docs: separate installer artifact trust boundary
This commit is contained in:
@@ -69,6 +69,13 @@ journey needs and supplies contracts shared by all five stages.
|
|||||||
8. **Release proof.** Version alignment, clean install/upgrade, module
|
8. **Release proof.** Version alignment, clean install/upgrade, module
|
||||||
permutations, backup/restore, degraded-provider behavior, security checks,
|
permutations, backup/restore, degraded-provider behavior, security checks,
|
||||||
and target-environment acceptance gate product claims.
|
and target-environment acceptance gate product claims.
|
||||||
|
9. **Artifact and infrastructure egress.** Tenant connectors use the pinned
|
||||||
|
connector boundary. Installer artifacts use a separate deployment-owned
|
||||||
|
trust path: approved origins, bounded pinned download or operator prefetch,
|
||||||
|
signature/checksum verification, safe extraction, and offline package-manager
|
||||||
|
execution. Database, broker, cache, and worker channels are constrained by
|
||||||
|
deployment network policy and authenticated transport rather than treated as
|
||||||
|
tenant connector profiles.
|
||||||
|
|
||||||
## Documentation contract for every reference stage
|
## Documentation contract for every reference stage
|
||||||
|
|
||||||
|
|||||||
@@ -70,10 +70,16 @@ The canonical backlog item is
|
|||||||
state and can reconnect without losing progress.
|
state and can reconnect without losing progress.
|
||||||
5. Package signature/checksum, version alignment, contract closure, migration
|
5. Package signature/checksum, version alignment, contract closure, migration
|
||||||
graph, configuration schema, and health checks are mandatory gates.
|
graph, configuration schema, and health checks are mandatory gates.
|
||||||
6. A failed or interrupted operation reaches a visible retry, forward-recovery,
|
6. Remote artifacts are acquired by a deployment-owned downloader that permits
|
||||||
|
approved origins, pins the validated connection peer, enforces size and time
|
||||||
|
limits, and verifies signature/checksum before making a local immutable
|
||||||
|
artifact available. `pip`, `npm`, archive tools, and any compatibility Git
|
||||||
|
importer then run without unrestricted network access. A restricted-network
|
||||||
|
profile can satisfy the same contract through operator-prefetched artifacts.
|
||||||
|
7. A failed or interrupted operation reaches a visible retry, forward-recovery,
|
||||||
rollback, or manual-intervention state. It never reports success merely
|
rollback, or manual-intervention state. It never reports success merely
|
||||||
because the initiating request returned.
|
because the initiating request returned.
|
||||||
7. An available update follows the same preview and confirmation path. Exact
|
8. An available update follows the same preview and confirmation path. Exact
|
||||||
repeated requests are idempotent.
|
repeated requests are idempotent.
|
||||||
|
|
||||||
### Horizontal scaling
|
### Horizontal scaling
|
||||||
@@ -114,6 +120,10 @@ The canonical backlog item is
|
|||||||
|
|
||||||
- Catalogs, artifacts, recipes, and configuration revisions have signatures,
|
- Catalogs, artifacts, recipes, and configuration revisions have signatures,
|
||||||
checksums, provenance, expiry/revocation semantics, and audit evidence.
|
checksums, provenance, expiry/revocation semantics, and audit evidence.
|
||||||
|
- Catalog and artifact retrieval is not delegated to an unrestricted package
|
||||||
|
manager. Approved-origin and peer-pinned download, response bounds,
|
||||||
|
signature/checksum verification, extraction safety, offline installation, and
|
||||||
|
deployment egress policy form separate defenses.
|
||||||
- The installer has a dedicated narrow authority; normal domain permissions do
|
- The installer has a dedicated narrow authority; normal domain permissions do
|
||||||
not imply host/package-management access.
|
not imply host/package-management access.
|
||||||
- The UI distinguishes reversible configuration rollback from database or
|
- The UI distinguishes reversible configuration rollback from database or
|
||||||
|
|||||||
Reference in New Issue
Block a user