ak.profile.sovereign_deployment.v1
ak.profile.sovereign_deployment.v1
description
"Deployment and conformance profile for an organization-controlled Arkret service domain. It is advertised only through ServiceDescribe.supported_profiles and remains orthogonal to Realm structural role, organization relationship, current governance-Station selection and joined-member Station routing. It creates no Realm hosting field, primary service or complete-history authority. See zh/sync/sovereign-deployment.md sections 2, 3.2 and 7.1." enforcement_phases
[
"build",
"conformance"
] operation_requirements
[
{
"direction": "provide",
"operation_id": "ak.server.read.describe.v1",
"binding_kind": "http_json"
},
{
"direction": "provide",
"operation_id": "ak.root.identity.read.resolve.v1",
"binding_kind": "http_json"
},
{
"direction": "provide",
"operation_id": "ak.self.authz.read.check.v1",
"binding_kind": "http_json"
},
{
"direction": "provide",
"operation_id": "ak.self.events.command.submit.v1",
"binding_kind": "http_json"
},
{
"direction": "provide",
"operation_id": "ak.self.committed_event.read.scan.v1",
"binding_kind": "http_json"
},
{
"direction": "provide",
"operation_id": "ak.peer.events.command.submit.v1",
"binding_kind": "http_json"
},
{
"direction": "provide",
"operation_id": "ak.peer.committed_event.read.scan.v1",
"binding_kind": "http_json"
}
] inherits
[
"ak.profile.station.v1",
"ak.profile.identity_registry.v1"
] required_event_kinds
[
"ak.capability.grant",
"ak.capability.revoke",
"ak.realm.policy_bundle"
] rejected_event_kinds
[] required_schemas
[
"ak.schema.policy.v1",
"ak.schema.capability.v1",
"ak.schema.key_transparency.v1"
] required_fixtures
[
"did-webvh-v1-fixture.json",
"key-transparency-fixture.json"
] optional_extensions
[
"isolated_resolver",
"bridge_quarantine"
] feature_discovery
{
"required": [
"resolver_policy",
"federation_boundary",
"audit_policy",
"did_webvh_1_0",
"key_transparency_inclusion_proof",
"key_transparency_consistency_proof"
],
"unsupported_optional": "deny bridge until explicit policy exists"
} forbidden_features
[
"ak.feature.mls_last_resort_keypackage.v1"
] additional_requirements
{
"sender_constrained_session_pop_must": "Per RFC 9700 (BCP 240) sender-constrained-token guidance, production current-v1 protected endpoints MUST reject bare Authorization: Bearer presentation unless it is bound by DPoP, an RFC 9421 HTTP Message Signature, detached JWS, mTLS, or equivalent sender-constrained proof. For this high-security profile, every protected ak.self.* operation MUST use RFC 9421 HTTP Message Signature whose signing key is the session's session_public_key delegated by ak.session.grant, binding @method/@target-uri/@authority, content-digest (when body present), and participating Idempotency-Key, with created/expires inside the existing replay window. The ak.self. prefix is the machine-enforceable default-protected surface; new or unknown operations default to fail closed. The operation registry may explicitly allow an unauthenticated public-metadata projection, but without valid proof it MUST return only that public projection and MUST NOT treat bare bearer as session/capability authentication. See api-conventions.md §3.2 and service-http-binding.md §8.",
"mls_last_resort_forbidden_must": "Realms claiming this profile MUST NOT allow last-resort KeyPackage join: services MUST NOT advertise ak.feature.mls_last_resort_keypackage.v1 for those Realms, claim responses MUST NOT return last_resort=true packages, and requesters MUST treat any last_resort=true claim record as profile-forbidden and fail closed.",
"key_transparency_must": "High-risk identity, recovery, service delegation and membership decisions MUST verify ak.schema.key_transparency.v1 inclusion and consistency proofs under ak.profile.key_transparency.v1; missing or invalid proof fails closed.",
"realm_hosting_boundary_must": "This deployment profile is advertised only through ServiceDescribe.supported_profiles and MUST NOT be written into Realm genesis, schema_refs or any Realm facet. It creates no primary_server, hosted_on, home_server, canonical mirror or complete-history authority.",
"canonical_realm_data_path_must": "Realm creation, facets, invitation, membership, Event persistence, federation and recovery MUST use registered ak.* Event kinds and operations backed by the canonical durable Event store. Private /_soland/* endpoints, in-memory Realm records, caller-seeded Realm ids and arbitrary JSON store-and-forward queues MUST NOT satisfy this profile.",
"live_claim_gate_must": "ServiceDescribe MUST omit this profile unless live conformance evidence covers independent Station processes and databases, restart on both sides, durable-outbox outage recovery, external-member boundaries, and effective federation_policy enforcement on ingress, destination selection and fanout. Static fixture ids and private state-machine tests are insufficient."
}