Skip to content

Plan: pilot allowlist implementation - #108

Merged
zmanian merged 2 commits into
mainfrom
plan-pilot-allowlist
May 17, 2026
Merged

zmanian merged 2 commits into
mainfrom
plan-pilot-allowlist

Conversation

@zmanian

@zmanian zmanian commented May 17, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Implementation plan against the pilot-allowlist spec merged in Spec: pilot allowlist on the upload-claim issuer #107. Three slices, ten tasks, no new direct deps.
  • New module `trace_upload_claim_allowlist` (snapshot type + `FileAllowlistSource` + `hash_invite_code` helper + `DenialCounter`).
  • Additive changes on `trace_upload_claim_issuer`: one new optional `invite_code` field on `WorkloadClaims`, one new optional `policy_label` field on `UploadClaimClaims`, four new `IssuerError` variants.
  • Optional second axum bind for `/v1/admin/allowlist-status` with a startup guard that refuses non-loopback addresses unless the operator sets an opt-in env. Operator runbook at `docs/operator/pilot-allowlist.md`.

What's in the plan, what's not

In Out
File-source allowlist NEAR view-call source (reserved as a CLI variant, not built)
Emitting `policy_label` on the minted JWT Reading `policy_label` on the ingest side (follow-up slice)
Localhost-only admin bind Operator-bearer alternative (Task 8 lists it as additive if ops asks later)
`--hash-invite-code` CLI helper Any Ironclaw-client wiring for `invite_code` (lives on the client side)

Verification

Each slice ends with the four CI commands the repo already enforces (`cargo check`, `cargo test --no-run`, `cargo clippy`, `cargo fmt --check`) plus the new module-targeted `cargo test trace_upload_claim_allowlist`. Full `cargo test -p trace-commons-server` green at end-of-plan is the exit criterion.

Test plan

  • Render the plan on GitHub, confirm the file map + slices read as actionable.
  • Cross-check the file map against the actual `trace_upload_claim_issuer.rs` line numbers in the spec (333, 354) — they should still be current.
  • If approved, the executor picks up Slice 1 Task 1.

Implementation plan against
docs/superpowers/specs/2026-05-17-pilot-allowlist-design.md (merged in
PR #107). Three slices, ten tasks. No new direct deps.

Slice 1 — invite_code field on WorkloadClaims, policy_label on
UploadClaimClaims, AllowlistSource trait + FileAllowlistSource with
refresh-cached snapshots.
Slice 2 — wire the snapshot check into the issuance handler, emit
policy_label on the minted claim, integration tests for the round-trip.
Slice 3 — DenialCounter, /v1/admin/allowlist-status on an optional
localhost-only second axum bind, operator runbook, --hash-invite-code
CLI helper.

Risk register covers the five things most likely to bite: raw codes
committed by mistake, file deletion in production, admin endpoint
accidental public exposure, signers unaware of the new field, hashing
drift between operator and issuer.

Executor guidance pinned at the bottom: no refactor of the existing
1,643-line issuer module, no logging of raw invite codes, admin
endpoint is optional, no new direct deps.
@zmanian
zmanian merged commit ec4f090 into main May 17, 2026
7 checks passed
@zmanian
zmanian deleted the plan-pilot-allowlist branch May 17, 2026 23:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant