Can a passive observer bind a signed JobResult back to the JobRequest offline? #942
Unanswered
source-origin
asked this question in
Q&A
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
The credential-free worker model is a genuinely different bet from the usual "keep every credential in the worker process", and the two properties you name — the worker cannot decrypt its own secrets, and cannot forge requests back to the controller — are exactly the ones that matter for running vendor code. I read the signing seams closely and hit one I can't resolve.
You sign a
JobRequestand aJobResultseparately (talos-workflow-job-protocol), and the encrypted secrets envelope binds ciphertext to the signed job request via AEAD. So the request→result binding is the thing that carries authorization across the process boundary.The question is what a verifier who holds only the signed artifacts can check, after the fact:
JobResultsignature commit the hash of theJobRequestit answers (so result→request is recomputable from the evidence alone), or is that binding enforced live by the controller?verify()/verify_no_replay()precisely because passive observers (audit subscribers) can't participate in the cache. That reads like the signed artifact alone does not carry replay-finality — a later auditor re-verifying offline can't detect that a given result was already consumed. Is offline, artifact-only replay detection in scope, or is "finality" only knowable while the verifier state is live?Not a critique — I'm mapping where the trust boundary sits when the controller is gone.
All reactions