feat(acl): admit GF Darwin worker route (TIN-2998) - #21
Draft
Jesssullivan wants to merge 2 commits into
Draft
Conversation
|
Owner
Author
|
CI classification for run 31534013437: source Dhall type-check/build and secret detection passed. Live validation did not reach policy comparison; it failed with HTTP 401 API token invalid. This is credential/publisher custody evidence, not a policy-diff failure and not authority to remint or bypass. Draft/hard hold remains: repair through the governed #20 publisher ritual, then rerun exact-head validation before any readiness or merge. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Contributes to TIN-2998 under Linear carrier comments
c89b99d0-3010-4b2d-b7cf-a93e46694f40and44df2310-7773-4987-8487-fc234dd8372c.tag:gf-reapi-cell-egressandtag:gf-reapi-darwin-workertag:tag-authority, never the Kubernetes operator, to assign the PZM worker tagtcp:8981This is the public tailnet ACL SSOT. It does not configure PZM, GF, or the owner overlay, and it makes no network-exclusivity claim while PZM retains
tag:dollhouse; exact mTLS remains the authorization boundary.Hard hold
SOURCE REVIEW ONLY. DO NOT READY OR MERGE.
Current
.github/workflows/cd.ymlpublishes unconditionally on every main push after ignoring validation/dry-run failures. The referencedproductionenvironment is unprotected,tailnet-acl-productiondoes not exist, and workflow238207465remains active.Release this hold only after the independent hard prerequisites on #20 establish the governed publisher and the release is recorded on this PR. Do not repair or bypass CD in this branch. Merging this draft would be a live ACL mutation.
After release, TIN-2998 activation order remains: ACL policy -> PZM tag and mTLS readiness -> governed owner-overlay apply -> forced Darwin proof and rollback.
Evidence
a04f1868759be886577015318f06a9ca796fbcfdand5a0ad86ab0d690d4ecdd3822d7ec9ffd8eabbe09dhall format --check constants.dhalldhall format --check fragments/core.dhalljq -e . grants.jsongit diff --checkNo live validation, ACL publication, device-tag write, credential change, or runtime mutation occurred.