Files
2026-07-13 19:45:53 +08:00

1.8 KiB

ADDED Requirements

Requirement: Host identity can be established by direct registration

The internal Host Agent API SHALL accept a fresh Host registration without a pre-shared deployment credential, SHALL assign a durable Host identifier, and SHALL store only the digest of the Host-generated secret for subsequent host-scoped authentication.

Scenario: Fresh Host establishes an identity

  • WHEN a fresh Host Agent submits a valid registration request containing its instance identifier and generated secret
  • THEN the control plane returns a durable Host identifier and stores only the secret digest bound to that Host

Scenario: Registration request is retried

  • WHEN the same Host Agent repeats registration with its original instance identifier and secret after a lost response
  • THEN the control plane returns the existing Host identifier without creating a second Host identity

MODIFIED Requirements

Requirement: Host identity is authenticated and bound to one host id

After direct registration, the internal Host Agent API SHALL require a host-scoped bearer principal for all Host operational requests and SHALL reject any request that attempts to act for a host_id different from the authenticated principal's bound host. The initial registration endpoint is the only exception and establishes that bound principal.

Scenario: Host authenticates as itself after registration

  • WHEN a Host Agent presents the persisted generated secret bound to its requested host_id
  • THEN the internal API authorizes permitted heartbeat, claim, renewal, and result operations

Scenario: Host attempts to impersonate another host

  • WHEN valid credentials bound to host A are used on a request for host B
  • THEN the internal API rejects the request without reading or modifying host B's state