Documentation embedded in this build.
AuthBox — the support matrix
What AuthBox does, one row per capability, joined to the evidence that it does it. Every cell below is either a name stated in docs/assurance/capabilities.yaml that a test resolves — a setting in the settings register, a package in the coverage register, a status subsystem in the exercise ledger, an OpenAPI document, a plan, an embedded page — or a figure this renderer derives from those registers on each make docs run. Nothing here is typed by hand, and a name that does not resolve fails the build (TestEveryCapabilityRowResolves); a surface with no row fails it too (TestEveryCapabilityIsRegistered).
Floors and tiers are printed; measured percentages are not — a measurement is the output of a run and is stale by the next commit, so this document states the floor a gate holds and the tiers that reach a row, and leaves the measured figures where they are actually produced: the evidence report cmd/authbox-testreport assembles at a tag (make report, published under docs/reports).
An em dash is a statement, not a gap in the rendering: a row whose Proven cell is — is reached by no recorded exercise, and that is the finding this page exists to make visible.
Legend
| Column | Words it uses |
|---|---|
| Kind | binary, surface, client, subsystem, tool, sdk |
| Listener | mtls, intake, public, ldaps, dedicated, none — where the surface answers; dedicated is a listener one capability owns |
| Authorized | desk, operators, mtls, invitation, eab, signed-action, anonymous, none — how a caller earns entry; anonymous is unauthenticated by design, none is not a network surface at all |
| Door | D1, D2, D3, D4, D5, D6, direct, none — the docs/plans/045 front door this stands behind; direct is reached without one |
| Storage | store, dataset, ca-keystore, audit-chain, tlog-tiles, bundle, none — what it durably writes, and so what a backup must carry |
| Proven | unit, integration, omni, scenario, federation — the tiers that reach this row, in ascending strength |
- Switch · default — the one setting that decides whether the capability is on, and its registered default. A
.listensetting is on when its default names an address and off when it names none; a boolean is on when it defaults true.alwaysis a capability nothing switches — the store backends are chosen, not enabled. - Authorized — the declared mode, and where the row names an OpenAPI document, that document's operation count and how many of those operations declare an authorization requirement. The count is of the WHOLE document: several rows share
services/authbox/openapi.yamlandservices/enroll/openapi.yaml, and nothing in this repository partitions a specification by capability. A document whose operations declare their shape in a grammar of their own rather than thex-authboxrequirement — authboxvault's and authboxportal's — readsown grammar, because it is authorized by its door, not unauthorized. - Proven — every tier that reaches any of this row's settings, status subsystems, specification operations or console route, from
docs/assurance/exercises.yaml.federationis an exercise whose package istest/integration/federation(docs/plans/108); it is named besideintegrationrather than instead of it, because that is the suite it runs in. - Floor — the statement-coverage floor each package may not fall under, from
docs/assurance/coverage.yaml.(all)marks a floor held against the all-tiers measurement, which folds the compiled binaries in (docs/plans/108) and is not comparable with a unit-report floor.exempt→<tier>names the tier a package's proof lives in instead. - Rulings · mutations — the normative rules in
docs/assurance/requirements.yamlwhose section names one of the row's plans, and the mutations indocs/assurance/mutations.yamlthat prove those rules are not vacuous.0 · 0is printed as itself: a capability whose plans made no ruling is a finding, not a blank. - The backticked word after a capability's name is its id in the register — the name the Services page, the exercise ledger's operators and this document all use for the same row.
- EVIDENCE.md is the same join asked the other way round: one row per capability grouped by KIND OF PROOF rather than by column — the floor, the ledger tiers, the rehearsal behaviours that drive it and the mutations that prove its tests bite (docs/plans/147).
Components
What is shipped and run: 10 binaries, 1 generated SDK, and 17 build-time tools this repository's own claims depend on. Listeners is the component's own plus every listener the surfaces it carries answer on; On by default counts the surfaces a deployment that configures nothing still gets.
| Component | Kind | Listeners | On by default | Health / metrics | Floor | Runbook | Plans |
|---|---|---|---|---|---|---|---|
authboxd authboxd |
binary | mtls · intake · public · ldaps · dedicated | 5 of 20 | health.listen, kas.health.listen, telemetry.metrics.enabled, telemetry.metrics.listen |
cmd/authboxd 75 (all) · internal/server 90 · internal/config 85 · internal/tlsx 90 |
runbook | 017 · 023 · 133 |
authboxproxy authboxproxy |
binary | mtls · public · dedicated | 2 of 7 | proxy.health.listen, proxy.telemetry.metrics.enabled |
cmd/authboxproxy 75 (all) · internal/proxy 90 |
runbook | 039 · 045 |
authboxvault authboxvault |
binary | mtls · public | 1 of 2 | vault.health.listen |
cmd/authboxvault 70 (all) · internal/vault 80 |
runbook | 043 |
authboxportal authboxportal |
binary | mtls | 1 of 1 | portal.health.listen |
cmd/authboxportal 70 (all) · internal/portal 80 |
— | 080 · 139 · 144 · 145 · 170 |
authboxkas authboxkas |
binary | mtls | — | — | cmd/authboxkas 70 (all) · internal/kas 90 · sdk/marked/tdf — |
runbook | 143 · 169 |
authboxldapsync authboxldapsync |
binary | none | — | — | cmd/authboxldapsync 35 (all) · internal/ldapsync 75 |
— | 087 · 079 · 169 |
authboxscimsync authboxscimsync |
binary | none | — | — | cmd/authboxscimsync exempt→unit · internal/scimsync 80 |
runbook | 154 · 079 · 169 |
authbox-agent authbox-agent |
binary | none | — | — | cmd/authbox-agent exempt→integration |
runbook | 037 |
authboxjs authboxjs |
sdk | none | — | — | cmd/authbox-sdk exempt→unit |
— | 042 · 044 |
Documentation and register renderer docs-renderer |
tool | none | — | — | cmd/authbox-docs exempt→unit |
— | 040 · 056 · 067 · 147 |
The mark and the tool that derives it brand-mark |
tool | none | — | — | cmd/authbox-brand 85 · internal/brand 90 |
— | 163 |
Mutation harness mutation-harness |
tool | none | — | — | cmd/authbox-assure exempt→unit |
— | 030 · 038 |
Release evidence report evidence-report |
tool | none | — | — | cmd/authbox-testreport exempt→unit · internal/testreport 90 |
— | 038 |
Benchmark regression gate bench-gate |
tool | none | — | — | cmd/authbox-benchcompare exempt→unit · internal/benchcompare 90 |
— | 030 |
Software bill of materials sbom |
tool | none | — | — | cmd/authbox-sbom exempt→unit · internal/sbom 85 |
— | 024 |
Release signing release-signing |
tool | none | — | — | cmd/authbox-sign exempt→unit · internal/relsign 85 · internal/changelog 85 · internal/provenance 80 |
runbook | 024 · 120 |
Release courier bundle release-media |
tool | none | — | — | cmd/authbox-release exempt→unit · internal/relbundle 85 · internal/relimages 90 |
runbook | 178 · 024 |
Reference stream sink stream-sink |
tool | mtls | — | — | cmd/authbox-ingest 25 |
runbook | 117 |
Object store object-store |
binary | mtls | — | — | cmd/authbox-store 50 · internal/objectstore 90 · internal/authboxkit exempt→unit |
runbook | 160 · 161 · 162 · 169 · 171 |
Local S3 shim store-shim |
tool | none | — | — | cmd/authbox-store-shim 25 |
runbook | 160 |
Dialect sidecar dialect-sidecar |
binary | mtls | — | — | cmd/authbox-dialect 20 · internal/dialectserve 80 · internal/dialect 90 · internal/dialectconform 80 |
— | 173 · 175 |
Marked-response showcase showcase-records |
tool | mtls | — | — | cmd/authbox-showcase-records 55 |
runbook | 141 · 143 |
OIDC login showcase showcase-oidc |
tool | none | — | — | cmd/authbox-showcase-oidc 50 |
runbook | 153 · 169 |
SAML service provider showcase showcase-saml |
tool | none | — | — | cmd/authbox-showcase-saml 65 |
— | 154 · 169 |
Fixture PKI and demonstration data fixture-data |
tool | none | — | — | cmd/authbox-testpki 30 (all) · cmd/authbox-demogen 85 · internal/testpki 85 · internal/testkit exempt→integration |
— | 022 · 094 |
Rehearsal population rehearsal |
tool | none | — | — | cmd/authbox-simulate exempt→unit · internal/simulate 50 |
runbook | 116 · 169 |
Compose-to-Kubernetes translation compose-translation |
tool | none | — | — | cmd/authbox-kube exempt→unit · internal/composekube 90 |
— | 112 |
Scanner gate and suppression register scan-gate |
tool | none | — | — | cmd/authbox-scan 80 · internal/scanreg 85 |
— | 118 |
Capabilities
Every surface, client and subsystem the components carry, grouped as the register groups them.
Client programs
| Capability | Component · listener | Protocol / standards | Switch · default | Authorized | UI | Door | Storage | Observed | Proven | Floor | Rulings · mutations | Docs | Plans |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
authboxclient authboxclient |
authboxclient · none | HTTPS client against the enrolment and administration surfaces · RFC 2986, RFC 5280 | always | none | — | none | none | — | — | cmd/authboxclient 35 (all) · internal/client 85 · internal/pki/keystore 90 |
4 · 4 | guide | 037 |
authboxctl authboxctl |
authboxctl · none | local administration of a deployment's own state | always | none | — | none | store · dataset · audit-chain · ca-keystore | — | — | cmd/authboxctl 70 (all) |
0 · 0 | guide · runbook | 001 |
Enrolment and PKI
| Capability | Component · listener | Protocol / standards | Switch · default | Authorized | UI | Door | Storage | Observed | Proven | Floor | Rulings · mutations | Docs | Plans |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Enrolment intake enrolment-intake |
authboxd · intake | CSR intake over HTTPS · RFC 2986, RFC 5280 | enroll.listen · off |
invitation (2 ops, 2 declared) | /ui/enrollments |
D4 | store · ca-keystore | authbox_enroll_rejected_total |
unit · integration | internal/api/enroll 85 · internal/pki 85 |
0 · 0 | guide | 008 · 009 |
ACME server acme |
authboxd · intake | ACME with device-attest-01 · RFC 8555, draft-acme-device-attest | acme.enabled · off |
eab (2 ops, 2 declared) | — | D4 | store · ca-keystore | acme |
unit · integration · scenario · federation | internal/acme 80 |
15 · 16 | guide | 013 · 060 · 169 |
EST server est |
authboxd · intake | Enrollment over Secure Transport · RFC 7030 | est.enabled · off |
invitation (2 ops, 2 declared) | — | D4 | store · ca-keystore | — | unit · integration · federation | internal/est 85 |
2 · 3 | guide | 063 · 169 |
Registration authority registration-authority |
authboxd · intake | PKCS#10 forwarded over EST or ACME to the organisation's own CA · RFC 7030, RFC 8555, RFC 2986 | pki.issuer.backend · on |
invitation (2 ops, 2 declared) | — | D4 | store | — | unit · integration | internal/pki/ra 70 · internal/pki 85 |
6 · 6 | guide · runbook | 127 |
Enrolment invitations invitations |
authboxd · mtls | single-use expiring token | always | mtls (83 ops, 83 declared) | /ui/invitations |
D5 | store | — | unit · integration · federation | internal/invite 90 |
0 · 0 | guide | 009 |
The door follows the project door-follows-project |
authboxproxy · mtls | route records derived from the signed bundle a door already polls | proxy.routes_source · on |
mtls (83 ops, 83 declared) | portal /projects/{dn}/services/new | D5 | store | — | unit · integration · federation | internal/dataset 90 · internal/proxy 90 · internal/replica 90 · internal/credential 95 · internal/api/admin 85 · internal/api/enroll 85 · internal/portal 80 |
1 · 4 | guide | 150 |
Service certificates service-certificates |
authboxd · mtls | derived identity plus a bounded, single-use invitation | proxy.credential.serve · off |
mtls (83 ops, 83 declared) | portal /projects/{dn}/services | D5 | store | — | unit · integration · federation | internal/dataset 90 · internal/pki 85 · internal/api/admin 85 · internal/api/enroll 85 · internal/client 85 · internal/credential 95 · internal/proxy 90 · internal/portal 80 · internal/acme 80 · internal/vault 80 |
2 · 6 | guide | 149 |
Invitation mail invitation-mail |
authboxvault · mtls | SMTP submission to the organization's relay · RFC 5321 | vault.mail.relay · on |
mtls (1 op, 1 declared) | vault delegator | D6 | none | — | unit · integration | internal/vault 80 · internal/smtpsink exempt→integration |
7 · 7 | guide | 088 · 169 |
Credential claim credential-claim |
authboxvault · public | HTTPS with no client certificate | vault.courier.enabled · off |
invitation (9 ops, own grammar) | claim page | D6 | none | — | unit · integration | internal/vault 80 |
0 · 0 | guide · runbook | 043 |
Attested custody attested-custody |
authboxd · intake | recorded key-custody claim on an issued credential | enroll.key_custody · on |
invitation (2 ops, 2 declared) | /ui/enrollments |
D4 | store | — | unit · integration | internal/attestrecord 100 |
10 · 11 | guide | 060 |
Device attestation device-attestation |
authboxd · intake | key-attestation statements verified against manufacturer roots · draft-acme-device-attest | always | invitation (2 ops, 2 declared) | — | D4 | store · dataset | — | unit · integration | internal/attestverify 95 |
10 · 11 | guide | 060 |
CA hierarchy ca-hierarchy |
authboxd · none | X.509 issuance · RFC 5280 | always | none | /ui/status |
none | ca-keystore | ca |
unit · integration | internal/pki 85 · internal/pki/keystore 90 |
6 · 8 | guide · runbook | 028 · 095 |
CRL distribution crl-distribution |
authboxd · none | X.509 certificate revocation lists · RFC 5280 | pki.crl.dir · off |
none | /ui/revocations |
none | ca-keystore | authbox_crl_age_seconds · authbox_crl_budget_seconds |
unit · integration · federation | internal/pki 85 |
7 · 8 | guide · runbook | 029 · 169 |
OCSP responder ocsp-responder |
authboxd · public | OCSP over HTTP · RFC 6960 | ocsp.enabled · off |
anonymous | — | D2 | store · ca-keystore | ocsp |
unit · integration · omni · federation | internal/ocsp 80 |
6 · 7 | guide | 012 · 169 |
OCSP client ocsp-client |
authboxd · none | OCSP over HTTP against an upstream CA · RFC 6960 | ocsp_client.freshness · on |
none | /ui/status |
none | none | — | unit · integration | internal/ocsp 80 |
6 · 7 | guide | 012 · 169 |
Post-quantum issuance post-quantum |
authboxd · none | ML-DSA certificates alongside the classical set · FIPS 204 | verify.allow_ml_dsa · off |
none | — | none | ca-keystore | — | unit | internal/pki 85 |
1 · 1 | guide · runbook | 064 |
PKCS#12 export pkcs12-export |
authboxclient · none | PKCS#12 with PBES2 and an SHA-256 HMAC · RFC 7292, RFC 8018 | always | none | — | none | none | — | — | internal/pkcs12 85 |
4 · 4 | guide | 037 |
Short-lived profile short-lived-profile |
authboxd · none | certificate profiles with a validity measured in hours · RFC 5280 | profiles[].short_lived · off |
none | — | none | ca-keystore | — | unit · integration | internal/pki 85 |
2 · 2 | guide · runbook | 059 |
Identity and authorization
| Capability | Component · listener | Protocol / standards | Switch · default | Authorized | UI | Door | Storage | Observed | Proven | Floor | Rulings · mutations | Docs | Plans |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Administration API admin-api |
authboxd · mtls | HTTPS over mutual TLS · OpenAPI 3.1 | always | mtls (83 ops, 83 declared) | /ui/ |
D1 | store · audit-chain | — | unit · integration · federation | internal/api/admin 85 · internal/server 90 |
12 · 12 | guide | 019 · 046 |
Console console |
authboxd · mtls | server-rendered HTML over mutual TLS · OpenAPI 3.1 | ui.enabled · on |
desk (79 ops, 79 declared) | /ui/ |
D5 | store | — | unit · integration · scenario · federation | internal/ui 85 · internal/consoleproject 95 |
23 · 32 | guide | 019 · 070 · 072 · 142 |
Entities and groups entities-and-groups |
authboxd · mtls | X.500-shaped directory of subjects · RFC 4514 | store.require_entity_kind · off |
desk (83 ops, 83 declared) | /ui/entities |
D5 | store · dataset | — | unit · integration · omni · federation | internal/dataset 90 · internal/identity 90 |
19 · 27 | guide | 006 · 010 · 020 · 142 |
Dynamic group membership members-everyone |
authboxd · none | a declared membership, resolved at load into the ordinary member list | always | none | — | none | dataset | — | — | internal/dataset 90 · internal/authz 90 |
10 · 9 | guide | 162 |
Missions missions |
authboxd · mtls | named requirements over a subject's standing | authz.delete_requires_owner · on |
desk (83 ops, 83 declared) | /ui/missions |
D5 | store | — | unit · integration · omni · federation | internal/authz 90 |
24 · 30 | guide | 006 · 007 · 140 · 144 |
Brokerage brokerage |
authboxd · mtls | mission brokerage over HTTPS · OpenAPI 3.1 | brokerage.enabled · off |
mtls (4 ops, 4 declared) | /ui/requests |
D1 | store · audit-chain | — | unit · integration · federation | internal/api/brokerage 80 |
27 · 33 | guide | 061 · 140 · 144 |
Clearance authority clearance |
authboxd · mtls | clearance question over HTTPS · OpenAPI 3.1 | clearance.enabled · off |
mtls (3 ops, 3 declared) | — | D1 | store | — | unit · integration · omni | internal/api/clearance 85 |
10 · 12 | guide | 011 · 065 |
self self |
authboxd · mtls | self-description over HTTPS · OpenAPI 3.1 | self.enabled · off |
mtls (2 ops, 2 declared) | /ui/you/history |
D1 | store | — | unit · integration · omni · federation | internal/api/self 85 |
14 · 14 | guide | 019 · 090 |
Data markings data-markings |
authboxd · none | OpenTDF attribute URIs · OpenTDF 4.3.0 | clearance.opentdf_namespace · off |
none | — | none | dataset | — | unit · integration | internal/opentdf 90 |
5 · 5 | guide | 011 |
Obligations obligations |
authboxd · mtls | standing compliance questions over the store | always | desk (79 ops, 79 declared) | /ui/obligations |
D5 | store | — | unit · integration · scenario · federation | internal/obligation 95 |
3 · 3 | guide | 081 |
Goals goals |
authboxd · mtls | obligation reports joined over a project tree | always | desk (79 ops, 79 declared) | /ui/goals |
D5 | store · audit-chain | goal_snapshots |
unit · integration · scenario · federation | internal/goal 80 |
3 · 6 | guide | 106 |
Standing agreements agreements |
authboxportal · mtls | HTTPS over mutual TLS · OpenAPI 3.1 | always | mtls (42 ops, own grammar) | agreements | D4 | audit-chain | — | unit · integration · federation | internal/portal 80 |
12 · 16 | guide | 080 · 145 |
Delegated identity (XPE) xpe |
authboxd · mtls | X-ProxiedEntitiesChain and X-ProxiedIssuers-Chain | xpe.enabled · off |
mtls (83 ops, 83 declared) | /ui/topology |
D1 | store | asserters |
unit · integration · omni · federation | internal/xpe 95 |
13 · 14 | guide · runbook | 005 · 031 · 051 |
WebAuthn step-up webauthn |
authboxd · mtls | WebAuthn assertion as a second signature · W3C WebAuthn Level 2 | webauthn.rp_id · off |
desk (79 ops, 79 declared) | /ui/webauthn |
D5 | store | — | unit · integration · scenario · federation | internal/webauthn 85 |
5 · 6 | guide | 068 |
Signed actions signed-actions |
authboxd · mtls | actor signature over one action, and a periodic chain-head countersignature · RFC 7515 | audit.signing_key_id · off |
signed-action (83 ops, 83 declared) | /ui/audit |
D1 | audit-chain | anchor_signing |
unit · integration · omni · federation | internal/attest 85 |
12 · 13 | guide · runbook | 033 |
Decision receipts receipts |
authboxd · mtls | JWS over one permitted decision · RFC 7515 | authzen.receipt.issuer · off |
mtls (6 ops, 6 declared) | /ui/policy |
D1 | none | authboxproxy_receipts_minted_total |
unit · integration · federation | internal/receipt 95 |
6 · 9 | guide | 057 · 101 |
Authorization engine authorization-engine |
authboxd · none | the specification IS the authorization map · OpenAPI 3.1 | spec.path · off |
none (83 ops, 83 declared) | /ui/policy |
none | store | callers · authbox_decisions_total · authbox_decision_duration_seconds |
unit · integration · federation | internal/authz 90 · internal/spec 95 · internal/conformance 85 |
4 · 4 | guide · runbook | 003 · 047 |
Activity projection activity |
authboxd · mtls | a projection over the decision record and this process's own counters | always | desk (79 ops, 79 declared) | /ui/activity |
D5 | audit-chain | authbox_handshake_total · authbox_decisions_total · authbox_enroll_rejected_total · authbox_active_connections · authbox_active_subjects · authbox_audit_records_total · authbox_audit_write_failures_total |
unit · integration · scenario · federation | internal/activity 90 |
15 · 12 | guide | 116 |
Entity history entity-history |
authboxd · mtls | a projection over records that already exist | always | desk (79 ops, 79 declared) | /ui/entities/{dn}/history |
D5 | store · audit-chain | — | unit · integration · scenario · federation | internal/history 90 |
6 · 6 | guide | 082 · 090 |
Standards surfaces
| Capability | Component · listener | Protocol / standards | Switch · default | Authorized | UI | Door | Storage | Observed | Proven | Floor | Rulings · mutations | Docs | Plans |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
SAML identity provider saml-provider |
authboxd · intake | SAML 2.0 Web Browser SSO, HTTP-Redirect and HTTP-POST bindings, signing only · SAML 2.0 Core, SAML 2.0 Bindings, SAML 2.0 Metadata, XML Signature, Exclusive XML Canonicalization 1.0 | saml.enabled · off |
mtls | — | none | store | — | unit | internal/saml 90 |
7 · 23 | guide · runbook | 154 · 169 |
OIDC provider oidc-provider |
authboxd · intake | OpenID Connect authorization code flow with PKCE · OpenID Connect Core 1.0, RFC 8705, RFC 7636 | oidc_provider.enabled · off |
mtls (4 ops, 4 declared) | — | D4 | store | oidc |
unit · integration · federation | internal/oidc 85 |
6 · 6 | guide · runbook | 014 · 169 |
AuthZEN PDP authzen |
authboxd · mtls | OpenID AuthZEN Authorization API · OpenID AuthZEN Authorization API 1.0 | authzen.enabled · off |
mtls (6 ops, 6 declared) | — | D1 | store · audit-chain | — | unit · integration · federation | internal/api/authzen 95 |
4 · 4 | guide | 053 |
Shared signals transmitter shared-signals |
authboxd · mtls | OpenID Shared Signals Framework, RFC 8936 poll, RFC 8417 tokens · RFC 8417, RFC 8936, RFC 9493, OpenID CAEP 1.0, OpenID RISC 1.0 | ssf.enabled · off |
mtls (9 ops, 9 declared) | — | D1 | audit-chain · store | ssf · authbox_ssf_events_total · authbox_ssf_poll_total · authbox_ssf_stream_lag_records |
unit · integration | internal/ssf 80 |
13 · 20 | runbook | 130 · 142 |
LDAPS directory ldaps-directory |
authboxd · ldaps | LDAP v3 over TLS, read-only, SASL EXTERNAL bind · RFC 4511, RFC 4513 | ldap.listen · on |
mtls | — | direct | store | — | unit · integration · federation | internal/ldapserve 80 |
13 · 22 | guide | 087 · 142 · 169 |
SPIFFE federation spiffe-federation |
authboxd · mtls | X509-SVID peers from declared foreign trust domains · SPIFFE X509-SVID | federation.accept_bundles · off |
mtls | /ui/topology |
D1 | dataset | — | unit · integration · federation | internal/federation 95 · internal/spiffeid 85 |
4 · 5 | guide · runbook | 066 |
Foreign-schema codec seam foreign |
authboxd · none | seam between AuthBox's model and a foreign one | always | none | — | none | dataset | — | — | sdk/foreign — · internal/foreign 90 |
8 · 9 | guide | 004 · 138 |
STANAG label seam stanag |
authboxd · none | seam between a NATO confidentiality label and this dictionary · STANAG 4774, STANAG 4778 | always | none | — | none | dataset | — | — | internal/stanag 90 |
11 · 14 | guide | 004 · 065 |
Distribution
| Capability | Component · listener | Protocol / standards | Switch · default | Authorized | UI | Door | Storage | Observed | Proven | Floor | Rulings · mutations | Docs | Plans |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Replicas replicas |
authboxd · mtls | signed dataset bundles with a monotonic serial | replica.enabled · off |
operators (83 ops, 83 declared) | /ui/topology |
D1 | bundle · dataset | replica · authbox_replica_adoption_failures_total · authbox_replica_bundle_age_seconds |
unit · integration · federation | internal/replica 90 |
3 · 4 | guide | 016 · 169 |
Replica publish replica-publish |
authboxd · mtls | signed replica bundle of the live store, on a cadence, served on request | replica_publish.enabled · off |
mtls (83 ops, 83 declared) | /ui/topology |
D1 | bundle · store | published_topology |
unit · integration · scenario · federation | internal/replica 90 |
26 · 27 | guide · runbook | 071 · 117 · 168 |
Sync engine and live cascade sync-engine |
authboxd · mtls | authority bundles, adopted from an upstream and served per consumer | sync.live.enabled · off |
operators (83 ops, 83 declared) | /ui/topology |
D1 | bundle · store | consumers · reported_topology · authbox_sync_adoption_failures_total · authbox_upstream_age_seconds |
unit · integration · federation | internal/syncengine 95 · internal/authoritybundle 75 · internal/authorityserve 80 |
22 · 26 | guide · runbook | 034 · 071 · 168 |
Project authority federation project-authority |
authboxd · mtls | a project owned by another AuthBox, with a freshness budget | upstreams[].name · off |
operators (83 ops, 83 declared) | /ui/authorities/{name} |
D1 | store | upstreams · cached_projects |
unit · integration · federation | internal/upstream 75 |
9 · 9 | guide | 018 · 007 |
Org attribute authorities org-attribute-authorities |
authboxd · none | signed assertions over an attribute name somebody else owns | always | none | /ui/authorities/{name} |
none | bundle · dataset | — | unit · integration · omni · federation | internal/authoritybundle 75 |
0 · 0 | guide | 079 |
The federation's names federation-names |
authboxproxy · dedicated | authoritative DNS over UDP and TCP, with DNSSEC signing · RFC 1035, RFC 4034, RFC 4035 | proxy.names.serve.listen · off |
anonymous | /ui/frontdoor |
direct | none | authboxproxy_dns_answers_total |
unit · integration · scenario · federation | internal/names 95 · internal/dnsserve 80 |
8 · 29 | guide · runbook | 099 · 100 |
The anonymous door anonymous-door |
authboxproxy · public | match, strip, forward — no decision and no injected identity | proxy.anonymous.listen · off |
anonymous | /ui/frontdoor |
D2 | none | — | unit · integration · scenario | internal/proxy 90 |
1 · 1 | guide · runbook | 045 |
The front door's directory front-door-directory |
authboxproxy · public | one HTML page, GET, no client certificate — drawn from the route table | proxy.anonymous.directory.enabled · off |
anonymous | — | D2 | none | — | unit · scenario | internal/proxy 90 · internal/authboxkit exempt→unit |
3 · 3 | guide · runbook | 157 |
Kubernetes ingress mode proxy-kubernetes |
authboxproxy · none | list and watch over this cluster's Services | proxy.kubernetes.enabled · off |
none | /ui/frontdoor |
none | none | — | unit · integration · scenario | internal/proxy 90 |
17 · 17 | guide · runbook | 039 |
Authorized streams streams |
authboxproxy · mtls | labelled frames over one long-lived request, fanned out by marking | always | mtls | /ui/streams |
D1 | audit-chain | streams · authboxproxy_stream_frames_total · authboxproxy_stream_bytes_total · authboxproxy_streams_open · authboxproxy_stream_closed_total |
unit · integration | internal/stream 80 · internal/proxy 90 |
13 · 13 | guide · runbook | 117 |
The marked response marked |
authboxproxy · mtls | one response header carrying a marking, compared against the caller's chain | always | mtls | — | D1 | audit-chain | — | unit | internal/proxy 90 · sdk/marked — |
8 · 14 | guide · runbook | 141 |
SSH through the door ssh-through-the-door |
authboxproxy · mtls | a raw connection wrapped in mutual TLS, routed by SNI, spliced unread · RFC 4253 | proxy.routes[].kind · off |
mtls | — | D1 | audit-chain | authboxproxy_tcp_sessions_total · authboxproxy_tcp_bytes_total · authboxproxy_tcp_sessions_open · authboxproxy_tcp_closed_total |
unit | internal/splice 95 · internal/proxy 90 |
6 · 6 | guide · runbook | 135 |
Self-enrolling credential managed-credential |
authboxproxy · none | the companion enrols and renews its own certificate | proxy.credential.managed · off |
invitation | — | none | none | — | unit | internal/credential 95 · internal/credential/selfenroll 80 |
0 · 0 | guide · runbook | 049 |
Evidence and operations
| Capability | Component · listener | Protocol / standards | Switch · default | Authorized | UI | Door | Storage | Observed | Proven | Floor | Rulings · mutations | Docs | Plans |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Audit chain audit-chain |
authboxd · mtls | append-only hash-chained records, sealed into segments | audit.path · off |
desk (83 ops, 83 declared) | /ui/audit |
D1 | audit-chain | audit_segments · authbox_audit_records_total · authbox_audit_write_failures_total |
unit · integration · omni · federation | internal/audit 95 |
5 · 5 | guide · runbook | 026 |
Signed audit export audit-export |
authboxctl · none | a sealed segment turned into an artifact a SIEM can prove it received | always | none | — | none | audit-chain | — | — | internal/auditexport 80 |
2 · 4 | guide · runbook | 055 |
Front-door audit hand-off door-audit-handoff |
authboxproxy · mtls | one plan-055 signed export per sealed segment, POSTed in ordinal order | audit.doors_path · off |
mtls (83 ops, 83 declared) | /ui/activity |
none | audit-chain | authbox_door_segments_accepted_total · authbox_door_segments_refused_total |
unit · integration · federation | internal/auditexport 80 · internal/activity 90 |
5 · 5 | guide · runbook | 122 |
Transparency log transparency-log |
authboxd · none | static tile tree with signed-note checkpoints · C2SP tlog-tiles, C2SP signed-note | log.enabled · off |
none | — | none | tlog-tiles | — | unit · integration | internal/tlog 90 |
6 · 6 | guide | 058 |
Backup and restore backup-restore |
authboxctl · none | a manifest-wrapped tar of the dataset, the audit segments and the keystore | always | none | /ui/status |
none | store · audit-chain · ca-keystore | restored_audit |
unit · integration | internal/backup 75 |
5 · 5 | guide · runbook | 026 · 169 |
Policy export policy-export |
authboxd · none | the declared requirements as Rego and Cedar | always | none | /ui/policy/{operationId} |
none | none | — | unit · integration | internal/policycodec 90 |
5 · 5 | guide · runbook | 067 |
Control mapping and OSCAL controls |
authboxd · none | NIST 800-53 control mapping, emitted as an OSCAL component definition · NIST SP 800-53 Rev. 5, OSCAL 1.1 | always | none | /ui/docs/{collection}/{slug} |
none | none | — | integration | internal/assurance 75 |
2 · 2 | guide | 056 · 062 · 091 |
Public listener public-listener |
authboxd · public | HTTPS with no client certificate requested | public.enabled · off |
anonymous | / |
D2 | none | — | unit | internal/api/public 85 |
0 · 0 | guide | 008 · 086 · 096 |
Embedded documentation embedded-docs |
authboxd · mtls | the accreditation collection rendered into the binary | public.docs · on |
desk (79 ops, 79 declared) | /ui/docs |
D5 | none | — | unit · integration · scenario · federation | internal/docs 90 · internal/docrender 90 |
5 · 5 | guide | 040 · 096 |
Health health |
authboxd · dedicated | liveness and readiness over HTTPS | health.listen · off |
anonymous | — | direct | none | — | unit | internal/health 95 |
1 · 1 | guide | 002 |
Metrics metrics |
authboxd · dedicated | Prometheus text exposition | telemetry.metrics.enabled · off |
operators | /ui/status |
direct | none | active_subjects · authbox_build_info · authbox_active_subjects |
unit · integration · omni | internal/telemetry 90 |
4 · 4 | guide | 021 |
Operational log operational-log |
authboxd · none | structured operational logging | telemetry.log.level · on |
none | — | none | none | — | unit · omni | internal/telemetry 90 |
4 · 4 | guide | 021 |
Store backends store-backends |
authboxd · none | memory, file, PostgreSQL and MySQL behind one repository interface | store.backend · on |
none | /ui/settings |
none | store · dataset | store |
unit · integration · federation | internal/store 75 · internal/store/file 75 · internal/store/memory 95 · internal/store/sqlstore exempt→db · internal/store/sqlstore/postgres exempt→db · internal/store/sqlstore/mysql exempt→db |
12 · 9 | guide | 025 · 026 |
Status and topology deployment-status |
authboxd · mtls | the deployment's own state, computed and drawn | always | desk (79 ops, 79 declared) | /ui/topology |
D5 | store | — | unit · integration · scenario · federation | internal/status 95 · internal/topology 95 |
7 · 8 | guide | 041 · 047 · 074 · 166 · 168 |
The Register — AuthBox's own design system design-system |
authboxd · none | one stylesheet and three embedded faces in, every door AuthBox draws out | always | none | — | none | none | — | — | internal/authboxkit exempt→unit |
5 · 6 | guide | 161 · 164 · 165 |
SSH certificate authority ssh-certificate-authority |
authboxd · intake | OpenSSH certificates (PROTOCOL.certkeys) and revocation lists (PROTOCOL.krl) · RFC 4251, RFC 5656 | ssh.enabled · off |
invitation (2 ops, 2 declared) | — | D4 | store · ca-keystore · dataset | authbox_ssh_issued_total · authbox_ssh_principals_granted_total |
unit · integration · scenario | internal/sshcert 85 · internal/pki 85 · internal/api/enroll 85 |
12 · 16 | guide · runbook | 131 · 132 · 169 |
The jump door jump-door |
authboxproxy · dedicated | SSH — an SSH server on the front door that a client jumps through, one direct-tcpip channel per decision · RFC 4253, RFC 4252, RFC 4254 | proxy.ssh.listen · off |
mtls | — | D1 | audit-chain | authboxproxy_jump_auth_total · authboxproxy_jump_channels_total · authboxproxy_jump_channels_open |
unit · integration | internal/jumpdoor 95 · internal/proxy 90 · internal/sshcert 85 · internal/splice 95 |
6 · 6 | guide · runbook | 136 |
A day in the harbour watch walkthrough |
build · none | six acts over a running federated composition, asserted as it goes | always | none | — | none | none | — | — | — | 1 · 1 | guide | 152 |