Skip to content

docs: establish identity product and architecture baseline - #75

Merged
seonghobae merged 33 commits into
mainfrom
docs/product-architecture-baseline-2026-08-09
Aug 11, 2026
Merged

docs: establish identity product and architecture baseline#75
seonghobae merged 33 commits into
mainfrom
docs/product-architecture-baseline-2026-08-09

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 9, 2026

Copy link
Copy Markdown
Contributor

Purpose

Make Keyverse's cross-cutting product, technical, data, security, operating, and decision memory canonical and machine-checkable instead of reconstructing it from README, ARCHITECTURE.md, feature specs, doctoring pages, operations pages, and PR bodies.

The branch was created from and revalidated against exact protected main c8968ec1e68fab16d0ad8216fb5c8fd0b385e95f.

Added

  • DOCUMENTATION.md documentation map and maturity vocabulary
  • docs/PRD.md
  • docs/TRD.md
  • docs/UML.md
  • docs/ERD.md for Keyverse-owned state while preserving Keycloak schema ownership
  • docs/THREAT_MODEL.md
  • docs/TEST_STRATEGY.md
  • docs/OPERABILITY.md
  • docs/TRACEABILITY.md
  • ADR index plus seven governing ADRs
  • tests/test_documentation_contract.py

Existing records preserved

ARCHITECTURE.md, docs/topology.md, federation/RP onboarding, merge/unification flow, docs/operations/, docs/doctoring/, and docs/papers/ remain authoritative for their existing slices. This PR consolidates discoverability and cross-cutting invariants rather than duplicating those documents.

Truth boundary

The docs describe protected-main passwordless Keycloak hub, account unification, SCIM, SAML/OIDC and LDAP desired-state boundaries, secret-free RP reconciliation, operation locking, deployment-controller ownership, and current quality gates.

PR #72's closed OIDC RP mapper profile and PR #74's hourly GitHub API remediation remain explicitly active-PR, not protected-main/released behavior. Controlled external login/bind/downstream authorization acceptance is kept separate from side-effect-free preflight readiness.

Verification contract

The documentation contract runs in the existing pytest suite and prevents disappearance of canonical records, false ownership of Keycloak internal persistence, missing ADRs, or promotion of active PR work into mainline claims. Exact current-head CI, 100% production statement/branch/docstring gates, package/realm/deployment validation, CodeQL, Semgrep, Security Scan, independent review, and branch protection must pass before merge.

Summary by CodeRabbit

  • 문서화

    • 제품 요구사항, 기술 기준, 아키텍처, 데이터 모델, 운영, 보안 위협 및 추적성 문서를 추가했습니다.
    • 인증, 계정 매칭, 비밀번호 없는 로그인, 상태 조정, 비밀 관리 및 자동화 권한에 대한 주요 결정사항을 문서화했습니다.
    • 온보딩, 복구, 릴리스 기준과 관련 표준 문서 링크를 정리했습니다.
    • 애플리케이션별 토큰 검증, 테넌트 경계 및 인가 기준을 명확히 했습니다.
  • 테스트

    • 필수 문서, 문서 링크, 활성 변경사항 상태 및 주요 아키텍처 결정사항을 검증하는 문서 계약 테스트를 추가했습니다.

@coderabbitai

coderabbitai Bot commented Aug 9, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@seonghobae, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 47 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: b131c382-a67d-441b-8fb8-f34dd9495bf4

📥 Commits

Reviewing files that changed from the base of the PR and between 1c834e6 and c8e3656.

📒 Files selected for processing (1)
  • docs/adr/0008-keyverse-rp-authorization-boundary.md
📝 Walkthrough

Walkthrough

Keyverse의 제품·기술 요구사항, 데이터 모델, 보안·운영 기준, ADR, UML 및 문서 계약 테스트를 추가했다. 문서는 protected main, active PR, Keycloak 소유 데이터와 desired-state reconciliation 경계를 정의한다.

Changes

제품 계약과 거버넌스

Layer / File(s) Summary
제품·기술 요구사항과 추적성
DOCUMENTATION.md, docs/PRD.md, docs/TRD.md, docs/TRACEABILITY.md
제품 범위, 기술 기준, 문서 성숙도, 요구사항 추적성 및 릴리스 조건을 정의한다.
아키텍처 결정과 RP 권한 경계
docs/adr/*, ARCHITECTURE.md, CHANGELOG.md
Keycloak 허브, passwordless 계정, 신원 매칭, desired-state reconciliation, 비밀 소유권, 자동화 권한 및 downstream RP 인가 경계를 기록한다.

영속성·신원 수명주기

Layer / File(s) Summary
영속 데이터 모델과 소유권
docs/ERD.md
Keyverse의 desired state, receipt, 감사 기록, 잠금 상태와 Keycloak이 소유하는 canonical 상태를 구분한다. 테넌트 격리와 데이터베이스 제약을 정의한다.
Reconciliation 및 사용자 작업 흐름
docs/UML.md, docs/merge-unification-flow.md
Federation 적용, RP 등록, 계정 병합, SCIM 변경 및 공통 사용자 작업 잠금 흐름을 정의한다.

보안·운영·검증

Layer / File(s) Summary
위협 모델과 보안 검증
docs/THREAT_MODEL.md, docs/TEST_STRATEGY.md, ARCHITECTURE.md
신뢰 경계, STRIDE 위협, 필수 통제와 인증·SCIM·연합·RP·복구 테스트 기준을 추가한다.
운영 상태와 복구 절차
docs/OPERABILITY.md
상태 모델, SLI, 온보딩, reconciliation 복구, 백업·복원, 롤백 및 릴리스 게이트를 정의한다.
문서 계약 테스트
tests/test_documentation_contract.py
필수 문서, 링크, active-PR 상태, Keycloak 스키마 소유권 및 ADR 인덱스를 검증한다.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 Keyverse의 제품 및 아키텍처 문서 기준선을 수립하는 변경사항을 간결하고 정확하게 설명합니다.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch docs/product-architecture-baseline-2026-08-09

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 10

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/adr/0006-user-operation-lock.md`:
- Around line 1-6: Include the SCIM patch_user flow in the shared cross-process
user-operation lock boundary. Protect its get_user and deactivate_user
read-modify-write sequence with user_operation_locks.hold(user_id), matching
replace_user; otherwise explicitly exclude PATCH through a separate contract and
update the ADR and merge documentation accordingly.

In `@docs/adr/README.md`:
- Line 19: The documentation contract uses the undefined term “doctoring”;
replace it with the established documentation, doctrine, or actual runbook
terminology and path. Update docs/adr/README.md lines 19-19 and
docs/TEST_STRATEGY.md lines 88-88 consistently, including the
“doctoring/operations links” reference.

In `@docs/ERD.md`:
- Around line 105-111: Update the EXTERNAL_IDENTITY_LINK definition to add a
composite unique constraint on (federation_source_id, external_subject_hash),
preventing one external subject within a federation source from linking to
multiple Keycloak users. Document that federation_source_id defines the
identity-provider scope for this uniqueness rule.
- Around line 31-37: Update the ERD definitions for IDP_CONFIG_ENTRY and the
related entities at the referenced sections so config_key, federation_alias,
directory_alias, client_id, and keycloak_user_uuid are documented as
tenant-scoped composite unique keys with tenant_deployment_id, while retaining
global uniqueness only for UUID identifiers.
- Around line 51-58: Update the three receipt entities, including
FEDERATION_APPLY_RECEIPT, to store the desired-state version or hash alongside
observed_state_hash, outcome, and timestamp. Define documentation rules for
identifying the latest desired version and handling duplicate receipts,
consistent with the versioned contract in THREAT_MODEL.md.

In `@docs/OPERABILITY.md`:
- Line 59: Update the wording around the PR `#72` claim mapper acceptance
statement in OPERABILITY.md to consistently use “Naruon” for the
product/platform and “naruon-web” only for the RP client ID. Clarify whether
authorization readiness refers to the Naruon product or the naruon-web client so
operators know which authentication flow and scope to validate.

In `@docs/TRD.md`:
- Around line 45-49: Synchronize the native loopback redirect exception between
docs/TRD.md and docs/PRD.md: either remove “except separately reviewed native
loopback profile” from the RP clients contract, or, if native loopback is
supported, document its exact exception conditions in PRD-FR-005, the threat
model, test strategy, and traceability documentation.

In `@docs/UML.md`:
- Around line 24-28: Update the UML storage relationships so the Keycloak
PostgreSQL node is explicitly Keycloak-owned and the Keyverse-owned store is
represented as a separate node. Remove the direct ADMIN --> PG relationship,
retain Keycloak’s connection to its own database, and route ADMIN through the
Keycloak Admin API to the Keycloak engine while preserving the existing
deployment relationships.

In `@tests/test_documentation_contract.py`:
- Around line 68-81: Update test_adr_index_contains_governing_identity_decisions
to verify each listed ADR both appears in docs/adr/README.md and exists as a
file at ROOT / "docs" / "adr" / adr, using is_file().
- Around line 49-57: Strengthen test_active_pr_features_are_not_promoted_to_main
so each PR’s identifier is directly associated with active-PR in both
docs/PRD.md and docs/TRACEABILITY.md. Replace the current independent substring
assertions and unrelated RP `#72` exclusion with per-PR checks that validate PR
`#72` and PR `#74` each retain active-PR status in their corresponding documentation
entries.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 16a1fb5b-db38-42b8-b622-4be30efcd86c

📥 Commits

Reviewing files that changed from the base of the PR and between c8968ec and ee38d88.

📒 Files selected for processing (18)
  • DOCUMENTATION.md
  • docs/ERD.md
  • docs/OPERABILITY.md
  • docs/PRD.md
  • docs/TEST_STRATEGY.md
  • docs/THREAT_MODEL.md
  • docs/TRACEABILITY.md
  • docs/TRD.md
  • docs/UML.md
  • docs/adr/0001-keycloak-hub.md
  • docs/adr/0002-passwordless-local-accounts.md
  • docs/adr/0003-identity-matching.md
  • docs/adr/0004-desired-state-reconciliation.md
  • docs/adr/0005-secret-ownership.md
  • docs/adr/0006-user-operation-lock.md
  • docs/adr/0007-automation-authority.md
  • docs/adr/README.md
  • tests/test_documentation_contract.py

Comment thread docs/adr/0006-user-operation-lock.md Outdated
Comment thread docs/adr/README.md Outdated
Comment thread docs/ERD.md
Comment thread docs/ERD.md
Comment thread docs/ERD.md
Comment thread docs/OPERABILITY.md Outdated
Comment thread docs/TRD.md
Comment thread docs/UML.md Outdated
Comment thread tests/test_documentation_contract.py Outdated
Comment thread tests/test_documentation_contract.py Outdated

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please re-review current exact head 4d2841071e9a8136298bb7198229d47ff406284d. Current head narrows the shared user-operation-lock guarantee to merge + SCIM full replacement, explicitly excludes current PATCH active=false from that guarantee, separates Keycloak-owned vs Keyverse-owned persistence, defines tenant-scoped uniqueness/receipt version binding, and keeps PR #72/#74 active rather than shipped. Evaluate the current source/documentation contract; prior review evidence is stale-head.

@coderabbitai

coderabbitai Bot commented Aug 9, 2026

Copy link
Copy Markdown

@seonghobae I will review exact head 4d2841071e9a8136298bb7198229d47ff406284d.

I will verify the source and documentation contract for:

  • The merge and SCIM full-replacement user-operation-lock boundary.
  • The exclusion of current PATCH active=false.
  • Keycloak-owned versus Keyverse-owned persistence.
  • Tenant-scoped uniqueness and receipt version binding.
  • PR #72 and PR #74 remaining active-PR, not protected-main behavior.
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
docs/ERD.md (1)

187-189: 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

ERD의 USER_OPERATION_LOCK_STATE와 구현된 잠금 스키마의 차이를 매핑하세요.

USER_OPERATION_LOCK_STATE가 물리 스키마라면 lock_name TEXT PRIMARY KEYrequested_user_ids TEXT가 있는 현재 SqliteUserOperationLocks._SCHEMA와 일치하지 않습니다. 논리 모델이라면 SQLite sidecar의 전역 mutex를 ERD의 per-user FK/lease 필드에 어떻게 매핑하는지 문서에 명시하세요. 어용지 구현 없이 lease_expires_at 동시성 테스트를 검증할 수 없습니다.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@docs/ERD.md` around lines 187 - 189, Update the ERD documentation to
explicitly map USER_OPERATION_LOCK_STATE to the implementation in
SqliteUserOperationLocks._SCHEMA: document whether it is a logical model or
physical schema, reconcile lock_name TEXT PRIMARY KEY and requested_user_ids
TEXT with the ERD fields, and describe how the SQLite sidecar’s global mutex
maps to per-user foreign-key and lease fields, including the lease_expires_at
concurrency-test implications.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/ERD.md`:
- Line 154: Update the physical migration constraints for EXTERNAL_IDENTITY_LINK
and ACCOUNT_MERGE_AUDIT so each child record references parent records within
the same TENANT_DEPLOYMENT, using composite foreign keys or an equivalent
database constraint that includes tenant_deployment_id. Ensure cross-tenant
federation-source, Keycloak-user, and merge-audit associations are rejected
regardless of documentation labels.

---

Outside diff comments:
In `@docs/ERD.md`:
- Around line 187-189: Update the ERD documentation to explicitly map
USER_OPERATION_LOCK_STATE to the implementation in
SqliteUserOperationLocks._SCHEMA: document whether it is a logical model or
physical schema, reconcile lock_name TEXT PRIMARY KEY and requested_user_ids
TEXT with the ERD fields, and describe how the SQLite sidecar’s global mutex
maps to per-user foreign-key and lease fields, including the lease_expires_at
concurrency-test implications.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 93be661b-de48-455f-941e-b30b02630e44

📥 Commits

Reviewing files that changed from the base of the PR and between ee38d88 and 4d28410.

📒 Files selected for processing (11)
  • docs/ERD.md
  • docs/OPERABILITY.md
  • docs/PRD.md
  • docs/TEST_STRATEGY.md
  • docs/TRACEABILITY.md
  • docs/TRD.md
  • docs/UML.md
  • docs/adr/0006-user-operation-lock.md
  • docs/adr/README.md
  • docs/merge-unification-flow.md
  • tests/test_documentation_contract.py
🚧 Files skipped from review as they are similar to previous changes (8)
  • docs/PRD.md
  • docs/UML.md
  • docs/TRD.md
  • tests/test_documentation_contract.py
  • docs/TEST_STRATEGY.md
  • docs/adr/README.md
  • docs/OPERABILITY.md
  • docs/TRACEABILITY.md

Comment thread docs/ERD.md

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode cannot approve yet because required coverage evidence did not pass.

Review outcome

1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence

  • Problem: The required coverage-evidence job result was failure, so OpenCode cannot establish approval sufficiency for this head.

  • Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.

  • Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports success with required evidence or explicit no-source not-applicable evidence.

  • Regression test: Keep the approval branch checking needs.coverage-evidence.result == success before posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present.

  • Result: REQUEST_CHANGES

  • Reason: coverage-evidence result was failure, so required test/docstring evidence was not proven for current head 4d2841071e9a8136298bb7198229d47ff406284d.

  • Head SHA: 4d2841071e9a8136298bb7198229d47ff406284d

  • Workflow run: 31315176332

  • Workflow attempt: 1

Coverage evidence

Coverage evidence job did not run or did not publish coverage evidence.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file: DOCUMENTATION.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file: DOCUMENTATION.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Docs (17 files)"]
  S2 --> I2["operator or user guidance"]
  I2 --> R2["Review risk: Docs (17 files)"]
  R2 --> V2["docs review"]
  Evidence --> S3["Test: test_documentation_contract.py"]
  S3 --> I3["regression suite"]
  I3 --> R3["Review risk: Test: test_documentation_contract.py"]
  R3 --> V3["targeted test run"]
Loading

@opencode-agent

opencode-agent Bot commented Aug 9, 2026

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

  • Head SHA: 4d2841071e9a8136298bb7198229d47ff406284d
  • Workflow run: 31315176332
  • Workflow attempt: 1
  • Gate result: REQUEST_CHANGES (approval step)

Pull request overview

OpenCode cannot approve yet because required coverage evidence did not pass.

Review outcome

1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence

  • Problem: The required coverage-evidence job result was failure, so OpenCode cannot establish approval sufficiency for this head.

  • Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.

  • Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports success with required evidence or explicit no-source not-applicable evidence.

  • Regression test: Keep the approval branch checking needs.coverage-evidence.result == success before posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present.

  • Result: REQUEST_CHANGES

  • Reason: coverage-evidence result was failure, so required test/docstring evidence was not proven for current head 4d2841071e9a8136298bb7198229d47ff406284d.

  • Head SHA: 4d2841071e9a8136298bb7198229d47ff406284d

  • Workflow run: 31315176332

  • Workflow attempt: 1

Coverage evidence

Coverage evidence job did not run or did not publish coverage evidence.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file: DOCUMENTATION.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file: DOCUMENTATION.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Docs (17 files)"]
  S2 --> I2["operator or user guidance"]
  I2 --> R2["Review risk: Docs (17 files)"]
  R2 --> V2["docs review"]
  Evidence --> S3["Test: test_documentation_contract.py"]
  S3 --> I3["regression suite"]
  I3 --> R3["Review risk: Test: test_documentation_contract.py"]
  R3 --> V3["targeted test run"]
Loading

@seonghobae

Copy link
Copy Markdown
Contributor Author

Review follow-up on exact head 1c834e6da66f33d9805fd16b01bfa71090852983: applied the ERD tenant-qualified composite foreign-key fix for EXTERNAL_IDENTITY_LINK and both ACCOUNT_MERGE_AUDIT user references. Added ADR-0008 with the six non-fork RP authorization audit and app-specific ABAC/RBAC remediation directions, plus synchronized PRD/TRD/Architecture/UML/Threat/Test/Operability/Traceability records. Please re-review this exact head after checks; do not carry predecessor findings forward.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/adr/0008-keyverse-rp-authorization-boundary.md`:
- Around line 15-17: Update the external RP audit documentation to record the
README-referenced revision and each audited RP’s immutable commit SHA, branch,
or equivalent evidence link alongside the audit date and repository paths.
Ensure the authorization status in Lines 21-26 remains reproducible;
alternatively, explicitly label the table as a snapshot and exclude it from
evidence supporting the authorization-ready determination.
- Around line 49-57: Update the Keyverse claim contract in this ADR to
explicitly define required and optional claims, enumerate the allowed bounded
role values and format, and specify tenant/workspace binding and validation
rules for org and workspace. Reconcile the statement that applications need not
support every claim with these requirements, and link the contract to the
relevant acceptance tests so RP implementations use consistent authorization
rules.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 5190ffa2-7edc-4af9-b56b-945ec63a593a

📥 Commits

Reviewing files that changed from the base of the PR and between 4d28410 and 1c834e6.

📒 Files selected for processing (13)
  • ARCHITECTURE.md
  • CHANGELOG.md
  • docs/ERD.md
  • docs/OPERABILITY.md
  • docs/PRD.md
  • docs/TEST_STRATEGY.md
  • docs/THREAT_MODEL.md
  • docs/TRACEABILITY.md
  • docs/TRD.md
  • docs/UML.md
  • docs/adr/0008-keyverse-rp-authorization-boundary.md
  • docs/adr/README.md
  • tests/test_documentation_contract.py
🚧 Files skipped from review as they are similar to previous changes (8)
  • docs/adr/README.md
  • tests/test_documentation_contract.py
  • docs/UML.md
  • docs/THREAT_MODEL.md
  • docs/OPERABILITY.md
  • docs/TEST_STRATEGY.md
  • docs/ERD.md
  • docs/TRACEABILITY.md

Comment thread docs/adr/0008-keyverse-rp-authorization-boundary.md Outdated
Comment thread docs/adr/0008-keyverse-rp-authorization-boundary.md Outdated
@seonghobae

Copy link
Copy Markdown
Contributor Author

@opencode-agent @cwl-noema-review

Review exact current head 4da37dc18f7e65dcdac9fcf0344684750d99e75e only. ADR-0008 now includes immutable audit refs, explicit required/optional claim validation, bounded role rules, tenant/workspace binding, acceptance-test paths, and latest SDP PR #58 head. Current-head checks are rerunning; do not carry predecessor findings forward.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Correction: exact current head is 4da37dccc441719ed5ebf05330e0e1eb8d3cfb80. Please use this SHA for the review; the preceding comment had a mistyped full SHA.

@seonghobae
seonghobae dismissed opencode-agent[bot]’s stale review August 11, 2026 11:19

Superseded by current head 4da37dc: the predecessor coverage-evidence blocker was resolved, ADR findings were addressed, and all current-head checks pass. This dismissal is not an approval.

@seonghobae
seonghobae merged commit 6a3a595 into main Aug 11, 2026
30 checks passed
@seonghobae
seonghobae deleted the docs/product-architecture-baseline-2026-08-09 branch August 11, 2026 11:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant