Skip to content

Add Policy Fabric admission stub for AgentPod activation #4

@mdheller

Description

@mdheller

Context

Agent Machine renderers can now produce typed plans, deployment receipts, Quadlet skeletons, and Kubernetes skeletons. These artifacts are evidence only. Sensitive activation must fail closed without Policy Fabric admission.

Required outcome

Define a Policy Fabric admission stub for AgentPod activation.

Acceptance criteria

  • Add a documented admission request/response shape.
  • Admission request includes AgentPod object, deployment plan, manifest/artifact digest, AgentMachine profile, provider facts, storage/cache facts, requested network exposure, requested storage classes, and side-effect scope.
  • Admission response includes decision reference, decision digest, allowed scope, denied scope, obligations, expiration, and revocation hook reference.
  • Activation semantics state: if policyFabricRequired=true and no admission decision exists, activation fails closed.
  • No secret values, raw prompts, raw KV-cache contents, or private memory contents are included in admission payloads.

Related docs

  • docs/architecture/world-class-release-gate.md
  • docs/architecture/receipt-chain.md
  • docs/architecture/deployment-safety.md

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions