Session: Vedanta backend completion for the live lifecycle proof #49
Labels
No labels
Compat/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Meta/Campaign
Meta/Epic
Meta/Session
Priority/Critical
Priority/High
Priority/Low
Priority/Medium
Reviewed/Confirmed
Reviewed/Curated
Reviewed/Duplicate
Reviewed/Invalid
Reviewed/Won't Fix
Scope/Campaign
Status/Abandoned
Status/Blocked
Status/Conflicted
Status/In Progress
Status/In Review
Status/Need Grooming
Status/Need More Info
Status/Ready
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Blocks
Reference
Ting/Vedanta#49
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Proposal
Why
Vedanta#20 closed 2026-09-03 with the lease contract, private command ABI, both mutation adapters, and lost-response semantics proven against capture doubles only (its closure comment says so plainly). A 2026-09-05 gap analysis of fastlane
02fa9adagainst the ratifiedcontracts.identity.openbao-lease-backendspec (store1d8f945, 16 requirements) found the remaining distance to the live lifecycle: one requirement unimplemented (queen handover), nine partial, and six normative divergences. This Session completes the backend to the point where the production proof (flake-ops#435/#154) can exercise it — capture-double-completable work only; live-environment acts stay operator-gated elsewhere.Scope
Everything below is library code proven against capture doubles. No live Kanidm/Forgejo/OpenBao contact, no deployment, no service wiring beyond what tests exercise.
Design
Projects from
contracts.identity.openbao-lease-backend(spec + design) and the canonical acceptance spec (forge-lifecyclereferences, Gates 3A, 5, 6, 7). Structural parent: Ting/Ting#60. Continues Vedanta#20 (closed; not reopened — this is new scope found in review, per the no-bounce doctrine).Two divergences are resolved by the ratified spec's own text (queen ruling, disclosed provenance, Vedanta run 2026-09-05):
private_api.rs'sOperationReplaydenial changes to routing replays toJournal::status.private_api.rs:566-573) converges to the plugin's subset semantics (issue.rs:290-296).The pool-ownership question (D1 of the gap memo:
PoolDirectorycreates principals while the transcribed contract assigns creation to providers) is excluded pending the freeholder's ruling — no productionPoolDirectoryadapter in this Session.Tasks
MutationAdapter:ValidatedCommand→ kanidm/forgejo calls (mint/rotate/invalidate incl. Forge token delete-with-verification), double-tested.IssueService/LeaseServiceexercised against the realValidator+Journal(catches the unfilled invalidation command,lease.rs:310-343).read/rotate.RevocationPending⇒ worker ineligible; deletion-verified step before a slot frees.kanidm_event_idnaming).WrapStorewith one-shot/consume/expiry semantics proven against a double.reconcile.rs).Specification Delta
None — this Session implements the existing ratified spec; it amends nothing. Any discovered need to change normative wording returns to the freeholder as a decision, not a code edit.
Provenance
Filed by the 2026-09-05 Vedanta lifecycle run (queen seat, DSH session aaa849b2) under vedanta-implementation-plan.md §2. Evidence: gap-analysis memo against store
1d8f945and Vedanta02fa9ad(run journal~/.agents/vedanta-run-2026-09-05/).