whitehat-security/docs/noisy-neighbour-runbook.md
tegwick 43327183d8 Finish WHITEHAT-WP-0001 and own live residuals in WP-0006
Close T05 and T06 on the same applicable-target rule as T03: E3 cadence
and in-process calibration, platform-pg not_applicable, P1/P2 evaluator
proven against known-good and known-bad samples. Persist offline capacity
calibration. Live E3, P1/P2, flex-auth E2, and a later audit-core run
move to WHITEHAT-WP-0006, which authorizes no packet.

Assistant: grok
Assistant-Session: 01a05e32-c776-72a3-86ec-c490e027aca9
2026-09-01 20:26:47 +02:00

1.5 KiB

Noisy-neighbour characterization

There is no standing authorization or default ceiling for this technique. A run requires a separate operator-approved target, namespace, time window, aggressor allowance, concurrency/resource ceilings, service classes, headroom threshold, and abort thresholds.

For each co-resident consumer the artifact records a quiet baseline and a loaded sample: latency, error rate, throughput and the declared service class. The aggressor may reach but never exceed its own allowance. The artifact also records whether the governor bound, peak versus ceiling, aggregate headroom, and each neighbour's measured degradation.

Zero degradation is not the expected assertion on shared infrastructure. Whether measured degradation is acceptable belongs to the responsible owner; whitehat records the observation. A governor that does not bind, an exceeded probe ceiling, missing neighbour samples, or an abort threshold produces a finding/abort rather than a stronger retry.

The evaluator is calibrated offline with:

PYTHONPATH=src python3 -m whitehat_security.cli capacity-fixture

That command generates no load and is not P1/P2 target evidence. Known-good binds and stays within ceiling; known-bad detects an unbound governor, an exceeded ceiling, and a missing neighbour sample. evidence/offline-capacity-calibration.json is the fixture artifact. A live run is owned by WHITEHAT-WP-0006 and still requires an operator-approved window and aggressor ceiling.