Record Core authorization boundary and pending GitOps tool projection
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
parent
743def17be
commit
ff34d596f9
2 changed files with 22 additions and 3 deletions
|
|
@ -12,9 +12,14 @@ identities. Public source reads need no repository credential. A general reposit
|
||||||
write PAT cannot enforce image-only changes by itself: the executor must validate
|
write PAT cannot enforce image-only changes by itself: the executor must validate
|
||||||
the exact before/after commits and authenticated receipts before writing, while
|
the exact before/after commits and authenticated receipts before writing, while
|
||||||
protected branches and required checks prevent bypass. Restrict its repository
|
protected branches and required checks prevent bypass. Restrict its repository
|
||||||
membership to the release repository and its ArgoCD role to get/sync the single
|
membership to the release repository and reconciliation to the single
|
||||||
`activity-core/activity-core` application. No root sync, application spec updates,
|
`activity-core/activity-core` application. This installation is ArgoCD Core:
|
||||||
project updates, exec, prune, overrides, secrets or other applications.
|
there is no ArgoCD API-server role/token lane to reuse. Kubernetes RBAC cannot
|
||||||
|
restrict Application patch access to only the operation fields. Use a narrowly
|
||||||
|
implemented sync broker with admission enforcement before granting such patch
|
||||||
|
access; an Application-scoped Kubernetes Role alone is insufficient. No root-wide
|
||||||
|
sync, arbitrary application spec updates, project updates, exec, prune, overrides,
|
||||||
|
secrets or other applications.
|
||||||
|
|
||||||
The present parent Application pins the child's source revision in the platform
|
The present parent Application pins the child's source revision in the platform
|
||||||
repository. Therefore an app-only ArgoCD sync grant alone cannot perform durable
|
repository. Therefore an app-only ArgoCD sync grant alone cannot perform durable
|
||||||
|
|
|
||||||
|
|
@ -100,3 +100,17 @@ Credential routing inspection found no ready scoped unattended ArgoCD/Forgejo
|
||||||
release lane. ACTIVITY-WP-0041-T03 remains the authority/admission owner; no broad
|
release lane. ACTIVITY-WP-0041-T03 remains the authority/admission owner; no broad
|
||||||
operator token was copied or delegated. Its concrete executor contract is in
|
operator token was copied or delegated. Its concrete executor contract is in
|
||||||
`docs/activity-core-release-admission.md`.
|
`docs/activity-core-release-admission.md`.
|
||||||
|
|
||||||
|
The production worker currently mounts an older platform checkout's script
|
||||||
|
(SHA256 0baacfd07b74ddd4317f79aa0de818c25186e15303a67c08d29edc73ad74a870).
|
||||||
|
Deploy the new script as a pinned GitOps projection, verify worker readback and a
|
||||||
|
non-destructive planner fixture, then close T03. Do not silently overwrite the
|
||||||
|
host checkout: it is outside the newly adopted nine-resource projection. Current
|
||||||
|
baseline aliases remain protected; no prune was executed during verification.
|
||||||
|
|
||||||
|
ArgoCD Core has no API-server token/role lane. T02 admission must prove a broker
|
||||||
|
that restricts both the platform child revision update and Kubernetes Application
|
||||||
|
sync operation; resource-name RBAC alone cannot restrict patch fields. This is
|
||||||
|
concrete implementation work retained here and in ACTIVITY-WP-0041-T03, not a
|
||||||
|
reason to ask the founder to approve each release. Tests in the owner checkout:
|
||||||
|
20 passed across retention and additive inventory suites.
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue