Repository navigation
Conversation
…er (Req-3) The 2026-10 review of #82 artifacts found the root-cause gap: the audit cycle is the ONLY revocation path for expired JIT tickets, and nothing scheduled it - so an expired security_auditor admin grant had lingered for months (unrevoked user, tickets stuck active:true). Adds repo-managed, user-scope scheduling (no root, no /etc): - systemd/localobserve-jit-audit.service + .timer: hourly oneshot audit cycle, Persistent=true for missed-cycle catch-up after downtime; deliberately no cross-manager After=/Wants= (user units cannot order against docker.service; a down stack fails the run safely and the next hour retries). - scripts/install-jit-timer.sh: install/dry-run/status/remove, reusing the install-logrotate.sh REPO_ROOT sed convention; verifies generated units with systemd-analyze; documents enable-linger for headless hosts. - Taskfile: install-jit-timer / jit-timer-status / remove-jit-timer. - docs/compliance_crosswalk.md Req-3: revocation-scheduling note. - tests/test_jit_audit_timer.py: 5 hermetic static guards keeping units, installer, and Taskfile in sync with the tool subcommand. Out of scope deliberately: no timer for compliance-ledger-audit - it appends to the VCS-tracked audit_ledger.json and would keep the working tree permanently dirty; ledger appends stay a change-hygiene step.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The #82 artifact review traced a lingering admin user + stuck
active:truetickets to one gap:tools/compliance_rbac_jit.py auditis the only revocation path for expired JIT grants — and nothing ran it on a schedule. The tool fixes (idempotent 404 revoke, honestprovisionedstatus) shipped in #111/#85-adjacent work; this closes the operational half.What
Repo-managed, user-scope scheduling (no root, no
/etcchanges — safe for a laptop dev host):systemd/localobserve-jit-audit.service+.timer— hourly oneshot cycle,Persistent=truecatch-up after downtime; intentionally no cross-managerAfter=/Wants=(user units cannot order againstdocker.service; a down stack fails the run safely and the next hour retries)scripts/install-jit-timer.sh—--install / --dry-run / --status / --remove, sameREPO_ROOTsed-localization convention asinstall-logrotate.sh;systemd-analyze verifys generated unitsinstall-jit-timer,jit-timer-status,remove-jit-timertests/test_jit_audit_timer.py— 5 hermetic static guards tying units/installer/Taskfile to the actual tool subcommandDeliberately excluded
No timer for
compliance-ledger-audit: it appends to the VCS-trackedaudit_ledger.json, which would keep working trees permanently dirty. Ledger appends stay a change-hygiene step.Validation
bash -ninstaller;systemd-analyze verifyclean on generated units (dry-run, nothing installed)tests/test_jit_audit_timer.py5/5; fullpytest tests/greentask install-jit-timer)