Persist the operation journal and non-secret status acknowledgements #21
Labels
No labels
Compat/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Meta/Campaign
Meta/Epic
Meta/Session
Priority/Critical
Priority/High
Priority/Low
Priority/Medium
Reviewed/Confirmed
Reviewed/Curated
Reviewed/Duplicate
Reviewed/Invalid
Reviewed/Won't Fix
Scope/Campaign
Status/Abandoned
Status/Blocked
Status/Conflicted
Status/In Progress
Status/In Review
Status/Need Grooming
Status/Need More Info
Status/Ready
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Reference
Ting/Vedanta#21
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Proposal
Persist Vedanta lifecycle operations so each mutation is write-ahead, idempotent, restart-safe, and observable without credential material.
Delivery class
agent-unit— addsrc/operations.rswith restart and replay tests.Design
Write a durable record before mutation. One operation ID causes at most one Kanidm mutation. Completed status and acknowledgement contain identifiers and outcomes only. Local audit failure denies before mutation.
Tasks
Specification Delta
Requirement: one operation ID mutates at most once
Scenario: a completed operation is replayed
OpenSpec
OpenSpec 20
Structural parent
Vedanta#20
Persist replay-safe lifecycle operations and compensate lost deliveryto Persist the operation journal and non-secret status acknowledgementslarandar referenced this issue2026-08-30 08:55:04 +00:00
larandar referenced this issue2026-09-02 19:23:32 +00:00