2 OpenSpec 103 forge identity lifecycle audit
~larandar edited this page 2026-08-29 22:08:01 +02:00
This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

OpenSpec 103 — Forge identity lifecycle audit

Status: proposed
Version: 0.1.0
Session: Ting/Jostoph#103
Epics: Ting/Ting#60, Jostoph#84

Proposal

Jostoph independently ingests and correlates lifecycle evidence across OpenBao, Vedanta, Kanidm, the adapter, and Forgejo. It reports missing, contradictory, pending, and drifted state without identity authority and without credential values.

Design

The formal package is under openspec/changes/forge-identity-lifecycle-audit. The complete source package is pinned in references/canonical/ with the common manifest. OpenSpec 61 remains governing.

This package amends the older #70/#84 vocabulary: Vedanta is a private effector in this lifecycle, not the ruling authority. Jostoph observes and joins evidence; it does not mint, revoke, activate, or infer success.

Tasks

  • #104 — define the canonical lifecycle audit envelope.
  • #106 — authenticate, validate, and durably append lifecycle events.
  • #107 — materialize the lifecycle correlation view.
  • #108 — prove replay, duplicate, restart, and quarantine behavior.
  • #105 — detect canonical lifecycle drift C01C08.
  • #109 — render production acceptance and old-path exit readiness.

Specification Delta

The delta adds an independent evidence chain keyed by grant, lease, operation, token and resource event; preserves per-layer outcomes; forbids bearer values; detects every canonical drift class; and requires all production acceptance facts rather than a nearby success. The six leaves form one Session because the resulting contract, implementation, and evidence fit one PR review—not because of a fixed leaf-count rule.