DESIGN_READY_FOR_OPERATOR_REVIEW: StarIntel deployment configuration and trusted extension boundary #192
Labels
No labels
bug
design
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
research
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
nsaspy/starintel-auto-research#192
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Design-review transaction for Auto-Research #191 and
lost-rob0t/starintel-server#38.The canonical design will preserve the repaired Nix OCI/Compose deployment and define the residual boundary between validated data-only runtime configuration, runtime secret references, and explicitly trusted executable Lisp startup extensions.
It will include RED-first slices for deterministic config normalization, unknown/unsafe setting rejection, consistent
VALUE/VALUE_FILEhandling, secret redaction, and observed TLS/base-path/runtime behavior.Implementation authorization remains PENDING / AWAITING_OPERATOR_APPROVAL. Design readiness, publication, issue state, or machine review cannot authorize implementation.