Skip to content

Reconcile AZ-06 assurance evidence and define bounded Nexus/Boot Lite profiles #35

Description

@01rabbit

Context

Deception declares 0.2.0.dev0 and pins Fabric v0.8.0. Canonical packages, decision signing/anti-replay, strict reference posture, lifecycle/evidence, heartbeat/reconciliation, provenance/SBOM paths, and virtual tests exist, while current documents disagree about pins and completed/open gates.

Scope

  1. Reconcile package metadata with README, roadmap, Fabric pin, implementation status, contracts, safety model, source traceability, changelog, and live-gate checklist.
  2. Create one evidence-backed assurance ledger separating software/virtual proof from physical/HIL proof.
  3. Define signed nexus-embedded-lite and boot-emergency-lite packages with finite resource/evidence budgets and the existing canonical verifier.
  4. Prove overlays are reductions of signed packages and cannot add/widen services, images, ports, routes, DNS, mounts, capabilities, commands, credentials, or resources.
  5. Bind lifecycle operations to authenticated one-shot Edge decisions, boot/session/environment identity, resource key, and lease.
  6. Separate fixed-bound route withdrawal from runtime cleanup and continuously attest isolation.
  7. Bound hostile telemetry and preserve Core audit/lease resources.
  8. Define ephemeral encrypted state, credential invalidation, cryptographic reset, and post-reset persistence checks.

Acceptance criteria

  • Current-facing docs consistently state Fabric v0.8.0 and product 0.2.0.dev0 until release.
  • Every live gate is checked, open, or profile-not-applicable and links evidence.
  • Lite package digest, signer role, image digests, provenance, SBOM, component set, and rendered manifest verify before runtime access.
  • Property tests prove every overlay is a subset/reduction.
  • Replayed, expired, wrong-node/package/tier/session/environment, altered, or consumed decisions fail before exposure.
  • HIL proves zero decoy reachability to protected, management, control plane, runtime socket, and Internet over IPv4/IPv6/DNS/link-local/multicast paths.
  • DHCP/RA, route/ruleset/DNS/VLAN/interface drift, runtime/host restart, and firewall flush withdraw exposure within the declared SLO.
  • Telemetry/disk/inode/PID/OOM pressure cannot consume Core reserves.
  • Reset retains finalized evidence, invalidates lures, and removes declared runtime state.
  • Combined networked Edge-to-Lite lifecycle passes for each release profile.
  • Boot Lite remains disabled when current-host isolation cannot be proven.

Parent plan: https://github.com/01rabbit/Azazel/blob/main/docs/roadmaps/nexus-boot-program-plan.md

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions