Skip to content

M11 design update#9

Merged
mikeappsec merged 2 commits into
mainfrom
m11-design-update
Apr 28, 2026
Merged

M11 design update#9
mikeappsec merged 2 commits into
mainfrom
m11-design-update

Conversation

@mikeappsec

Copy link
Copy Markdown
Owner

No description provided.

Converts the M11 milestone bullet into the standard '✅' done-form, with subsections describing what shipped per slice: pkg/upstream resilience, pkg/ratelimit per-tenant limits, IdentityProvider tenant overrides, pkg/configstream + ConfigDiscovery gRPC push, lwauthctl validate/diff/explain, and the audit.Discard comparable-singleton fix. The ### Next divider moves down to sit before M12.
Per maintainer direction: supply-chain hardening (DHI bases, Cosign, SBOM) is not on the user-visible runtime path and should not block v1.0. Move it to M13 (after the v1.0 release) and promote v1.0 to M12. The new M12 block now spells out, before tagging: (1) the full feature inventory of M1-M11 we are committing to support, (2) what testing already exists in CI today, (3) the additional testing planned for v1.0 (envtest end-to-end, multi-client xDS push under reconnect storms, soak/load, chaos against pkg/upstream, fuzzing on credential parsers, hot-reload concurrency stress, golden-config backwards-compat lock), and (4) the scope of the secure code review (cryptography, authn/authz correctness, untrusted-input parsing, resource exhaustion, plugin trust boundary, multi-tenancy isolation, dependencies). M13 supply-chain content is unchanged but now framed as 'after v1.0, on its own cadence'.
@mikeappsec
mikeappsec merged commit c4c2f97 into main Apr 28, 2026
2 checks passed
@mikeappsec
mikeappsec deleted the m11-design-update branch April 28, 2026 04:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant