Skip to content

[P0] Add an authoritative PostgreSQL control plane with tenant isolation and recoverable migrations #80

Description

@seonghobae

Production blocker and current protected truth — refreshed 2026-09-20 KST

Protected/default Wardnet truth remains main@f8260f1e03836039ff9463dd99fa982e4e270c4b. Production mode still does not use PostgreSQL as authoritative state; StateAuthority::Postgres remains deliberately disabled on protected truth. Draft PostgreSQL work is implementation evidence, not protected/released authority.

Wardnet still needs PostgreSQL to be the only production authority for durable control-plane/security-evidence state while retaining JSON/file state only for standalone/community operation. The production boundary must provide multi-replica concurrency, tenant isolation, transactional mutation+audit, recoverable migrations, bounded connection degradation and independently verifiable recovery evidence. Issue #192 owns detailed durable reputation/publication/uniqueness invariants. Issue #243 owns machine-verifiable 100% owned-production statement/line, branch, edge and public-rustdoc evidence.

Current dependency state

Canonical order remains:

#140 -> #193 -> #194 -> #196 -> #198 -> #199 -> #200 -> #207 -> #208 -> #209 -> #212 -> #216 -> #217 -> #219 -> #221 -> #223 -> #224 -> #225 -> #226 -> #228 -> #229 -> #231 -> #233 -> #234 -> #236 -> #241 -> #242 -> #244

#227/#230/#232/#235/#239/#240/#243 remain acceptance/RED or completion lanes. Every parent/head movement requires ordinary non-force adoption and fresh exact-head evidence; predecessor checks do not transfer.

Runtime Configuration foundation #140 is now exact 99c7c6c798f13c9c37d00d9f586f102585ad3494, directly based on protected main@f8260f1e03836039ff9463dd99fa982e4e270c4b, mechanically mergeable and still Draft. The earlier protected-base synthesis/reconciliation lineage has already been integrated into this canonical root: one immutable Runtime Configuration snapshot composes with protected #155 credential/RBAC/public-bind semantics, so stale ambient run_from_env state is no longer the candidate authority. Repository-owned CI/Fuzz/SAST/Security evidence on this exact root is terminal GREEN; delegated CodeQL terminal settlement remains central .github#1929 ownership and is not Wardnet source/test/SARIF failure evidence.

This foundation is therefore technically reconciled but not yet normally integrable under all live governance. Do not restack #193 or later children, add no-op churn, transfer predecessor GREEN, self/model approve, weaken gates or use routine administrator bypass while the unchanged root still lacks terminal-valid delegated review/governance settlement.

First PostgreSQL child #193 remains on its historical parent until foundation-first non-force restack is legitimate. Current tip #244 remains Draft implementation evidence only; its exact lineage includes real PostgreSQL preflight/probe performance evidence, but that evidence does not transfer across the pending dependency restack. Keep the full chain intact and parked rather than force/rebase or manufacture disposable checks.

Draft implementation contract already demonstrated

On real postgres:18.4-bookworm, without enabling production authority, the Draft lineage has demonstrated fail-closed authority selection behind configuration/credential boundaries; durable tenant/source generation token+ordinal uniqueness; atomic publication/history/current-head state with actor/decision attribution; ENABLE+FORCE RLS plus constrained runtime roles; failure-atomic migrations/rollback/reapply; transaction-local tenant context and pool cleanup; typed repositories with no production raw-SQL escape hatch; exact replay/conflict and explicit unknown-COMMIT semantics; bounded pool replacement/reconnect; physical base-backup/WAL/PITR destructive restore; divergent-writer serialization; half-open protocol preflight; and a real 200-sample PostgreSQL preflight+probe buyer-path measurement at p95 <=20 ms on that Draft lineage.

These receipts must be reacquired after dependency-first integration. cargo test is not proof of the standing 100% coverage/rustdoc contract.

Production ownership / integrity contract

Every mutable production row carries explicit tenant and actor/service ownership where applicable. Stable IDs/timestamps come from authority rather than trusted clients. Keyverse supplies authenticated subject/tenant claims through a released contract; Wardnet validates action context and binds tenant authority to its own transaction. Display names, email addresses, HTTP headers and connection-string text are never authorization keys.

Migrations are versioned and failure-atomic. PK/FK/uniqueness/check/domain constraints enforce durable invariants. Critical mutations and Wardnet audit evidence are atomic. Production repositories expose bounded typed operations, not arbitrary SQL callbacks. Once database work begins, connection loss/timeout never causes automatic replay; unknown COMMIT stays explicit and can only be reconciled by later byte-identical typed commands. ENABLE+FORCE RLS is default-deny; runtime LOGINs remain non-owner/non-superuser/non-BYPASSRLS; tenant context is Wardnet-validated and transaction-local. Wardnet migrations do not create long-lived credentials.

No explicit database lock or long-lived transaction may remain open across LLM calls, external I/O, sandbox execution or long-running computation. Read bounded state and end the transaction, perform slow work outside the transaction, then open a bounded write transaction and revalidate the required optimistic/concurrency predicate before commit. Cross-service SQL remains forbidden.

Reliability / recovery contract

Pool capacity is bounded; failed members have bounded replacement authority and cannot head-of-line block healthy members. Protocol progress is checked before business work without replay; stale/desynchronised sessions are removed before reuse. Liveness/startup/readiness remain distinct. Physical backup + WAL/PITR is canonical database recovery with destructive restore evidence. Production backup cadence, retention, archive durability, storage/encryption/key/IAM authority and measured RPO/RTO/SLO remain deployment/operability contracts rather than lab claims.

Remaining production gate

One unchanged dependency-restacked integration candidate still needs protected integration of #140 first and every PostgreSQL child in order; exact 100% owned-production statement/branch/edge/public-rustdoc evidence; production backup/WAL retention, storage/encryption/key/IAM authority and recovery evidence; exact-current startup/readiness/degraded behavior; revalidation of cross-tenant denial, actor/decision attribution, immutable publication/current-head integrity, divergent-writer conflict, byte-identical replay, unknown COMMIT, half-open protocol loss and no-replay semantics; terminal CI/Fuzz/security/SAST/CodeQL/review/thread/package/SBOM/provenance/reproducibility/governance evidence on the same head; and immutable release identity tying source, schema/migrations, package/image, SBOM/provenance/signature, recovery and rollback together.

Close only after PostgreSQL is technically enforced as production authority, RLS is proven below application filtering, critical mutations are transactional/auditable, degraded/unknown outcomes remain bounded/non-replaying, backup/restore meets accepted production objectives, startup/readiness fails closed, exact coverage/rustdoc evidence is complete, and the exact protected integration is published as an immutable verified Wardnet release.

Boundaries

Keyverse owns authenticated identity claims; Wardnet owns Wardnet authorization and transaction binding. Billing/credit products retain financial-ledger authority. EgressWeave, quarantine-sandbox-runtime, contextual-orchestrator, AppGuardrail, Context Graph Contracts and EA Core remain separate canonical owners; no source copy, mutable runtime dependency or cross-service SQL. .github remains canonical for reusable workflow/governance/control-plane repair. Generic solo-maintainer approval remains .github#772; runner/OpenCode control-plane defects remain .github#712/#1234; delegated CodeQL settlement remains .github#1929 or verified successors.

Do not close because a Draft stack is GREEN, a database fixture restores, a p95 sample meets target, or documentation names PostgreSQL.

References

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: accessibilityAccessibility and assistive-technology supportarea: authAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: securitySecurity boundary, hardening, or vulnerability preventionenhancementNew feature or requestpriority: criticalImmediate blocker, P0, urgent deadlock, or critical incidentstatus: triagedOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behaviortype: featureNew or expanded product capability

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions