Skip to content

docs(v0.6): admit fleet operations and Kafka security planning - #147

Merged
akhiabanchian merged 16 commits into
mainfrom
docs/v0.6-fleet-security-planning
Sep 24, 2026
Merged

akhiabanchian merged 16 commits into
mainfrom
docs/v0.6-fleet-security-planning

Conversation

@ammarheidari

Copy link
Copy Markdown
Contributor

Authority and purpose

Ammar explicitly accepted the detailed Gate 6 scope/safety boundaries in #145 on 2026-09-23 and authorized completing the planning package, with implementation only after governed planning admission. Scope gate #145 is completed; tracker #146 owns planning and subsequent delivery.

This is a docs-only planning PR, not v0.6 implementation or release promotion.

  • Inspected/current base: e5de0ec142d5dd06ef52f59718c60c3109d1070a (v0.5.1).
  • Initial exact planning head: d4d5ce625360b88251d5667a689729a5767e50d2.
  • Diff: 16 Markdown files: 14 new planning documents, ROADMAP reconciliation, and append-only Gate 6 approval-log entry.
  • No source, tests, migrations, workflows, dependency versions, package versions or release-manifest changes.

Package

Start at docs/implementation/v0.6-planning-package.md.

The package contains RFC-0006, product specification, ADR-0007, shared runtime/long-running progress architecture, exact authorization/risk matrix, security/threat-model delta, reassignment/decommission contracts, transfer/replication security, provider capability evidence matrix, API/OpenAPI/UI principles, test strategy, W41-W50 implementation plan and Gate 6 approval record.

Architecture and security decisions for review

  • Extend the v0.5 mutation kernel; keep one operation identity and versioned subordinate progress/checkpoints.
  • Separate renewable worker leases from persistent outstanding-effect conflict obligations; lease expiry never proves provider non-application.
  • Preserve v0.5 kinds 1-14, single-action/cluster normalization and existing hashes; add closed server-derived compound requirements only for new kinds.
  • Require current requester/eligible approver authorization before every new effect; do not reconstruct OIDC groups or use provider credentials as user permission.
  • SCRAM is always CRITICAL, with independent approval followed by requester re-submission of HMAC-bound ephemeral material through the common coordinator.
  • Cross-cluster movement requires source read AND export plus destination produce and explicit transfer actions; byte-preserving transfer is unavailable if it cannot honor applicable masking policy.
  • Reassignment/RF/cordon/decommission remain typed and capability-gated. No shell, host orchestration, controller-quorum mutation or invented broker read-only mode.
  • MirrorMaker integration enumerates hidden writes and control limits; it cannot bypass the same security boundary through existing Connect routes.
  • Numerical defaults/hard caps are proposed design budgets, not performance claims; provider references are not passing-test or pinned-client support claims.

Compatibility and migration impact

Planning proposes additive versioned progress records in the existing SQLite/PostgreSQL provider strategy, safe restore/reconciliation behavior and refusal of incompatible mixed-version mutation execution. No migration is applied by this PR. W41 must prove pinned-client API availability and shared persistence/authorization safety before dependent adapters.

Evidence and admission

The exact diff was compared against the current protected-main base: documentation only, 1 commit ahead, 0 behind. The commit includes the required DCO trailer. CI/review are pending at PR creation. No local test execution is claimed; runtime is unchanged and new v0.6 suites are requirements for later workstreams.

Merge only after current base/head reconciliation, successful applicable exact-head CI, substantive architecture/security review, fresh CODEOWNER approval from akhiabanchian, zero unresolved required threads and active ruleset compliance. Use expected-head guarded merge; after post-merge verification update #146 before activating W41.

Release/tag/OCI promotion/publication and v0.7+ remain separately owner-approval-bound. Published v0.5/v0.5.1 identities and .github/release/release.json remain untouched.

Signed-off-by: Ammar Heidari ammar@arad-itc.org

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-24T05:13:41.406221Z 9e5fa93 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copy link
Copy Markdown
Contributor Author

@codex review

Please review exact planning head d4d5ce625360b88251d5667a689729a5767e50d2 against accepted #145 and inspected v0.5.1 main. This is docs-only; no implementation is authorized until planning admission. Focus on: (1) durable outstanding-effect obligations versus expiring leases and v0.5 conflict paths; (2) closed compound authorization without weakening old kinds/hashes; (3) CRITICAL SCRAM independent approval then ephemeral material finalization; (4) transfer masking/exfiltration and acknowledgement/checkpoint ambiguity; (5) MM2 hidden side effects and existing Connect alternate-route guards; (6) version/client capability evidence and explicit unsupported behavior; (7) cross-document consistency, finite budgets and W41-W50 dependencies. Do not equate provider documentation with passing pinned-client/integration evidence.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d4d5ce6253

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/adr/0007-durable-fleet-operation-progress.md Outdated
Comment thread docs/architecture/v0.6-transfer-replication.md Outdated
Comment thread docs/api/v0.6-authorization-risk-matrix.md Outdated
Comment thread docs/architecture/v0.6-fleet-runtime.md Outdated
akhiabanchian
akhiabanchian previously approved these changes Sep 23, 2026
Addresses exact-head architecture/security review findings by governing unresolved-effect disposition, closing MM2 activation/internal-write authorization gaps, and bounding cumulative long-running observation.

Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
@ammarheidari
ammarheidari force-pushed the docs/v0.6-fleet-security-planning branch from b5676af to 01b2211 Compare September 23, 2026 18:34

Copy link
Copy Markdown
Contributor Author

@codex review

Please re-review exact head 01b2211b02d4137dd286f6722a8fe517f51ab47f. The prior four architecture/security findings were addressed and their outdated threads resolved. Focus on the new governed uncertainty-disposition contract, MM2 internal-write/activation authorization, and cumulative observation budget. No implementation is admitted by this PR.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 01b2211b02

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/architecture/v0.6-transfer-replication.md Outdated
Comment thread docs/architecture/v0.6-fleet-runtime.md Outdated
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>

Copy link
Copy Markdown
Contributor Author

@codex review

Please review current exact head ff67a29d3a07d0cc5b552305e4f6c15e7954dc71, including the governed mapped-destination topic-creation contract and lifetime observation hard-cap corrections.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ff67a29d3a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/api/v0.6-authorization-risk-matrix.md Outdated
Comment thread docs/architecture/v0.6-fleet-runtime.md Outdated
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>

Copy link
Copy Markdown
Contributor Author

@codex review

Fresh exact-head review requested for 20d161ca38b02acc43b42358c5caf6c86369ad69 after addressing the two latest planning-contract findings. Please review the current head only.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 20d161ca38

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/api/v0.6-authorization-risk-matrix.md Outdated
Comment thread docs/api/v0.6-authorization-risk-matrix.md Outdated
Address current planning review by making Connect activation permissions lifecycle-specific and by materializing the exact read permissions required for reassignment/RF/throttle/maintenance previews.

Signed-off-by: Ammar Heidari <ammar@arad-itc.org>

Copy link
Copy Markdown
Contributor Author

@codex review

Please review current exact head 9b5359865b94bfc3d3e99a237c0f4bba4ad0f77d. The latest docs-only planning change closes the two current findings by making replication Connect authorization lifecycle-specific and by requiring the exact topology/config read conjunction for reassignment/RF/throttle/maintenance previews.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9b5359865b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/architecture/v0.6-transfer-replication.md Outdated
Comment thread docs/api/v0.6-authorization-risk-matrix.md Outdated
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d97e0dcdae

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/api/v0.6-authorization-risk-matrix.md Outdated
Comment thread docs/api/v0.6-authorization-risk-matrix.md Outdated
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Keep it up!

Reviewed commit: 3618ce1514

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Reconcile PR #147 with the protected-main branding and deterministic test-fix merges without changing the submitted v0.6 planning content.

Signed-off-by: Ammar Heidari <ammar@arad-itc.org>

Copy link
Copy Markdown
Contributor Author

@codex review

Fresh exact-head review requested after reconciling the docs-only v0.6 planning branch with protected main b695dc2687c91e20e5d47ee856cd16e08bad6d26. New exact head: a167f36f5e5f7a9deaba85e90d996707a95f74f9. Planning content remains the same 16 Markdown files; no executable v0.6 implementation was added.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a167f36f5e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/api/v0.6-authorization-risk-matrix.md Outdated
Comment thread docs/implementation/v0.6-implementation-plan.md Outdated
akhiabanchian
akhiabanchian previously approved these changes Sep 24, 2026
Define exact topic/broker throttle mutation targets and a read-only skew-analysis authorization conjunction without weakening ordinary config or mutation boundaries.

Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Require read-only skew authorization evidence and exact typed throttle write/read denial coverage in the W45 contract.

Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Add denial evidence for skew visibility and exact throttle write/read conjunctions, while preserving ordinary config-route throttle rejection.

Signed-off-by: Ammar Heidari <ammar@arad-itc.org>

Copy link
Copy Markdown
Contributor Author

@codex review

Please perform a fresh exact-head review of 9e5fa938aa0652e0e1ebb5b4aa395f05b088dabe. The two P2 findings from a167f36f... were addressed by closing the exact reassignment-throttle write/read conjunction and defining a read-only skew-analysis authorization contract plus negative W45 tests. Planning remains docs-only.

Copy link
Copy Markdown
Contributor Author

@codex review

Fresh exact-head review requested for 9e5fa938aa0652e0e1ebb5b4aa395f05b088dabe after addressing the two P2 authorization findings from the prior review: (1) closed exact throttle write/read conjunction and route boundary; (2) separate read-only skew-analysis authorization plus missing-read evidence. Protected main remains b695dc2687c91e20e5d47ee856cd16e08bad6d26; live compare remains exactly 16 Markdown files, 16 commits ahead / 0 behind, with no executable v0.6 implementation.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Bravo.

Reviewed commit: 9e5fa938aa

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants