-
Notifications
You must be signed in to change notification settings - Fork 1
Module auth Roadmap
Navigation: Home > Modules
Production authentication runtime exists across JWT/OIDC, Kerberos, MFA, OAuth, SAML, LDAP, API-key, mTLS, WebAuthn, session/revocation, and zero-trust verification paths. v1.3.0 distributed token blacklist is complete: TBLK/v1 binary TCP protocol, leader push, follower pull, server listener, LWW merge β all shipped and covered by DBL-01..DBL-17.
- hardening of distributed revocation, federation, and policy-edge behavior (Target: Q3 2026)
- benchmark and release-gate consolidation for token/session hot paths (Target: Q3 2026)
- consistency hardening for async/provider-integration reliability (Target: Q3 2026)
- [~] Wave C benchmark gate execution and evidence capture in CI (AUTH-GRG-01..06) (Target: Q4 2026)
- Dispatched:
CI β Benchmarksrun#40(32765349559) ondevelopwith filterbench_auth_hotpaths|AHP- - Pending: run completion on representative hardware and artifact-to-gate mapping evidence
- Dispatched:
- async/non-blocking LDAP authentication calls (authenticateAsync with AuthWorkerThreadPool)
- async/non-blocking HTTP authentication calls (new AsyncHTTPAuth class)
- LDAP connection pooling with health checks and reuse (LDAPConnectionPool)
- HTTP retry logic with exponential backoff for transient failures
- Thread-safe worker pool for concurrent auth operations
- Token blacklist persistence to RocksDB (RocksDBTokenBlacklist)
- Leader election for distributed deployments (node-ID ordering, performLeaderElection)
- Atomic blacklist validation during cluster sync (fail-closed isRevoked with RocksDB read)
- Distributed token blacklist with cluster synchronization β TBLK/v1 binary TCP protocol:
- TCP server listener on
local_node.rpc_port; bind is non-fatal (outbound still works) - Leader PUSH: serializes all non-expired JTI entries and pushes to each follower
- Follower PULL: sends PULL_REQ, receives PULL_RESP, applies entries with LWW semantics
-
performClusterSync(): leader election β push to all peers (leader) or pull from leader (follower) -
pushRevisionsToFollower()/pullRevisionsFromLeader(): full production implementation -
serveIncomingConnections()/handlePeerConnection(): server-side PUSH and PULL_REQ dispatch -
getAllEntries()/applyEntries(): RocksDB helpers with LWW conflict resolution - Wire format: 10-byte header (magic "TBLK", version 0x01, type, count) + variable entries
- Files:
include/auth/distributed_token_blacklist.h,src/auth/distributed_token_blacklist.cpp
- TCP server listener on
- Comprehensive test coverage for distributed scenarios (tests/auth/test_auth_distributed_blacklist.cpp, DBL-01..DBL-17)
Source: MODULE_GAP_ANALYSIS_WAVE2.md Β§Wave 4-B Β· gap-verifier subagent 2026-08-25
Verified real gaps: 7 CRITICAL (missing audit events), 7 HIGH (retry + crypto), 1 MEDIUM
FP closed (14): sensitive_data_logging (all 155) β scanner matched variable names not values; mTLS cipher claim wrong file scope (MTLSAuthenticator has no SSL_CTX)
- 2026-08-26
passkey_authenticator.cpp:880-892β injectAuthAuditLogger*; calllogPasskeySuccess(credential_id)/logPasskeyFailure(reason)fromverifyAuthentication()β zero audit calls currently (CRITICAL) (Target: Q4 2026) - 2026-08-26
mtls_authenticator.cpp:281β injectAuthAuditLogger*; addlogMTLSSuccess(principal,serial)/logMTLSFailure(reason)β noAuthAuditLoggerinclude or call in file (CRITICAL) (Target: Q4 2026) - 2026-08-26
federated_identity_manager.cpp:202-578β addAuthAuditLogger*injection; calllogJWTSuccess/Failure/logFederatedSuccess/FailureinvalidateToken()andexchangeToken()β file has no#include "auth/auth_audit_logger.h"(CRITICAL) (Target: Q4 2026) - 2026-08-26
auth_audit_logger.cppβ addSecurityEventType::ROLE_CHANGED,PERMISSION_CHANGED; addlogRoleChange(user_id, role, old_role)andlogPermissionChange(user_id, resource, old_perm, new_perm)(CRITICAL) (Target: Q4 2026) - 2026-08-26
jwt_key_rotation_manager.cpp:54β add try/catch aroundmax_keysthrow to fireKEY_ROTATION_FAILEDaudit event before re-throwing β logger assigned on line 77, after throw, so never reached (HIGH) (Target: Q4 2026) - 2026-08-26
jwt_key_rotation_manager.cpp:99-100β emitKEY_REVOCATION_FAILEDevent beforereturn falseon unknownkidβ THEMIS_WARN only, no audit trail for key ID probing (HIGH) (Target: Q4 2026) - 2026-08-26
auth_audit_logger.cppβ addlogPasskeyRegistered(user_id, credential_id, rp_id); call fromregisterCredential()βlogMFAEnrolledcovers TOTP only (HIGH) (Target: Q4 2026)
- 2026-08-26
ldap_connection_pool.cpp:173-181β add inner retry loop (max 3Γ, base 100ms, Γ2, Β±20ms jitter) aroundcreateConnection(); on exhaustion βthrow AuthException(PROVIDER_DEGRADED); current:nullptrfalls through to CV wait without backoff (HIGH) (Target: Q4 2026) - 2026-08-26
federated_identity_manager.cpp:390-393β wraphttpPost()in retry loop (max 3Γ, jittered backoff); retry onCURLE_COULDNT_CONNECT,CURLE_OPERATION_TIMEDOUT, HTTP 429/503 β currently throws immediately (HIGH) (Target: Q4 2026) - 2026-08-26
oauth_pkce_flow.cpp:317-318β same fix as B-2 above; factor into shared retryinghttpPost()helper (HIGH) (Target: Q4 2026) - 2026-08-26
oauth_device_flow.cpp:399-400β retry individual HTTP transport errors within the RFC poll loop (not the poll interval itself β RFC 8628 Β§3.5 poll loop is correct); distinguishCURLEtransport failure fromauthorization_pending(MEDIUM) (Target: Q4 2026)
- 2026-08-26
passkey_authenticator.cpp:407-483β add COSEalgfield allowlist incoseKeyToEvpPkey(); rejectkty=2ifalg != -7(ES256); rejectkty=3ifalg != -257(RS256); enforce stored credential algorithm matches (HIGH β cross-algorithm substitution risk) (Target: Q4 2026) - 2026-08-26
mtls_authenticator.cpp:173-283β addX509_get_ext_d2i(cert, NID_ext_key_usage)check; reject certs lackingid-kp-clientAuthOID; adddigitalSignaturekey-usage bit check (HIGH β serverAuth-only certs currently accepted) (Target: Q4 2026) - 2026-08-26
passkey_authenticator.cpp:447-482β after RSA EVP_PKEY construction, callEVP_PKEY_get_bits(pkey)and reject if< 2048(MEDIUM β 512/1024-bit RSA keys currently accepted) (Target: Q4 2026)
-
tests/auth/test_wave4b_auth_hardening.cppβ minimum 14 tests covering all verified gaps above -
tests/auth/test_wave4b_auth_hardening2.cppβ 12+ additional tests; registered withwave_b release_criticallabels (added 2026-08-26)
- sensitive_data_logging (155): scanner matched variable names near log calls, not log values;
// NOPIIalready on ambiguous sites; no raw credential in any spdlog format argument - mTLS cipher list:
MTLSAuthenticatoris a PEM-level verifier with no SSL_CTX; TLS cipher enforcement belongs in the transport layer wrapping this component
Source: MODULE_GAP_ANALYSIS_WAVE2.md Β§Wave 2-A, gap scanner verified 2026-08-25
Gap count: 155sensitive_data_logging(HIGH), 7missing_audit_log(CRITICAL), 22no_retry_logic, 9crypto_weakness
- Sensitive data redaction: FP CONFIRMED β 100% false positive per subagent triage (2026-08-25); preventive lint policy recommended as follow-up
- Add missing audit events: all 14 Wave 4-B gaps closed 2026-08-26
- Auth retry logic: LDAP createConnection retry, federated/PKCE/device-flow retry β all closed 2026-08-26
- Crypto weakness: passkey COSE alg allowlist, RSA key size, mTLS EKU β all closed 2026-08-26
Source: Semantic analysis 2026-08-25 β
ldap_authenticator.cpphas ~12 stubbed functions
- 2026-08-26 LDAP Connection Pool: real pool management (bind context, bounded size, timeout) in
ldap_authenticator.cpp(Target: Q4 2026)- Inputs: LDAP server config (host, port, bind-DN, timeout)
- Outputs: pooled LDAP connection with automatic rebind on staleness
- Errors:
LDAP_CONNECT_TIMEOUTon pool exhaustion; retry with backoff -
checkout()timeout now throwsAuthException(PROVIDER_DEGRADED)instead of returningnullptr - Tests:
tests/auth/test_wave7_auth_ldap_federated.cpp(WP-01..WP-06, WA-01..WA-04)
- 2026-08-26 LDAP Search Pagination: controlled, bounded result pagination in
ldap_authenticator.cpp(Target: Q4 2026)- Unix/OpenLDAP path: paginated
ldap_search_ext_sloop withldap_create_page_control/ldap_parse_page_control; page_size=500, max_results=5000; partial results returned on pagination error withTHEMIS_WARN
- Unix/OpenLDAP path: paginated
- 2026-08-26
federated_identity_manager.cpp: Cross-provider state sync β 9 new methods implemented (Target: Q4 2026)-
addCrossProviderTrust/removeCrossProviderTrust/isTrustedBy/getCrossProviderTrusts: in-memory trust registry protected bytrust_mutex_ -
cacheValidationResult/getCachedResult/evictExpiredCacheEntries/clearTokenCache/tokenCacheSize:std::unordered_map-backed token validation cache withstd::chrono::system_clockexpiry; auto-populated byvalidateToken() - Tests:
tests/auth/test_wave7_auth_ldap_federated.cpp(FR-01..FR-03, FT-01..FT-05, FC-01..FC-07)
-
- tighten fail-closed behavior for optional provider-degraded scenarios (Target: Q4 2026)
- expand deterministic integration regressions across auth protocol matrixes (Target: Q4 2026)
- improve operator diagnostics for policy/revocation/federation decision classes (Target: Q4 2026)
Source:
src/MODULE_GAP_ANALYSIS_WAVE2.md Β§Wave 8
- W8-15
ldap_authenticator.cpp:699β722β LDAP pagination error handling: add retry loop (max 3, exponential backoff) +AuthAuditLoggerevent on each transient LDAP error; currentbreakreturns partial group membership silently (Target: Q4 2026) β IMPLEMENTED 2026-08-26 - W8-16
federated_identity_manager.cpp:209β218β Token cache DoS hardening: addkTokenCacheMaxSizecap +std::listLRU eviction + SHA-256(token) β hex string as cache key; current cache is unbounded and keyed on raw token strings (Target: Q4 2026) β IMPLEMENTED 2026-08-26 - W8-17
ldap_connection_pool.cpp:208β217β Pool exhaustion audit: injectAuthAuditLogger; emit structured audit event on pool exhaustion before throw (LOW, Target: Q4 2026) β IMPLEMENTED 2026-08-26 - Test:
tests/auth/test_wave8_auth_hardening.cppβ 10+ tests covering pagination retry, partial-result detection, cache eviction under size pressure, pool-exhaustion audit trail
- reduce remaining proxy-like benchmark targets through dedicated auth microbenchmarks (Target: Q1 2027)
- re-baseline auth p95/p99 envelopes on representative production profiles (Target: Q1 2027)
- harden multi-realm and distributed trust-state synchronization paths (Target: Q1 2027)
- freeze authentication and principal-contract semantics for active major line (Target: Q3 2026)
- Delivered:
include/auth/auth_principal_contract.hβ frozen v1.x contract (principal sizes, temporal bounds, failure classes, fail-closed semantics, revocation backend contract, provider capability contract, async contract)
- Delivered:
- define explicit failure contracts per provider integration and policy gate (Target: Q3 2026)
- Delivered: failure contract sections added to
distributed_token_blacklist.h,federated_identity_manager.h,session_manager.h; new error codes PROVIDER_DEGRADED, PROVIDER_CAPABILITY_MISMATCH, FEDERATION_UNKNOWN_REALM, FEDERATION_REALM_UNAVAILABLE, REVOCATION_BACKEND_UNAVAILABLE, REVOCATION_ENTRY_INVALID, REVOCATION_CLUSTER_SYNC_FAILED, POLICY_EDGE_UNDEFINED, POLICY_MISSING_REQUIRED_CLAIM, ASYNC_PROVIDER_TIMEOUT, ASYNC_POOL_EXHAUSTED, ASYNC_PROVIDER_EXCEPTION registered inauth_error.h+auth_error.cpp
- Delivered: failure contract sections added to
- RocksDB persistence layer for token blacklisting (RocksDBTokenBlacklist, DistributedTokenBlacklist)
- TBLK/v1 binary TCP RPC protocol β
pushRevisionsToFollower(),pullRevisionsFromLeader(),serveIncomingConnections(),handlePeerConnection()(src/auth/distributed_token_blacklist.cpp) - Leader election based on node-ID lexicographic ordering (performLeaderElection)
- LWW (Last-Write-Wins) conflict resolution in
applyEntries()β lower-timestamp entries silently overwritten - complete remaining hardening in revocation/federation/provider execution paths (Target: Q3 2026)
-
add()now validates JTI empty/size early with REVOCATION_ENTRY_INVALID (fail-closed) -
validateToken()/realmProvider()/exchangeToken()now throw FEDERATION_UNKNOWN_REALM for unknown issuers (previously JWT_ISSUER_MISMATCH β now callers can distinguish realm-not-found from cryptographic failure) -
validateToken()reclassifies unstructured provider exceptions as PROVIDER_DEGRADED (fail-closed) -
exchangeToken()non-HTTPS endpoint check throws PROVIDER_CAPABILITY_MISMATCH
-
- align session/trust behavior to shared bounded runtime contracts (Target: Q3 2026)
-
session_manager.hupdated with bounded runtime contract cross-referencing auth_principal_contract.h
-
- PasskeyAuthenticator concrete class and real CBOR/OpenSSL verification (Target: Q4 2026)
-
include/auth/passkey_authenticator.h: addedPasskeyAuthenticatorclass implementingIPasskeyAuthenticatorwith thread-safe in-memory credential store and pending-challenge lifecycle -
src/auth/passkey_authenticator.cpp: TODO stubs replaced with real base64url decode (OpenSSL BIO), CBOR attestation-object parsing, authenticatorData parsing (rpIdHash, flags, signCount, AAGUID, credential ID, COSE public key), ECDSA-P256/RS256 signature verification viaEVP_DigestVerify, and sign_count clone detection
-
- standardize fail-closed behavior for malformed auth artifacts and degraded backends (Target: Q3 2026)
- Delivered:
isFailClosedClass()predicate inauth_principal_contract.hΒ§4 -
distributed_token_blacklist.cpp::add()validates empty/oversized JTI early -
federated_identity_manager.cpp::validateToken()wraps unstructured exceptions as PROVIDER_DEGRADED
- Delivered:
- unify error taxonomy and diagnostics across protocol adapters (Target: Q3 2026)
- Delivered: 12 new AuthErrorCode entries (9420-9452) for provider/revocation/policy/async failures,
all registered with actionable operator guidance in
auth_error.cpp::registerAuthErrors()
- Delivered: 12 new AuthErrorCode entries (9420-9452) for provider/revocation/policy/async failures,
all registered with actionable operator guidance in
- close catch_all_swallow, unchecked_result, resource_leaked_in_exception gaps (Target: Q3 2026; delivered 2026-08-24)
-
jwks_security.cpp: RAII wrappers (UniqueX509, UniqueOSSLBuf, UniqueOSSLChar) applied tocomputeSPKIHashFromFile,computeSPKIHashFromPEM,getCertificateInfoβ 3 resource_leaked_in_exception closed -
ldap_authenticator.cpp: 4 uncheckedldap_set_optioncalls (TIMELIMITΓ2, PROTOCOL_VERSION, NETWORK_TIMEOUT, TIMEOUT) now log warnings on failure β 4 unchecked_result closed -
rate_limiter_backend.cpp: 5 bridge-functioncatch(...)blocks now log before fallback β 5 catch_all_swallow closed -
http_auth_async.cpp:performConnectivityCheckcatch(...)now logs at debug level β 1 catch_all_swallow closed -
auth_rate_limiter.cpp:reset()lock-ordering hazard fixed (stats_mutex_ no longer held over sub-object reset calls); constructor andincrementAndGetBreachCount()Redis blocks wrapped with logged exception guards β 1 circular_lock_ordering + 2 catch_all_swallow closed
-
- DBL-01..DBL-08: core CRUD (add, isRevoked, purge, concurrency) β tests/auth/test_auth_distributed_blacklist.cpp
- DBL-09..DBL-11: leader election semantics (sole node, lowest node_id wins, isLeader() state)
- DBL-12..DBL-14: cluster API (syncWithCluster future, single-node convergence, timeout with unreachable peer)
- DBL-15..DBL-17: observability + lifecycle (ReplicationStats zero-init, config accessor, RAII destructor)
- expand focused regressions for concurrency, replay, and distributed-edge scenarios (Target: Q3 2026)
- Delivered:
tests/auth/test_auth_hardening_revocation_federation.cppRFP-01..08 (revocation edge cases: concurrent, oversized JTI, empty JTI, purge selectivity)
- Delivered:
- extend deterministic fixture coverage for provider/federation matrix permutations (Target: Q3 2026)
- Delivered: FED-01..08 (federation: unknown realm code, duplicate realm, malformed token, non-HTTPS endpoint, missing endpoint, multi-realm coexistence, realm count)
- Delivered: ASY-01..08 (session/async: empty user_id, unknown session, expired session, idempotent terminate, terminateAllOther, sess_ prefix invariant, pruneExpired, per-user limit)
- Wave C test gates delivered (Target: Q4 2026)
- Delivered:
tests/auth/test_auth_wavec_authentication_methods.cpp(AUTH-Auth-01..08: JWT/SAML/mTLS validation edge cases) - Delivered:
tests/auth/test_auth_wavec_token_lifecycle.cpp(AUTH-Token-01..08: SessionManager + DistributedTokenBlacklist lifecycle) - Delivered:
tests/auth/test_auth_wavec_federation_providers.cpp(AUTH-Provider-01..06: FederatedIdentityManager failover, degradation, realm management) - Delivered:
tests/auth/test_auth_wavec_authorization.cpp(AUTH-AuthZ-01..08: authorization policy contract types) - Delivered:
tests/auth/test_auth_wavec_rate_limiting.cpp(AUTH-RateLimit-01..06: AuthRateLimiter per-user, concurrency, reset)
- Delivered:
- isRevoked() confirmed O(1) RocksDB point read (< 1 Β΅s warm cache); hot path unaffected by background sync
- add() confirmed < 1 ms (single RocksDB Put)
- cluster sync every 30 s (configurable sync_interval_seconds); background thread
- leader election local-only (O(#peers) string comparison) converges < 1 s
- lock benchmark-backed release gates for token/session/revocation hotspots (Target: Q3 2026)
- Delivered:
benchmarks/auth/bench_auth_hotpaths.cppβ AHP-01..08 with GATE-AHP-01..06 (blacklist hit/miss p99 β€ 1 Β΅s, session create p99 β€ 5 ms, session validate p99 β€ 1 ms, distributed add p99 β€ 2 ms, distributed isRevoked warm p99 β€ 1 Β΅s) - Registered in
benchmarks/CMakeLists.txtasbench_auth_hotpaths
- Delivered:
- validate p95/p99 and throughput behavior against release baselines (Target: Q3 2026)
- Gate thresholds documented in AHP benchmark file and PERFORMANCE_EXPECTATIONS.md
- 2026-09-09:
bench_auth_hotpaths.cppnow exports p50/p95/p99 and gate counters so the broad baseline refresh lane can publish reusable artifacts; first refresh run queued asBuild: Benchmarksrun34345454063.
- core auth module docs aligned to source-verifiable behavior
- roadmap/future planning separated from historical changelog entries
- Clarify distributed revocation and backend-capability expectations across blacklist and rate-limiter backend headers
-
distributed_token_blacklist.hfailure/degradation contract section added (Β§ failure/degradation contract)
-
- Add explicit provider-degradation guidance for network-bound authentication adapters
-
federated_identity_manager.hprovider-degradation contract section added
-
- Document benchmark-backed compatibility guarantees for token/session hot paths in header docs
-
session_manager.hbounded runtime contract section added
-
- core auth surfaces documented and source-verified
- module-level security and failure behavior documented
- benchmark mapping documented in performance expectations
- distributed blacklist RPC layer (TBLK/v1) fully implemented and tested (DBL-01..DBL-17)
- remaining hardening tasks closed for provider edge cases
- release-gate benchmark stabilization complete
- PasskeyAuthenticator TODO stubs replaced with real CBOR/OpenSSL verification logic (2026-08-19)
- Wave C test gates delivered: AUTH-Auth-01..08, AUTH-Token-01..08, AUTH-Provider-01..06, AUTH-AuthZ-01..08, AUTH-RateLimit-01..06 (2026-08-19)
- Batch 5 gap closure: resource_leaked_in_exception (jwks_security.cpp RAII), unchecked_result (ldap_authenticator.cpp), catch_all_swallow (rate_limiter_backend.cpp, http_auth_async.cpp, auth_rate_limiter.cpp), circular_lock_ordering (auth_rate_limiter.cpp reset()) β delivered 2026-08-24
- audit_logger.h filename collision resolved: include/api/audit_logger.h renamed to include/api/graphql_audit_logger.h; ws_handler.cpp updated β delivered 2026-08-24 (unblocks build validation for AUTH-GRG gate evidence)
- [~] Wave C benchmark gates executed (AUTH-GRG-01..06) β CI run
CI β Benchmarks#40 (32765349559) pending completion as of 2026-08-24T19:20Z; evidence capture follows artifact publication - Short-term hardening complete: fail-closed provider-degraded, protocol matrix regression tests, operator diagnostics decision_class β delivered 2026-09-16
- Mid-term items complete: AHP-09..11 auth microbenchmarks (bench_auth_protocol_micro), p95/p99 design targets in PERFORMANCE_EXPECTATIONS.md, multi-realm syncTrustState() β delivered 2026-09-16
- Wave D contributions complete: high-cardinality stress tests (test_auth_highcardinality_stress.cpp), soak tests (test_auth_soak.cpp), operator runbook (RUNBOOK.md), operator_hint JSON field in 9420β9452 error registry entries β delivered 2026-09-16
- behavior remains partially capability-dependent on configured identity providers and backends.
- Hardware-measured p95/p99 benchmark baselines are design-target-only pending a dedicated benchmark hardware run (see
PERFORMANCE_EXPECTATIONS.md Β§Re-baseline procedure). - Wave C benchmark gate evidence (AUTH-GRG-01..06) pending CI artifact publication from run
32765349559.
No breaking auth-module contract planned. Any contract-breaking change requires migration notes and changelog entry before merge.
This module is a contributing module in the program-level Wave A β B β C β D execution model.
It does not own a primary wave deliverable but must remain release_critical-green throughout all waves
and must deliver Wave D operability improvements in Q1 2027.
See ../../ROADMAP.md for the full wave model and exit criteria.
- Deliver or validate distributed tracing, high-cardinality stress coverage, exporter reliability, and operator remediation hints as applicable to this module (Target: Q1 2027)
- Contribute to or validate long-duration soak test coverage for this module's primary paths (Target: Q1 2027)
- Ensure runbook coverage for operator-critical scenarios in this module (Target: Q1 2027)
-
release_criticalCI must remain green ondevelopthroughout all waves (Target: ongoing) - p95/p99 benchmarks must be refreshed on representative hardware before Wave D sign-off (Target: Q1 2027)
- No behavioral regression may be introduced into modules in Wave A/B/C scope from changes in this module.
- This module's distributed/acceleration paths fail closed (Target: Q1 2027)
- Validated: PROVIDER_DEGRADED fail-closed on empty sub, HTTP 5xx, and provider exceptions; syncTrustState() for multi-realm distribution; all revocation backends are fail-closed by default.
- Benchmark-backed p95/p99 baselines exist on representative hardware (Target: Q1 2027)
- Design targets established in
src/auth/PERFORMANCE_EXPECTATIONS.mdGATE-AHP-01..10; hardware-measured baselines pending dedicated CI benchmark hardware run (see re-baseline procedure in PERFORMANCE_EXPECTATIONS.md).
- Design targets established in
- Operator-critical paths have diagnostics, alerts, and runbooks (Target: Q1 2027)
-
src/auth/RUNBOOK.mdcovers all 5 operator-critical scenarios;decision_classfield in audit events; structuredoperator_hintJSON in all 9420β9452 error registry entries.
-
ThemisDB 1.9.0-beta Β· Home Β· Module-Index Β· GitHub Β· Issues
ThemisDB 1.9.0-beta Β· Home Β· Wiki-Index Β· Module-Index Β· FAQ Β· Quick-Reference Β· GitHub Β· Issues Β· Discussions Β· License
- Home
- Hero Articles
- All Wiki Pages
- FAQ
- Edition Comparison
- Repository README
- Changelog
- Roadmap
- Versioning
- Integration Mapping
- Overview
- Readme
- Appendix D Feature Status
- Appendix E Incident Runbooks
- Appendix F AQL Cheatsheet
- Appendix G Configuration
- Appendix H Glossary
- Appendix I Troubleshooting
- Appendix Literatur
- Chapter 00 Genesis
- Chapter 01 Introduction
- Chapter 02 Architecture
- Chapter 03 Multimodel
- Chapter 04 Installation
- Chapter 05 Relational
- Chapter 06 Graph
- Chapter 07 Document
- Chapter 08 Storage Layer
- Chapter 08 Vector
- Chapter 09 Timeseries
- Chapter 10 Enterprise
- Chapter 11 Realtime
- Chapter 12 Computervision
- Chapter 13 Fulltext
- Chapter 14 Geospatial
- Chapter 15 Analytics
- Chapter 16 Ml
- Chapter 16 Sharding
- Chapter 17 LLM Integration
- Chapter 17 Scaling
- Chapter 18 HA
- Chapter 18 Ml
- Chapter 19 Monitoring
- Chapter 19 Monitoring Observability
- Chapter 20 Backup
- Chapter 20 Performance
- Chapter 21 Auth
- Chapter 21 Performance
- Chapter 22 Clients
- Chapter 22 Encryption
- Chapter 23 Testing Qa
- Chapter 24 Ai Ethics
- Chapter 25 Devops Infrastructure
- Chapter 26 Migration Legacy
- Chapter 27 Troubleshooting
- Chapter 28 AQL Reference
- Chapter 29 Analytics Process Mining
- Chapter 30 Deployment Operations
- Chapter 31 API Protocols
- Chapter 32 API Design Rest Principles
- Chapter 32 AQL Oop Implementation
- Chapter 33 Best Practices
- Chapter 34 Query Optimization
- Chapter 35 Data Modeling Patterns
- Chapter 36 Security Hardening
- Chapter 37 Ecosystem Integration
- Chapter 38 Observability Sre
- Chapter 39 Performance Tuning Cookbook
- Chapter 40 Data Governance Compliance
- Chapter 41 Hands On Labs
- Chapter 42 Docs Assistant Usage
- Chapter MVCC Hlc
- Cover
- Cover Book
- Index
- Preface
- Test Links Example
- Batch Operations
- Best Practices
- CRUD Tutorial
- Custom Document Ingestion
- Getting Started Tutorial
- Interactive Examples
- Schema Design
- Video Tutorials
- AQL Reference
- AQL Examples
- AQL Overview
- AQL Feature Roadmap
- AQL Geospatial Guide
- AQL LLM Migration Guide
- AQL API
- AQL Grammar (EBNF)
- AQL Root Overview
- AQL Examples (root)
- API Reference
- API Module README
- OpenAPI Overview
- Client SDK Overview
- SDK Overview
- Operations
- Operations Overview
- Operations Runbook
- Operations Handbook
- ThemisCtl Admin Guide
- Pipeline E2E SOPs
- Docker Overview
- Docker Hub README
- Helm Overview
- Packaging Overview
- Operator Overview
- Security Policy
- Production Hardening Checklist
- Security Hardening Guide
- Encryption Key Management
- Access Control Framework
- Zero Trust Policy
- API Authentication & Authorization
- HSM Production Setup
- PKCS11 Integration
- DSGVO / SOC2 Checklist
- Access Model Runbooks
- Access Model Dashboard
- Maturity Automation Runbook
- Access Review Automation
- Access Model Dashboard
- Access Model Runbooks
- Rights Revocation
- Dr Checklists
- Dr Testing
- Incident Response Playbook
- Incident Response Testing
- GPU Oom Recovery
- Grammar Debugging
- Metrics Scrape Troubleshooting
- Model Swap Procedure
- Quota Tuning
- Subagent Deployment
- Logging Configuration
- Content Model
- Crypto & Keys
- Feature Flags Reference
- Modular Architecture Roadmap
- Modularization Guide
- Module Architecture Index
- PostgreSQL Wire Protocol
- Query Scheduling
- Raft Consensus Design
- Resource Pooling
- Source Directory Guide
- Unified Access Model
- E1 001 Layered Retrieval Design
- E1 002 Ann Abstraction Strategy
- E1 003 Tensor Summary Types
- E1 004 Lora Package Distinction
- E1 005 Model Switch Compatibility
- E1 006 Federated Tensor Summaries
- E2 001 Evaluation Framework Design
- E2 002 Hardware Profile Strategy
- E2 003 Query Planner Routing Model
- E2 004 Approximation Governance Rules
- E2 005 Cross Layer Fallback Confidence Policy
- E3 001 Distributed Tensor Design
- E3 002 Manifest Coordination Strategy
- E3 003 Recovery And Erasure Choice
- E3 004 Tensor Fabric Infrastructure
- Contributing
- Contributing (root)
- Code of Conduct
- Support
- Maintainers
- CTest Guide
- Build Quick Reference
- Developer Wiki Index
- Build / Test / CI
- Module Index
- Branching Strategy
- Release Strategy
- CI Policy Gates Wave C
- Disabled Stub Policy
- Docs PR Policy
- GA Promotion Sign Off
- Github Milestones Setup
- Governance Policies Phase1
- GPU Self Hosted Runner Requirements
- Hardening Phase 1 2 Summary 2026 09 23
- Maturity Claim Verification Checklist
- Maturity Evidence Registry
- Merge Gate Bot Config
- Merge Gate Status Live
- Phase 1 Closure Report
- Phase 1 Infrastructure Deployment
- Phase 1 Infrastructure Deployment Complete
- Phase 3 Baseline Capture
- Phase 3 Refinement Spec
- Phase 4 Sign Off And Closure
- Phase Closure Policy
- Phase Dependency Graph
- Phase3 Enforcement Runbook
- Plugin Submodule Rollback
- PR Version Targeting
- PR Version Targeting Backfill
- Production Ready 2026 Delivery Plan
- Publish Workflow Audit 2026 09 23
- Query Module Status
- Readme
- Release Governance
- Release Promotion Gate Policy
- Release Validation Checklist
- Root Hygiene Policy
- SBOM Approved Versions
- Security Compliance Audit Report 2026 08 10
- Security Module 5671 Evidence Summary
- Sharding P6 Residual Risk Acceptance
- Sourcecode Compliance Governance
- Src Module Documentation Compliance 2026 09 20
- Updates Development Status Sign Off
- Wave C Implementation Complete
- Wave C Implementation Plan
- Wave C Ml Exit Gate Sign Off
- Wave C Policy Gate Evidence
- Wiki Publish Tracking Guide
- Blob Storage
- Cuda
- Ethics Ai
- Exporters
- Huggingface
- Image Analysis
- Importers
- RPC
- Scraper
- Themisdb Ai Watermark Detector
- User Storage Encrypted
- Chimera Architecture
- Chimera Future
- Chimera Readme
- Chimera Roadmap
- Covina Fastapi Ingestion Architecture
- Covina Fastapi Ingestion Future
- Covina Fastapi Ingestion Roadmap
- Vcc Base Architecture
- Vcc Base Future
- Vcc Base Roadmap
- Vcc Clara Ingestion Architecture
- Vcc Clara Ingestion Future
- Vcc Clara Ingestion Roadmap
- Vcc Veritas Architecture
- Vcc Veritas Future
- Vcc Veritas Roadmap
- 01 Hello World
- 02 Todo App
- 03 Contact Manager
- 04 Inventory System
- 05 Time Series Monitor
- 06 Graph Social Network
- 07 Vector Search Documents
- 08 Dms Erp System
- 09 Iot Sensor Network
- 10 Drone Image Analysis
- 11 Blog Wiki
- 12 Expense Tracker
- 13 Recipe Manager
- 14 Ecommerce Catalog
- 15 Event Management
- 16 Kanban Board
- 17 Crm
- 18 Realtime Chat
- 19 Recommendation Engine
- 20 Smart Home
- 21 Coding Platform
- 22 AQL Diagram Tool
- 23 Traveling Salesman
- 24 Moral Philosophy Debates
- API Versioning
- Distributed Sharding
- Feedback Plugins
- Geo
- Gnn
- Image Analysis
- Legal Lora Training
- LLM
- Lora Sync
- Migration
- Nlp
- Performance
- Railway
- Replication
- Rope Visualization
- Sample Product Config
- Security
- Client SDK Overview
- Quickstart
- Sdk Enhancements
- Sdk Implementation Summary
- Test Suite Readme
- Go
- Java
- Javascript
- Php
- Python
- Ruby
- Rust
- Typescript
- 01 Grundlegende Operationen
- 02 AQL Queries
- 03 Graph Daten
- 04 Multimodell Anwendung
- 01 Quickstart Guide
- 02 AQL Referenz Kurzuebersicht
- 03 Datenmodellierung Guide
- 04 Uebungsaufgaben
- 05 Best Practices Guide
- Training Documents
- Training Overview
- 01 Einfuehrung Und Uebersicht
- 02 Datenmodelle Und Architektur
- 03 AQL Abfragesprache
- 04 Installation Und Setup
- 05 Anwendungsbeispiele
- Training Presentations
- Dependencies Readme
- Processmonitor Readme
- Themis.admintools.shared Readme
- Themis.aqlquerybuilder Readme
- Themis.aqlquerybuilder Roadmap
- Themis.auditlogviewer Readme
- Themis.auditlogviewer Roadmap
- Themis.classificationdashboard Readme
- Themis.classificationdashboard Roadmap
- Themis.compliancereports Readme
- Themis.compliancereports Roadmap
- Themis.gisviewer.controlpanel Readme
- Themis.gisviewer.controlpanel Roadmap
- Themis.impactanalysisviewer Readme
- Themis.impactanalysisviewer Roadmap
- Themis.ingestiontool Readme
- Themis.ingestiontool Roadmap
- Themis.keyrotationdashboard Readme
- Themis.keyrotationdashboard Roadmap
- Themis.piimanager Readme
- Themis.piimanager Roadmap
- Themis.retentionmanager Readme
- Themis.retentionmanager Roadmap
- Themis.sagaverifier Readme
- Themis.sagaverifier Roadmap
- Themis.usbadmintool Readme
- Themis.usbadmintool Roadmap
- Architecture Generator Readme
- CI Readme
- CI Roadmap
- Compiler Diagnostics Readme
- Compiler Diagnostics Roadmap
- Completion Readme
- Copilot Ollama Router Readme
- Copilot Ollama Router Roadmap
- Gnn Readme
- Gnn Roadmap
- Rope Visualizer Readme
- Rope Visualizer Roadmap
- Tco Calculator Readme
- Tco Calculator Roadmap
- Tests Readme
- Tests Roadmap
- Themis Config Wx Readme
- Themis Docs Builder Readme
- Wikipedia Ingestion Readme
- Ai Metadata And Provenance
- Build / Test / CI
- Governance And Roadmap
- Developer Wiki Index
- Module Direct Doxygen Check
- Module Doxygen Baseline Summary
- Module Doxygen Batch
- Module Doxygen Coverage Summary
- Module Doxygen Smoke Summary
- Modules And Apis
- Retrieval Direct Doxygen Check
- Soll Ist Gap Summary
- Wiki Delta Report