feat(grove): add actor authentication and orb dev controls - #400
Merged
Conversation
Introduce Person JIT binding, explicit Agent enrollment, Home Host ownership, currentness, and capability-containment enforcement. The actor authority is the single transaction owner for identity and access mutations. Amp-Thread-ID: https://ampcode.com/threads/T-019ff6db-1023-70fd-8fd0-6e6442a84f46 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff6db-1023-70fd-8fd0-6e6442a84f46 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff6db-1023-70fd-8fd0-6e6442a84f46 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff6db-1023-70fd-8fd0-6e6442a84f46 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff6db-1023-70fd-8fd0-6e6442a84f46 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff6db-1023-70fd-8fd0-6e6442a84f46 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff6db-1023-70fd-8fd0-6e6442a84f46 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff6db-1023-70fd-8fd0-6e6442a84f46 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff6db-1023-70fd-8fd0-6e6442a84f46 Co-authored-by: Eli <elisha.dukes@gmail.com>
Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff8d4-eb3e-76b9-90c6-e9bccdbe3444 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff8d4-eb3e-76b9-90c6-e9bccdbe3444 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff8d4-eb3e-76b9-90c6-e9bccdbe3444 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff8d4-eb3e-76b9-90c6-e9bccdbe3444 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff8d4-eb3e-76b9-90c6-e9bccdbe3444 Co-authored-by: Eli <elisha.dukes@gmail.com>
Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff934-6c8d-704d-abfe-ab78e4015616 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff934-6c8d-704d-abfe-ab78e4015616 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff934-6c8d-704d-abfe-ab78e4015616 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff934-6c8d-704d-abfe-ab78e4015616 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff934-6c8d-704d-abfe-ab78e4015616 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff934-6c8d-704d-abfe-ab78e4015616 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff934-6c8d-704d-abfe-ab78e4015616 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff934-6c8d-704d-abfe-ab78e4015616 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff934-6c8d-704d-abfe-ab78e4015616 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff934-6c8d-704d-abfe-ab78e4015616 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff934-6c8d-704d-abfe-ab78e4015616 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff934-6c8d-704d-abfe-ab78e4015616 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff934-6c8d-704d-abfe-ab78e4015616 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff934-6c8d-704d-abfe-ab78e4015616 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019ff934-6c8d-704d-abfe-ab78e4015616 Co-authored-by: Eli <elisha.dukes@gmail.com>
Use one file descriptor for bounded browser-log writes and signing-key assertions so file validation and use cannot race. Keep the operational MCP client as a direct runtime dependency and remove test-only exports rejected by strict Knip. Amp-Thread-ID: https://ampcode.com/threads/T-019fecd4-51da-72c7-a3bc-081241c51785 Co-authored-by: Eli <elisha.dukes@gmail.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019fecd4-51da-72c7-a3bc-081241c51785 Co-authored-by: Eli <elisha.dukes@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
__devlogin/logout/preflight, bounded sanitized browser logs, persistent dev signing keys, and explicit MCP Agent enrollmentSecurity boundaries
/mcpgrove:mcpis transport admission, not blanket command capability__devrequires both a SvelteKit development build andGROVE_ORB_DEV_AUTH=1; production build verification excludes its implementationValidation
vp run --filter @petalnet/grove test— 79/79 passedvp run --filter @petalnet/grove check— 0 errors, 0 warningsvp run --filter @petalnet/grove build— passed, including production control-plane exclusionvp run --filter @petalnet/effect-api test— 14/14 passedgit diff --checkpassed during the audited implementation runOperational entrypoint
Run
.agents/ensure-grovefrom the repository root. Grove-specific orb guidance lives inapps/grove/AGENTS.md.