V0: Vedanta stands up #70

Open
opened 2026-08-12 16:16:16 +00:00 by agent.teyla · 1 comment
Contributor

V frontier

Milestone V context: Vedanta is not a feature of Jostoph. It is the second steward: a sibling service on the same jostoph-rs substrate, with its own rules, its own policy derivation, its own record chain — and the one power Jostoph is deliberately denied: minting rights. Vedanta stewards the identity plane (Kanidm and Bao): service-account lifecycle, group standing, PKI epochs and succession, token policy, custody.

Separation of powers, stated as law: the steward that judges the forge holds no identity; the steward that mints identity holds no forge standing. Jostoph can never approve its own credentials into existence; Vedanta can never merge the PR that changes its own rules. Every escalation in either estate crosses the seam between them, where a human stands.

In scope

  • Ting/Vedanta: substrate, service unit, policy split (rules in Rust, parameters crystallized from Nix), record chain per S1/S2 — the Jostoph pattern, second instance.
  • Event sources: Kanidm and Bao audit streams in, the same way Forgejo webhooks feed Jostoph. Signed at ingestion boundary, recorded, ruled on.
  • Answers-only at birth: declares effects (a mint it would perform, a membership it would revoke), performs none.

Out of scope

  • Any performed mint (Vedanta's own M3, gated on its own dry-run corpus, as X1 was).

Boundary

  • Vedanta holds no Forgejo credential and no forge standing, ever. The flake check assertion that guards Jostoph's listener guards this in mirror image.

Acceptance

  • A Kanidm group change and a Bao issuance each produce one ruled, signed record; Jostoph's chain independently carries the fact that Vedanta ruled.

Source: JOSTOPH-BACKLOG.md, Milestone V.

`V` `frontier` Milestone V context: Vedanta is not a feature of Jostoph. It is the **second steward**: a sibling service on the same jostoph-rs substrate, with its own rules, its own policy derivation, its own record chain — and the one power Jostoph is deliberately denied: **minting rights**. Vedanta stewards the identity plane (Kanidm and Bao): service-account lifecycle, group standing, PKI epochs and succession, token policy, custody. Separation of powers, stated as law: *the steward that judges the forge holds no identity; the steward that mints identity holds no forge standing.* Jostoph can never approve its own credentials into existence; Vedanta can never merge the PR that changes its own rules. Every escalation in either estate crosses the seam between them, where a human stands. **In scope** - `Ting/Vedanta`: substrate, service unit, policy split (rules in Rust, parameters crystallized from Nix), record chain per S1/S2 — the Jostoph pattern, second instance. - Event sources: Kanidm and Bao audit streams in, the same way Forgejo webhooks feed Jostoph. Signed at ingestion boundary, recorded, ruled on. - Answers-only at birth: declares effects (a mint it would perform, a membership it would revoke), performs none. **Out of scope** - Any performed mint (Vedanta's own M3, gated on its own dry-run corpus, as X1 was). **Boundary** - Vedanta holds no Forgejo credential and no forge standing, ever. The `flake check` assertion that guards Jostoph's listener guards this in mirror image. **Acceptance** - A Kanidm group change and a Bao issuance each produce one ruled, signed record; Jostoph's chain independently carries the fact that Vedanta ruled. Source: JOSTOPH-BACKLOG.md, Milestone V.
Owner

Lifecycle contract reconciliation: Vedanta is the hidden lifecycle effector, not the independent ruling or evidence authority. Jostoph owns observation and correlation across OpenBao, Vedanta, Kanidm, and Forgejo without joining the credential path. See Jostoph#103 and OpenSpec 103.

<!-- forge-identity-lifecycle-distribution:2026-08-29 --> Lifecycle contract reconciliation: Vedanta is the hidden lifecycle effector, not the independent ruling or evidence authority. Jostoph owns observation and correlation across OpenBao, Vedanta, Kanidm, and Forgejo without joining the credential path. See [Jostoph#103](https://jo.et0.pw/Ting/Jostoph/issues/103) and [OpenSpec 103](https://jo.et0.pw/Ting/Jostoph/wiki/OpenSpec-103-forge-identity-lifecycle-audit).
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference
Ting/Jostoph#70
No description provided.