feat: add fail-closed Hub access profile foundation
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 3s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 11:44:50 +02:00
parent df39fd5f43
commit 3e386147fd
35 changed files with 2009 additions and 195 deletions

View file

@ -38,9 +38,21 @@ class RuntimeSettings:
legacy_health: bool = False
statehub_inbox_reads: bool = False
statehub_inbox_agent: str = "state-hub"
access_mode: str = "auto"
@property
def enforce_access(self) -> bool:
return self.access_mode == "enforce" or (
self.access_mode == "auto" and self.environment not in {"development", "test"}
)
def __post_init__(self) -> None:
if self.statehub_inbox_reads and (self.backend != "postgresql" or not self.api_token):
if self.access_mode not in {"auto", "enforce", "development"}:
raise ValueError("unsupported access mode")
if self.access_mode == "development" and self.environment not in {"development", "test"}:
raise ValueError("development access is forbidden outside development/test")
if self.statehub_inbox_reads and (self.backend != "postgresql" or
(not self.enforce_access and not self.api_token)):
raise ValueError("State Hub inbox reads require PostgreSQL and operator token")
if self.repo_manager_timeout_seconds <= 0:
raise ValueError("Repo Manager timeout must be positive")
@ -87,6 +99,7 @@ class RuntimeSettings:
legacy_health=_env_bool("HUB_CORE_LEGACY_HEALTH", False),
statehub_inbox_reads=_env_bool("HUB_CORE_STATEHUB_INBOX_READS", False),
statehub_inbox_agent=os.getenv("HUB_CORE_STATEHUB_INBOX_AGENT", "state-hub"),
access_mode=os.getenv("HUB_CORE_ACCESS_MODE", "auto"),
)
def readiness_checks(self, store_backend: str) -> dict[str, str]:
@ -99,7 +112,8 @@ class RuntimeSettings:
"operator",
}
authorization_ready = (
not protected_groups
self.enforce_access
or not protected_groups
or bool(self.api_token)
or store_backend == "postgresql"
)