Skip to content

Docs: Zero Trust "impossible vs tedious" design test in SECURITY.md #493

Description

@krokoko

Context: ROADMAP.md → Zero Trust control review


Doc area

Design / architecture (docs/design/)

Describe the issue

Roadmap calls for a standing design test in SECURITY.md: prefer controls that remove capability over friction-only mitigations (rate limits, observe-only DNS). No documented criterion for prioritizing DNS enforcement, credential scoping, and containment vs throttling.

Affected docs

  • docs/design/SECURITY.md (primary)
  • docs/guides/DEVELOPER_GUIDE.md (link from security section)
  • ADR candidate if governance wants formal status

Suggested change

  1. Add section "Impossible vs tedious" with decision rubric and examples (DNS enforce mode, credential binding, circuit breaker vs turn caps only).
  2. Checklist for PR reviewers on security-sensitive changes.
  3. Cross-link behavioral circuit breaker and emergency containment drafts.
  4. Run mise //docs:sync after edit.

Other information

  • Lightweight doc issue; no runtime code required.
  • Aligns with ADR-009 security posture themes.

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentationsecurityCedar/HITL, IAM least-privilege, secrets, PII/DLP, guardrails, supply-chain/CVE

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions