Rewrite ADR-025 around the group-based design: groups gate (admin- managed identity), labels place, OpenBao enforces via external groups; batch tokens with 1h TTL make expiry re-login the membership sync. Iteration trail preserved under 025-device-secret-access/ (025-1 JWT claim scoping, 025-2 entity-by-policy as built, 025-3 the scale and security analysis with verified sources). Add the user-facing guide and the implementation + branch-consolidation rollout plan.
2.9 KiB
2.9 KiB
Summary
Use Cases
Component Catalogs
Developer Guides
- Developer Guide
- Writing a Score
- Writing a Topology
- Adding Capabilities
- Web Authentication and CSRF Security
- Operator Dashboard SSO (Zitadel) — setup
- Fleet Device Secrets
Configuration
Architecture Decision Records
- ADR Overview
- 000 · ADR Template
- 001 · Why Rust
- 002 · Hexagonal Architecture
- 003 · Infrastructure Abstractions
- 004 · iPXE
- 005 · Interactive Project
- 006 · Secret Management
- 007 · Default Runtime
- 008 · Score Display Formatting
- 009 · Helm and Kustomize Handling
- 010 · Monitoring and Alerting
- 011 · Multi-Tenant Cluster
- 012 · Project Delivery Automation
- 013 · Monitoring Notifications
- 015 · Higher Order Topologies
- 016 · Harmony Agent and Global Mesh
- 017-1 · NATS Clusters Interconnection
- 018 · Template Hydration for Workload Deployment
- 019 · Network Bond Setup
- 020 · Interactive Configuration Crate
- 020-1 · Zitadel + OpenBao Secure Config Store
- 025 · Fleet Device Secret Access
- 025-3 · Groups as the Security Boundary