@lssm/integration.osint-managed-runtime
v2.0.2
Published
Managed PostgreSQL and AuthOS adapters for OSINT services.
Readme
@lssm/integration.osint-managed-runtime
Managed infrastructure adapters shared by the OSINT API, worker, and MCP
composition packages. It verifies OIDC grants against HTTPS JWKS, obtains a
fresh scoped authority decision for every request or effect, and adapts the
postgres driver to the FORCE-RLS OSINT store ports.
assertManagedOsintDatabaseRoleV0 verifies the exact PostgreSQL
current_user and rejects superuser or BYPASSRLS connections. Runtime
compositions use this readiness gate before dedicated rights workers can claim
deletion work; application filtering never substitutes for database isolation.
Authority responses must bind the exact actor, requested scope, grants, purpose, request digest, decision evidence, and expiry. The runtime rejects widening, stale decisions, malformed bearer tokens, and credential-bearing endpoints.
createManagedOsintOperationHandlerV0 is the single managed REST/MCP handler:
authorized reads use canonical scoped SQL and mutations enter the same durable
queue with a canonical digest.
ManagedOsintOutboxStreamBrokerV0 turns the append-only Postgres outbox into
scope-isolated SSE/WebSocket delivery. Each subscriber replays strictly after
its numeric cursor under transaction-local FORCE-RLS context; malformed rows
retain the cursor and surface only a redacted failure code. The API closes the
poller before releasing its database pool.
Managed compositions can bind the same fail-closed runtime controls to every
surface. Global, per-program, export, and research switches reject requests
before SQL reads or durable queue writes. Environment-backed compositions use
strict true/false values and default the global kill switch to active.
Fresh worker authority decisions retain their evidence references so downstream provider policy checks bind the exact server-side membership decision rather than treating a decision identifier as an implicit grant.
createManagedOsintTelemetryV0 emits structured lifecycle and bounded HTTP
route-class logs without raw paths, entity IDs, tenants, query strings, or
credentials. Metrics and traces use OpenTelemetry only when an explicit OTLP
endpoint is configured; otherwise the adapter remains structured-log-only and
does not activate the console exporter.
The managed self-improvement adapters reuse the same Postgres pool without transferring ownership, construct tenant/workspace-bound durable stores, and resolve a fresh, exact self-improvement authority decision for every HTTP request. Phase execution and review/evidence reads go to a credential-free HTTPS control plane with a bounded workload token and bounded response bodies. The control plane must return immutable decision/evidence receipts; malformed or denied responses fail closed. A readiness probe verifies all four durable tables and deliberately does not run migrations from a runtime role.
