Skip to content

Complete production admin API identity and credential lifecycle controls #33

Description

@alexeygrigorev

Parent epic: #7

Normative spec: 06 — Studio and admin API

Decision dependencies: #20, #28

Foundation dependency: #87 (which builds on closed #86)

Outcome

Complete the production admin API after the owner approves production staff identity/break-glass behavior in #20 and final credential/high-risk controls in #28. #87 supplies the decision-free API-principal, Bearer credential, API convention, OpenAPI, rate, operation, and parity foundation with credential lifecycle adapters kept test-only and absent from runtime.

Scope

Non-goals

Acceptance criteria

  • Approved Decision: Select the staff OIDC provider and break-glass policy #20 human-principal identity, offboarding, session, and break-glass behavior is integrated without weakening Build the decision-free admin API and service-principal foundation #87's service-principal isolation or deny-by-default authorization.
  • Approved Decision: Confirm high-risk action approvals and reauthentication #28 credential lifecycle policy is registered in production for create/rotate/revoke with exact scope/count/impact, fresh-authentication/API-equivalent evidence, confirmation, concurrency, idempotency, audit, cancellation, and any approved dual approval.
  • Every production management capability has exact Studio/admin-API permission, service, object/field policy, schema, concurrency/idempotency/rate, audit, and result parity.
  • Production credentials remain one-time/non-recoverable, bounded, revocable, monitored, retained/cleaned up per approved policy, and secret-free in every persistence/log/audit/artifact path.
  • Final OpenAPI 3.1 and resolver parity cover every production admin operation and contain no fixture/legacy-auth drift.
  • Full security, PostgreSQL concurrency, compatibility, accessibility, browser, operational, and production-identity acceptance suites pass.

Dependencies

Implementation/completion depends on #87, #20, and #28, plus #32 for the shared final Studio high-risk/identity controls. Domain operations depend on their owning services.

Delivery convention

Follow _docs/PROCESS.md. No production credential lifecycle route may be enabled merely because #87 closes; this issue requires fresh PM/QA acceptance after the owner decisions are resolved.

Metadata

Metadata

Assignees

No one assigned

    Labels

    P0Must-have or release-blockingadminArea: adminauthArea: authintegrationArea: integration

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions