Skip to content

feat(platform): verify Gravitino identity and gate production identity - #95

Merged
zhouning merged 3 commits into
mainfrom
feat/metadata-fabric-gravitino-identity-mainline
Aug 17, 2026
Merged

feat(platform): verify Gravitino identity and gate production identity#95
zhouning merged 3 commits into
mainfrom
feat/metadata-fabric-gravitino-identity-mainline

Conversation

@zhouning

Copy link
Copy Markdown
Owner

Summary

  • rehearse an isolated Gravitino 1.3.0 Basic IdP with exact table-create grants, denied catalog creation, credential rotation, revocation, and cleanup
  • add a fail-closed production Metadata Fabric identity profile and attestation gate covering OIDC/workload/tenant binding, TLS, persistent catalog, operations, and derived claims
  • register both local-only runtimes and synchronize CI and staging candidate release tests

Evidence boundary

The Gravitino result proves only a local Basic identity rehearsal over loopback HTTP with a memory probe catalog. The production identity profile is valid but has 40 explicit external blockers and no protected attestation. OIDC, TLS, protected workload identity, persistent production catalog, provider-wide production minimum privilege, production identity, and production readiness remain false.

Gravitino evidence SHA: f0b0de1f80f079d43318937e0a0cc151a8546e9e307bef204738b1367f9b29fd
Production profile SHA: 2e9d5cac3560b853820f923669f6794ead63bcb36a528639fc0e9539e148ee2f
Readiness report SHA: c607589ee25a87acc8a1ab71372618a9a4c10c1e8ebff15b8db7e78b37600b9f

Verification

  • 25 platform and Metadata Fabric validators passed
  • focused identity/platform-truth tests: 46 passed
  • required platform suite: 683 passed
  • PostgreSQL contract suite on a clean temporary database: 5 passed
  • runtime dependency constraints: 4 passed
  • git diff check and compile checks passed

Supersedes historical stacked PRs #20 and #21 after this replacement is merged.

@zhouning
zhouning merged commit b0140e3 into main Aug 17, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant