Implement authenticated alert receipt acknowledgments and audit delivery
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
This commit is contained in:
parent
67283b66c2
commit
e7282e493d
25 changed files with 1881 additions and 0 deletions
12
integration/fixtures.json
Normal file
12
integration/fixtures.json
Normal file
|
|
@ -0,0 +1,12 @@
|
|||
[
|
||||
{
|
||||
"id": "unknown-request-denied",
|
||||
"request": {
|
||||
"id": "unknown",
|
||||
"subject": {"id": "unknown", "type": "human"},
|
||||
"action": "acknowledge",
|
||||
"resource": {"id": "alert:unknown", "type": "telemetry-alert", "system": "railiance-telemetry"}
|
||||
},
|
||||
"expect": {"effect": "deny"}
|
||||
}
|
||||
]
|
||||
20
integration/keycape-client.json
Normal file
20
integration/keycape-client.json
Normal file
|
|
@ -0,0 +1,20 @@
|
|||
{
|
||||
"clientId": "railiance-telemetry-admin",
|
||||
"displayName": "Railiance Alert Acknowledgment",
|
||||
"audience": "railiance-telemetry",
|
||||
"redirectUris": [
|
||||
"https://telemetry.coulomb.social/ack/auth/callback"
|
||||
],
|
||||
"allowedScopes": [
|
||||
"openid",
|
||||
"profile",
|
||||
"email",
|
||||
"telemetry:read",
|
||||
"telemetry:acknowledge"
|
||||
],
|
||||
"grantTypes": [
|
||||
"authorization_code"
|
||||
],
|
||||
"clientType": "public",
|
||||
"mfaRequired": true
|
||||
}
|
||||
42
integration/railiance-admin-directory.py
Normal file
42
integration/railiance-admin-directory.py
Normal file
|
|
@ -0,0 +1,42 @@
|
|||
"""Run inside the existing identity-provisioner pod; never print credentials.
|
||||
|
||||
Default is read-only. --apply adds only the approved user's named group.
|
||||
"""
|
||||
import json
|
||||
import os
|
||||
import sys
|
||||
from provisioner import LLDAPProvisioner
|
||||
|
||||
|
||||
def main():
|
||||
apply = sys.argv[1:] == ['--apply']
|
||||
if sys.argv[1:] not in ([], ['--apply']):
|
||||
raise ValueError()
|
||||
if os.environ['LLDAP_URL'] != 'http://lldap.sso.svc.cluster.local:17170':
|
||||
raise ValueError()
|
||||
client = LLDAPProvisioner(base_url=os.environ['LLDAP_URL'], admin_password=os.environ['LLDAP_ADMIN_PASSWORD'])
|
||||
token = client._login()
|
||||
user = client._user(token, 'tegwick')
|
||||
if not user or user['id'] != 'tegwick' or user['email'].lower() != 'bernd.worsch@gmail.com':
|
||||
raise ValueError()
|
||||
before = {g['displayName'] for g in user['groups']}
|
||||
if apply and 'railiance-admins' not in before:
|
||||
groups = client._gql(token, 'query { groups { id displayName } }', {})['groups']
|
||||
group = client._ensure_group(token, groups, 'railiance-admins')
|
||||
client._add_group(token, 'tegwick', group)
|
||||
after = {g['displayName'] for g in client._user(token, 'tegwick')['groups']}
|
||||
if not before <= after or after - before - {'railiance-admins'}:
|
||||
raise ValueError()
|
||||
if apply and 'railiance-admins' not in after:
|
||||
raise ValueError()
|
||||
print(json.dumps({'mode': 'apply' if apply else 'inspect', 'directory_user': 'tegwick',
|
||||
'email_matches_requested_recipient': True, 'group': 'railiance-admins',
|
||||
'member': 'railiance-admins' in after, 'other_memberships_preserved': True,
|
||||
'signed_role_claim_verified': False}))
|
||||
|
||||
|
||||
try:
|
||||
main()
|
||||
except Exception:
|
||||
print('{"status":"directory-operation-refused"}')
|
||||
sys.exit(1)
|
||||
11
integration/registry.json
Normal file
11
integration/registry.json
Normal file
|
|
@ -0,0 +1,11 @@
|
|||
{
|
||||
"subjects": [{
|
||||
"id": "uid=tegwick,ou=people,dc=netkingdom,dc=local",
|
||||
"type": "Human",
|
||||
"tenant": "tenant:platform",
|
||||
"display_name": "Bernd Worsch",
|
||||
"organization_relation": "ServiceProvider",
|
||||
"roles": ["railiance-admin"]
|
||||
}],
|
||||
"resources": []
|
||||
}
|
||||
71
integration/telemetry-policy.md
Normal file
71
integration/telemetry-policy.md
Normal file
|
|
@ -0,0 +1,71 @@
|
|||
---
|
||||
id: railiance-telemetry.alert-acknowledgment
|
||||
name: Railiance admin alert receipt acknowledgment
|
||||
namespace: railiance-telemetry:telemetry-alert
|
||||
version: v1
|
||||
status: ready
|
||||
package: flexauth.railiance_telemetry.alert_acknowledgment
|
||||
allow_ttl: 30s
|
||||
actions: [read, acknowledge]
|
||||
owner: flex-auth
|
||||
fixtures: [fixtures.json]
|
||||
caring:
|
||||
profile: caring-0.4.0-rc2
|
||||
enforce: false
|
||||
activation:
|
||||
mode: local
|
||||
---
|
||||
|
||||
# Requested telemetry admin mandate
|
||||
|
||||
Bernd Worsch authorized the named Railiance admin role and receipt actions on
|
||||
September 28 under RTEL-WP-0002-T04. Native service caller admission and directory
|
||||
membership remain required. This policy permits no alert silencing, resolution,
|
||||
configuration change or unrelated estate operation. The caller must validate
|
||||
the signed KeyCape session and supply its unchanged identity/assurance facts.
|
||||
|
||||
```rego
|
||||
import rego.v1
|
||||
|
||||
decision := {"effect": "allow", "reason": "railiance_admin_alert_receipt"} if {
|
||||
input.tenant == "tenant:platform"
|
||||
input.subject.type == "human"
|
||||
input.subject.tenant == "tenant:platform"
|
||||
is_string(input.subject.id)
|
||||
input.subject.id != ""
|
||||
input.subject.id == "uid=tegwick,ou=people,dc=netkingdom,dc=local"
|
||||
"railiance-admin" in input.subject.attributes.roles
|
||||
authentication := input.context.authentication
|
||||
authentication.issuer == "https://kc.coulomb.social"
|
||||
authentication.principal_type_source == "authentication-derived"
|
||||
authentication.tenant_source == "directory-asserted"
|
||||
"railiance-admin" in authentication.roles
|
||||
"railiance-admins" in authentication.groups
|
||||
assurance := authentication.assurance
|
||||
assurance.level == "aal2"
|
||||
assurance.mfa == true
|
||||
assurance.source == "key-cape"
|
||||
assurance.methods == ["pwd", "otp"]
|
||||
is_number(assurance.at)
|
||||
age := time.now_ns() / 1000000000 - assurance.at
|
||||
age >= -30
|
||||
age <= 900
|
||||
input.resource.system == "railiance-telemetry"
|
||||
input.resource.type == "telemetry-alert"
|
||||
input.resource.tenant == "tenant:platform"
|
||||
regex.match("^alert:[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$", input.resource.id)
|
||||
input.action in {"read", "acknowledge"}
|
||||
} else := {"effect": "deny", "reason": "telemetry_identity_or_scope_refused"} if {
|
||||
true
|
||||
}
|
||||
```
|
||||
|
||||
```rego test
|
||||
package flexauth.railiance_telemetry.alert_acknowledgment_test
|
||||
import rego.v1
|
||||
import data.flexauth.railiance_telemetry.alert_acknowledgment
|
||||
|
||||
test_unknown_request_denied if {
|
||||
alert_acknowledgment.decision.effect == "deny" with input as {}
|
||||
}
|
||||
```
|
||||
Loading…
Add table
Add a link
Reference in a new issue