ak.profile.traffic_metadata_hardened.v1
ak.profile.traffic_metadata_hardened.v1
role
"admin" description
"Service/deployment hardening profile for high-privacy traffic metadata. A declaring service exposes support through ServiceDescribe.supported_profiles and applies the profile to deployment-configured routes; federation fanout timing, batch size, Welcome size, push wakeups, and retry cadence MUST satisfy the declared observable bounds. Arkret v1 defines no Realm activation carrier for this profile." enforcement_phases
[
"build",
"conformance"
] operation_requirements
[
{
"direction": "provide",
"operation_id": "ak.self.events.command.submit.v1",
"binding_kind": "http_json"
},
{
"direction": "provide",
"operation_id": "ak.self.committed_event.stream.subscribe.v1",
"binding_kind": "http_json"
},
{
"direction": "provide",
"operation_id": "ak.edge.push.command.notify.v1",
"binding_kind": "http_json"
}
] required_event_kinds
[
"ak.message.create",
"ak.mls.commit"
] rejected_event_kinds
[] required_schemas
[
"ak.schema.event.v1",
"ak.schema.encrypted_envelope.v1",
"ak.schema.notification.v1"
] required_fixtures
[
"privacy-security-fixture.json"
] optional_extensions
[
"ohttp_relay",
"relay_indirection",
"decoy_wakeup"
] feature_discovery
{
"required": [
"federation_batch_padding",
"welcome_padding_bucket",
"bounded_send_jitter",
"blind_or_batch_wakeup",
"retry_cadence_padding",
"traffic_metadata_observability_bounds"
],
"unsupported_optional": "fail closed before claiming traffic metadata hardening"
} profile_parameters
{
"federation_batch_min_item_count": {
"minimum": 2,
"default": 8,
"description": "Minimum outbound federation batch size before padding. Empty/padded batches count toward the observable batch size.",
"value_shape": "integer"
},
"welcome_padding_buckets_bytes": {
"items": {
"minimum": 4096,
"value_shape": "integer"
},
"default": [
4096,
16384,
65536
],
"description": "Allowed padded Welcome / GroupInfo blob sizes. Sender MUST round up to the smallest bucket that fits and MUST NOT leak exact leaf count by raw ciphertext length.",
"value_shape": "array"
},
"send_jitter_ms": {
"required": [
"min",
"max"
],
"properties": {
"min": {
"minimum": 0,
"default": 250,
"value_shape": "integer"
},
"max": {
"minimum": 1,
"default": 3000,
"value_shape": "integer"
}
},
"description": "Bounded randomized delay added before federation fanout and retry scheduling. Implementations MUST NOT encode activity by selecting deterministic edge values.",
"value_shape": "object"
},
"push_wakeup_mode": {
"enum": [
"blind_wakeup",
"batch_wakeup",
"no_notification"
],
"default": "batch_wakeup",
"description": "High-privacy push default. visible_notification is incompatible unless Realm policy explicitly opts out of this hardening profile for that recipient route.",
"value_shape": "string"
},
"relay_requirement": {
"enum": [
"ohttp",
"trusted_relay",
"decoy_traffic"
],
"description": "At least one relay/indirection/decoy mechanism MUST be enabled for cross-domain high-privacy routes.",
"value_shape": "string"
}
}