feat: add fail-closed Hub access profile foundation
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 3s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 11:44:50 +02:00
parent df39fd5f43
commit 3e386147fd
35 changed files with 2009 additions and 195 deletions

View file

@ -44,8 +44,9 @@ PYTHONDONTWRITEBYTECODE=1 .venv/bin/python tools/build_access_inventory.py \
Omit `--check` to refresh source rows after intentional changes, then review the
diff. Cluster metadata is a dated reviewed input, not silently refreshed by this
command. The checker detects source drift, missing profile/test references and
missing/duplicate cluster-object mappings. It does not test authorization. Actual
allow/deny cases are all marked `not-run`; implementation tasks must supply the
missing/duplicate cluster-object mappings. It does not test authorization. Live
allow/deny cases remain marked `not-run`; the [source candidate](access-profile-v1.md)
adds local enforcement tests. Implementation tasks must still supply the
client fixtures, isolated mutations, independent readbacks and live receipts.
## Findings that affect implementation