Split Security into Security: Basics + Advanced; add Config Tokens/SSO
Concepts:
- Rename Security -> Security: Basics (operational surfaces unchanged).
- New Security: Advanced - the mechanisms behind the surfaces: the token
model (two kinds, fingerprint storage, the two-question check with cache
TTL + write-bypass, admin bootstrap), the machine door (two doors,
private-network listener, shared-secret vs mutual certs), and single
sign-on (SAML contract, login/refresh flow, offline token validation,
pasted-URL browsing), plus ironclad defaults + audit.
Configuration: Advanced - two operator sections:
- Tokens: store on the primary's /app/data, first-boot bootstrap secret,
expiry / switch-off tunables, deployment-choice vs -cfg-<tag> bake.
- Single sign-on: resources/ drop, entityID / IdP-cert / role settings,
gateway signing-cert + allowed-origins.
Sidebar + cross-refs re-pointed: SSO-specific links -> Advanced;
scope/delegation/network links -> Basics.
Sourced from com.metafluent.rest/docs/design.md; property keys deferred to
Configuration: Reference pending the shipped implementation.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj
Split Security & Entitlements into Access Control + Security
Separate the combined Concepts page into two:
- Access Control (Architect) - client authentication, entitlements
(authorization), and transitive entitlement for derived content. New
lead. Placed after Architecture: Basics in the sidebar.
- Security (Architect, Operator) - the operational surfaces: REST/admin
access, cluster-internal traffic, transport, and deployment secrets.
Keeps the original "Elastic MDS's security..." lead, adapted. Placed
after Architecture: Advanced.
Drops the "security surfaces" list; re-points all cross-references
(Glossary, Entitlements-Context, Configuration-Advanced, How-to-Read to
Access Control; Deployment-Advanced, API-Token-Administration, REST-API
to Security).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj
Stop codifying REST as "not a content-access interface"
Drop the "not a content-access interface" remark from the REST API
page - it overstated an early assumption. Remove the redundant word
"surface" from the Security cross-link and reword the How to Read
pointer to "the control-plane to use".
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
Move Component state to Architecture: Basics
Component state is a foundational lifecycle concept (referenced by Monitoring,
Troubleshooting, Logging), and read orphaned at the tail of Architecture:
Advanced. Move the section - definition, two-phase model, and state diagram -
into Architecture: Basics after "How a request is handled". Retarget the
state-model references (Troubleshooting FAQ, Operations: Monitoring,
How-to-Read) to Basics; trim the Advanced intro; add a state<->role pointer
between the two pages.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
How to Read: drop REST-vs-data asides; positive v5 framing; fix table links
- Remove the "you don't need REST" line (developer path) and the "not how
applications get data" clause (operator path) - belaboring a non-issue.
- v5 section: drop "the one delta" (reads as an obligation); positive framing -
code runs unchanged, the MarketData context unlocks new capabilities.
- Fix the "looking for something specific?" table: [[Label|Slug]] wiki-links
collide with the table's own | delimiters and don't resolve; use
[Label](Slug) markdown links instead.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9
Add "How to Read This Guide" - role-specific reading paths
Expansive on-ramp under Getting Started: makes explicit that you don't read
the guide front to back and that the paths are role-specific. Ordered routes
for evaluating / application developer / operator / architect / v5 user, each
page annotated with why it's on the path, plus a "looking for something
specific?" table. REST is kept strictly to the operator/architect (control
plane) routes - out of the developer path; the MarketData context leads the
developer path, Entitlements demoted to optional. Home's "Start here" points
in; sidebar entry added.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9