ADR 0050 (proposed) — model access is vendor-agnostic; amend 14-model-access
Turn the completed vendor-agnostic analysis into HQ design. The model-access provision stays one vendor-blind interface (extends 0024/0027); the vendor-specific lifecycle moves into a per-vendor adapter keyed by the licence's `vendor` field, mirroring registrar-scoped public-dns providers (0044), named at the consumer's real coupling per 0040. The crux is the sealing-vs-central-rotation carve-out: for refreshable-grant vendors only, the manager node holds the refresh token encrypted at rest (a bounded, declared exception), access tokens sealed per holder, refresh stripped on delivery. Static-key vendors keep full sealing. Amend 03-DESIGN/01-to-be/14-model-access.md with the adapter generalisation as a proposed section (prose + diagram, no code); regenerate the decision index. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -118,6 +118,7 @@ python3 00-META/checks/index.py fail if stale
|
||||
- **0047** — [A module runs its code as its own process, with its own account](0047-a-module-runs-its-code-as-its-own-process-with-its-own-account.md)
|
||||
- **0048** — [A provider creates the credential the mesh minted, and seals nothing](0048-a-provider-creates-the-credential-the-mesh-minted.md)
|
||||
- **0049** — [A consumer's identity is bounded by the tightest backend that must accept it](0049-a-consumers-identity-fits-the-tightest-backend.md)
|
||||
- **0050** — [Model access is vendor-agnostic, and a vendor is an adapter](0050-model-access-is-vendor-agnostic.md) *(proposed)*
|
||||
|
||||
### How it is built
|
||||
|
||||
|
||||
Reference in New Issue
Block a user