Promote stable identities from council declarations #16

Closed
opened 2026-08-26 10:23:57 +00:00 by agent.odin · 1 comment
Owner

Proposal

Coordinate the declared promotion path: flake-ops is the council-declaration authority; NixOps4 providers apply every declaratively expressible mutation; Vedanta may expose a runtime duplicate only for workflow-time needs.

Design

  • The declaration names the stable Kanidm UUID, permanent mount binding, promoted role, council evidence, and ruling identity.
  • NixOps4 providers converge declared identity and role state before Vedanta can perform an optional runtime credential operation.

Tasks

  • Complete the declaration, provider, and runtime sessions.

Specification Delta

Requirement: declared promotion is declarative-first

  • GIVEN a council promotion declaration in flake-ops
  • WHEN the promotion is applied
  • THEN NixOps4 providers apply every declaratively expressible change before any Vedanta runtime endpoint acts
## Proposal Coordinate the declared promotion path: flake-ops is the council-declaration authority; NixOps4 providers apply every declaratively expressible mutation; Vedanta may expose a runtime duplicate only for workflow-time needs. ## Design - The declaration names the stable Kanidm UUID, permanent mount binding, promoted role, council evidence, and ruling identity. - NixOps4 providers converge declared identity and role state before Vedanta can perform an optional runtime credential operation. ## Tasks - [ ] Complete the declaration, provider, and runtime sessions. ## Specification Delta ### Requirement: declared promotion is declarative-first - GIVEN a council promotion declaration in flake-ops - WHEN the promotion is applied - THEN NixOps4 providers apply every declaratively expressible change before any Vedanta runtime endpoint acts
Owner

Superseded by Ting/Ting#86 — freeholder ruling Q1 (2026-09-04): this Epic (promotion) moves to the estate tracker.

The work spans three repositories, and Vedanta holds the optional half — providers are the required declarative path, and this repository "must not be the sole implementation of any declaratively expressible operation". A record governed from the repository that owns its optional half is governed from the wrong place, and its OpenSpec package would have lived in this wiki rather than the estate store.

The contract is now OpenSpec 85, authored today. The Session tier was dissolved by Q3: the six nodes become Deliverables under their Epics, each reviewed in the repository that builds it.

Nothing is lost by closing this. The grooming history here — including the 2026-08-26 sizing ruling that governs the decomposition — is cited from the superseding record. Vedanta keeps its own two Deliverables, #18 and #19, re-pointed at the new Epics.

**Superseded by [Ting/Ting#86](https://jo.et0.pw/Ting/Ting/issues/86)** — freeholder ruling Q1 (2026-09-04): this Epic (promotion) moves to the estate tracker. The work spans three repositories, and Vedanta holds the **optional** half — providers are the required declarative path, and this repository *"must not be the sole implementation of any declaratively expressible operation"*. A record governed from the repository that owns its optional half is governed from the wrong place, and its OpenSpec package would have lived in this wiki rather than the estate store. The contract is now [OpenSpec 85](https://jo.et0.pw/Ting/Ting/wiki/OpenSpec-85-stable-identity-promotion-and-suppression), authored today. The Session tier was dissolved by Q3: the six nodes become Deliverables under their Epics, each reviewed in the repository that builds it. **Nothing is lost by closing this.** The grooming history here — including the 2026-08-26 sizing ruling that governs the decomposition — is cited from the superseding record. Vedanta keeps its own two Deliverables, [#18](https://jo.et0.pw/Ting/Vedanta/issues/18) and [#19](https://jo.et0.pw/Ting/Vedanta/issues/19), re-pointed at the new Epics.
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
Ting/Vedanta#16
No description provided.