跳转到内容

ak.profile.sovereign_deployment.v1

← Profiles

ak.profile.sovereign_deployment.v1

description

"Deployment and conformance profile for an organization-controlled Arkret service domain. It is advertised only through ServiceDescribe.supported_profiles and remains orthogonal to Realm structural role, organization relationship, current governance-Station selection and joined-member Station routing. It creates no Realm hosting field, primary service or complete-history authority. See zh/sync/sovereign-deployment.md sections 2, 3.2 and 7.1."

enforcement_phases

[
  "build",
  "conformance"
]

operation_requirements

[
  {
    "direction": "provide",
    "operation_id": "ak.server.read.describe.v1",
    "binding_kind": "http_json"
  },
  {
    "direction": "provide",
    "operation_id": "ak.root.identity.read.resolve.v1",
    "binding_kind": "http_json"
  },
  {
    "direction": "provide",
    "operation_id": "ak.self.authz.read.check.v1",
    "binding_kind": "http_json"
  },
  {
    "direction": "provide",
    "operation_id": "ak.self.events.command.submit.v1",
    "binding_kind": "http_json"
  },
  {
    "direction": "provide",
    "operation_id": "ak.self.committed_event.read.scan.v1",
    "binding_kind": "http_json"
  },
  {
    "direction": "provide",
    "operation_id": "ak.peer.events.command.submit.v1",
    "binding_kind": "http_json"
  },
  {
    "direction": "provide",
    "operation_id": "ak.peer.committed_event.read.scan.v1",
    "binding_kind": "http_json"
  }
]

inherits

[
  "ak.profile.station.v1",
  "ak.profile.identity_registry.v1"
]

required_event_kinds

[
  "ak.capability.grant",
  "ak.capability.revoke",
  "ak.realm.policy_bundle"
]

rejected_event_kinds

[]

required_schemas

[
  "ak.schema.policy.v1",
  "ak.schema.capability.v1",
  "ak.schema.key_transparency.v1"
]

required_fixtures

[
  "did-webvh-v1-fixture.json",
  "key-transparency-fixture.json"
]

optional_extensions

[
  "isolated_resolver",
  "bridge_quarantine"
]

feature_discovery

{
  "required": [
    "resolver_policy",
    "federation_boundary",
    "audit_policy",
    "did_webvh_1_0",
    "key_transparency_inclusion_proof",
    "key_transparency_consistency_proof"
  ],
  "unsupported_optional": "deny bridge until explicit policy exists"
}

forbidden_features

[
  "ak.feature.mls_last_resort_keypackage.v1"
]

additional_requirements

{
  "sender_constrained_session_pop_must": "Per RFC 9700 (BCP 240) sender-constrained-token guidance, production current-v1 protected endpoints MUST reject bare Authorization: Bearer presentation unless it is bound by DPoP, an RFC 9421 HTTP Message Signature, detached JWS, mTLS, or equivalent sender-constrained proof. For this high-security profile, every protected ak.self.* operation MUST use RFC 9421 HTTP Message Signature whose signing key is the session's session_public_key delegated by ak.session.grant, binding @method/@target-uri/@authority, content-digest (when body present), and participating Idempotency-Key, with created/expires inside the existing replay window. The ak.self. prefix is the machine-enforceable default-protected surface; new or unknown operations default to fail closed. The operation registry may explicitly allow an unauthenticated public-metadata projection, but without valid proof it MUST return only that public projection and MUST NOT treat bare bearer as session/capability authentication. See api-conventions.md §3.2 and service-http-binding.md §8.",
  "mls_last_resort_forbidden_must": "Realms claiming this profile MUST NOT allow last-resort KeyPackage join: services MUST NOT advertise ak.feature.mls_last_resort_keypackage.v1 for those Realms, claim responses MUST NOT return last_resort=true packages, and requesters MUST treat any last_resort=true claim record as profile-forbidden and fail closed.",
  "key_transparency_must": "High-risk identity, recovery, service delegation and membership decisions MUST verify ak.schema.key_transparency.v1 inclusion and consistency proofs under ak.profile.key_transparency.v1; missing or invalid proof fails closed.",
  "realm_hosting_boundary_must": "This deployment profile is advertised only through ServiceDescribe.supported_profiles and MUST NOT be written into Realm genesis, schema_refs or any Realm facet. It creates no primary_server, hosted_on, home_server, canonical mirror or complete-history authority.",
  "canonical_realm_data_path_must": "Realm creation, facets, invitation, membership, Event persistence, federation and recovery MUST use registered ak.* Event kinds and operations backed by the canonical durable Event store. Private /_soland/* endpoints, in-memory Realm records, caller-seeded Realm ids and arbitrary JSON store-and-forward queues MUST NOT satisfy this profile.",
  "live_claim_gate_must": "ServiceDescribe MUST omit this profile unless live conformance evidence covers independent Station processes and databases, restart on both sides, durable-outbox outage recovery, external-member boundaries, and effective federation_policy enforcement on ingress, destination selection and fanout. Static fixture ids and private state-machine tests are insufficient."
}

Source