From 1fb0c76cac9f03e462b2d1214a5b418e51242ce9 Mon Sep 17 00:00:00 2001 From: toki Date: Sun, 21 Jun 2026 23:19:25 +0900 Subject: [PATCH] =?UTF-8?q?[roadmap]=20Control=20Plane=20=EB=B3=B4?= =?UTF-8?q?=EC=95=88=C2=B7=EA=B0=90=EC=82=AC=20Milestone=20=EA=B3=84?= =?UTF-8?q?=ED=9A=8D=20=EC=83=81=ED=83=9C=20=EA=B0=B1=EC=8B=A0=20-=20SDD?= =?UTF-8?q?=20=EC=8A=B9=EC=9D=B8,=20=EA=B5=AC=ED=98=84=20=EC=9E=A0?= =?UTF-8?q?=EA=B8=88=20=ED=95=B4=EC=A0=9C,=20=EA=B5=AC=ED=98=84=20scope=20?= =?UTF-8?q?=EA=B5=AC=EC=B2=B4=ED=99=94?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .../control-plane-product-surface/PHASE.md | 2 +- .../control-plane-security-audit-surface.md | 37 ++++++++----------- 2 files changed, 17 insertions(+), 22 deletions(-) diff --git a/agent-roadmap/phase/control-plane-product-surface/PHASE.md b/agent-roadmap/phase/control-plane-product-surface/PHASE.md index 81c638c..e6c3406 100644 --- a/agent-roadmap/phase/control-plane-product-surface/PHASE.md +++ b/agent-roadmap/phase/control-plane-product-surface/PHASE.md @@ -30,7 +30,7 @@ - [완료] Runner proto-socket transport hardening - 경로: `agent-roadmap/archive/phase/control-plane-product-surface/milestones/runner-proto-socket-transport-hardening.md` - 요약: OTO Server와 runner의 기본 내부 연결을 proto-socket push/session 기준으로 다듬고, HTTP job claim/polling 잔존 경로를 compatibility 경계로 축소한다. -- [스케치] Control Plane 운영 보안·감사 표면 +- [계획] Control Plane 운영 보안·감사 표면 - 경로: `agent-roadmap/phase/control-plane-product-surface/milestones/control-plane-security-audit-surface.md` - 요약: write action 표면 이후 필요한 인증/권한, 감사 로그, 민감 정보 마스킹, UI 노출 경계를 SDD와 구현 가능한 Task로 구체화한다. diff --git a/agent-roadmap/phase/control-plane-product-surface/milestones/control-plane-security-audit-surface.md b/agent-roadmap/phase/control-plane-product-surface/milestones/control-plane-security-audit-surface.md index 5904241..7f50b5d 100644 --- a/agent-roadmap/phase/control-plane-product-surface/milestones/control-plane-security-audit-surface.md +++ b/agent-roadmap/phase/control-plane-product-surface/milestones/control-plane-security-audit-surface.md @@ -12,47 +12,42 @@ Control Plane write action 표면 위에 운영 권한, 확인 가능한 감사 ## 상태 -[스케치] +[계획] ## 승격 조건 -- [ ] 인증/권한의 최소 제품 범위와 책임 경계를 확정한다. -- [ ] 감사 로그의 source of truth, 보존 범위, UI 노출 범위를 확정한다. -- [ ] 신규 Core API/schema/proto가 필요한지 기존 endpoint 조합으로 충분한지 판정한다. -- [ ] SDD 작성 범위와 사용자 결정 필요 항목을 분리한다. -- [ ] 구현 가능한 기능 Task와 검증 기준을 `[계획]` 상태로 정리한다. +- 충족: SDD가 `[승인됨]`이고 D01-D03 사용자 결정이 `user_review_0.log`로 해결되어 최소 인증/권한, 감사 source of truth, UI 노출/마스킹 기준이 구현 계획으로 전환 가능한 범위로 고정되었다. ## 구현 잠금 -- 상태: 잠금 +- 상태: 해제 - SDD: 필요 - SDD 문서: `agent-roadmap/sdd/control-plane-product-surface/control-plane-security-audit-surface/SDD.md` - SDD 사유: 인증/권한, 감사 로그, write action 책임 경계는 API/schema/UI 상태와 사용자 승인 gate에 영향을 주므로 구현 전에 source of truth와 상태 전이를 고정해야 한다. - 잠금 해제 조건: - - [ ] SDD 상태가 `[승인됨]`이고 SDD 잠금이 해제되어 있다. - - [ ] SDD `USER_REVIEW.md`가 없거나 승인/해결되었다. - - [ ] Acceptance Scenario가 Milestone 기능 Task와 연결되어 있다. - - [ ] Evidence Map이 plan의 `Spec Targets`와 완료 시 `Spec Completion`으로 검증 가능하게 연결되어 있다. -- 결정 필요: - - 최소 인증 모델과 권한 역할을 어디까지 이 Phase에 포함할지 결정한다. - - 감사 로그의 저장 책임이 Core in-memory/event surface인지 durable persistence 후보인지 결정한다. - - 사용자에게 노출할 감사 이벤트 범위와 민감 정보 마스킹 기준을 결정한다. + - [x] SDD 상태가 `[승인됨]`이고 SDD 잠금이 해제되어 있다. + - [x] SDD `USER_REVIEW.md`가 없거나 승인/해결되었다. + - [x] Acceptance Scenario가 Milestone 기능 Task와 연결되어 있다. + - [x] Evidence Map이 plan의 `Spec Targets`와 완료 시 `Spec Completion`으로 검증 가능하게 연결되어 있다. +- 결정 필요: 없음 ## 범위 - `services/core` write endpoint 주변의 인증/권한 hook 또는 audit source of truth 필요 여부를 정의한다. - `apps/client`와 `packages/flutter/oto_console`에서 운영 action 결과와 감사/권한 상태를 표현할 UI 범위를 정의한다. - 기존 Control Plane 제품 표면 흐름을 기준으로 하며, production-grade identity provider 연동은 기본 구현 범위로 확정하지 않는다. +- 최소 인증 모델은 production identity provider 없이 operator/admin 단일 역할과 표시 가능한 token reference를 기준으로 한다. +- 감사 범위는 Control Plane write action의 actor, action, target, outcome, timestamp, optional reason metadata로 한정한다. ## 기능 ### Epic: [security-audit] 운영 보안·감사 경계 정의 -write action 이후 필요한 운영 보안과 감사 capability를 구현 가능한 계획으로 구체화한다. +write action 이후 필요한 운영 보안과 감사 capability를 SDD 기준으로 구현하고 검증한다. -- [ ] [security-sdd] 인증/권한, 감사 source of truth, 민감 정보 마스킹, 실패/거부 UX, 검증 evidence를 SDD로 고정한다. -- [ ] [auth-scope] 최소 인증/권한 모델과 UI disabled/error 상태 범위를 기능 Task로 확정한다. -- [ ] [audit-scope] 감사 이벤트 기록/조회/표시 범위와 후속 persistence 후보를 기능 Task로 확정한다. +- [x] [security-sdd] 인증/권한, 감사 source of truth, 민감 정보 마스킹, 실패/거부 UX, 검증 evidence를 SDD로 고정한다. 검증: `SDD.md` 상태가 `[승인됨]`이고 SDD 잠금이 `해제`이며 `user_review_0.log`가 남아 있다. +- [ ] [auth-scope] Core write endpoint와 Flutter action surface에 operator/admin 단일 역할 및 표시 가능한 token reference 기준의 허용/거부, disabled/error 상태를 구현한다. 검증: Core handler/route 테스트 또는 adapter/widget 테스트로 권한 허용/거부와 UI 상태를 확인한다. +- [ ] [audit-scope] Control Plane write action의 actor, action, target, outcome, timestamp, optional reason 감사 metadata와 UI 노출/마스킹 경계를 구현한다. 검증: audit event field, in-memory/event surface boundary, UI masking/widget 테스트 또는 민감 문자열 미노출 검색으로 확인한다. ## 완료 리뷰 @@ -64,7 +59,7 @@ write action 이후 필요한 운영 보안과 감사 capability를 구현 가 ## 범위 제외 -- production identity provider, 장기 secret rotation, 조직/테넌트 모델 완성은 이 스케치에서 바로 구현하지 않는다. +- production identity provider, 장기 secret rotation, 조직/테넌트 모델 완성은 이 Milestone에서 바로 구현하지 않는다. - durable audit storage를 구현 범위로 확정하지 않는다. 필요하면 별도 Milestone 또는 SDD 결정으로 분리한다. - 기존 runner production job 운영 정책 전체를 완성하지 않는다. @@ -74,4 +69,4 @@ write action 이후 필요한 운영 보안과 감사 capability를 구현 가 - 표준선(선택): 기존 Core route와 Flutter action surface를 source of truth 후보로 먼저 검토하고, API/schema 확장이 필요할 때만 별도 계약 변경으로 분리한다. - 선행 작업: `Control Plane 운영 액션 표면` - 후속 작업: 운영 대시보드 고도화, durable persistence UI -- 확인 필요: `구현 잠금 > 결정 필요` 항목과 SDD 사용자 리뷰로 분리한다. +- 확인 필요: 없음. 후속 구현 계획은 SDD `Evidence Map`을 `Spec Targets`와 `Spec Completion`으로 연결한다.