Enforce SSH workflow capabilities locally

This commit is contained in:
Eric Wendland 2026-05-19 15:44:13 +02:00
commit f7e85960f7
8 changed files with 328 additions and 62 deletions

View file

@ -230,8 +230,16 @@ resource-scoped capability decisions.
manual command.
- `[x]` SSH metadata live-sync stores per-peer high-water cursors in
`module_state` and requests only records at or beyond the cursor.
- `[ ]` Future completion requires auth checks for local request, approve,
import, publish, and read capabilities.
- `[x]` Local SSH cert request/read/approve/import commands can enforce
`ssh_cert.request`, `ssh_cert.read`, `ssh_cert.approve`, and
`ssh_cert.import` for explicit non-owner `--subject` principals.
- `[x]` Local SSH revocation publish/read/import commands can enforce
`ssh_revocation.publish`, `ssh_revocation.read`, and
`ssh_revocation.import` for explicit non-owner `--subject` principals.
- `[x]` Tests cover denied and granted non-owner local SSH cert request and
revocation publish flows.
- `[ ]` Future completion requires all accepted SSH cert/revocation records
to be signed and reducible before replication.
## Phase 3: CAS, KV, And Pubsub