Skip to content

Phase A — Contract definition + policy-authoring workflow + example Verb Governance Spec #96

Description

@hyperpolymath

Weeks 1–2. Define the gateway↔BoJ contract; the Verb Governance Spec DSL authoring workflow; a worked example spec for BoJ's HTTP surface. No gateway/BoJ HTTP code changes yet. Source: ADR-0004 §phases, docs/integration/http-capability-gateway-plan.md, http-capability-gateway-audit.md. Repo: hyperpolymath/http-capability-gateway.

Parent: standards#91 (ADR-0004 phase A). Single-channel: do not work out of phase order; A→B→C→D→E.

Activity

  1. hyperpolymath commented on May 18, 2026

    @hyperpolymath
    OwnerAuthor

    Phase A in progress — boj-server#78 (specification-only, no code).

    Deliverables landed in boj-server (paths normatively prescribed by docs/integration/http-capability-gateway-plan.md §Phase A):

    • A1 docs/integration/http-capability-gateway-boj-contract.md
    • A2 docs/integration/http-capability-gateway-policy-authoring.md
    • A3 config/gateway-policy-boj-example.yaml (27 rules, DSL v1 validated)

    Load-bearing finding: BojRest.Router bypasses trust enforcement for loopback callers ⇒ inbound X-Trust-Level stripping + back-side network isolation are mandatory invariants (contract §3), feeding Phase B/C.

    Phases B–E (#97–#100) NOT started — strict sequential order held. PR uses Refs, does not close (requirements-target / joint-close).

  2. hyperpolymath commented on May 18, 2026

    @hyperpolymath
    OwnerAuthor

    Phase A merged: boj-server#78 (squash). A1 contract / A2 authoring workflow / A3 example policy (27 rules, DSL v1 validated) are on boj-server main.

    Phase A is complete. Per joint-close discipline this issue is left OPEN (major,requirements-target) — close only on explicit agreement. Next in the strictly-sequential channel is Phase B (#97, mTLS primary path); not started (out-of-phase work prohibited).

  3. hyperpolymath commented on May 31, 2026

    @hyperpolymath
    OwnerAuthor

    Phase A (#96) — closing complete (2026-05-31)

    Closing per owner direction ("if entirely done, remove from the list"). Phase A is fully delivered and has been on boj-server main since boj#78:

    • A1 docs/integration/http-capability-gateway-boj-contract.md
    • A2 docs/integration/http-capability-gateway-policy-authoring.md
    • A3 config/gateway-policy-boj-example.yaml (28 rules after boj#165's SSE-route resync)

    Phases B (#97) and C (#98) — which build directly on this contract — are already closed; closing A brings it in line. The §3 invariant-3 deny-clause that Phase A surfaced is in code (boj#106).

    The live umbrella state, the remaining gates (Phase D-4 baseline flip → Phase E rollout), and the full finish line are consolidated on the parent — standards#91 (comment 2026-05-31). #91 stays open until D-4 + Phase E land.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    majorMajor / load-bearing workrequirements-targetTracked requirements-target item (joint-close)

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions