||||
|
availability axis and canonical provider declaration now cover the remaining
|
||||||
|
shape. Assessing
|
||||||
against them turned up two things we did not know we were carrying:
|
against them turned up two things we did not know we were carrying:
|
||||||
|
|
||||||
1. **`/v1/check` authenticates no caller.** Any workload with network reach to
|
1. **`/v1/check` authenticates no caller.** Any workload with network reach to
|
||||||
|
|
@ -104,9 +106,19 @@ with the §13 evidence artifact: a test that an unbound request is refused.
|
||||||
|
|
||||||
Ship through the FLEX-WP-0011 staged-promotion path, not by direct apply.
|
Ship through the FLEX-WP-0011 staged-promotion path, not by direct apply.
|
||||||
|
|
||||||
|
2026-08-18 source outcome: ADR 0004 selects audience-scoped Kubernetes
|
||||||
|
ServiceAccount TokenReview with a separately projected reviewer identity and
|
||||||
|
exact `resource.system` → ServiceAccount bindings. Both check endpoints share
|
||||||
|
the choke point; missing/mismatched identity fails 401/403 and reviewer outage
|
||||||
|
fails 503. Unit and handler tests include the required unbound request. Desired
|
||||||
|
manifests select enforce mode and carry narrow TokenReview RBAC. The running
|
||||||
|
digest is unchanged, so `tenancy.current.A` honestly remains 0 while
|
||||||
|
`tenancy.implemented.A` is 2. Remaining: build/pin/promote through
|
||||||
|
FLEX-WP-0011, migrate both callers and capture the live negative probe.
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: FLEX-WP-0015-T03
|
id: FLEX-WP-0015-T03
|
||||||
status: todo
|
status: done
|
||||||
priority: medium
|
priority: medium
|
||||||
state_hub_task_id: "64eb7652-3b67-4bfb-879b-8588deeec8b5"
|
state_hub_task_id: "64eb7652-3b67-4bfb-879b-8588deeec8b5"
|
||||||
```
|
```
|
||||||
|
|
@ -125,6 +137,12 @@ say so in the review record rather than leaving it as latent capability.
|
||||||
|
|
||||||
Update `tenancy.yaml` `I` either way.
|
Update `tenancy.yaml` `I` either way.
|
||||||
|
|
||||||
|
Completed 2026-08-18 by deletion. Repository-wide search found no non-test
|
||||||
|
caller and no policy consuming `tenant_roles`; wiring it would add a
|
||||||
|
synchronous dependency without a decision that uses the result. The adapter
|
||||||
|
and its isolated tests were removed, and the review records that any future
|
||||||
|
live-role policy must introduce the dependency explicitly.
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: FLEX-WP-0015-T04
|
id: FLEX-WP-0015-T04
|
||||||
status: wait
|
status: wait
|
||||||
|
|
@ -147,7 +165,7 @@ this task and may be worth doing first.
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: FLEX-WP-0015-T05
|
id: FLEX-WP-0015-T05
|
||||||
status: todo
|
status: done
|
||||||
priority: medium
|
priority: medium
|
||||||
state_hub_task_id: "9195ba20-ab0f-4d75-b293-86978073beb1"
|
state_hub_task_id: "9195ba20-ab0f-4d75-b293-86978073beb1"
|
||||||
```
|
```
|
||||||
|
|
@ -165,3 +183,8 @@ prove: that the `/v1/check` handler has caller authentication iff
|
||||||
Designed for invisible failure per §12: posture regression returns
|
Designed for invisible failure per §12: posture regression returns
|
||||||
correct-looking responses, exactly like the two silent pin rollbacks the
|
correct-looking responses, exactly like the two silent pin rollbacks the
|
||||||
estate has already been bitten by.
|
estate has already been bitten by.
|
||||||
|
|
||||||
|
Completed 2026-08-18. `make verify-posture` checks the current/implemented
|
||||||
|
distinction, both authenticated handlers, enforce-mode desired manifests,
|
||||||
|
TokenReview RBAC, absence of a latent tenant-engine caller, and the stateless
|
||||||
|
deployment assumptions behind `R: n/a`.
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue