Define fresh DNS workload authorization decisions #14

Merged
ams-tech merged 1 commit from codex/dns-workload-authorization into main 2026-09-30 23:51:18 -04:00
ams-tech commented 2026-09-29 00:50:28 -04:00 (Migrated from github.com)

DNS controllers need an authenticated, fresh fleet decision for the active device instance and its assigned DNS name. Add the closed DNSWorkloadAuthorization response, nonce binding, five-second validity, canonical identity/name consistency rules, and fail-closed consumer checks.

This is stacked on #13. Existing enrollment and WorkloadBinding contracts are unchanged. The response is a transient RPC decision, not a durable registry record or production admission approval.

Validation: 116 Python tests, site generation and link checks (20 contracts), Node walkthrough, and whitespace checks passed locally.

DNS controllers need an authenticated, fresh fleet decision for the active device instance and its assigned DNS name. Add the closed DNSWorkloadAuthorization response, nonce binding, five-second validity, canonical identity/name consistency rules, and fail-closed consumer checks. This is stacked on #13. Existing enrollment and WorkloadBinding contracts are unchanged. The response is a transient RPC decision, not a durable registry record or production admission approval. Validation: 116 Python tests, site generation and link checks (20 contracts), Node walkthrough, and whitespace checks passed locally.
Sign in to join this conversation.
No description provided.