跳转到内容

ak.profile.sovereign_enclave.v1

← Profiles

ak.profile.sovereign_enclave.v1

description

"Controlled-collaboration enclave deployment variant. It runs alongside or downstream of a sovereign main domain and serves ordinary ak.schema.realm.v1 Collaboration Realms whose external members, policy and routing remain canonical Realm state. The profile is a ServiceDescribe.supported_profiles deployment/conformance claim only: no Realm deployment_profile, hosted_on, primary_server or complete-history authority exists. Outbound federation is denied by default and may target only destinations allowed by effective Realm federation policy, joined-member routing projection and the deployment peer allowlist. Public discovery and public DID resolution remain disabled. See zh/sync/sovereign-deployment.md sections 2, 3.2, 4 and 7.1."

enforcement_phases

[
  "build",
  "conformance"
]

operation_requirements

[
  {
    "direction": "provide",
    "operation_id": "ak.server.read.describe.v1",
    "binding_kind": "http_json"
  },
  {
    "direction": "provide",
    "operation_id": "ak.root.identity.read.resolve.v1",
    "binding_kind": "http_json"
  },
  {
    "direction": "provide",
    "operation_id": "ak.self.authz.read.check.v1",
    "binding_kind": "http_json"
  },
  {
    "direction": "provide",
    "operation_id": "ak.self.events.command.submit.v1",
    "binding_kind": "http_json"
  },
  {
    "direction": "provide",
    "operation_id": "ak.self.committed_event.read.scan.v1",
    "binding_kind": "http_json"
  },
  {
    "direction": "provide",
    "operation_id": "ak.peer.events.command.submit.v1",
    "binding_kind": "http_json"
  },
  {
    "direction": "provide",
    "operation_id": "ak.peer.committed_event.read.scan.v1",
    "binding_kind": "http_json"
  }
]

inherits

[
  "ak.profile.sovereign_deployment.v1"
]

required_event_kinds

[
  "ak.realm.create",
  "ak.realm.profile",
  "ak.realm.policy_bundle",
  "ak.realm.join_rule",
  "ak.realm.history_access",
  "ak.realm.discovery",
  "ak.realm.organization",
  "ak.invite.create",
  "ak.invite.accept",
  "ak.member.state"
]

rejected_event_kinds

[]

required_schemas

[
  "ak.schema.policy.v1",
  "ak.schema.realm_genesis.v1",
  "ak.schema.realm.v1",
  "ak.schema.event_payload.v1"
]

required_fixtures

[]

optional_extensions

[]

feature_discovery

{
  "required": [
    "resolver_policy",
    "federation_boundary",
    "audit_policy",
    "outbound_allowlist"
  ],
  "unsupported_optional": "deny outbound HTTP until allowlist contains the destination host"
}

additional_requirements

{
  "canonical_boundary_flow_must": "Main/enclave Realm, invite, membership and Event flows MUST use the registered canonical Event and operation surfaces. Deployment-local export/import review, malware scanning, declassification, watermarking and boundary audit records are not Arkret wire state and MUST NOT be advertised as interoperable features.",
  "live_claim_gate_must": "ServiceDescribe MUST omit this profile unless live tests use two Station processes with independent databases and cover restart on both sides, disconnection and durable recovery, external-member join/leave/ban, and closed/restricted/quarantine enforcement on ingress, destination selection and fanout. In-memory maps, fixture Realm ids, repeated seeding and private endpoints are not conformance evidence."
}

Source