OpenSpec follow-up: gateway auth and non-SPIFFE edge identity #3179

Open
opened 2026-04-24 02:29:54 +00:00 by mfreeman451 · 0 comments
Owner

OpenSpec IDs:

  • harden-gateway-proxy-auth
  • remove-agent-gateway-spiffe-dependency

Priority: P2

Why this is next:

  • Existing open issues overlap: #878, #631, #1037.
  • This is security-sensitive, but should be sequenced after deployment and topology work unless it blocks hosted edge rollout.

Initial scope:

  • Verify current passive proxy auth and non-SPIFFE mTLS behavior.
  • Update stale OpenSpec task state where Helm/docs/runtime already changed.
  • Define a focused hardening slice with tests before changing auth behavior.
OpenSpec IDs: - `harden-gateway-proxy-auth` - `remove-agent-gateway-spiffe-dependency` Priority: P2 Why this is next: - Existing open issues overlap: #878, #631, #1037. - This is security-sensitive, but should be sequenced after deployment and topology work unless it blocks hosted edge rollout. Initial scope: - Verify current passive proxy auth and non-SPIFFE mTLS behavior. - Update stale OpenSpec task state where Helm/docs/runtime already changed. - Define a focused hardening slice with tests before changing auth behavior.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
carverauto/serviceradar#3179
No description provided.