V0: Vedanta stands up #70
Labels
No labels
Compat/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Meta/Campaign
Meta/Epic
Meta/Session
Priority/Critical
Priority/High
Priority/Low
Priority/Medium
Reviewed/Confirmed
Reviewed/Curated
Reviewed/Duplicate
Reviewed/Invalid
Reviewed/Won't Fix
Scope/Campaign
Status/Abandoned
Status/Blocked
Status/Conflicted
Status/In Progress
Status/In Review
Status/Need Grooming
Status/Need More Info
Status/Ready
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Blocks
#84 Epic: Vedanta ceremony and custody governance
Ting/Jostoph
Reference
Ting/Jostoph#70
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
VfrontierMilestone V context: Vedanta is not a feature of Jostoph. It is the second steward: a sibling service on the same jostoph-rs substrate, with its own rules, its own policy derivation, its own record chain — and the one power Jostoph is deliberately denied: minting rights. Vedanta stewards the identity plane (Kanidm and Bao): service-account lifecycle, group standing, PKI epochs and succession, token policy, custody.
Separation of powers, stated as law: the steward that judges the forge holds no identity; the steward that mints identity holds no forge standing. Jostoph can never approve its own credentials into existence; Vedanta can never merge the PR that changes its own rules. Every escalation in either estate crosses the seam between them, where a human stands.
In scope
Ting/Vedanta: substrate, service unit, policy split (rules in Rust, parameters crystallized from Nix), record chain per S1/S2 — the Jostoph pattern, second instance.Out of scope
Boundary
flake checkassertion that guards Jostoph's listener guards this in mirror image.Acceptance
Source: JOSTOPH-BACKLOG.md, Milestone V.
larandar referenced this issue2026-08-29 17:05:03 +00:00
Lifecycle contract reconciliation: Vedanta is the hidden lifecycle effector, not the independent ruling or evidence authority. Jostoph owns observation and correlation across OpenBao, Vedanta, Kanidm, and Forgejo without joining the credential path. See Jostoph#103 and OpenSpec 103.