Skip to content

Define control-plane and participant-access trust boundaries #1356

Description

@Brad-Edwards

Administrative credentials can read both participant projections and full snapshots. This is unsafe if those credentials are also used as participant-view credentials; the deployment boundary is currently unclear.

Acceptance criteria

  • Inventory public runtime entry points and credentials, including snapshot, projection, operation, history, error, and event access. Specify who may use each surface and where authorization is enforced.
  • Decide whether participant clients access RAE directly or through a backend boundary. Specify the required principal, audience, participant, and episode bindings for the selected exposure model.
  • Cover alternate retrieval and mutation paths, cached/readback results, and cross-participant access. Authentication principals do not require new SDL participant declarations or roles.
  • Publish the accepted trust-boundary decision, route/authority matrix, deployment requirements, and affected API-404/ADR-104 clauses. Keep organizational identity and policy responsibilities with the backend.

References: Diagnosis, Control-plane authorization, Ecosystem responsibilities.

Requirements

  • API-404 — Secure, Durable, And Idempotent Control-Plane Semantics

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:runtimeRuntime and control-plane codedocumentationImprovements or additions to documentationsecuritySecurity vulnerabilities and hardening issues

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions