Skip to content

feat(integration): compose authenticated Vault plugin operator authority - #243

Draft
seonghobae wants to merge 10 commits into
feat/plugin-vault-secret-store-v1from
feat/plugin-vault-operator-composition-v1
Draft

feat(integration): compose authenticated Vault plugin operator authority#243
seonghobae wants to merge 10 commits into
feat/plugin-vault-secret-store-v1from
feat/plugin-vault-operator-composition-v1

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Buyer/security outcome

Advances #130 beyond a standalone Vault adapter by composing it with authenticated Plugin operator authority. The composition reads verifier/Vault configuration only from Integration-owned configuration, combines signed workspace+user authority with durable replay consumption, and routes credential plaintext only through PluginVaultSecretStore; durable LifeOS metadata retains only opaque secret references.

Current stack

Parent #242 remains e753de422be91d0962a8fd260c5ce366994acb54. Current exact #243 head d03b886f67552e6bb2b53352087d2041dedba07c is open Draft/mergeable and ahead-only of the current parent. No predecessor check/review evidence transfers.

This slice preserves authenticated Vault operator composition, INTEGRATION_PLUGIN_VAULT_*-only configuration authority and Proposed ADR 0004. Hosted PostgreSQL bootstrap remains a successor rather than being pulled backward into this bounded slice.

Hosted successor #244 remains exact f0b91869f306b1b7d0d5759307acf347e413aa06. Concrete PostgreSQL/default-entrypoint successor #245 is now workflow-free exact 39ebec99d907356a99a1a15528a3a1df713472ed. Its lineage retains PostgreSQL driver/migration acceptance, replay fences after provider I/O, and real Vault KV v2 + migrated PostgreSQL lifecycle acceptance.

The real-Vault gap is no longer prose-only. Exact #245 ancestor 21b5c206decf1ca6a9b337811a56bddce39ff730 completed hosted run 34166380591 across installation → credential create → exact replay → installation revocation fencing → runtime restart → credential revocation → idempotent cleanup using concrete Vault and Integration-owned PostgreSQL. A later complete PostgreSQL-enabled suite exposed three inherited #245 test-expectation defects; #245 owner run 34195380880, job 101961833554, reproduced and minimally repaired them, passed focused PostgreSQL tests, Integration typecheck and the complete PostgreSQL-enabled Integration suite, published 39ebec99... by ordinary descendant and retired the purpose writer.

Current #250/#251 descendants have already adopted that repaired parent non-destructively; #252 independently adopted #245 and is now proving a separate dependency-error boundary. That successor evidence does not transfer unchanged-head repository/security/review authority backward into #243 and does not make any stack layer protected shipped truth.

Keep Draft until prerequisites integrate normally and exact-head package/coverage/security/review evidence is reacquired after required ancestry moves.

The network transport boundary remains separate: LifeOS must not treat origin grant authority as network authorization or copy mutable EgressWeave source. Fresh EgressWeave release inventory is empty, so an immutable released/versioned owner boundary is still unavailable. LifeOS-owned durable delivery attempt/outcome/retry/recovery persistence may proceed separately while outbound networking remains fail closed.

No source copy, cross-service SQL, mutable dependency, self-approval, bypass or force-push.

Refs #130, #205, #235, #241, #242, #244, #245, #250, #251, #252.

@coderabbitai

coderabbitai Bot commented Sep 3, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant