Epic: promote stable identities from council declarations #86

Open
opened 2026-09-03 23:08:24 +00:00 by larandar · 0 comments
Owner

Proposal

Coordinate the declared promotion path: flake-ops is the council-declaration authority, NixOps4 providers apply every declaratively expressible mutation, and Vedanta may expose a runtime duplicate only for workflow-time needs.

Design

  • The declaration names the stable Kanidm UUID, permanent mount binding, promoted role, council evidence, and ruling identity.
  • Providers converge declared identity and role state before Vedanta may perform any optional runtime credential operation.
  • Promotion is one-way. It is not a grant that later lapses.

Deliverables

Each lives in the repository that builds it. The Session tier was dissolved by freeholder ruling (Q3, 2026-09-04) — these are Deliverables under this Epic, not Sessions:

A Session re-forms only where the OpenSpec package's derived leaves show a coherent bundle of two or more in one repository.

Specification Delta

Requirement: declared promotion is declarative-first

Scenario: a council promotion declaration is applied

  • GIVEN a council promotion declaration in flake-ops
  • WHEN the promotion is applied
  • THEN NixOps4 providers apply every declaratively expressible change before any Vedanta runtime endpoint acts

Structural parent

Ting/Ting#85

Provenance

Superseding Ting/Vedanta#16.

## Proposal Coordinate the declared promotion path: flake-ops is the council-declaration authority, NixOps4 providers apply every declaratively expressible mutation, and Vedanta may expose a runtime duplicate only for workflow-time needs. ## Design - The declaration names the stable Kanidm UUID, permanent mount binding, promoted role, council evidence, and ruling identity. - Providers converge declared identity and role state **before** Vedanta may perform any optional runtime credential operation. - Promotion is one-way. It is not a grant that later lapses. ## Deliverables Each lives in the repository that builds it. The Session tier was dissolved by freeholder ruling (Q3, 2026-09-04) — these are Deliverables under this Epic, not Sessions: - [ ] [lar.ad/flake-ops#403](https://jo.et0.pw/lar.ad/flake-ops/issues/403) — declare council promotion rulings - [ ] [lar.ad/nixops4-providers#25](https://jo.et0.pw/lar.ad/nixops4-providers/issues/25) — apply declared promotion through nixops-kanidm - [ ] [Ting/Vedanta#18](https://jo.et0.pw/Ting/Vedanta/issues/18) — runtime credentials for declared promotion A Session re-forms only where the OpenSpec package's derived leaves show a coherent bundle of two or more in one repository. ## Specification Delta ### Requirement: declared promotion is declarative-first #### Scenario: a council promotion declaration is applied - **GIVEN** a council promotion declaration in flake-ops - **WHEN** the promotion is applied - **THEN** NixOps4 providers apply every declaratively expressible change before any Vedanta runtime endpoint acts ## Structural parent [Ting/Ting#85](https://jo.et0.pw/Ting/Ting/issues/85) ## Provenance Superseding [Ting/Vedanta#16](https://jo.et0.pw/Ting/Vedanta/issues/16).
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference
Ting/Ting#86
No description provided.