ADRs tagged auth¶
Auto-generated by scripts/docs/generate-adr-by-tag.sh. Edit ADR Tags: lines to update.
9 ADR(s) carry this tag.
| ID | Title |
|---|---|
| ADR-0794 | Multi-Tenant Auth Gateway for vmafx-controller |
| ADR-0967 | MCP HTTP transport security — add auth + body limit + safer bind default (Round 26 audit A.1) |
| ADR-1021 | Constant-time session-token comparison + JWT nbf-claim validation |
| ADR-1518 | The controller authorises every gRPC call against one per-method role table, and a method without an entry is refused |
| ADR-1519 | The controller reads its tenants from VmafxTenant resources (or a file of them), verifies each token against its own tenant's provider, and refuses what it cannot verify |
| ADR-1522 | Every job read of the controller is scoped to the caller's tenant in the query, and a node session belongs to the tenant that registered it |
| ADR-1563 | a dedicated vmafx:node role is the only role that reaches the controller's node API |
| ADR-1569 | the operator presents a bearer token to the controller from a file it reads on every call, through credentials shared with the node |
| ADR-1577 | each tenant scores only inputs under its own scoring roots, denied by default, checked by the controller and again by the node |