Skip to content

ADRs tagged auth

Auto-generated by scripts/docs/generate-adr-by-tag.sh. Edit ADR Tags: lines to update.

9 ADR(s) carry this tag.

ID Title
ADR-0794 Multi-Tenant Auth Gateway for vmafx-controller
ADR-0967 MCP HTTP transport security — add auth + body limit + safer bind default (Round 26 audit A.1)
ADR-1021 Constant-time session-token comparison + JWT nbf-claim validation
ADR-1518 The controller authorises every gRPC call against one per-method role table, and a method without an entry is refused
ADR-1519 The controller reads its tenants from VmafxTenant resources (or a file of them), verifies each token against its own tenant's provider, and refuses what it cannot verify
ADR-1522 Every job read of the controller is scoped to the caller's tenant in the query, and a node session belongs to the tenant that registered it
ADR-1563 a dedicated vmafx:node role is the only role that reaches the controller's node API
ADR-1569 the operator presents a bearer token to the controller from a file it reads on every call, through credentials shared with the node
ADR-1577 each tenant scores only inputs under its own scoring roots, denied by default, checked by the controller and again by the node