Skip to content

Harden ACL publication authority and RKE2 egress policy - #20

Draft
Jesssullivan wants to merge 1 commit into
mainfrom
codex/tin-620-rke2-egress-acl-20260729
Draft

Harden ACL publication authority and RKE2 egress policy#20
Jesssullivan wants to merge 1 commit into
mainfrom
codex/tin-620-rke2-egress-acl-20260729

Conversation

@Jesssullivan

Copy link
Copy Markdown
Owner

Contributes to TIN-620.

Source boundary

  • Replaces credentialed PR-time ACL reads with source-only Dhall/policy validation on literal tinyland-nix.
  • Adds exact-head, digest-bound, ETag/If-Match publication with durable receipts and fail-closed ambiguity handling.
  • Adds direct alias/IP/CIDR/wildcard recurrence guards and documents the mutable selector/tag overlap boundary.
  • Tombstones the old push-on-main publisher source and introduces a manual-only publisher path.

Evidence

  • Signed exact head: 75f5c0a.
  • 40/40 source and workflow-authority tests passed with ResourceWarnings fatal.
  • 6/6 effective-policy tests passed against exact-main artifact 8670426013 from run 30311167443.
  • actionlint, Python AST, just parse/dry-run, diff checks, and gitleaks passed.
  • Independent terminal review: P0=0 / P1=0 / P2=0.

Hard holds

This draft is source review only. Do not merge until tailnet-acl-production is protected, historical CD workflow ID 238207465 is permanently retired, dispatch/replay denial including run 30311167574 is proven, and tombstone landing is proven not to re-enable that identity. Landing does not authorize plan, apply, credential/environment mutation, or live ACL changes.

@Jesssullivan

Copy link
Copy Markdown
Owner Author

Crash-recovered exact-state audit for the governed publisher bootstrap (2026-08-11): NO-GO remains.

Verified current control-plane state:

  • repository Actions is enabled with allowed_actions=all;
  • historical workflow 238207465 is active and retains 18 runs, including credentialed run 30311167574;
  • production exists with no protection rules; tailnet-acl-production does not exist;
  • only Jesssullivan is a repository collaborator;
  • stale TAILSCALE_API_KEY entries remain at repository and production environment scope;
  • Harden ACL publication authority and RKE2 egress policy #20's required checks are cancelled rather than green;
  • feat(acl): admit GF Darwin worker route (TIN-2998) #21's 401 proves only that the presented credential is invalid, not that historical authority was revoked.

Release prerequisites, all required:

  1. name and grant read access to an independent deployment reviewer;
  2. create tailnet-acl-production with that reviewer, prevent_self_review=true, and a custom branch policy allowing only main;
  3. create separate least-privilege Tailscale OAuth clients for read/plan and write/apply, store only their exact environment-scoped IDs/secrets, revoke the old broad credential, and remove both stale TAILSCALE_API_KEY entries;
  4. disable workflow 238207465 only (never repository Actions) and prove dispatch, retained-ref dispatch, rerun, and failed-job rerun denial while its run count remains 18;
  5. rerun Harden ACL publication authority and RKE2 egress policy #20's exact head and require both source checks green.

After those controls are observed: merge #20 normally, exact-main attended plan, review the source/live/generated digests plus ETag and policy diff, exact-digest attended apply, require accepted/reconciled digest equality, then prove a second plan is already converged. Only then may #21 be rebased, revalidated, and have its independent draft hold explicitly released.

The tombstoned cd.yml alone is not the revocation boundary while the historical workflow and credential replay surfaces remain live. No repository, workflow, environment, credential, or ACL state was changed by this audit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant