Record accepted platform tenant and notify dependency owners
Some checks failed
ci / validate (push) Failing after 3m33s
Some checks failed
ci / validate (push) Failing after 3m33s
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
This commit is contained in:
parent
59b042e637
commit
a20b9f3861
5 changed files with 87 additions and 11 deletions
26
docs/platform-tenant-decision.md
Normal file
26
docs/platform-tenant-decision.md
Normal file
|
|
@ -0,0 +1,26 @@
|
|||
# Platform management tenant decision
|
||||
|
||||
Date: 2026-09-06
|
||||
Status: accepted by Bernd Worsch
|
||||
Tracking: GLAS-WP-0015-T03
|
||||
|
||||
`tenant:platform` identifies the platform management, administration and services
|
||||
tenant: the landlord zone supporting the other tenants. This describes its
|
||||
operational role; access across tenant boundaries requires explicit policy grants.
|
||||
|
||||
For the first Glas production dependency chain, use the exact string
|
||||
`tenant:platform` in the approval store configuration, the JWT tenant claims for
|
||||
`secrets-engine-approval` and `approval-engine-operator`, and the secrets-engine
|
||||
lifecycle CheckRequest tenant. Retain exact tenant comparison and v2 wrong-tenant
|
||||
denial. Neither bare `platform` nor `tenant:coulomb` is an alias.
|
||||
|
||||
This decision authorizes alignment of those two proposed service registrations
|
||||
and the undeployed approval service. It does not change unrelated clients, human
|
||||
directory defaults, scopes or other tenant policies. Custody, runtime admission
|
||||
and actual end-to-end verification remain separate outstanding gates.
|
||||
|
||||
Owner implementation and evidence are requested on the existing KeyCape,
|
||||
approval-engine, secrets-engine, flex-auth and railiance-platform handoff threads.
|
||||
See platform-tenant-decision-receipts.json for the State Hub decision and delivery
|
||||
receipts. The accepted choice resolves the decision blocker; implementation is
|
||||
not yet verified.
|
||||
Loading…
Add table
Add a link
Reference in a new issue