| id |
name |
namespace |
version |
status |
package |
allow_ttl |
actions |
owner |
fixtures |
caring |
activation |
| railiance-telemetry.alert-acknowledgment |
Railiance admin alert receipt acknowledgment |
railiance-telemetry:telemetry-alert |
v1 |
ready |
flexauth.railiance_telemetry.alert_acknowledgment |
30s |
|
flex-auth |
|
| profile |
enforce |
| caring-0.4.0-rc2 |
false |
|
|
Requested telemetry admin mandate
Bernd Worsch authorized the named Railiance admin role and receipt actions on
September 28 under RTEL-WP-0002-T04. Native service caller admission and directory
membership remain required. This policy permits no alert silencing, resolution,
configuration change or unrelated estate operation. The caller must validate
the signed KeyCape session and supply its unchanged identity/assurance facts.
import rego.v1
decision := {"effect": "allow", "reason": "railiance_admin_alert_receipt"} if {
input.tenant == "tenant:platform"
input.subject.type == "human"
input.subject.tenant == "tenant:platform"
is_string(input.subject.id)
input.subject.id != ""
input.subject.id == "uid=tegwick,ou=people,dc=netkingdom,dc=local"
"railiance-admin" in input.subject.attributes.roles
authentication := input.context.authentication
authentication.issuer == "https://kc.coulomb.social"
authentication.principal_type_source == "authentication-derived"
authentication.tenant_source == "directory-asserted"
"railiance-admin" in authentication.roles
"railiance-admins" in authentication.groups
assurance := authentication.assurance
assurance.level == "aal2"
assurance.mfa == true
assurance.source == "key-cape"
assurance.methods == ["pwd", "otp"]
is_number(assurance.at)
age := time.now_ns() / 1000000000 - assurance.at
age >= -30
age <= 900
input.resource.system == "railiance-telemetry"
input.resource.type == "telemetry-alert"
input.resource.tenant == "tenant:platform"
regex.match("^alert:[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$", input.resource.id)
input.action in {"read", "acknowledge"}
} else := {"effect": "deny", "reason": "telemetry_identity_or_scope_refused"} if {
true
}
package flexauth.railiance_telemetry.alert_acknowledgment_test
import rego.v1
import data.flexauth.railiance_telemetry.alert_acknowledgment
test_unknown_request_denied if {
alert_acknowledgment.decision.effect == "deny" with input as {}
}