docs(spec): AP-SPEC-063, the generalized gateway (draft) - #178
Merged
Merged
Conversation
Specifies the gateway work that the 2026-09-24 review pass and the Stripe vertical showed is needed. It covers five parts: - recovery capability per recipe; - the provider capabilities the Stripe vertical proved necessary; - one spend limit; - an operator plane the application cannot interfere with; - evidence and assurance, including gateway outcome /2 and audit /2. It has eight epics with done gates. Nothing is implemented. The owner decides in §12 whether the gateway becomes the single provider-write path (option A, recommended) or both paths remain. §13's readings are PROVISIONAL until the owner reviews them. The program board gains a backlog entry and a decisions-log row. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The owner chose consolidation on 2026-09-27. The gateway becomes the single provider-write path, and epic 8 retires the five local-agent effect profiles in one cutover. §12 keeps option B's column as the record of what was not chosen, and option A's column as the list of what production gives up. Other changes: - §6's two-limit warning now applies only until epic 8 lands; - epic 8 is no longer conditional; - epic 8's done gate now includes checking AGENTS.md's summary of the boundary plan. The program board records the decision. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Check the spec's present-tense claims against main at fe7a1cc and correct the ones that merged work has made false or stale. Design text, §12's options, §13's readings, and the owner's option A edits are unchanged. #166 (admin-socket capacity the application cannot take): - Status: names what #166 and #168 already implement instead of saying nothing is implemented. - §1: the operator-plane gap no longer lists its own capacity and deadlines, which #166 merged. - §5.5: step 7 (the started call runs to completion and keeps its capacity permit) is marked as today's behaviour. - §7.1: states what #166 implements (two listeners with fixed capacities of 64 and 4, the admin peer check, the application deadlines, and the accept back-off) and what the section adds (`--app-capacity`, the admin probe, commit, and drain bounds, and the descriptor check). - §10: `gateway.serve.accept-failed` and `gateway.admin.peer-refused` are marked as existing since #166. - §14: adds the conflict with the socket paragraph #166 added to 053 §3 (a fixed application capacity; admin changes that wait for work in progress). #168 (scheduled fuzz campaign run from xtask): - §15: Epic 6 step 1, the Fuzz job repair with a test on captured libFuzzer logs, is marked merged; scheduled runs pass from 2026-09-27. - §8.5: fuzz targets are registered in the campaign's `CAMPAIGN_TARGETS` in `xtask/src/fuzz.rs`, not in a workflow matrix, and the Epic 6 step 1 dependency is marked merged. Public record: - §12: #147 covers receipt clocks in the PostgreSQL vertical only. Checked and still accurate: cited file paths, type and function names, schema versions (attempt /2, outcome /1, observe /1, audit /1, installation /2, `auths.lifecycle.postgresql/4`, evaluator /1, `auths.provider-connection/1`), the `auths-node` command after #175, the P-256 key forms after #176, fixture and corpus counts, stable codes, and every relative link. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…tial generation Since #164, disable and enable advance a connection's generation without storing a secret, and the reference commitment stays bound to the generation at which the secret was installed or rotated. Record /1 does not carry that generation, so §7.3's install --join and cross-process rotate could not recompute the commitment after any state change. Record auths.provider-connection/2 adds credential_generation: - install and rotate set it; - state changes leave it unchanged. Joining, rotating and leasing compute and check the commitment under it. /1 is retired, and auths-connections joins the scope. Epic 5's done gate covers a join, and a cross-process rotate, after a disable and enable. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds AP-SPEC-063, a draft spec for the generalized gateway. It was written on owner direction before its epic starts. Docs only; nothing is implemented.
What it specifies
/2(§3) with a recovery capability per recipe (§4).auths.gateway-outcome/2, audit/2, and the echo verification.Needs the owner
Program board: a §3 backlog entry and a §4 decisions-log row.
Notes
auths-node gateway recipe checkname from feat(cli): run the packaged CLI as auths #175.🤖 Generated with Claude Code