Files
git.stella-ops.org/docs/implplan/SPRINT_120_policy_reasoning.md
master 75c2bcafce
Some checks failed
Docs CI / lint-and-preview (push) Has been cancelled
Add LDAP Distinguished Name Helper and Credential Audit Context
- Implemented LdapDistinguishedNameHelper for escaping RDN and filter values.
- Created AuthorityCredentialAuditContext and IAuthorityCredentialAuditContextAccessor for managing credential audit context.
- Developed StandardCredentialAuditLogger with tests for success, failure, and lockout events.
- Introduced AuthorityAuditSink for persisting audit records with structured logging.
- Added CryptoPro related classes for certificate resolution and signing operations.
2025-11-09 12:21:38 +02:00

2.8 KiB

Sprint 120 - Policy & Reasoning

Last updated: November 8, 2025. Implementation order is DOING → TODO → BLOCKED.

Focus areas below were split out of the previous combined sprint; execute sections in order unless noted.

Findings.I

Dependency: Sprint 110.A - AdvisoryAI (must land before this track). Focus: Policy & Reasoning focus on Findings (phase I).

# Task ID & handle State Key dependency / next step Owners
1 LEDGER-29-007 TODO Instrument metrics (ledger_write_latency, projection_lag_seconds, ledger_events_total), structured logs, and Merkle anchoring alerts; publish dashboards (Deps: LEDGER-29-006) Findings Ledger Guild, Observability Guild / src/Findings/StellaOps.Findings.Ledger
2 LEDGER-29-008 TODO Develop unit/property/integration tests, replay/restore tooling, determinism harness, and load tests at 5M findings/tenant (Deps: LEDGER-29-007) Findings Ledger Guild, QA Guild / src/Findings/StellaOps.Findings.Ledger
3 LEDGER-29-009 TODO Provide deployment manifests (Helm/Compose), backup/restore guidance, Merkle anchor externalization (optional), and offline kit instructions (Deps: LEDGER-29-008) Findings Ledger Guild, DevOps Guild / src/Findings/StellaOps.Findings.Ledger
4 LEDGER-34-101 TODO Link orchestrator run ledger exports into Findings Ledger provenance chain, index by artifact hash, and expose audit queries (Deps: LEDGER-29-009) Findings Ledger Guild / src/Findings/StellaOps.Findings.Ledger
5 LEDGER-AIRGAP-56-001 TODO Record bundle provenance (bundle_id, merkle_root, time_anchor) on ledger events for advisories/VEX/policies imported via Mirror Bundles Findings Ledger Guild / src/Findings/StellaOps.Findings.Ledger
6 LEDGER-AIRGAP-56-002 TODO Surface staleness metrics for findings and block risk-critical exports when stale beyond thresholds; provide remediation messaging (Deps: LEDGER-AIRGAP-56-001) Findings Ledger Guild, AirGap Time Guild / src/Findings/StellaOps.Findings.Ledger
7 LEDGER-AIRGAP-57-001 TODO Link findings evidence snapshots to portable evidence bundles and ensure cross-enclave verification works (Deps: LEDGER-AIRGAP-56-002) Findings Ledger Guild, Evidence Locker Guild / src/Findings/StellaOps.Findings.Ledger
8 LEDGER-AIRGAP-58-001 TODO Emit timeline events for bundle import impacts (new findings, remediation changes) with sealed-mode context (Deps: LEDGER-AIRGAP-57-001) Findings Ledger Guild, AirGap Controller Guild / src/Findings/StellaOps.Findings.Ledger
9 LEDGER-ATTEST-73-001 TODO Persist pointers from findings to verification reports and attestation envelopes for explainability Findings Ledger Guild, Attestor Service Guild / src/Findings/StellaOps.Findings.Ledger