feat: add fail-closed Hub access profile foundation
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
parent
df39fd5f43
commit
3e386147fd
35 changed files with 2009 additions and 195 deletions
|
|
@ -40,10 +40,11 @@ exposure waits for access-control evidence and a separate approved rollout.
|
|||
[Architecture blueprint](../docs/netkingdom-access-blueprint.md) defines the
|
||||
contract and reviewed baseline. This is the single new integration workplan;
|
||||
existing retirement and rollout plans retain their tasks. Core Hub receives no
|
||||
new product feature work. This planning session does not implement or activate
|
||||
grants, enroll factors, deploy policies, expose services or retire State Hub.
|
||||
new product feature work. The 2026-09-28 implementation session is authorized
|
||||
for source implementation and verification. Live grant/factor/policy delivery,
|
||||
public exposure and retirement retain their concrete owner acceptance gates.
|
||||
|
||||
Inventory work is active. Cross-owner policy, root identity binding and live
|
||||
Inventory and local enforcement implementation are active. Cross-owner policy, root identity binding and live
|
||||
acceptance are not yet reviewed. The user has selected the root-first scope;
|
||||
there is no need to reopen that product decision. Dependencies below are
|
||||
per-task sequencing, not a blanket wait for every related workplan to finish.
|
||||
|
|
@ -84,12 +85,12 @@ platform-root login or enforcement test is claimed by inventory validation.
|
|||
|
||||
```task
|
||||
id: HUB-WP-0012-T02
|
||||
status: todo
|
||||
status: progress
|
||||
priority: high
|
||||
state_hub_task_id: "9a955fbf-f289-51b7-9682-bbe471694595"
|
||||
```
|
||||
|
||||
Depends on T01. Owners: NetKingdom/KeyCape, user-engine and tenant-engine;
|
||||
Live admission depends on T01; independently testable source may proceed. Owners: NetKingdom/KeyCape, user-engine and tenant-engine;
|
||||
hub-core owns consumption. Resolve the existing root account to `(iss, sub)`
|
||||
without recording credentials. Establish its explicit platform entitlement,
|
||||
map existing platform-operator vocabulary, register Hub clients/audiences and
|
||||
|
|
@ -109,7 +110,7 @@ step-up implementation is actually required.
|
|||
|
||||
```task
|
||||
id: HUB-WP-0012-T03
|
||||
status: todo
|
||||
status: progress
|
||||
priority: high
|
||||
state_hub_task_id: "feea8f20-aad4-583b-958a-a8efeb9c133c"
|
||||
```
|
||||
|
|
@ -133,12 +134,12 @@ substituted for evidence of production custody and delivery.
|
|||
|
||||
```task
|
||||
id: HUB-WP-0012-T04
|
||||
status: todo
|
||||
status: progress
|
||||
priority: high
|
||||
state_hub_task_id: "15bc3cae-4575-56c9-afd2-e1e348109ca9"
|
||||
```
|
||||
|
||||
Depends on T02/T03. Add the reusable verified actor/tenant context and local
|
||||
Live admission depends on T02/T03; the default-deny source seam may proceed. Add the reusable verified actor/tenant context and local
|
||||
enforcement seam to all native ports, projections, compatibility routes/aliases,
|
||||
catalogs/docs, browser, MCP and embedded router paths. Minimal liveness and
|
||||
login mechanics are the only public exceptions. Bind messaging/event producer
|
||||
|
|
@ -236,6 +237,41 @@ remains explicit and auditable. Do not create a second workplan merely to defer
|
|||
this task; this plan stays open after M1 until Phase 2 is completed or explicitly
|
||||
re-scoped with a durable owner.
|
||||
|
||||
## Implementation review — 2026-09-28
|
||||
|
||||
The [candidate security profile](../docs/access-profile-v1.md) records the concrete
|
||||
contract, configuration, source evidence and owner integration gaps. Source changes
|
||||
are executable preparation; dependencies above gate live admission, not isolated
|
||||
implementation against explicit test doubles. No root subject or entitlement was
|
||||
invented and no live service, grant or public listener was changed.
|
||||
|
||||
- T01: retained all 161 source surfaces/48 platform rows/250 objects; added a
|
||||
packaged runtime action catalog and drift/anonymous-denial tests. This does not
|
||||
complete per-service routes or substitute for the named owners' review.
|
||||
- T02: implemented IAM v0.3 access-token verification with discovery, signature,
|
||||
audience/type/lifetime/assurance validation and rotating keys. Live root binding,
|
||||
PKCE sessions/MFA/logout and authoritative account/tenant adapters remain open.
|
||||
- T03: implemented authenticated workload PDP calls, trusted rotating public keys,
|
||||
signed envelope, submitted request digest, caller/structured binding/lifetime
|
||||
checks and fail-closed obligations. Real Go fixtures prove interoperability.
|
||||
Hub policy, fact provenance approval, key delivery and durable audit remain open.
|
||||
- T04: production/enforce defaults protect runtime routes and refuse missing
|
||||
dependencies. Shared-key fallback is removed in that mode. Added verified event
|
||||
attribution, sender binding, per-invocation MCP credentials and an embedded-host
|
||||
seam. Normal production CLI requests remain closed until an admitted composition
|
||||
factory supplies real owners. Do not promote this candidate as an ordinary upgrade.
|
||||
- T05–T08 remain open: no actual extension, full platform/Railiance, public or
|
||||
multi-tenant acceptance receipt exists. Source-only tests cannot close them.
|
||||
|
||||
Review corrections: flex-auth's consumer join is `submitted_request_digest`;
|
||||
its Go serializer preserves struct declaration order (sorting every JSON key is
|
||||
incorrect). Root decisions need live tenant/account facts on **every** access,
|
||||
including reads, rather than a five-minute cached root grant. Unsupported decision
|
||||
obligations refuse access. Existing test fixtures for legacy behavior now identify
|
||||
themselves as `test`, since production no longer permits anonymous durable ports.
|
||||
|
||||
Validation results are recorded in [implementation evidence](../docs/evidence/hub-wp-0012-source-20260928.md).
|
||||
|
||||
## Acceptance checkpoints
|
||||
|
||||
- [x] Architecture/source/runtime review captured; new implementation owner is hub-core
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue