Some checks failed
Docs CI / lint-and-preview (push) Has been cancelled
This commit introduces the OpenSslLegacyShim class, which sets the LD_LIBRARY_PATH environment variable to include the directory containing OpenSSL 1.1 native libraries. This is necessary for Mongo2Go to function correctly on Linux platforms that do not ship these libraries by default. The shim checks if the current operating system is Linux and whether the required directory exists before modifying the environment variable.
1.7 KiB
1.7 KiB
2025-11-01 · Authority adds Orch.Admin quota controls
What changed
- Introduced new
orch:quotascope and expandedOrch.Adminrole for Orchestrator quota, burst, and historical backfill adjustments. - Client credential requests for
orch:quotanow requirequota_reason(≤256 chars) and accept optionalquota_ticket(≤128 chars). Authority records both values underquota.reason/quota.ticketaudit properties. - Added dedicated
orch:backfillscope. Tokens must includebackfill_reason(≤256 chars) andbackfill_ticket(≤128 chars); Authority persists them asbackfill.reason/backfill.ticketclaims and audit properties alongside operator metadata. - Tokens embedding
orch:quotaororch:backfillexpose the corresponding reason/ticket claims so downstream services and audit tooling can trace quota increases or emergency backfills. - Console, CLI, and configuration samples include the updated role plus environment variables (
STELLAOPS_ORCH_QUOTA_REASON,STELLAOPS_ORCH_QUOTA_TICKET,STELLAOPS_ORCH_BACKFILL_REASON,STELLAOPS_ORCH_BACKFILL_TICKET) for automation.
Why
Quotas and replay backfills materially affect tenant isolation and platform capacity. Capturing explicit operator intent keeps change windows reviewable and aligns with platform audit requirements.
Actions
- Update Authority configuration/offline bundles to seed
Orch.Adminrole for the handful of ops identities that manage quotas. - Adjust automation to pass
quota_reason/quota_ticketwhen exchanging tokens fororch:quotaandbackfill_reason/backfill_ticketfororch:backfill. - Monitor
authority.client_credentials.grantrecords for the newquota.*andbackfill.*audit properties when reviewing change windows.