-
Notifications
You must be signed in to change notification settings - Fork 0
Document threat model and privilege boundaries #27
Copy link
Copy link
Open
Labels
area/securityPermissions, secrets, controller exposure, hardening, and audits.Permissions, secrets, controller exposure, hardening, and audits.area/serviceService backends, systemd units, deployment scope, and migration.Service backends, systemd units, deployment scope, and migration.area/tunTUN mode, capability checks, routing preflight, and recovery.TUN mode, capability checks, routing preflight, and recovery.priority/P1-v1Required for the v1.0 roadmap.Required for the v1.0 roadmap.type/docsDocumentation, guides, tracking, or decision records.Documentation, guides, tracking, or decision records.
Milestone
Description
Metadata
Metadata
Assignees
Labels
area/securityPermissions, secrets, controller exposure, hardening, and audits.Permissions, secrets, controller exposure, hardening, and audits.area/serviceService backends, systemd units, deployment scope, and migration.Service backends, systemd units, deployment scope, and migration.area/tunTUN mode, capability checks, routing preflight, and recovery.TUN mode, capability checks, routing preflight, and recovery.priority/P1-v1Required for the v1.0 roadmap.Required for the v1.0 roadmap.type/docsDocumentation, guides, tracking, or decision records.Documentation, guides, tracking, or decision records.
Context
Roadmap item imported from
PLAN_REQUEST.mdandPLAN_RESPONSE.mdfor v1.0.0 — Stabilization.Upstream references
Upstream decision
Reason: Reimplemented as Mihoto documentation for service, TUN, controller, and secret boundaries.
Scope
Acceptance criteria
Out of scope
v1.1+ — Post-v1 Backlog.Dependencies
Security and rollback considerations
Apply Mihoto's safety rule for this issue: updates, migrations, service changes, TUN/DNS changes, and credential handling must be explicit, validated, auditable, and recoverable. Secrets and subscription URLs must be redacted from logs and issue artifacts.