CB-548: config-declared architect slots + Role.ARCHITECT authz #19

Closed
agent wants to merge 0 commits from worker/cb-548-authz-264363-5 into main
Member

CB-548 -- config + identity/authz foundation for a config-declared architect role, independent of lifecycle admission/queueing (a separate unit).

  • Config: an architects: registry (gateway-local unique slot name -> strong-model workers: profile + optional terminal), modeled on leaders:. validateArchitects() rejects a slot whose profile references no configured worker profile at startup (config has access to workerProfiles). Slot names are unique by construction (map keys).
  • Role.ARCHITECT + connection-derived principals: a pane bound to a slot resolves to ARCHITECT (carrying the slot name) via the LIVE terminal->slot binding, checked after leads and before the generic worker fallback. Live binding is injectable/live (a supplier, like leads), never a request argument — no self-declared architect, no reply-as-another-terminal (ownsSession applies).
  • Exposes an ArchitectRegistry (slot->profile snapshot + live terminal binding) as the minimal abstraction the future spawn lifecycle calls; nothing spawns a slot here.
  • Authz matrix: architect May SEND, REPLY/ASK only as its own pane, READ/METRICS; may NOT SPAWN/STOP/DRAIN. Role is its own — WORKER not widened, PRIMARY not reused. Existing leader behaviour preserved (lead checked before architect; lead resolves to PRIMARY unchanged).
  • MCP: callerRole stash round-trips ARCHITECT; bridge_whoami reports role:"architect" + architect:<slot> + sessionId.

Tests run: fully green. mvn clean install -> Tests run: 506, Failures: 0, Errors: 0, Skipped: 0; BUILD SUCCESS.

CB-548 -- config + identity/authz foundation for a config-declared architect role, independent of lifecycle admission/queueing (a separate unit). - Config: an `architects:` registry (gateway-local unique slot name -> strong-model `workers:` profile + optional `terminal`), modeled on `leaders:`. `validateArchitects()` rejects a slot whose profile references no configured worker profile at startup (config has access to workerProfiles). Slot names are unique by construction (map keys). - Role.ARCHITECT + connection-derived principals: a pane bound to a slot resolves to ARCHITECT (carrying the slot name) via the LIVE terminal->slot binding, checked after leads and before the generic worker fallback. Live binding is injectable/live (a supplier, like leads), never a request argument — no self-declared architect, no reply-as-another-terminal (ownsSession applies). - Exposes an ArchitectRegistry (slot->profile snapshot + live terminal binding) as the minimal abstraction the future spawn lifecycle calls; nothing spawns a slot here. - Authz matrix: architect May SEND, REPLY/ASK only as its own pane, READ/METRICS; may NOT SPAWN/STOP/DRAIN. Role is its own — WORKER not widened, PRIMARY not reused. Existing leader behaviour preserved (lead checked before architect; lead resolves to PRIMARY unchanged). - MCP: callerRole stash round-trips ARCHITECT; bridge_whoami reports `role:"architect"` + `architect:<slot>` + sessionId. Tests run: fully green. mvn clean install -> Tests run: 506, Failures: 0, Errors: 0, Skipped: 0; BUILD SUCCESS.
agent added 1 commit 2026-08-13 17:28:44 +02:00
CB-548: config-declared architect slots + Role.ARCHITECT authz
CI / build (pull_request) Successful in 55s
CI / contract (pull_request) Successful in 1m6s
21cfc09f8e
ltms closed this pull request 2026-08-13 18:10:00 +02:00
Some checks are pending
CI / build (pull_request) Successful in 55s
CI / contract (pull_request) Successful in 1m6s

Pull request closed

Sign in to join this conversation.