Split Security into Security: Basics + Advanced; add Config Tokens/SSO
Concepts:
- Rename Security -> Security: Basics (operational surfaces unchanged).
- New Security: Advanced - the mechanisms behind the surfaces: the token
model (two kinds, fingerprint storage, the two-question check with cache
TTL + write-bypass, admin bootstrap), the machine door (two doors,
private-network listener, shared-secret vs mutual certs), and single
sign-on (SAML contract, login/refresh flow, offline token validation,
pasted-URL browsing), plus ironclad defaults + audit.
Configuration: Advanced - two operator sections:
- Tokens: store on the primary's /app/data, first-boot bootstrap secret,
expiry / switch-off tunables, deployment-choice vs -cfg-<tag> bake.
- Single sign-on: resources/ drop, entityID / IdP-cert / role settings,
gateway signing-cert + allowed-origins.
Sidebar + cross-refs re-pointed: SSO-specific links -> Advanced;
scope/delegation/network links -> Basics.
Sourced from com.metafluent.rest/docs/design.md; property keys deferred to
Configuration: Reference pending the shipped implementation.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj
Split Security & Entitlements into Access Control + Security
Separate the combined Concepts page into two:
- Access Control (Architect) - client authentication, entitlements
(authorization), and transitive entitlement for derived content. New
lead. Placed after Architecture: Basics in the sidebar.
- Security (Architect, Operator) - the operational surfaces: REST/admin
access, cluster-internal traffic, transport, and deployment secrets.
Keeps the original "Elastic MDS's security..." lead, adapted. Placed
after Architecture: Advanced.
Drops the "security surfaces" list; re-points all cross-references
(Glossary, Entitlements-Context, Configuration-Advanced, How-to-Read to
Access Control; Deployment-Advanced, API-Token-Administration, REST-API
to Security).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj
Security: add cluster machine-secret surface + procedure; fix token-page REST link
Security & Entitlements gains a "Cluster-internal access" surface and section: the shared
machine secret model, presence-based enforcement, the loud non-functional failure on
mismatch, and the generate-once/distribute-everywhere procedure using generate-machine-secret
(deploy-mf-api-gateway). API Token Administration: correct the REST link (Develop-REST ->
REST-API).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
API Token Administration: operator guide replacing the placeholder
Full operator page: presence-based enforcement, the generate-bootstrap-secret flow
(deploy-mf-api-gateway), minting with scopes and expiry, listing/auditing with the
predicate grammar, revocation and rotation, and the SSO personal-token pointer.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
Security & Entitlements: rework entitlements + authn frameworks; tokens as shipped
Entitlements section rewritten as the access-control (authorization)
framework, not the JMS entitlements-context (removes the circular
reference): DACS/alternative behind a pluggable entitlements service
abstraction that content adapters bind to independently (per-table binding
as a footnote); framework capabilities - row-level read AND write, transitive
access through the derived-content framework, live refresh of access.
Client authentication: add the authn framework capabilities - refreshable,
independent of authz, multiple principals (Subjects).
Admin/REST access: write API tokens in present tense (shipping soon); gloss
the administration + SSO login UI and link to a new API Token Administration
page (in preparation). REST API: authentication note now present-tense.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9