Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
71 lines
2.4 KiB
Markdown
71 lines
2.4 KiB
Markdown
---
|
|
id: railiance-telemetry.alert-acknowledgment
|
|
name: Railiance admin alert receipt acknowledgment
|
|
namespace: railiance-telemetry:telemetry-alert
|
|
version: v1
|
|
status: ready
|
|
package: flexauth.railiance_telemetry.alert_acknowledgment
|
|
allow_ttl: 30s
|
|
actions: [read, acknowledge]
|
|
owner: flex-auth
|
|
fixtures: [fixtures.json]
|
|
caring:
|
|
profile: caring-0.4.0-rc2
|
|
enforce: false
|
|
activation:
|
|
mode: local
|
|
---
|
|
|
|
# Requested telemetry admin mandate
|
|
|
|
Bernd Worsch authorized the named Railiance admin role and receipt actions on
|
|
September 28 under RTEL-WP-0002-T04. Native service caller admission and directory
|
|
membership remain required. This policy permits no alert silencing, resolution,
|
|
configuration change or unrelated estate operation. The caller must validate
|
|
the signed KeyCape session and supply its unchanged identity/assurance facts.
|
|
|
|
```rego
|
|
import rego.v1
|
|
|
|
decision := {"effect": "allow", "reason": "railiance_admin_alert_receipt"} if {
|
|
input.tenant == "tenant:platform"
|
|
input.subject.type == "human"
|
|
input.subject.tenant == "tenant:platform"
|
|
is_string(input.subject.id)
|
|
input.subject.id != ""
|
|
input.subject.id == "uid=tegwick,ou=people,dc=netkingdom,dc=local"
|
|
"railiance-admin" in input.subject.attributes.roles
|
|
authentication := input.context.authentication
|
|
authentication.issuer == "https://kc.coulomb.social"
|
|
authentication.principal_type_source == "authentication-derived"
|
|
authentication.tenant_source == "directory-asserted"
|
|
"railiance-admin" in authentication.roles
|
|
"railiance-admins" in authentication.groups
|
|
assurance := authentication.assurance
|
|
assurance.level == "aal2"
|
|
assurance.mfa == true
|
|
assurance.source == "key-cape"
|
|
assurance.methods == ["pwd", "otp"]
|
|
is_number(assurance.at)
|
|
age := time.now_ns() / 1000000000 - assurance.at
|
|
age >= -30
|
|
age <= 900
|
|
input.resource.system == "railiance-telemetry"
|
|
input.resource.type == "telemetry-alert"
|
|
input.resource.tenant == "tenant:platform"
|
|
regex.match("^alert:[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$", input.resource.id)
|
|
input.action in {"read", "acknowledge"}
|
|
} else := {"effect": "deny", "reason": "telemetry_identity_or_scope_refused"} if {
|
|
true
|
|
}
|
|
```
|
|
|
|
```rego test
|
|
package flexauth.railiance_telemetry.alert_acknowledgment_test
|
|
import rego.v1
|
|
import data.flexauth.railiance_telemetry.alert_acknowledgment
|
|
|
|
test_unknown_request_denied if {
|
|
alert_acknowledgment.decision.effect == "deny" with input as {}
|
|
}
|
|
```
|