Skip to content

feat(platform): gate metadata provider identity - #21

Open
zhouning wants to merge 1 commit into
feat/ar1-metadata-fabric-gravitino-identityfrom
feat/ar1-metadata-fabric-identity-readiness-gate
Open

feat(platform): gate metadata provider identity#21
zhouning wants to merge 1 commit into
feat/ar1-metadata-fabric-gravitino-identityfrom
feat/ar1-metadata-fabric-identity-readiness-gate

Conversation

@zhouning

Copy link
Copy Markdown
Owner

Summary

  • add a versioned production Metadata Fabric identity profile and fail-closed profile/attestation/report gate
  • bind OpenMetadata 1.13.1 and Gravitino 1.3.0 to the exact M3-5/M3-6 local identity evidence and minimum-privilege contracts
  • require explicit OIDC/workload/tenant, digest-pinned provider authentication, TLS/mTLS, persistent catalog, tenant isolation, lifecycle and operational decisions
  • add ADR-053, roadmap/System-of-Record updates, CI validation and 26 focused tests

Evidence boundary

  • the checked-in profile is structurally valid but exposes 40 external production blockers
  • Gravitino 1.3.0 ships the Basic IdP jar only; this gate allows a custom OIDC authenticator or identity-aware proxy and does not invent native OIDC support
  • no production identity component is deployed and no real production attestation is committed
  • all production identity claims and overall production_ready remain false

Verification

  • 26 focused identity-gate tests passed
  • platform truth validation passed
  • required platform suite: 655 passed
  • profile fingerprint: 2e9d5cac3560b853820f923669f6794ead63bcb36a528639fc0e9539e148ee2f
  • report fingerprint: c607589ee25a87acc8a1ab71372618a9a4c10c1e8ebff15b8db7e78b37600b9f

Stack

Depends on #20 and targets feat/ar1-metadata-fabric-gravitino-identity. Do not merge this PR before its parent.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant