Skip to content

docs(spec): AP-SPEC-063, the generalized gateway (draft) - #178

Merged
bordumb merged 4 commits into
mainfrom
audit-2026-09-24-gateway-spec
Sep 27, 2026
Merged

bordumb merged 4 commits into
mainfrom
audit-2026-09-24-gateway-spec

Conversation

@bordumb

@bordumb bordumb commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

Adds AP-SPEC-063, a draft spec for the generalized gateway. It was written on owner direction before its epic starts. Docs only; nothing is implemented.

What it specifies

  • Recipe source /2 (§3) with a recovery capability per recipe (§4).
  • The provider capabilities the Stripe vertical proved necessary (§5), including the ordered admission stages.
  • One spend limit (§6), which replaces per-actor window counts.
  • An operator plane (§7) that the application cannot interfere with.
  • Evidence and assurance (§8): auths.gateway-outcome/2, audit /2, and the echo verification.
  • The store contract, stable codes and formal obligations (§9–§11).
  • Eight epics with done gates (§15).

Needs the owner

  • §12: does the gateway become the single provider-write path, retiring the local agent's hand-built effect profiles (option A, recommended), or do both paths remain (option B)? Every other section holds under either option.
  • §13: eleven readings, all PROVISIONAL until reviewed.

Program board: a §3 backlog entry and a §4 decisions-log row.

Notes

🤖 Generated with Claude Code

bordumb and others added 4 commits September 27, 2026 12:18
Specifies the gateway work that the 2026-09-24 review pass and the
Stripe vertical showed is needed. It covers five parts:
- recovery capability per recipe;
- the provider capabilities the Stripe vertical proved necessary;
- one spend limit;
- an operator plane the application cannot interfere with;
- evidence and assurance, including gateway outcome /2 and audit /2.

It has eight epics with done gates. Nothing is implemented.

The owner decides in §12 whether the gateway becomes the single
provider-write path (option A, recommended) or both paths remain.
§13's readings are PROVISIONAL until the owner reviews them.

The program board gains a backlog entry and a decisions-log row.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The owner chose consolidation on 2026-09-27. The gateway becomes the
single provider-write path, and epic 8 retires the five local-agent
effect profiles in one cutover.

§12 keeps option B's column as the record of what was not chosen, and
option A's column as the list of what production gives up.

Other changes:
- §6's two-limit warning now applies only until epic 8 lands;
- epic 8 is no longer conditional;
- epic 8's done gate now includes checking AGENTS.md's summary of the
  boundary plan.

The program board records the decision.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Check the spec's present-tense claims against main at fe7a1cc and correct
the ones that merged work has made false or stale. Design text, §12's
options, §13's readings, and the owner's option A edits are unchanged.

#166 (admin-socket capacity the application cannot take):
- Status: names what #166 and #168 already implement instead of saying
  nothing is implemented.
- §1: the operator-plane gap no longer lists its own capacity and
  deadlines, which #166 merged.
- §5.5: step 7 (the started call runs to completion and keeps its capacity
  permit) is marked as today's behaviour.
- §7.1: states what #166 implements (two listeners with fixed capacities
  of 64 and 4, the admin peer check, the application deadlines, and the
  accept back-off) and what the section adds (`--app-capacity`, the admin
  probe, commit, and drain bounds, and the descriptor check).
- §10: `gateway.serve.accept-failed` and `gateway.admin.peer-refused` are
  marked as existing since #166.
- §14: adds the conflict with the socket paragraph #166 added to 053 §3 (a
  fixed application capacity; admin changes that wait for work in
  progress).

#168 (scheduled fuzz campaign run from xtask):
- §15: Epic 6 step 1, the Fuzz job repair with a test on captured
  libFuzzer logs, is marked merged; scheduled runs pass from 2026-09-27.
- §8.5: fuzz targets are registered in the campaign's `CAMPAIGN_TARGETS`
  in `xtask/src/fuzz.rs`, not in a workflow matrix, and the Epic 6 step 1
  dependency is marked merged.

Public record:
- §12: #147 covers receipt clocks in the PostgreSQL vertical only.

Checked and still accurate: cited file paths, type and function names,
schema versions (attempt /2, outcome /1, observe /1, audit /1,
installation /2, `auths.lifecycle.postgresql/4`, evaluator /1,
`auths.provider-connection/1`), the `auths-node` command after #175, the
P-256 key forms after #176, fixture and corpus counts, stable codes, and
every relative link.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…tial generation

Since #164, disable and enable advance a connection's generation without
storing a secret, and the reference commitment stays bound to the
generation at which the secret was installed or rotated. Record /1 does
not carry that generation, so §7.3's install --join and cross-process
rotate could not recompute the commitment after any state change.

Record auths.provider-connection/2 adds credential_generation:
- install and rotate set it;
- state changes leave it unchanged.

Joining, rotating and leasing compute and check the commitment under it.
/1 is retired, and auths-connections joins the scope. Epic 5's done gate
covers a join, and a cross-process rotate, after a disable and enable.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@bordumb
bordumb merged commit b10ff6e into main Sep 27, 2026
26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant