Guardana Control 0.2.0-alpha
Pre-release
Pre-release
·
12 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
The second release. It fixes how an approval's expiry is kept, how much
of the plane a stdio upstream is handed, where a plaintext export may go,
and how numbers and uncertain results are recorded. It adds an image of
the gateway beside the archives, and pages that say what the plane
protects, what it records and which failures it survives.
docs/status.md says what is implemented and what is
experimental. Nothing here is a security boundary yet.
Added
- Reason code
APPROVAL_STATE_UNKNOWN(44,INDETERMINATE): a lost hold
whose approval the plane could not read or trust closes with it, where
it closed asAPPROVAL_EXPIREDbefore
(ADR-0027). - A benchmark of the gateway round trip, and
scripts/bench.sh --publish,
which records a run from a clean tree, with its hardware and Go
settings, in a tracked file underbench/results/
(docs/reference/benchmarks.md). - Each release is to publish
ghcr.io/guardana/control-gateway:<version>
for linux/amd64 and linux/arm64, signed keyless and with build
provenance, its digest named in the release notes;
RELEASING.md says how to check it and
docs/guides/run-in-a-container.md
how to run it. - A page of the failures the plane is built to survive: the collector, the
spool, the decision point, an upstream dying mid-call, the pause file
and a restart with calls held, each with a test that runs the built
binary against a real failure
(docs/reference/failure-modes.md). - A threat model and a privacy page: what the plane protects, from whom
and where it stops; what a record holds, where it goes and how long it
stays (docs/concepts/threat-model.md,
docs/concepts/privacy.md).
Changed
- A stdio upstream no longer inherits the plane's environment. It gets
PATH,HOME,LANG,LC_ALL,TMPDIRandUSER, each where the
plane has it, and the variables its newupstreams.N.envlist names;
a name underGUARDANA_CONTROL_is refused, so the exporter's and the
decision point's header credentials are no longer handed to it. An
upstream that read any other inherited variable starts without it:
list each one it needs, anddoctormarks a listed name the plane's
environment lacks
(ADR-0028). export.allow_plaintextadmits a plaintext collector on a loopback IP
literal only, aspdp.allow_plaintextalready did and as
ADR-0020
states. A plaintext endpoint on any other host, a name such aslocalhost
included, is refused at start.
Fixed
- A tool whose definition holds a fractional number, such as
"default": 0.7, is fingerprinted and can be classified, and a call
whose arguments hold a fraction a double represents exactly is decided.
The digest binds a number's value, so1.0and1digest alike, and
every digest of arguments accepted before is unchanged
(ADR-0029). - A resumed call whose approval expired by the plane's clock before it
was handed to the upstream is not sent: it is blocked with
APPROVAL_EXPIRED, and the approval stays spent. - A call whose answer the gateway could not read, or could not complete
over HTTP (a malformed answer, a connection the upstream closed after
reading the call, a 429 or 5xx status), is recorded with anUNKNOWN
result rather than as the upstream's failure: whether it took effect
is unknown. - A decision point's answer that reaches the gateway after the call's
deadline is a timeout (PDP_TIMEOUT), whatever its status and headers.
Such an answer could be read as refused or as unavailable instead.
Image: ghcr.io/guardana/control-gateway@sha256:98aa83285892899b124353e327a2055c0d72bedd479eca492aa2f9452b70e4a0