Some checks failed
ci / validate (push) Failing after 3m33s
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
26 lines
1.4 KiB
Markdown
26 lines
1.4 KiB
Markdown
# Platform management tenant decision
|
|
|
|
Date: 2026-09-06
|
|
Status: accepted by Bernd Worsch
|
|
Tracking: GLAS-WP-0015-T03
|
|
|
|
`tenant:platform` identifies the platform management, administration and services
|
|
tenant: the landlord zone supporting the other tenants. This describes its
|
|
operational role; access across tenant boundaries requires explicit policy grants.
|
|
|
|
For the first Glas production dependency chain, use the exact string
|
|
`tenant:platform` in the approval store configuration, the JWT tenant claims for
|
|
`secrets-engine-approval` and `approval-engine-operator`, and the secrets-engine
|
|
lifecycle CheckRequest tenant. Retain exact tenant comparison and v2 wrong-tenant
|
|
denial. Neither bare `platform` nor `tenant:coulomb` is an alias.
|
|
|
|
This decision authorizes alignment of those two proposed service registrations
|
|
and the undeployed approval service. It does not change unrelated clients, human
|
|
directory defaults, scopes or other tenant policies. Custody, runtime admission
|
|
and actual end-to-end verification remain separate outstanding gates.
|
|
|
|
Owner implementation and evidence are requested on the existing KeyCape,
|
|
approval-engine, secrets-engine, flex-auth and railiance-platform handoff threads.
|
|
See platform-tenant-decision-receipts.json for the State Hub decision and delivery
|
|
receipts. The accepted choice resolves the decision blocker; implementation is
|
|
not yet verified.
|