Define the canonical lifecycle audit envelope #104

Closed
opened 2026-08-29 17:05:57 +00:00 by larandar · 1 comment
Owner

Objective

Define the normative, non-secret lifecycle event envelope shared by OpenBao, Vedanta, Kanidm integration, the Forge adapter, and Jostoph.

Scope

Specify event kinds, emitter identity, correlation IDs, generations, timestamps, outcomes, reason codes, retryability, provenance, and forbidden fields. This leaf changes the contract and fixtures, not the ingest service.

Acceptance criteria

  • Every lifecycle layer has an explicit event kind and stable correlation fields.
  • Outcomes remain component-local and cannot imply another component succeeded.
  • Credential values and derived bearer material are normatively forbidden.
  • Valid, invalid, and forbidden-field fixtures are versioned for all consumers.

Spec Delta

The former ingest-and-correlation issue is narrowed to the shared envelope contract. Implementation is split into #106-#108.

OpenSpec

OpenSpec 103

## Objective Define the normative, non-secret lifecycle event envelope shared by OpenBao, Vedanta, Kanidm integration, the Forge adapter, and Jostoph. ## Scope Specify event kinds, emitter identity, correlation IDs, generations, timestamps, outcomes, reason codes, retryability, provenance, and forbidden fields. This leaf changes the contract and fixtures, not the ingest service. ## Acceptance criteria - [ ] Every lifecycle layer has an explicit event kind and stable correlation fields. - [ ] Outcomes remain component-local and cannot imply another component succeeded. - [ ] Credential values and derived bearer material are normatively forbidden. - [ ] Valid, invalid, and forbidden-field fixtures are versioned for all consumers. ## Spec Delta The former ingest-and-correlation issue is narrowed to the shared envelope contract. Implementation is split into #106-#108. ## OpenSpec [OpenSpec 103](https://jo.et0.pw/Ting/Jostoph/wiki/OpenSpec-103-forge-identity-lifecycle-audit)
larandar changed title from Ingest lifecycle events into an independent correlation chain to Define the canonical lifecycle audit envelope 2026-08-29 20:06:21 +00:00
Author
Owner

Closed under audit 2026-09-19/20, G13. Merged PR#120 (merged 2026-09-06) delivers the canonical lifecycle audit envelope for this record. Residual D3 and the unrun nix flake check are split to successor issue #125 (#125): Residue of Session #103: D3 decision + nix flake check (audit G13).

<!-- larandar:groom:v1 --> Closed under audit 2026-09-19/20, G13. Merged PR#120 (merged 2026-09-06) delivers the canonical lifecycle audit envelope for this record. Residual D3 and the unrun nix flake check are split to successor issue #125 (https://jo.et0.pw/Ting/Jostoph/issues/125): Residue of Session #103: D3 decision + nix flake check (audit G13).
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference
Ting/Jostoph#104
No description provided.