-
Notifications
You must be signed in to change notification settings - Fork 0
[G19] Audit trust admission and cross-worker secret boundaries #19
Copy link
Copy link
Open
Labels
agent:astra-xhighPrimary implementer: gpt-6-astra, xhigh reasoningPrimary implementer: gpt-6-astra, xhigh reasoningpriority:P0Critical contract, security or reliability dependencyCritical contract, security or reliability dependencyrelease:distributionApproved delivery sequencing; does not change acceptance or dependency gatesApproved delivery sequencing; does not change acceptance or dependency gatesrisk:highIndependent gpt-luna-max review on risky boundariesIndependent gpt-luna-max review on risky boundariestype:gateEvidence gate before dependent workEvidence gate before dependent work
Milestone
Description
Activity
Metadata
Metadata
Assignees
Labels
agent:astra-xhighPrimary implementer: gpt-6-astra, xhigh reasoningPrimary implementer: gpt-6-astra, xhigh reasoningpriority:P0Critical contract, security or reliability dependencyCritical contract, security or reliability dependencyrelease:distributionApproved delivery sequencing; does not change acceptance or dependency gatesApproved delivery sequencing; does not change acceptance or dependency gatesrisk:highIndependent gpt-luna-max review on risky boundariesIndependent gpt-luna-max review on risky boundariestype:gateEvidence gate before dependent workEvidence gate before dependent work
Type
Projects
- StatusShow more project fieldsBacklog
Goal
Verify and enforce the advertised trust profiles so untrusted work cannot enter trusted-only pools and jobs cannot reach manager credentials/control in the supported configuration.
Create one active Codex goal from the statement above when this issue is dispatched. The Project Goal field is a work specification; it does not start an agent. Do not invent a token budget.
Execution contract
Use one issue branch/worktree and one focused PR. Independent Luna max review is required for authentication, protocol, concurrency, resource ownership, cleanup or service identity boundaries; other changes need independent contract review. Model fields are routing instructions, not GitHub user assignments.
Dependencies
Dependencies must be Done before implementation begins. A new issue is not blocked simply because its future evidence has not been collected.
Scope
Threat-model closure, policy preflight, native UID and Docker DinD profiles, adversarial non-destructive probes. No unsupported claim of hostile-container isolation.
TDD and failure evidence
Capture a meaningful failing case before the implementation, then green evidence and relevant refactor checks. Tooling/prose-only work uses appropriate negative checks without artificial application tests. Live/runtime profiles require reviewed commits, a dedicated trusted test environment and explicit authorization for the concrete experiment. Public PR CI uses hosted environments without credentials. Planned or skipped tests never count as passed.
Acceptance criteria
Safety invariants
Preserve existing manual runners; no global Docker prune/context switching, broad process kill, implicit App enrollment, busy-job cancellation during ordinary scale-down or transparent workflow replay. Use only verifiably owned resources. Keep management credentials and raw secret-bearing SDK errors out of worker environments, logs, fixtures and commits; per-worker JIT transport follows G01. Native pools remain trusted-only.
Design references