docs(architecture): resolve OQ-06/07/08 — per-repo authz, registry backing, CRUD ops
ADR-011 (resolves OQ-08): per-repo authorization — grants live in repo records keyed on the stable logical identity id (alkcall ADR-025, referenced); policy is alkgit-core's authorize() function (public+read anonymous-first-class, write always authenticated+granted); alkgit stores no identity records; vault placement resolved as nothing to place in v1. ADR-012 (resolves OQ-06/OQ-07): registry backing + write surface — GitRegistryStore write supertrait (alknet ADR-035 read/write split shape); registry-file default (per-repo record files + in-memory index, config-seeded, op-mutable, no gitoxide); git/repo/* CRUD ops shipped External with scope+ownership ACL (create mints ownership and seeds creator grants; ownership never implies git access); the two-op-kind classification recorded (open op + call ops from one crate, per alkcall ADR-047); recorded split trigger for a downstream platform crate. Doc sync: backend.md (five-trait family, feature model split, two-op-kinds), doors.md + overview.md (authorize policy, dual-kind crate map), open-questions.md (OQ-06/07/08 resolved), README (ADR table, current state), oq-06 tracker task closed (resolved early). Verification: cargo test (default + --no-default-features), clippy -D warnings, fmt --check.
This commit is contained in:
1 parent
86bf5a0cf0
commit
addc874667
8 files changed
+492
-104
No files matched your search
@@ -32,10 +32,13 @@ Single crate `alkgit`:
|
||||
| Producer | `GitAdapter` (`alk/git` ALPN via alkcall `ProtocolHandler`), channels `register_openable` (repo id in open-op params — the negotiation + ACL point) | POC-1 verbatim |
|
||||
| Consumer | `GitSession` typed client (`connect_direct`, `open_via_channels`) — the replication/mirroring primitive for alknet | new, small (TtySession analog) |
|
||||
| Substrate | duplex session + stateless request/response layer (ADR-005); wire framing, V2 state machines (ADR-003) | POC-1, POC-3 |
|
||||
| Backends | `GitRegistry`, `GitRefs`, `GitPackGen`, `GitPackIngest` traits; gix impl behind the default-on `gix` feature | POC-2 (gix impl) |
|
||||
| Backends | `GitRegistry` (+ write supertrait), `GitRefs`, `GitPackGen`, `GitPackIngest` traits; impls behind the default-on `gix` (engine) and `registry-file` (records) features | POC-2 (gix impl) |
|
||||
| Management ops | `git/repo/*` call ops over `GitRegistryStore` (ADR-012 §3) — the JSON half alongside the `alk/git` open op (first dual-kind payload; ADR-012 §5) | thin over the store trait |
|
||||
|
||||
Feature model: `default-features = false` gives the wire/protocol layer
|
||||
without gix (wasm-clean as a side effect, not a goal); the `sha256`
|
||||
Feature model: `gix` (engine impls) and `registry-file` (record store +
|
||||
ops) are independent default-on seams (ADR-012 §4);
|
||||
`default-features = false` gives the wire/protocol layer without either
|
||||
(wasm-clean as a side effect, not a goal); the `sha256`
|
||||
passthrough and (eventually, in alkhttp) the `git` door feature ride the
|
||||
same pattern. Doors live in the door crates — see [doors.md](doors.md).
|
||||
|
||||
@@ -51,7 +54,9 @@ same pattern. Doors live in the door crates — see [doors.md](doors.md).
|
||||
4. **Registry-resolved repo identity** — wire names are ids, never paths
|
||||
(ADR-008).
|
||||
5. **No secret material on the wire or at rest outside alkvault** —
|
||||
metadata holds vault references; no env-var credential reads.
|
||||
metadata holds vault references; no env-var credential reads. (In v1
|
||||
alkgit's metadata holds no credential-shaped material at all, so
|
||||
nothing is vault-placed — ADR-011 §5.)
|
||||
6. **No shelling out to `git`** — pure Rust on gix primitives.
|
||||
7. **Bounded resources** — every session carries `Limits` (ADR-009).
|
||||
8. **Honest capability advertisement** — advertise exactly what we serve
|
||||
@@ -82,6 +87,8 @@ designed but not yet exercised (OQ-04).
|
||||
| [008](decisions/008-registry-resolved-repo-identity.md) | Repo identity | wire names are registry IDs |
|
||||
| [009](decisions/009-bounded-resources-budget.md) | Budgets | every session carries limits |
|
||||
| [010](decisions/010-pure-protocol-crate.md) | Pure protocol crate | single crate, producer/consumer halves, no doors/binary |
|
||||
| [011](decisions/011-per-repo-authorization.md) | Per-repo authorization | grants in repo records, policy in core, vault-nil |
|
||||
| [012](decisions/012-registry-backing-and-ops.md) | Registry + ops | read/write split, file default, CRUD ops, feature split |
|
||||
|
||||
## Open Questions
|
||||
|
||||
@@ -89,7 +96,13 @@ Key questions tracked in [open-questions.md](open-questions.md):
|
||||
|
||||
- **OQ-04**: receive-pack (push) validation gap (high — the
|
||||
always-authenticated half of the wire surface).
|
||||
- **OQ-06**: registry backing store for the gix feature (deferred on
|
||||
scale requirements).
|
||||
- **OQ-08**: registry identity space + vault placement (narrowed by
|
||||
ADR-010).
|
||||
- **OQ-02**: V2 multi-round negotiation (medium — efficiency, not
|
||||
correctness).
|
||||
- **OQ-03**: publish-time API freeze inventory (the `git/repo/*` op
|
||||
set enters it; ADR-012).
|
||||
- **OQ-05**: sha256 policy (deferred(scope), low).
|
||||
|
||||
Resolved this cycle: OQ-08 (ADR-011 — per-repo authorization, grants in
|
||||
records, vault-nil), OQ-06 (ADR-012 — `registry-file` default,
|
||||
persistence adapters additive), OQ-07 (ADR-012 — CRUD ops shipped
|
||||
External with scope+ownership ACL).
|
||||
Reference in new issue
Block a user