feat(credentials): add governed grants and purpose-limited observations - #554
feat(credentials): add governed grants and purpose-limited observations#554Pal Lakatos-Toth (pallakatos) wants to merge 35 commits into
Conversation
Preserve optional standalone behavior and isolate GitHub App credentials by exact identity, installation and repository. Include governed Actions logs and reviewed gzip/permission repairs. Local Rust/runtime qualification and bounded automated closure are complete; operator materialization, SRE privacy-gate integration and full acceptance remain explicit blockers. This is a local checkpoint, not public readiness or deployment. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Local, unpublished implementation checkpoint. Rust and real API qualification remain pending; the operator observation and GitHub issuer seams require the approved privacy integration. No release or security sign-off is implied. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Forward merge 7dc7281 locally for downstream issuer integration. Candidate qualification is still pending; no public push or sign-off. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Retain explicit unqualified lifecycle, UID and privacy blockers; this local checkpoint is not a publication or sign-off. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Forward exact d3dc3ce and reuse its mount helper once. Existing privacy ancestor 7dc7281 remains intact. Combined issuer and observer Rust qualification and recorded authority/lifecycle closures remain pending; no publication or sign-off. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Keep the reviewed runtime JSON schema unchanged. Rotate the private Secret and cached consumers for changed source/authority revisions even when material bytes are identical; preserve typed Pending privacy non-issuance. Add unrun Rust regressions and canonical App ID serialization. Combined Cargo qualification and recorded boundary closures remain pending. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Forward exact 068ae16 while retaining GitHub d3dc3ce and issuer rotation repairs. The offered Cargo lease was released unused before this prerequisite merge. Eleven read-only bootstrap fixtures and nineteen credential CLI/schema tests pass; combined Rust qualification and documented boundary closures remain pending. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Use read-only preflight before ordinary Ready without a self-bootstrap cycle. Preserve status lineage and pause UID-owned governed execution instead of deleting namespace/state. Keep optional observer availability independent of source readiness and prevent retired GitHub projections from returning through the legacy optional mount. Twenty fast tests and CLI types pass; new Rust regressions remain unrun. No Cargo lease held or publication approval claimed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Retain valid delivery after writer retirement, protect enrolled reader names, and add explicit observer egress and purpose boundaries. Active-SRE observation privacy remains an explicit architecture blocker; no rollout is authorized. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Forward public 550 at 2d85d5a without copying private implementation. Keep credential candidate scope and standalone behavior intact; qualification is recorded separately. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Record the public 550 forward, guarded Rust results, explicit lease release and remaining privacy/API qualification boundaries without claiming native Secret GET is UID-aware. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Verify current canonical observation credentials and full privacy authority on every bounded TLS request. Bind proofs to target, grant, recipient identities, purpose, version, scope and nonce; pin live verifier identity, expire credentials and gate readiness on real capability. Retain name-hold lifecycle guards and standalone defaults. Core qualification passed; real Kind/CNI, private BFF Rust and independent review remain required. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Repair ordered-mask attenuation, persistent import removal intent, local legacy discovery failures and referenced-credential rollout revisions. Replace Team credential unlaunch with owned pause/quiescence, current authority/receipt regeneration and fenced resume. Add focused API/full-reconcile regressions. Fast checks pass; core Rust qualification and bounded re-review remain required. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Apply the three explicitly approved compile corrections: point to the rebind tests, expose the unchanged runtime hold function at intended module scope, and import ListParams. Reviewed behavioral bodies are unchanged; private BFF is untouched. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Complete the approved test-module wiring correction without changing test or production behavior. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Use a lexical MutexGuard scope instead of explicit drop and collapse the equivalent CAS predicate in the API fixture. No production or test assertions changed; no lint waivers. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Record the approved mechanical corrections, passing targeted semantics and strict paired Clippy, immutable qualified code head, explicit Cargo lease release and remaining independent/private acceptance gates. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Use the existing full SHA-256 provider boundary for controller revisions, GitHub connection names and shared observation proof digests. Preserve the full 64-hex proof/revision contract and 16-hex connection suffix; do not use the truncated content identifier. Add a fixed wire digest regression and update the fixture without adding dependencies or crypto waivers. 32 affected cases and strict paired Clippy pass under the 8.5 GiB floor. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
…urce gates The production GitHub service now opens only its literal mounted configuration path; mutable path injection exists solely in test code, sharing the same bounded reader. No HTTP/configuration input can select another production file. Preserve credential rotation behavior and normal test fixtures. Extract the unchanged suspend/rebind replica decision into its owner module and cover all combinations, keeping the existing reconciler cap. Apply the full existing formatter instead of waiving CI. Affected tests, production binary checks, paired strict Clippy and the real cap/schema regression pass. No CodeQL alert is dismissed or query excluded. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
|
Owner-approved CodeQL disposition: alert 804 ( The sink at Only alert 804 is dispositioned. No query exclusion, security-check removal, audit-signature waiver, or merge approval is implied. Native credential/ServiceAccount/CNI and combined active-SRE qualification remain outstanding; this PR stays draft. |
Keep exact namespace UID checks using the actual Kubernetes JSON field despite the CEL NamespaceMetadata declaration mismatch. Add a native hosted positive/negative/positive probe using unchanged shipped predicates and owned fixtures, with precise denial assertions and bounded cleanup. Preserve bounded credential/GitHub schemas in generated Task/Team CRDs, compare rendered Helm includes, and add canonical grant CEL and standard labels. Local qualification: 30 Helm drift, 17 CNCF, 84 controller credential, 16 CLI contract and 53 Python harness cases; strict paired Clippy/fmt. Native API execution and complete hosted qualification remain pending. No audit signature or gate waiver. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…ures Replace the controller probe bytes_stream dependency with Response::chunk, preserving bounded buffering and explicit transport/JSON failure. Full paired builds masked the missing reqwest stream feature in controller-only benchmark compilation (job102638710681 at f8d641f). Add exact-limit, oversize, truncated-body-after-valid-JSON and invalid-JSON HTTP regressions. This is a LOCAL checkpoint: Rust execution and isolated-controller compilation are pending the exclusive composition qualification owner; no public push or benchmark waiver. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Combine Secret key lists rather than heterogeneous byte/string value maps; compare the nullable paused envelope digest dynamically; and dynamically select kind-specific exposure fields behind unchanged kind guards. Keep every UID, purpose, current-generation, Ready=False, selector, resource, denial and Fail/Deny constraint. The broader native API run against f8d641f exposed these type-check warnings; 17 CLI contract cases and Helm rendering pass for the repair. Native positive/negative cases are being added separately and remain required. No warning suppression or audit waiver; local checkpoint only. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Use unchanged rendered predicates in uniquely scoped real API fixtures. Require current warning-free type checks, exact intended allow/deny outcomes for Secret wire representations, nullable paused Task authority and public exposure, and UID-safe cleanup without starting custom controllers or public workloads. 74 unit/harness cases pass; no native result is claimed until hosted execution. Preserve all existing SRE/full gates and diagnostic privacy; native policy failure does not skip the unchanged bootstrap gate. No authentication, quiescence or CNI claim from administrative expression fixtures. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Kubernetes omits empty AdmissionRequest.subResource. Normalize only its absence to the primary-resource empty string across grant, reader-finalization and SRE token policies. Keep explicit status/token/finalize authority unchanged; no admission or permission bypass. Extend native policy qualification to install the actual grant-authority policy before primary creation, metadata and status updates, plus a regression refusing to pre-seed around admission. 75 unit/harness cases, 17 CLI contracts and Helm lint pass; expanded native qualification remains pending. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Reuse the existing minimal SRE fixture chart for the fresh-install case instead of rendering every unrelated template under the test deadline. Preserve all namespace/account ownership assertions and existing live-lookup upgrade cases. Make fresh rendering explicitly client-only and bound its child process below the unchanged test deadline. All 24 related namespace, SRE-authority and credential-contract cases passed. No production changes, timeout increase or skipped assertions. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Forward only the three match conditions from native-qualified SRE 3f20fac. Preserve protected oldObject names when collection DELETE omits request.name, without mixed string/dyn lists. Registrar/use/renew rules, bindings and existing optional-subresource repair remain intact. All three match-condition blocks compared byte-identical to 3f20; its job102698405012 proved nine ordinary/protected/admin collection cases. Current target passed 25 related CLI contracts and Helm lint. Target lifecycle/full SRE acceptance remains pending; no forced namespace finalization or gate waiver. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Real Kind API proof: Accept text/plain returns 406 for Pod logs, while application/json and wildcard return 200. Use wildcard only on the bounded upstream log path; keep the facade's plain-text response, byte/query caps, private authority checks and all JSON/media boundaries unchanged. Add HTTPS regression reproducing the native 406 before verifying raw log delivery. Python: 84 passed; no local Cargo, normal CI dependencies retained. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903 (cherry picked from commit 4b4a92a)
…ition Forward the reviewed typed-list projection from SRE026cda4f: native SecretList items may omit per-item TypeMeta, while conflicting types and typeless top-level values remain rejected. Preserve value/annotation redaction and list pagination metadata. The accurate native-list fixture exposed a 502 compatibility failure after the log-media forward; the corrected projection restores the intended 200 redacted response. All13 SRE proxy tests and strict paired-library Clippy pass under the8.5GiB guard (minimum9.79GiB). No raw credential exposure, ambient fallback or permission widening. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…ledgement Include v2 and GitHub bindings in the existing 30-second credential refresh backstop while preserving 300-second legacy cadence. Stop rebind phase/detail toggling after authority is already retracted, retaining every initial UID/resourceVersion-fenced status patch before receipt/hold/pause side effects and all-Pod quiescence. Reproduce the original status-churn regression, preserve actual no-op API semantics in the HTTP fixture, and add stable waiting and stale-acknowledgement rejection coverage. Final 90 controller-binary credential tests and strict paired all-target Clippy pass. Independent bounded source review found no significant issues. Actual downstream Team-rebind and grant-disable acceptance remain pending; no timeout, admission, ownership, attestation or audit waiver. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…e labels Share the exact existing runtime Pod labels between generation, observer RPC isolation proof, and approved sender egress evaluation. Correct the missing component-label false negative without changing any emitted label, NetworkPolicy, grant, namespace or port restriction. Add component baseline and exact-name sender regressions, retaining observer-only policy exclusion and foreign-selector rejection. All 92 controller-binary credential tests and strict paired all-target Clippy pass; bounded independent source review found no significant issues. Native observer/TLS/CNI and complete downstream acceptance remain required, with no human audit waiver. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…ition Forward exact c08465a policy and native regression repair. The composed API proof found ordinary ReplicaSet creation allowed but private creation denied for the built-in Deployment controller, which has cluster-wide ReplicaSet-create rather than Pod-create authority. Recognize that existing capability only for apps/replicasets; retain all other predicates and grant no RBAC. The resulting consumer policy is byte-identical to native-qualified 203e232. All 67 Python regressions and Helm lint pass, and independent bounded source review found no significant issues. Include real private Deployment-to-ReplicaSet-to-unscheduled-Pod UID-chain assertions. Fresh composed readiness and genuine audit signoffs remain required; no private active-run pin change or customer deployment. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…t lineage Actual native metadata-only audit showed the core controller receives 403 when existing observer verification gets its consumer ReplicaSet. Add only apps/replicasets GET to the existing credential-controller role, keeping its sole core ServiceAccount binding and all UID/Deployment-lineage checks. No list/watch/write permissions or other actor bindings are added. Add a rendered-role contract regression and record the existing ephemeral workspace scope. Helm lint passes; the locked local Vitest version is unavailable and a mismatched cache was rejected, so the existing hosted CLI job must qualify that regression before merge. Native observer issuance/TLS/CNI remain mandatory. No H100/customer/main change. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…ive diagnostics Keep all authority, TLS, proof and readiness decisions unchanged. Record only fixed failing stages, HTTP status and transport classification, including cancelled checks. Add diagnostic regression tests and operator interpretation guidance. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Match the existing serialized Status fixture pattern instead of the legacy unboxed ErrorResponse type. No production readiness or authority behavior changes. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
… stack Restack the existing credential PR on signed services source 6b34d5e while preserving the reviewed failure-only observer diagnostics. Retain v1/v2/GitHub and registered SRE refresh, full private workload/cleanup probes, and stronger current-epoch/control-version privacy semantics. No readiness, TLS, authority or egress policy is relaxed. Rustfmt, Helm lint, 108 SRE Python cases and 46 credential-schema cases pass. Local Cargo remains blocked by the shared disk floor; hosted Rust/Clippy and the private native workflow must qualify the changes. Diagnostics export only fixed stages/status/transport categories, not secrets or bodies. No new public diagnostic branch or H100 deployment. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Current candidate and publication position
Draft, unmerged:
5ba25c4f4cee2e36e63f431dae1b591520da64d8. Source repairs are published; complete native acceptance and genuine audit approval are still outstanding.This core credential/observer candidate is based on #550 and depends on the SRE prerequisite #551. Do not merge into the intermediate feature branch: qualify the full composition and retarget to protected
kars-bridgeafter its prerequisites land. The separate Bridge application remains private in pallakatos/kars-bridge#31; it is not copied here.Core scope
Latest concrete repairs
9897986c: v2 and GitHub credentials now use the existing 30-second authority-refresh backstop, while unbound legacy Sandboxes retain five minutes. Current rebind pause/waiting states no longer toggle on every reconciliation. Every initial status PATCH still checks UID/resourceVersion before receipt, hold or pause side effects; all remaining Pods, including terminating Pods, must stop.2d5dba10: observation policy evaluation and Pod generation share the exact same existing runtime labels. This fixes a missing-component-label false negative without changing actual labels, NetworkPolicies, ports, grant or privacy requirements.5ba25c4f: forwards the native-qualified SRE Deployment-controller handoff. Onlyapps/replicasetsworkload admission recognizes existing cluster-wide ReplicaSet-create authority. No RBAC grant or Pod/Deployment/Job/CronJob exception is added.Evidence and limits
The latest credential Rust source passed 92 controller-binary credential cases and strict paired all-target Clippy. Regressions cover refresh selection, stable pause/waiting state, stale-snapshot rejection before side effects, actual runtime-label selection and retained denials. The subsequent SRE policy/test forward passed 67 Python harness cases and Helm lint. Bounded independent source reviews closed these repairs; they do not supply human signatures.
The complete SRE consumer-policy template is byte-identical to isolated
203e2322, whose full Kind run passed 161 cases. Earlier public native jobs also prove the 42-case policy matrix and primary grant CREATE/UPDATE/status operations. These are scoped prerequisite results, not success of this entire composition.Exact-head full CI completed with the full Kind lane failing legacy SRE readiness at
migration.py:161; its other jobs passed. The audit gate remains blocked on genuine author/independent-reviewer signatures. No earlier feature waiver applies.Prior downstream native outcome at core
2d5dba10: 11 passed, 2 failed, 3 blocked. Grant revocation stopped its consumer in 58.93 seconds, within the unchanged 180-second gate. Team rebind resumed with updated credentials, current authority and a matching receipt, preserving object UIDs and namespace-owned data; the former Team gate nevertheless failed because it also demanded that an/sandboxmarker survive Pod replacement.Publication scope correction: both the canonical product and this public core use
emptyDirfor/sandbox. Persistent workspaces are a separate enhancement, not a requirement for publishing the existing product. The corrected downstream acceptance explicitly verifies the existing ephemeral volume before and after replacement, a new writable workspace, and all retained governance/UID/receipt/credential/namespace-resource continuity assertions. Its contract is named in the result; a fresh run against core5ba25c4fis pending. The historical failed run is not relabeled as a pass, and this release adds no PVC or migration feature.The independent observer Pod was Pending/Unschedulable; its precise scheduler reason was not retained. Fixed, secret-free scheduler categories have been added for the fresh run. Observer issuance, TLS/CNI traffic and rotation remain mandatory and unqualified, as does the complete active-SRE composition. Native Secret GET remains Kubernetes name-based authorization; do not infer end-to-end UID continuity from source checks alone. No security or credential lifecycle gate is waived, and no acceptance timeout is raised.
Audit: governed credential qualification record.
No
mainpromotion, customer/H100 deployment, image publication, private source disclosure or merge-safeguard exception is included.