Skip to content

feat(integration): compose hosted Vault plugin runtime - #244

Draft
seonghobae wants to merge 27 commits into
feat/plugin-vault-operator-composition-v1from
feat/plugin-vault-hosted-runtime-v1
Draft

feat(integration): compose hosted Vault plugin runtime#244
seonghobae wants to merge 27 commits into
feat/plugin-vault-operator-composition-v1from
feat/plugin-vault-hosted-runtime-v1

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

Buyer/security outcome

Advances #130 beyond application-only Vault composition by adding the hosted Integration runtime seam. This slice owns one Integration PostgreSQL pool boundary for installation lifecycle, credential metadata and replay; composes the authenticated Vault-backed operator before listener start; and ties runtime shutdown to the service lifecycle without making another bounded context the persistence owner.

Current stack

Parent #243 is now d03b886f67552e6bb2b53352087d2041dedba07c. Current exact head f0b91869f306b1b7d0d5759307acf347e413aa06 is a non-force two-parent descendant of prior #244 head c552fbbd94e1aaeca66d65ae30187386aea906de and current #243. Fresh compare from the parent is ahead-only (behind_by=0) with the same nine Integration/ADR/architecture paths. No predecessor check/review evidence transfers.

The preserved #244 RED→repair lineage covers exact INTEGRATION_DATABASE_URL, one Integration-owned SQL pool, bounded malformed-envelope cleanup, pre-listener operator composition, captured lifecycle authority and concrete PluginOperatorApplication acceptance. Proposed ADR 0005 remains Proposed until the concrete driver and real PostgreSQL/Vault acceptance exist.

Concrete successor #245 is now exact 45b5ad55b1575a677c9edf65fc350e55e3c68f8f, ahead-only from this #244 with ten Integration-owned paths. It retains self-contained PostgreSQL URI authority, URI query/fragment denial, verified TLS source policy, finite Pool/statement/query lifecycle, bounded idle-error evidence, acquisition cleanup, credential-free process startup failure, lazy-Pool readiness, hostile readiness-result handling, and one-time capture of both query and shutdown method authority. Latest shutdown-authority RED is 95c23186b09114e4ae01b6a6eaf1c8e4aec126ba → causal repair 0c6065378a57c99574694e203463b5111847238c, with edge coverage at exact successor head.

The frozen-lock RED remains: Integration manifest declares pg/@types/pg, while the root Integration importer lacks both direct entries. The accepted next repair is importer-only; prior broad lock regeneration is not accepted evidence.

Keep Draft until frozen-lock reproducibility and protected-lineage PostgreSQL + Vault/TLS acceptance exist. Only then advance #130 to connect-time SSRF/DNS-rebinding-safe outbound HTTPS, redirect/proxy policy, signing/idempotency, durable retry/dead-letter/recovery, revocation fencing and operator recovery.

Refs #130, #205, #235, #241, #242, #243, #245.

@coderabbitai

coderabbitai Bot commented Sep 4, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant