Define fresh DNS workload authorization decisions #14
No reviewers
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
kaiba/kaiba-contracts!14
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "codex/dns-workload-authorization"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
DNS controllers need an authenticated, fresh fleet decision for the active device instance and its assigned DNS name. Add the closed DNSWorkloadAuthorization response, nonce binding, five-second validity, canonical identity/name consistency rules, and fail-closed consumer checks.
This is stacked on #13. Existing enrollment and WorkloadBinding contracts are unchanged. The response is a transient RPC decision, not a durable registry record or production admission approval.
Validation: 116 Python tests, site generation and link checks (20 contracts), Node walkthrough, and whitespace checks passed locally.