Skip to content

W7 — Security boundary and threat model #466

Description

@phall1

The App holds trunk write on someone else's repository. That is close to the most dangerous permission that exists, and Bar D means strangers grant it to us.

Scope

  • Threat model
  • Permission scope justification — the smallest set that still works
  • Secret handling
  • What a compromised control plane can and cannot do
  • What the constitution-above-configuration boundary guarantees under compromise

Exit criteria

  • A written threat model an external reviewer can attack
  • The smallest permission set that still works, with each permission justified
  • Documented blast radius of a control-plane compromise

Gates Bar D. See docs/END-STATE.md §4 W7, docs/DESIGN.md §9, docs/CONFIGURATION.md.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions