feat(router): add scoped governed services and bounded telemetry - #550
Draft
Pal Lakatos-Toth (pallakatos) wants to merge 9 commits into
Draft
feat(router): add scoped governed services and bounded telemetry#550Pal Lakatos-Toth (pallakatos) wants to merge 9 commits into
Pal Lakatos-Toth (pallakatos) wants to merge 9 commits into
Conversation
Add separately authenticated operator controls, UID-qualified request scopes, bounded cancellation and policy-gated waits, metadata-only observations, and narrow router-only credential projection. Preserve existing policy enforcement and provider behavior. Add real Kind authentication/mount/reset coverage; independent review, hosted qualification and genuine audit sign-offs remain pending. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
Coordinate dispatch claims with cancellation/reset after awaited policy checks and retain claims through response handling. Distinguish accepted Responses/OpenAI semantic errors from completed generations without replay or byte changes. Keep the separate HIGH SRE credential-privacy prerequisite explicitly blocked. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Combine the exact SRE prerequisite with governed services. Distinguish pending qualification from privacy loss, quarantine canonical SRE before its early return, and preserve qualified authority across ordinary rollout health delays while fencing old cached credential consumers. Qualification remains pending; no deployment or signing approval is asserted. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Forward exact 447312d while retaining the governed privacy integration and repair history. The complete SRE Kind qualification and governed-services review remain pending; this local checkpoint is not a deployment or publication approval. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Paired offline/default-feature controller/router qualification passed: 43 controller tests, 11 router unit tests, and 29 governed HTTP integration tests. Strict all-target Clippy passed after these mechanical fixes. Hosted SRE Kind and independent review remain pending; no deployment or public publication approval is asserted. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Forward exact 8616229. The seven-file CLI/guide merge leaves the qualified controller, router, shared privacy code and Cargo manifests unchanged. Full hosted SRE Kind and bounded privacy review remain pending; no public push or deployment approval is asserted. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Forward exact ee24037, including the prepared-legacy Helm watcher sequencing and foundation audit ancestry. Qualified controller/router/shared privacy code and Cargo files remain unchanged. Full hosted SRE qualification and bounded review are still pending; no publication or deployment approval is asserted. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Remove workload availability from the credential privacy barrier. Fresh denial, v2/UID/epoch/template verification and termination of old cached credential Pods remain required. The continuity regression retains zero SRE/normal available replicas, removes the actual old Pod instead of mutating its version, and proves Ready unlocks SRE authorization. 39 targeted tests and strict paired all-target Clippy pass; full hosted qualification and review remain pending. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Forward exact 4e012ec with arbitrary nested SREAction JSON preserved through the shipped CRD schema. Existing governed privacy repair code is unchanged. New schema Rust tests and full hosted SRE qualification remain pending; no public push, deployment or sign-off is asserted. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Pal Lakatos-Toth (pallakatos)
changed the base branch from
public/pr6-credential-sources
to
public/pr7-sre-authority
September 8, 2026 19:52
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Current combined prerequisite candidate
Current head:
068ae16041ecf7bd2b8321dfeb22e381ebbd587b. This draft now follows #551 (public/pr7-sre-authority), not the already-assembled credential-source feature branch. Do not merge into that intermediate base; #551 must qualify and land before this slice is retargeted tokars-bridge.The SRE privacy prerequisite is now integrated into control-credential issuance/reuse and owned revocation/rotation. Independent bounded review closed canonical-SRE early-return quarantine and the migration/readiness cycle: fresh privacy/identity/current-epoch checks and complete old cached-Pod retirement remain mandatory, but ordinary workload availability is not a prerequisite for establishing privacy authority.
Migratingdoes not authorize issuance or reuse.The two repair batches passed their targeted Rust cases and strict paired Clippy; source-level closure is recorded separately from human approval. The forwarded SRE action-schema repair also has independent Rust/Helm-drift and real API evidence. Existing dispatch/cancel/reset and telemetry repairs are retained.
Full combined hosted CI and actual SRE/governed-service lifecycle acceptance remain pending. The SRE fixture issue still blocks prerequisite acceptance. No human sign-off or signature waiver is claimed here, and this PR remains draft. The new private observer route and GitHub App-store materializer belong to the separate credential integration slice; they are not claimed by this candidate. No main promotion, private Bridge publication or customer deployment occurs. Historical preparation states follow.
Publication stack
Follows #549 and targets its credential-source branch for a focused delta. Do not merge into the intermediate feature branch. After preceding slices land, retarget to the protected
kars-bridgeintegration branch and require fresh exact-head CI, genuine audit sign-offs and independent approval. Final promotion tomainremains separate.Scope
router-services-admin/control-tokenis mounted only in the inference router. The legacy admin token and localhost alone cannot authorize inspection, decisions or reset.isError/transport failures. Observers must not replay accepted generations or alter provider credential routing.docs/governed-services.md.Explicit boundaries and later integration
This is service infrastructure, not assignment delivery, runtime workers, an autonomous approval/grant broker, keyless GitHub services, managed MCP/skill/memory installation, a durable execution/receipt ledger, or aggregate task-budget enforcement. Existing unsupported finite/shared launch budgets remain rejected. Ordinary standalone Kars requires no Bridge installation.
Later task delivery must call
POST /internal/access-requests/resetusing the separate private service-control credential and currentscope_id. Do not restore the old agent-visible-token/unscoped-reset contract. A future grant worker must compare current live Task UID, generation and full effective authorization before acting; resetting a request queue is not grant revocation.Telemetry retains bounded identifiers/status/timing/usage, not prompts, assistant text, arguments/results, URLs, headers or credential bodies. Explicit request reasons remain bounded untrusted agent text. State is in-process and not durable billing evidence.
Remaining HIGH prerequisite — not review-ready
The legacy SRE agent can read cluster-wide Kubernetes Secrets with its mounted ServiceAccount credential, including the new operator token. Router-only mounts do not establish privacy. The operator-authorized registration/migration prerequisite is now published as draft #551, which must qualify and be integrated before this service layer: trusted UID enrollment, safe retirement of legacy grants, preserved Azure identity and pinned-image compatibility, and a real filtered Kubernetes access path. Names, labels and ownership-looking annotations are not sufficient authority. The current published candidate remains unsafe for deployment until that HIGH is closed.
The two MEDIUM findings are repaired in
11f4224d: cancellation/reset now coordinate with a dispatch claim after awaited policy checks, and accepted failed/incomplete Responses or error-plus-DONE streams no longer become completed telemetry. The claim is distinct from upstream acceptance; response bytes and no-replay behavior are preserved. Bounded source review is closed, 1,071 router unit plus 29 service integration tests passed, and strict router Clippy passed. The exact-head CI suite now passes apart from the missing genuine audit signatures, including the existing Kind smoke (https://github.com/Azure/kars/actions/runs/34185514205/job/101937153329). That suite does not cover the unresolved SRE-held Kubernetes credential path; the HIGH remains a deployment and merge blocker.Do not mark this draft ready or merge it while the SRE prerequisite or genuine review/signature gates remain open.
Evidence and remaining gates
Current candidate:
11f4224d7c830b2c57878e356d1b4b20b13751e0, based on qualified namespace/credential stack head8b206065.ab3a9a7c(112 cases, zero failures; https://github.com/Azure/kars/actions/runs/34179155035/job/101919697541 ). This initial smoke covers mounts, simple credential rejection and scope reset, but does not test SRE-held Kubernetes authority, the cancellation interleaving or accepted semantic model errors. That initial-head CI result does not close the HIGH SRE authority issue; the two MEDIUM repairs have separate evidence above. The genuine-signature gate also remains blocked.docs/security-audits/2026-09-08-governed-router-services.md. Two genuine author/independent-reviewer sign-offs remain pending; the audit gate must not be bypassed or satisfied with fabricated identities.No customer/H100 deployment, Azure mutation, public image release, integration merge or main merge is performed by preparing this draft.