AuthBox documentation — Technical documentation

Documentation embedded in this build.

AuthBox — the support matrix

What AuthBox does, one row per capability, joined to the evidence that it does it. Every cell below is either a name stated in docs/assurance/capabilities.yaml that a test resolves — a setting in the settings register, a package in the coverage register, a status subsystem in the exercise ledger, an OpenAPI document, a plan, an embedded page — or a figure this renderer derives from those registers on each make docs run. Nothing here is typed by hand, and a name that does not resolve fails the build (TestEveryCapabilityRowResolves); a surface with no row fails it too (TestEveryCapabilityIsRegistered).

Floors and tiers are printed; measured percentages are not — a measurement is the output of a run and is stale by the next commit, so this document states the floor a gate holds and the tiers that reach a row, and leaves the measured figures where they are actually produced: the evidence report cmd/authbox-testreport assembles at a tag (make report, published under docs/reports).

An em dash is a statement, not a gap in the rendering: a row whose Proven cell is — is reached by no recorded exercise, and that is the finding this page exists to make visible.

Legend

Column Words it uses
Kind binary, surface, client, subsystem, tool, sdk
Listener mtls, intake, public, ldaps, dedicated, none — where the surface answers; dedicated is a listener one capability owns
Authorized desk, operators, mtls, invitation, eab, signed-action, anonymous, none — how a caller earns entry; anonymous is unauthenticated by design, none is not a network surface at all
Door D1, D2, D3, D4, D5, D6, direct, none — the docs/plans/045 front door this stands behind; direct is reached without one
Storage store, dataset, ca-keystore, audit-chain, tlog-tiles, bundle, none — what it durably writes, and so what a backup must carry
Proven unit, integration, omni, scenario, federation — the tiers that reach this row, in ascending strength

Components

What is shipped and run: 10 binaries, 1 generated SDK, and 17 build-time tools this repository's own claims depend on. Listeners is the component's own plus every listener the surfaces it carries answer on; On by default counts the surfaces a deployment that configures nothing still gets.

Component Kind Listeners On by default Health / metrics Floor Runbook Plans
authboxd authboxd binary mtls · intake · public · ldaps · dedicated 5 of 20 health.listen, kas.health.listen, telemetry.metrics.enabled, telemetry.metrics.listen cmd/authboxd 75 (all) · internal/server 90 · internal/config 85 · internal/tlsx 90 runbook 017 · 023 · 133
authboxproxy authboxproxy binary mtls · public · dedicated 2 of 7 proxy.health.listen, proxy.telemetry.metrics.enabled cmd/authboxproxy 75 (all) · internal/proxy 90 runbook 039 · 045
authboxvault authboxvault binary mtls · public 1 of 2 vault.health.listen cmd/authboxvault 70 (all) · internal/vault 80 runbook 043
authboxportal authboxportal binary mtls 1 of 1 portal.health.listen cmd/authboxportal 70 (all) · internal/portal 80 — 080 · 139 · 144 · 145 · 170
authboxkas authboxkas binary mtls — — cmd/authboxkas 70 (all) · internal/kas 90 · sdk/marked/tdf — runbook 143 · 169
authboxldapsync authboxldapsync binary none — — cmd/authboxldapsync 35 (all) · internal/ldapsync 75 — 087 · 079 · 169
authboxscimsync authboxscimsync binary none — — cmd/authboxscimsync exempt→unit · internal/scimsync 80 runbook 154 · 079 · 169
authbox-agent authbox-agent binary none — — cmd/authbox-agent exempt→integration runbook 037
authboxjs authboxjs sdk none — — cmd/authbox-sdk exempt→unit — 042 · 044
Documentation and register renderer docs-renderer tool none — — cmd/authbox-docs exempt→unit — 040 · 056 · 067 · 147
The mark and the tool that derives it brand-mark tool none — — cmd/authbox-brand 85 · internal/brand 90 — 163
Mutation harness mutation-harness tool none — — cmd/authbox-assure exempt→unit — 030 · 038
Release evidence report evidence-report tool none — — cmd/authbox-testreport exempt→unit · internal/testreport 90 — 038
Benchmark regression gate bench-gate tool none — — cmd/authbox-benchcompare exempt→unit · internal/benchcompare 90 — 030
Software bill of materials sbom tool none — — cmd/authbox-sbom exempt→unit · internal/sbom 85 — 024
Release signing release-signing tool none — — cmd/authbox-sign exempt→unit · internal/relsign 85 · internal/changelog 85 · internal/provenance 80 runbook 024 · 120
Release courier bundle release-media tool none — — cmd/authbox-release exempt→unit · internal/relbundle 85 · internal/relimages 90 runbook 178 · 024
Reference stream sink stream-sink tool mtls — — cmd/authbox-ingest 25 runbook 117
Object store object-store binary mtls — — cmd/authbox-store 50 · internal/objectstore 90 · internal/authboxkit exempt→unit runbook 160 · 161 · 162 · 169 · 171
Local S3 shim store-shim tool none — — cmd/authbox-store-shim 25 runbook 160
Dialect sidecar dialect-sidecar binary mtls — — cmd/authbox-dialect 20 · internal/dialectserve 80 · internal/dialect 90 · internal/dialectconform 80 — 173 · 175
Marked-response showcase showcase-records tool mtls — — cmd/authbox-showcase-records 55 runbook 141 · 143
OIDC login showcase showcase-oidc tool none — — cmd/authbox-showcase-oidc 50 runbook 153 · 169
SAML service provider showcase showcase-saml tool none — — cmd/authbox-showcase-saml 65 — 154 · 169
Fixture PKI and demonstration data fixture-data tool none — — cmd/authbox-testpki 30 (all) · cmd/authbox-demogen 85 · internal/testpki 85 · internal/testkit exempt→integration — 022 · 094
Rehearsal population rehearsal tool none — — cmd/authbox-simulate exempt→unit · internal/simulate 50 runbook 116 · 169
Compose-to-Kubernetes translation compose-translation tool none — — cmd/authbox-kube exempt→unit · internal/composekube 90 — 112
Scanner gate and suppression register scan-gate tool none — — cmd/authbox-scan 80 · internal/scanreg 85 — 118

Capabilities

Every surface, client and subsystem the components carry, grouped as the register groups them.

Client programs

Capability Component · listener Protocol / standards Switch · default Authorized UI Door Storage Observed Proven Floor Rulings · mutations Docs Plans
authboxclient authboxclient authboxclient · none HTTPS client against the enrolment and administration surfaces · RFC 2986, RFC 5280 always none — none none — — cmd/authboxclient 35 (all) · internal/client 85 · internal/pki/keystore 90 4 · 4 guide 037
authboxctl authboxctl authboxctl · none local administration of a deployment's own state always none — none store · dataset · audit-chain · ca-keystore — — cmd/authboxctl 70 (all) 0 · 0 guide · runbook 001

Enrolment and PKI

Capability Component · listener Protocol / standards Switch · default Authorized UI Door Storage Observed Proven Floor Rulings · mutations Docs Plans
Enrolment intake enrolment-intake authboxd · intake CSR intake over HTTPS · RFC 2986, RFC 5280 enroll.listen · off invitation (2 ops, 2 declared) /ui/enrollments D4 store · ca-keystore authbox_enroll_rejected_total unit · integration internal/api/enroll 85 · internal/pki 85 0 · 0 guide 008 · 009
ACME server acme authboxd · intake ACME with device-attest-01 · RFC 8555, draft-acme-device-attest acme.enabled · off eab (2 ops, 2 declared) — D4 store · ca-keystore acme unit · integration · scenario · federation internal/acme 80 15 · 16 guide 013 · 060 · 169
EST server est authboxd · intake Enrollment over Secure Transport · RFC 7030 est.enabled · off invitation (2 ops, 2 declared) — D4 store · ca-keystore — unit · integration · federation internal/est 85 2 · 3 guide 063 · 169
Registration authority registration-authority authboxd · intake PKCS#10 forwarded over EST or ACME to the organisation's own CA · RFC 7030, RFC 8555, RFC 2986 pki.issuer.backend · on invitation (2 ops, 2 declared) — D4 store — unit · integration internal/pki/ra 70 · internal/pki 85 6 · 6 guide · runbook 127
Enrolment invitations invitations authboxd · mtls single-use expiring token always mtls (83 ops, 83 declared) /ui/invitations D5 store — unit · integration · federation internal/invite 90 0 · 0 guide 009
The door follows the project door-follows-project authboxproxy · mtls route records derived from the signed bundle a door already polls proxy.routes_source · on mtls (83 ops, 83 declared) portal /projects/{dn}/services/new D5 store — unit · integration · federation internal/dataset 90 · internal/proxy 90 · internal/replica 90 · internal/credential 95 · internal/api/admin 85 · internal/api/enroll 85 · internal/portal 80 1 · 4 guide 150
Service certificates service-certificates authboxd · mtls derived identity plus a bounded, single-use invitation proxy.credential.serve · off mtls (83 ops, 83 declared) portal /projects/{dn}/services D5 store — unit · integration · federation internal/dataset 90 · internal/pki 85 · internal/api/admin 85 · internal/api/enroll 85 · internal/client 85 · internal/credential 95 · internal/proxy 90 · internal/portal 80 · internal/acme 80 · internal/vault 80 2 · 6 guide 149
Invitation mail invitation-mail authboxvault · mtls SMTP submission to the organization's relay · RFC 5321 vault.mail.relay · on mtls (1 op, 1 declared) vault delegator D6 none — unit · integration internal/vault 80 · internal/smtpsink exempt→integration 7 · 7 guide 088 · 169
Credential claim credential-claim authboxvault · public HTTPS with no client certificate vault.courier.enabled · off invitation (9 ops, own grammar) claim page D6 none — unit · integration internal/vault 80 0 · 0 guide · runbook 043
Attested custody attested-custody authboxd · intake recorded key-custody claim on an issued credential enroll.key_custody · on invitation (2 ops, 2 declared) /ui/enrollments D4 store — unit · integration internal/attestrecord 100 10 · 11 guide 060
Device attestation device-attestation authboxd · intake key-attestation statements verified against manufacturer roots · draft-acme-device-attest always invitation (2 ops, 2 declared) — D4 store · dataset — unit · integration internal/attestverify 95 10 · 11 guide 060
CA hierarchy ca-hierarchy authboxd · none X.509 issuance · RFC 5280 always none /ui/status none ca-keystore ca unit · integration internal/pki 85 · internal/pki/keystore 90 6 · 8 guide · runbook 028 · 095
CRL distribution crl-distribution authboxd · none X.509 certificate revocation lists · RFC 5280 pki.crl.dir · off none /ui/revocations none ca-keystore authbox_crl_age_seconds · authbox_crl_budget_seconds unit · integration · federation internal/pki 85 7 · 8 guide · runbook 029 · 169
OCSP responder ocsp-responder authboxd · public OCSP over HTTP · RFC 6960 ocsp.enabled · off anonymous — D2 store · ca-keystore ocsp unit · integration · omni · federation internal/ocsp 80 6 · 7 guide 012 · 169
OCSP client ocsp-client authboxd · none OCSP over HTTP against an upstream CA · RFC 6960 ocsp_client.freshness · on none /ui/status none none — unit · integration internal/ocsp 80 6 · 7 guide 012 · 169
Post-quantum issuance post-quantum authboxd · none ML-DSA certificates alongside the classical set · FIPS 204 verify.allow_ml_dsa · off none — none ca-keystore — unit internal/pki 85 1 · 1 guide · runbook 064
PKCS#12 export pkcs12-export authboxclient · none PKCS#12 with PBES2 and an SHA-256 HMAC · RFC 7292, RFC 8018 always none — none none — — internal/pkcs12 85 4 · 4 guide 037
Short-lived profile short-lived-profile authboxd · none certificate profiles with a validity measured in hours · RFC 5280 profiles[].short_lived · off none — none ca-keystore — unit · integration internal/pki 85 2 · 2 guide · runbook 059

Identity and authorization

Capability Component · listener Protocol / standards Switch · default Authorized UI Door Storage Observed Proven Floor Rulings · mutations Docs Plans
Administration API admin-api authboxd · mtls HTTPS over mutual TLS · OpenAPI 3.1 always mtls (83 ops, 83 declared) /ui/ D1 store · audit-chain — unit · integration · federation internal/api/admin 85 · internal/server 90 12 · 12 guide 019 · 046
Console console authboxd · mtls server-rendered HTML over mutual TLS · OpenAPI 3.1 ui.enabled · on desk (79 ops, 79 declared) /ui/ D5 store — unit · integration · scenario · federation internal/ui 85 · internal/consoleproject 95 23 · 32 guide 019 · 070 · 072 · 142
Entities and groups entities-and-groups authboxd · mtls X.500-shaped directory of subjects · RFC 4514 store.require_entity_kind · off desk (83 ops, 83 declared) /ui/entities D5 store · dataset — unit · integration · omni · federation internal/dataset 90 · internal/identity 90 19 · 27 guide 006 · 010 · 020 · 142
Dynamic group membership members-everyone authboxd · none a declared membership, resolved at load into the ordinary member list always none — none dataset — — internal/dataset 90 · internal/authz 90 10 · 9 guide 162
Missions missions authboxd · mtls named requirements over a subject's standing authz.delete_requires_owner · on desk (83 ops, 83 declared) /ui/missions D5 store — unit · integration · omni · federation internal/authz 90 24 · 30 guide 006 · 007 · 140 · 144
Brokerage brokerage authboxd · mtls mission brokerage over HTTPS · OpenAPI 3.1 brokerage.enabled · off mtls (4 ops, 4 declared) /ui/requests D1 store · audit-chain — unit · integration · federation internal/api/brokerage 80 27 · 33 guide 061 · 140 · 144
Clearance authority clearance authboxd · mtls clearance question over HTTPS · OpenAPI 3.1 clearance.enabled · off mtls (3 ops, 3 declared) — D1 store — unit · integration · omni internal/api/clearance 85 10 · 12 guide 011 · 065
self self authboxd · mtls self-description over HTTPS · OpenAPI 3.1 self.enabled · off mtls (2 ops, 2 declared) /ui/you/history D1 store — unit · integration · omni · federation internal/api/self 85 14 · 14 guide 019 · 090
Data markings data-markings authboxd · none OpenTDF attribute URIs · OpenTDF 4.3.0 clearance.opentdf_namespace · off none — none dataset — unit · integration internal/opentdf 90 5 · 5 guide 011
Obligations obligations authboxd · mtls standing compliance questions over the store always desk (79 ops, 79 declared) /ui/obligations D5 store — unit · integration · scenario · federation internal/obligation 95 3 · 3 guide 081
Goals goals authboxd · mtls obligation reports joined over a project tree always desk (79 ops, 79 declared) /ui/goals D5 store · audit-chain goal_snapshots unit · integration · scenario · federation internal/goal 80 3 · 6 guide 106
Standing agreements agreements authboxportal · mtls HTTPS over mutual TLS · OpenAPI 3.1 always mtls (42 ops, own grammar) agreements D4 audit-chain — unit · integration · federation internal/portal 80 12 · 16 guide 080 · 145
Delegated identity (XPE) xpe authboxd · mtls X-ProxiedEntitiesChain and X-ProxiedIssuers-Chain xpe.enabled · off mtls (83 ops, 83 declared) /ui/topology D1 store asserters unit · integration · omni · federation internal/xpe 95 13 · 14 guide · runbook 005 · 031 · 051
WebAuthn step-up webauthn authboxd · mtls WebAuthn assertion as a second signature · W3C WebAuthn Level 2 webauthn.rp_id · off desk (79 ops, 79 declared) /ui/webauthn D5 store — unit · integration · scenario · federation internal/webauthn 85 5 · 6 guide 068
Signed actions signed-actions authboxd · mtls actor signature over one action, and a periodic chain-head countersignature · RFC 7515 audit.signing_key_id · off signed-action (83 ops, 83 declared) /ui/audit D1 audit-chain anchor_signing unit · integration · omni · federation internal/attest 85 12 · 13 guide · runbook 033
Decision receipts receipts authboxd · mtls JWS over one permitted decision · RFC 7515 authzen.receipt.issuer · off mtls (6 ops, 6 declared) /ui/policy D1 none authboxproxy_receipts_minted_total unit · integration · federation internal/receipt 95 6 · 9 guide 057 · 101
Authorization engine authorization-engine authboxd · none the specification IS the authorization map · OpenAPI 3.1 spec.path · off none (83 ops, 83 declared) /ui/policy none store callers · authbox_decisions_total · authbox_decision_duration_seconds unit · integration · federation internal/authz 90 · internal/spec 95 · internal/conformance 85 4 · 4 guide · runbook 003 · 047
Activity projection activity authboxd · mtls a projection over the decision record and this process's own counters always desk (79 ops, 79 declared) /ui/activity D5 audit-chain authbox_handshake_total · authbox_decisions_total · authbox_enroll_rejected_total · authbox_active_connections · authbox_active_subjects · authbox_audit_records_total · authbox_audit_write_failures_total unit · integration · scenario · federation internal/activity 90 15 · 12 guide 116
Entity history entity-history authboxd · mtls a projection over records that already exist always desk (79 ops, 79 declared) /ui/entities/{dn}/history D5 store · audit-chain — unit · integration · scenario · federation internal/history 90 6 · 6 guide 082 · 090

Standards surfaces

Capability Component · listener Protocol / standards Switch · default Authorized UI Door Storage Observed Proven Floor Rulings · mutations Docs Plans
SAML identity provider saml-provider authboxd · intake SAML 2.0 Web Browser SSO, HTTP-Redirect and HTTP-POST bindings, signing only · SAML 2.0 Core, SAML 2.0 Bindings, SAML 2.0 Metadata, XML Signature, Exclusive XML Canonicalization 1.0 saml.enabled · off mtls — none store — unit internal/saml 90 7 · 23 guide · runbook 154 · 169
OIDC provider oidc-provider authboxd · intake OpenID Connect authorization code flow with PKCE · OpenID Connect Core 1.0, RFC 8705, RFC 7636 oidc_provider.enabled · off mtls (4 ops, 4 declared) — D4 store oidc unit · integration · federation internal/oidc 85 6 · 6 guide · runbook 014 · 169
AuthZEN PDP authzen authboxd · mtls OpenID AuthZEN Authorization API · OpenID AuthZEN Authorization API 1.0 authzen.enabled · off mtls (6 ops, 6 declared) — D1 store · audit-chain — unit · integration · federation internal/api/authzen 95 4 · 4 guide 053
Shared signals transmitter shared-signals authboxd · mtls OpenID Shared Signals Framework, RFC 8936 poll, RFC 8417 tokens · RFC 8417, RFC 8936, RFC 9493, OpenID CAEP 1.0, OpenID RISC 1.0 ssf.enabled · off mtls (9 ops, 9 declared) — D1 audit-chain · store ssf · authbox_ssf_events_total · authbox_ssf_poll_total · authbox_ssf_stream_lag_records unit · integration internal/ssf 80 13 · 20 runbook 130 · 142
LDAPS directory ldaps-directory authboxd · ldaps LDAP v3 over TLS, read-only, SASL EXTERNAL bind · RFC 4511, RFC 4513 ldap.listen · on mtls — direct store — unit · integration · federation internal/ldapserve 80 13 · 22 guide 087 · 142 · 169
SPIFFE federation spiffe-federation authboxd · mtls X509-SVID peers from declared foreign trust domains · SPIFFE X509-SVID federation.accept_bundles · off mtls /ui/topology D1 dataset — unit · integration · federation internal/federation 95 · internal/spiffeid 85 4 · 5 guide · runbook 066
Foreign-schema codec seam foreign authboxd · none seam between AuthBox's model and a foreign one always none — none dataset — — sdk/foreign — · internal/foreign 90 8 · 9 guide 004 · 138
STANAG label seam stanag authboxd · none seam between a NATO confidentiality label and this dictionary · STANAG 4774, STANAG 4778 always none — none dataset — — internal/stanag 90 11 · 14 guide 004 · 065

Distribution

Capability Component · listener Protocol / standards Switch · default Authorized UI Door Storage Observed Proven Floor Rulings · mutations Docs Plans
Replicas replicas authboxd · mtls signed dataset bundles with a monotonic serial replica.enabled · off operators (83 ops, 83 declared) /ui/topology D1 bundle · dataset replica · authbox_replica_adoption_failures_total · authbox_replica_bundle_age_seconds unit · integration · federation internal/replica 90 3 · 4 guide 016 · 169
Replica publish replica-publish authboxd · mtls signed replica bundle of the live store, on a cadence, served on request replica_publish.enabled · off mtls (83 ops, 83 declared) /ui/topology D1 bundle · store published_topology unit · integration · scenario · federation internal/replica 90 26 · 27 guide · runbook 071 · 117 · 168
Sync engine and live cascade sync-engine authboxd · mtls authority bundles, adopted from an upstream and served per consumer sync.live.enabled · off operators (83 ops, 83 declared) /ui/topology D1 bundle · store consumers · reported_topology · authbox_sync_adoption_failures_total · authbox_upstream_age_seconds unit · integration · federation internal/syncengine 95 · internal/authoritybundle 75 · internal/authorityserve 80 22 · 26 guide · runbook 034 · 071 · 168
Project authority federation project-authority authboxd · mtls a project owned by another AuthBox, with a freshness budget upstreams[].name · off operators (83 ops, 83 declared) /ui/authorities/{name} D1 store upstreams · cached_projects unit · integration · federation internal/upstream 75 9 · 9 guide 018 · 007
Org attribute authorities org-attribute-authorities authboxd · none signed assertions over an attribute name somebody else owns always none /ui/authorities/{name} none bundle · dataset — unit · integration · omni · federation internal/authoritybundle 75 0 · 0 guide 079
The federation's names federation-names authboxproxy · dedicated authoritative DNS over UDP and TCP, with DNSSEC signing · RFC 1035, RFC 4034, RFC 4035 proxy.names.serve.listen · off anonymous /ui/frontdoor direct none authboxproxy_dns_answers_total unit · integration · scenario · federation internal/names 95 · internal/dnsserve 80 8 · 29 guide · runbook 099 · 100
The anonymous door anonymous-door authboxproxy · public match, strip, forward — no decision and no injected identity proxy.anonymous.listen · off anonymous /ui/frontdoor D2 none — unit · integration · scenario internal/proxy 90 1 · 1 guide · runbook 045
The front door's directory front-door-directory authboxproxy · public one HTML page, GET, no client certificate — drawn from the route table proxy.anonymous.directory.enabled · off anonymous — D2 none — unit · scenario internal/proxy 90 · internal/authboxkit exempt→unit 3 · 3 guide · runbook 157
Kubernetes ingress mode proxy-kubernetes authboxproxy · none list and watch over this cluster's Services proxy.kubernetes.enabled · off none /ui/frontdoor none none — unit · integration · scenario internal/proxy 90 17 · 17 guide · runbook 039
Authorized streams streams authboxproxy · mtls labelled frames over one long-lived request, fanned out by marking always mtls /ui/streams D1 audit-chain streams · authboxproxy_stream_frames_total · authboxproxy_stream_bytes_total · authboxproxy_streams_open · authboxproxy_stream_closed_total unit · integration internal/stream 80 · internal/proxy 90 13 · 13 guide · runbook 117
The marked response marked authboxproxy · mtls one response header carrying a marking, compared against the caller's chain always mtls — D1 audit-chain — unit internal/proxy 90 · sdk/marked — 8 · 14 guide · runbook 141
SSH through the door ssh-through-the-door authboxproxy · mtls a raw connection wrapped in mutual TLS, routed by SNI, spliced unread · RFC 4253 proxy.routes[].kind · off mtls — D1 audit-chain authboxproxy_tcp_sessions_total · authboxproxy_tcp_bytes_total · authboxproxy_tcp_sessions_open · authboxproxy_tcp_closed_total unit internal/splice 95 · internal/proxy 90 6 · 6 guide · runbook 135
Self-enrolling credential managed-credential authboxproxy · none the companion enrols and renews its own certificate proxy.credential.managed · off invitation — none none — unit internal/credential 95 · internal/credential/selfenroll 80 0 · 0 guide · runbook 049

Evidence and operations

Capability Component · listener Protocol / standards Switch · default Authorized UI Door Storage Observed Proven Floor Rulings · mutations Docs Plans
Audit chain audit-chain authboxd · mtls append-only hash-chained records, sealed into segments audit.path · off desk (83 ops, 83 declared) /ui/audit D1 audit-chain audit_segments · authbox_audit_records_total · authbox_audit_write_failures_total unit · integration · omni · federation internal/audit 95 5 · 5 guide · runbook 026
Signed audit export audit-export authboxctl · none a sealed segment turned into an artifact a SIEM can prove it received always none — none audit-chain — — internal/auditexport 80 2 · 4 guide · runbook 055
Front-door audit hand-off door-audit-handoff authboxproxy · mtls one plan-055 signed export per sealed segment, POSTed in ordinal order audit.doors_path · off mtls (83 ops, 83 declared) /ui/activity none audit-chain authbox_door_segments_accepted_total · authbox_door_segments_refused_total unit · integration · federation internal/auditexport 80 · internal/activity 90 5 · 5 guide · runbook 122
Transparency log transparency-log authboxd · none static tile tree with signed-note checkpoints · C2SP tlog-tiles, C2SP signed-note log.enabled · off none — none tlog-tiles — unit · integration internal/tlog 90 6 · 6 guide 058
Backup and restore backup-restore authboxctl · none a manifest-wrapped tar of the dataset, the audit segments and the keystore always none /ui/status none store · audit-chain · ca-keystore restored_audit unit · integration internal/backup 75 5 · 5 guide · runbook 026 · 169
Policy export policy-export authboxd · none the declared requirements as Rego and Cedar always none /ui/policy/{operationId} none none — unit · integration internal/policycodec 90 5 · 5 guide · runbook 067
Control mapping and OSCAL controls authboxd · none NIST 800-53 control mapping, emitted as an OSCAL component definition · NIST SP 800-53 Rev. 5, OSCAL 1.1 always none /ui/docs/{collection}/{slug} none none — integration internal/assurance 75 2 · 2 guide 056 · 062 · 091
Public listener public-listener authboxd · public HTTPS with no client certificate requested public.enabled · off anonymous / D2 none — unit internal/api/public 85 0 · 0 guide 008 · 086 · 096
Embedded documentation embedded-docs authboxd · mtls the accreditation collection rendered into the binary public.docs · on desk (79 ops, 79 declared) /ui/docs D5 none — unit · integration · scenario · federation internal/docs 90 · internal/docrender 90 5 · 5 guide 040 · 096
Health health authboxd · dedicated liveness and readiness over HTTPS health.listen · off anonymous — direct none — unit internal/health 95 1 · 1 guide 002
Metrics metrics authboxd · dedicated Prometheus text exposition telemetry.metrics.enabled · off operators /ui/status direct none active_subjects · authbox_build_info · authbox_active_subjects unit · integration · omni internal/telemetry 90 4 · 4 guide 021
Operational log operational-log authboxd · none structured operational logging telemetry.log.level · on none — none none — unit · omni internal/telemetry 90 4 · 4 guide 021
Store backends store-backends authboxd · none memory, file, PostgreSQL and MySQL behind one repository interface store.backend · on none /ui/settings none store · dataset store unit · integration · federation internal/store 75 · internal/store/file 75 · internal/store/memory 95 · internal/store/sqlstore exempt→db · internal/store/sqlstore/postgres exempt→db · internal/store/sqlstore/mysql exempt→db 12 · 9 guide 025 · 026
Status and topology deployment-status authboxd · mtls the deployment's own state, computed and drawn always desk (79 ops, 79 declared) /ui/topology D5 store — unit · integration · scenario · federation internal/status 95 · internal/topology 95 7 · 8 guide 041 · 047 · 074 · 166 · 168
The Register — AuthBox's own design system design-system authboxd · none one stylesheet and three embedded faces in, every door AuthBox draws out always none — none none — — internal/authboxkit exempt→unit 5 · 6 guide 161 · 164 · 165
SSH certificate authority ssh-certificate-authority authboxd · intake OpenSSH certificates (PROTOCOL.certkeys) and revocation lists (PROTOCOL.krl) · RFC 4251, RFC 5656 ssh.enabled · off invitation (2 ops, 2 declared) — D4 store · ca-keystore · dataset authbox_ssh_issued_total · authbox_ssh_principals_granted_total unit · integration · scenario internal/sshcert 85 · internal/pki 85 · internal/api/enroll 85 12 · 16 guide · runbook 131 · 132 · 169
The jump door jump-door authboxproxy · dedicated SSH — an SSH server on the front door that a client jumps through, one direct-tcpip channel per decision · RFC 4253, RFC 4252, RFC 4254 proxy.ssh.listen · off mtls — D1 audit-chain authboxproxy_jump_auth_total · authboxproxy_jump_channels_total · authboxproxy_jump_channels_open unit · integration internal/jumpdoor 95 · internal/proxy 90 · internal/sshcert 85 · internal/splice 95 6 · 6 guide · runbook 136
A day in the harbour watch walkthrough build · none six acts over a running federated composition, asserted as it goes always none — none none — — — 1 · 1 guide 152