Skip to content

[M0-S TRACKER] Safe Shared Research Platform #27

Description

@andreazedda

Milestone objective

Establish the security, authorization, collaboration, deployment, and operational baseline required for multi-user or externally accessible research workflows.

Work items

Exit definition

OBJECT_LEVEL_AUTHORIZATION = pass
RBAC_AND_ACCESS_AUDIT = active
PRODUCTION_SECURITY_PROFILE = pass
COMPUTATIONAL_COST_CONTROLS = active
CENTRAL_POLICY_AND_SELECTOR_LAYER = active
POSTGRES_AND_NON_ROOT_RUNTIME = verified
API_V1_AND_ARTIFACT_AUTHORIZATION = active
PRIVACY_SAFE_OBSERVABILITY = active
CONTRIBUTION_AND_LICENSE_GOVERNANCE = documented

Evidence required

  • role and route permission matrix;
  • negative IDOR and artifact-access tests;
  • HTTPS/CSP/security-header report;
  • rate, concurrency, timeout, and cancellation tests;
  • production container and PostgreSQL smoke evidence;
  • OpenAPI contract;
  • logging-redaction and readiness tests;
  • backup/restore and rollback evidence;
  • governance, CODEOWNERS, DCO/CLA, licensing, and security-contact decisions.

Non-goals

M0-S does not establish scientific validity. It makes shared research operation secure and governable.

Metadata

Metadata

Assignees

Projects

Relationships

None yet

Development

No branches or pull requests

Issue actions