Skip to content

Embed shared Access Flow relay in the container agent - #67

Merged
kcosr merged 42 commits into
mainfrom
feat/access-flow-identity-authorization
Jul 26, 2026
Merged

kcosr merged 42 commits into
mainfrom
feat/access-flow-identity-authorization

Conversation

@kcosr

@kcosr kcosr commented Jul 26, 2026

Copy link
Copy Markdown
Owner

Summary

  • embed the shared, product-neutral Access Flow relay in aw-container-agent with typed host-proxy socket configuration
  • manage relay readiness, lifecycle, cancellation-safe shutdown, and failure propagation without coupling the Gateway contract to ACL Proxy
  • preserve deployment flexibility: the proxy may remain in-container or run on the host depending on configuration
  • harden account lookup, test-home isolation, advisory-database custody, and executable test-fixture publication

Dependency

  • depends on kcosr/access-runtime#3 at immutable commit d571d88011923b0d639d1c3ea88ce43cfcfe1a3f

Verification

  • full Gateway suite passed in normal and clean-room map-root namespaces
  • 20 independent full-suite campaigns passed 16,240 aggregate tests with zero failures or ETXTBSY
  • final four-repository Gate X and both privileged relay smokes passed
  • signed local candidate sequence 12 passed clean-room verification
  • Keel review with claude-opus-5 / xhigh completed clean

Native Apple Container execution remains unrun because no Apple host is available; this is recorded as nonblocking.

@kcosr
kcosr merged commit 5736099 into main Jul 26, 2026
1 check failed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant