Epic: Forge identity lifecycle — OpenBao leases, Vedanta effect, Kanidm credentials #60
Labels
No labels
Compat/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Meta/Campaign
Meta/Epic
Meta/Session
Priority/Critical
Priority/High
Priority/Low
Priority/Medium
Reviewed/Confirmed
Reviewed/Curated
Reviewed/Duplicate
Reviewed/Invalid
Reviewed/Won't Fix
Scope/Campaign
Status/Abandoned
Status/Blocked
Status/Conflicted
Status/In Progress
Status/In Review
Status/Need Grooming
Status/Need More Info
Status/Ready
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Blocks
Depends on
You do not have permission to read 3 dependencies
Reference
Ting/Ting#60
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Proposal
Outcome
Deliver the ratified Forge identity lifecycle 0.1.4: OpenBao is the only workload-facing lease authority; Vedanta is its private effector; Kanidm owns durable principal and credential state; and Forge access uses bounded, per-lease capabilities without per-drone Forgejo accounts. Ordinary completion returns the same durable worker UUID to the pool under a new immutable grant and generation.
Why
The earlier backlog carried incompatible direct, KV-only, provider-minting, bootstrap, and policy-authority roads. The ratified contract and native Session graph make those roads temporary and give their retirement objective production gates.
Design
AssignmentGrantis the immutable, versioned authority join; RFC 8785 digest, UUID, generations, projections, custody, evidence, lifecycle, and decommission rules are binding.swarm-alpha/queenseat. A seat is runtime authority, not identity; handover revokes the old tenure before issuing a distinct successor tenure.swarm-alphapool has ten stable slots. Automation reserves each finalswarm-alpha-drone-<word>-<word>-<word>-<word>name before creation, creates or adopts the principal with swarm/slot metadata, reads and pins its UUID without renaming, and generates one distinct immutable queen-delegated grant for every pool member.revocation_pendingand blocks worker reuse.Delivery frontier
The native dependency graph is authoritative:
Within deployment:
#432/#433 deliver generic inactive machinery; #427 realizes and gates the ten-grant pool; #434 proves the private topology. The workload Session #435 ends at #154's operator-gated production lifecycle, same-UUID reuse, and legacy-path retirement proof.
Tasks
Specification Delta
Requirement: machinery precedes realized authority
Scenario: the pool becomes eligible for activation
Requirement: ordinary completion preserves the durable worker
Scenario: a production session ends
Requirement: legacy roads have measurable exits
Scenario: decommission is proposed
OpenSpec
OpenSpec 61 — Forge identity lifecycle contract 0.1.4
larandar referenced this issue from Ting/Jostoph2026-08-29 17:05:03 +00:00
larandar referenced this issue2026-08-29 21:06:44 +00:00
larandar referenced this issue2026-08-29 21:06:44 +00:00
larandar referenced this issue2026-08-29 21:06:45 +00:00
larandar referenced this issue2026-08-29 21:06:45 +00:00