feat: add fail-closed Hub access profile foundation
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 3s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 11:44:50 +02:00
parent df39fd5f43
commit 3e386147fd
35 changed files with 2009 additions and 195 deletions

View file

@ -40,10 +40,11 @@ exposure waits for access-control evidence and a separate approved rollout.
[Architecture blueprint](../docs/netkingdom-access-blueprint.md) defines the
contract and reviewed baseline. This is the single new integration workplan;
existing retirement and rollout plans retain their tasks. Core Hub receives no
new product feature work. This planning session does not implement or activate
grants, enroll factors, deploy policies, expose services or retire State Hub.
new product feature work. The 2026-09-28 implementation session is authorized
for source implementation and verification. Live grant/factor/policy delivery,
public exposure and retirement retain their concrete owner acceptance gates.
Inventory work is active. Cross-owner policy, root identity binding and live
Inventory and local enforcement implementation are active. Cross-owner policy, root identity binding and live
acceptance are not yet reviewed. The user has selected the root-first scope;
there is no need to reopen that product decision. Dependencies below are
per-task sequencing, not a blanket wait for every related workplan to finish.
@ -84,12 +85,12 @@ platform-root login or enforcement test is claimed by inventory validation.
```task
id: HUB-WP-0012-T02
status: todo
status: progress
priority: high
state_hub_task_id: "9a955fbf-f289-51b7-9682-bbe471694595"
```
Depends on T01. Owners: NetKingdom/KeyCape, user-engine and tenant-engine;
Live admission depends on T01; independently testable source may proceed. Owners: NetKingdom/KeyCape, user-engine and tenant-engine;
hub-core owns consumption. Resolve the existing root account to `(iss, sub)`
without recording credentials. Establish its explicit platform entitlement,
map existing platform-operator vocabulary, register Hub clients/audiences and
@ -109,7 +110,7 @@ step-up implementation is actually required.
```task
id: HUB-WP-0012-T03
status: todo
status: progress
priority: high
state_hub_task_id: "feea8f20-aad4-583b-958a-a8efeb9c133c"
```
@ -133,12 +134,12 @@ substituted for evidence of production custody and delivery.
```task
id: HUB-WP-0012-T04
status: todo
status: progress
priority: high
state_hub_task_id: "15bc3cae-4575-56c9-afd2-e1e348109ca9"
```
Depends on T02/T03. Add the reusable verified actor/tenant context and local
Live admission depends on T02/T03; the default-deny source seam may proceed. Add the reusable verified actor/tenant context and local
enforcement seam to all native ports, projections, compatibility routes/aliases,
catalogs/docs, browser, MCP and embedded router paths. Minimal liveness and
login mechanics are the only public exceptions. Bind messaging/event producer
@ -236,6 +237,41 @@ remains explicit and auditable. Do not create a second workplan merely to defer
this task; this plan stays open after M1 until Phase 2 is completed or explicitly
re-scoped with a durable owner.
## Implementation review — 2026-09-28
The [candidate security profile](../docs/access-profile-v1.md) records the concrete
contract, configuration, source evidence and owner integration gaps. Source changes
are executable preparation; dependencies above gate live admission, not isolated
implementation against explicit test doubles. No root subject or entitlement was
invented and no live service, grant or public listener was changed.
- T01: retained all 161 source surfaces/48 platform rows/250 objects; added a
packaged runtime action catalog and drift/anonymous-denial tests. This does not
complete per-service routes or substitute for the named owners' review.
- T02: implemented IAM v0.3 access-token verification with discovery, signature,
audience/type/lifetime/assurance validation and rotating keys. Live root binding,
PKCE sessions/MFA/logout and authoritative account/tenant adapters remain open.
- T03: implemented authenticated workload PDP calls, trusted rotating public keys,
signed envelope, submitted request digest, caller/structured binding/lifetime
checks and fail-closed obligations. Real Go fixtures prove interoperability.
Hub policy, fact provenance approval, key delivery and durable audit remain open.
- T04: production/enforce defaults protect runtime routes and refuse missing
dependencies. Shared-key fallback is removed in that mode. Added verified event
attribution, sender binding, per-invocation MCP credentials and an embedded-host
seam. Normal production CLI requests remain closed until an admitted composition
factory supplies real owners. Do not promote this candidate as an ordinary upgrade.
- T05–T08 remain open: no actual extension, full platform/Railiance, public or
multi-tenant acceptance receipt exists. Source-only tests cannot close them.
Review corrections: flex-auth's consumer join is `submitted_request_digest`;
its Go serializer preserves struct declaration order (sorting every JSON key is
incorrect). Root decisions need live tenant/account facts on **every** access,
including reads, rather than a five-minute cached root grant. Unsupported decision
obligations refuse access. Existing test fixtures for legacy behavior now identify
themselves as `test`, since production no longer permits anonymous durable ports.
Validation results are recorded in [implementation evidence](../docs/evidence/hub-wp-0012-source-20260928.md).
## Acceptance checkpoints
- [x] Architecture/source/runtime review captured; new implementation owner is hub-core