Skip to content

feat: scope middleman inference to workload permissions - #1965

Draft
rasmusfaber wants to merge 24 commits into
feat/sec-374-credential-authorityfrom
feat/sec-374-middleman-enforcement
Draft

rasmusfaber wants to merge 24 commits into
feat/sec-374-credential-authorityfrom
feat/sec-374-middleman-enforcement

Conversation

@rasmusfaber

@rasmusfaber rasmusfaber commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Overview

Workload inference must respect exact model approvals while charging usage and fair sharing to the submitting person. This adds workload authentication and model enforcement to Middleman, stacked on #1896.

Approach

Compare signed approvals with the exact registry entry dispatched, including opaque secret-model bindings. Read the shared issuer/audience/JWKS settings directly and validate the same string audience as the broker. Keep JWKS fetching and human issuer separation; invalid workload tokens never fall back to human authentication.

Authentication and traffic logs retain execution identity separately from accounting fields. Usage metrics and both priority paths require signed person/team attribution, so direct requests and executions share the person’s allocation. Dashboard queries retain legacy-log fallback and distinguish unknown from verified empty teams. New workload tokens reject missing/null attribution or teams; explicit empty teams remain valid. Preserve human email logging and metrics.

Risks

  • Roll issuer and consumers together with names-only workload identity; the previous nested settings and array-valued workload audiences are unsupported.
  • Historical execution-user metrics remain unchanged; team membership is captured at submission/resume.
  • Secret-target retargeting or binding-key rotation requires fresh approval.
  • Batch, background and legacy routes remain unavailable to workload credentials. Priority enforcement is not enabled by this change.

Testing & validation

All 2,087 Middleman tests and 180 affected Hawk tests passed. Coverage retains every provider route, real accounting/priority dispatch and malformed-attribution rejection. Full Hawk/Middleman types, Ruff/format, applicable hooks and independent spec/quality review passed. No deployment performed; live Logs Insights validation remains deployment acceptance.

  • Verified the change works (commands / manual steps described above)
  • Added or updated tests where it makes sense

Code quality

  • pre-commit run --all-files passes (ruff, basedpyright/mypy, eslint/prettier/tsc, shellcheck — what CI's Lint job runs)

Before merging

  • PR title is a Conventional Commit with a lower-case subject — it becomes the squash-merge commit subject and drives the SemVer bump
  • All commits are signed and show as Verified on GitHub — see Commit signing

@rasmusfaber
rasmusfaber force-pushed the feat/sec-374-middleman-enforcement branch 2 times, most recently from f4e7cf6 to adbb1a0 Compare October 1, 2026 09:35
@rasmusfaber
rasmusfaber force-pushed the feat/sec-374-credential-authority branch from cc0f241 to d34b0d5 Compare October 1, 2026 10:52
@rasmusfaber
rasmusfaber force-pushed the feat/sec-374-middleman-enforcement branch 2 times, most recently from b2598f3 to e64b48a Compare October 2, 2026 17:43
@rasmusfaber
rasmusfaber force-pushed the feat/sec-374-credential-authority branch from d34b0d5 to d25022e Compare October 2, 2026 17:43
@rasmusfaber
rasmusfaber force-pushed the feat/sec-374-middleman-enforcement branch from e64b48a to 3bc8a79 Compare October 2, 2026 18:57
@rasmusfaber
rasmusfaber force-pushed the feat/sec-374-middleman-enforcement branch from 3bc8a79 to 4771412 Compare October 2, 2026 19:07

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant