feat: add fail-closed Hub access profile foundation
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 3s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 11:44:50 +02:00
parent df39fd5f43
commit 3e386147fd
35 changed files with 2009 additions and 195 deletions

View file

@ -144,3 +144,11 @@ it against an isolated runtime with `hub-core conformance --base-url <url>`.
`docs/core-hub-absorption-plan.md` defines the capability-sized `/api/v2`
route and data move order, single-writer dual-run controls, evidence gates,
rollback, and final cutover criteria shared with `CORE-WP-0010`.
## Access enforcement candidate
See [access profile v1](access-profile-v1.md). Production now defaults to the shared
access boundary; the default factory fails closed until real identity/facts/policy/
audit adapters are composed. Only exact GET `/healthz` is public. Do not deploy this
source candidate over the current release before the HUB-WP-0012 admission gates.
Development/test retains the existing unauthenticated/native and legacy-key lanes.