Skip to content

[P1][Post-0.5][Qualification] Prove tenant, browser, and network isolation across remote workspaces #95

Description

@mightnent

Parent qualification epic: #79

Outcome

Automate two-organization remote-workspace browser and network qualification that proves tenant isolation, replay-resistant access, fail-closed routing, and private-target redaction.

Execution

  • Priority: P1 post-0.5 security qualification.
  • Deployment profiles: Hosted required; worktree remote fixture where representative.
  • Worktree boundary: Two-organization staging fixtures, browser/WebSocket tests, workspace network probes, redaction assertions, and evidence capture. Avoid product UI redesign and cloud-specific infrastructure implementation.

Scope

  • Exercise create, view/open, reconnect, stop, restart, persistence reuse, destroy, and purge for two organizations.
  • Deny cross-tenant and cross-workspace provider-ID substitution for every lifecycle and purge action.
  • Cover WebSocket reconnect, launch/grant expiry and replay, logout, live revocation, cleanup, and session replacement.
  • Prove metadata, unrestricted internet, unauthorized application-subnet, DNS-bypass, and private relay/control paths fail closed from the workspace.
  • Prove approved private model/connector routes and governed public egress continue to work.
  • Assert browser payloads, URLs, logs, fixtures, screenshots, traces, and evidence contain no private node/relay target, launch material, grants, tokens, certificates, or credentials.
  • Extend the matrix with Full C shared/dedicated placement and stale-generation cases as [P1][Post-0.5][Epic] Productionize the Full C multi-node workspace runtime #82 delivers them.

Non-goals

  • Implementing tenant placement, egress policy, or node routing behavior.
  • General product UI or accessibility regression coverage.
  • Publishing private network topology or certificate inventory.

Definition of success

  • Two-organization browser staging proves lifecycle, persistence ownership, purge, reconnect, expiry/replay, logout, and revocation isolation.
  • Cross-tenant/workspace provider IDs cannot view, open, update, stop, destroy, reuse persistence, or purge another workspace.
  • Metadata, unrestricted internet, unauthorized application, DNS-bypass, and private relay paths fail closed while approved routes work.
  • Secret/private-target scanning passes for all browser and machine-readable evidence.
  • Relevant Playwright, network-probe, focused security suites, and npm run verify:quick pass on the exact evidence SHA.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions