Skip to content

feat(integration): compose authenticated Vault plugin operator authority - #243

Draft
seonghobae wants to merge 10 commits into
feat/plugin-vault-secret-store-v1from
feat/plugin-vault-operator-composition-v1
Draft

feat(integration): compose authenticated Vault plugin operator authority#243
seonghobae wants to merge 10 commits into
feat/plugin-vault-secret-store-v1from
feat/plugin-vault-operator-composition-v1

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Buyer/security outcome

Advances #130 beyond a standalone Vault adapter by composing it with authenticated Plugin operator authority. The composition reads verifier/Vault configuration only from Integration-owned configuration, combines signed workspace+user authority with durable replay consumption, and routes credential plaintext only through PluginVaultSecretStore; durable LifeOS metadata retains only opaque secret references.

Current stack

Parent #242 is now e753de422be91d0962a8fd260c5ce366994acb54. Current exact head d03b886f67552e6bb2b53352087d2041dedba07c is a non-force two-parent descendant of prior #243 head a2a8b5395c843fee6438f173659b9409d240a545 and current #242. Fresh compare from the parent is ahead-only (behind_by=0) with the same six Integration/ADR/architecture paths. No predecessor check/review evidence transfers.

This slice preserves its authenticated Vault operator composition, INTEGRATION_PLUGIN_VAULT_*-only configuration authority and Proposed ADR 0004. Hosted PostgreSQL bootstrap remains a successor rather than being pulled backward into this bounded slice.

Current hosted successor #244 is f0b91869f306b1b7d0d5759307acf347e413aa06; concrete PostgreSQL/default-entrypoint successor #245 is 45b5ad55b1575a677c9edf65fc350e55e3c68f8f. #245 now preserves both one-time query authority and one-time shutdown authority. Latest RED 95c23186b09114e4ae01b6a6eaf1c8e4aec126ba → repair 0c6065378a57c99574694e203463b5111847238c closes the stateful end accessor gap; exact successor coverage also rejects throwing/non-callable shutdown accessors without reflecting native detail.

The apps/integration-service frozen-lock importer still lacks direct pg/@types/pg evidence, so RED a0b5653426f0d55e50f6baff6ad66543a57d932f remains open. Earlier whole-lock churn f3bc29112e691e1c30008c4e4132b486f20567ff was preserved and reverted by b6c1befd8fea6b9943d95461b9f19b1d9f4f5061; it is not accepted repair evidence.

Keep Draft until prerequisites integrate normally and exact-head package/coverage/security/review plus real PostgreSQL/Vault/TLS acceptance are reacquired. No source copy, cross-service SQL, mutable dependency, self-approval, bypass or force-push.

Refs #130, #205, #235, #241, #242, #244, #245.

@coderabbitai

coderabbitai Bot commented Sep 3, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant