Skip to content

[Spec 030] Freeze rotation contracts and audit boundary #77

Description

@XnLemon

Parent

#75 (#75)

Depends on

#76 (#76)

Goal

Freeze the language-neutral key identity, trust-set, rotation-operation, readiness, drain, and audit facts after policy approval.

Scope

  • Decide whether the active Router Credential v1 remains compatible or requires an additive companion contract.
  • Define immutable key-ID binding and deterministic key selection semantics.
  • Define authenticated readiness/convergence evidence without exposing key bodies, credentials, signatures, or token IDs.
  • Define operational audit facts outside the Invocation Ledger and outside Agent Card/Registry data.
  • Map exact errors for unknown, rebound, retired, stale, unavailable, and partially applied key state.

Acceptance criteria

  • Contract artifacts and ADRs are versioned and map every field to an owning boundary.
  • Existing v1 credential, Agent verification, Gateway/Router, and Ledger contracts remain explicit; historical artifacts are not runtime fallback paths.
  • Contract tests reject unknown members, key-ID rebinding, secret-shaped fields, and ambiguous multi-key selection.
  • Spec, plan, and tasks are updated before implementation begins.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:contractsVersioned schemas and API contractsenhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions