Skip to content

History / Access Control

Revisions

  • Split Security into Security: Basics + Advanced; add Config Tokens/SSO Concepts: - Rename Security -> Security: Basics (operational surfaces unchanged). - New Security: Advanced - the mechanisms behind the surfaces: the token model (two kinds, fingerprint storage, the two-question check with cache TTL + write-bypass, admin bootstrap), the machine door (two doors, private-network listener, shared-secret vs mutual certs), and single sign-on (SAML contract, login/refresh flow, offline token validation, pasted-URL browsing), plus ironclad defaults + audit. Configuration: Advanced - two operator sections: - Tokens: store on the primary's /app/data, first-boot bootstrap secret, expiry / switch-off tunables, deployment-choice vs -cfg-<tag> bake. - Single sign-on: resources/ drop, entityID / IdP-cert / role settings, gateway signing-cert + allowed-origins. Sidebar + cross-refs re-pointed: SSO-specific links -> Advanced; scope/delegation/network links -> Basics. Sourced from com.metafluent.rest/docs/design.md; property keys deferred to Configuration: Reference pending the shipped implementation. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 28, 2026
  • Split Security & Entitlements into Access Control + Security Separate the combined Concepts page into two: - Access Control (Architect) - client authentication, entitlements (authorization), and transitive entitlement for derived content. New lead. Placed after Architecture: Basics in the sidebar. - Security (Architect, Operator) - the operational surfaces: REST/admin access, cluster-internal traffic, transport, and deployment secrets. Keeps the original "Elastic MDS's security..." lead, adapted. Placed after Architecture: Advanced. Drops the "security surfaces" list; re-points all cross-references (Glossary, Entitlements-Context, Configuration-Advanced, How-to-Read to Access Control; Deployment-Advanced, API-Token-Administration, REST-API to Security). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 28, 2026