aws-samples / aws-samples/sample-autonomous-cloud-coding-agents
Docs: Zero Trust "impossible vs tedious" design test in SECURITY.md
- Vorherrschende Sprache
- TypeScript
- Sterne
- 146
- Forks
- 46
- Ø Merge
- 3 T. 10 Std.
- Gemergte PRs (30 T.)
- 24
Beschreibung
**Context:** ROADMAP.md → Zero Trust control review
---
## Doc area
Design / architecture (`docs/design/`)
## Describe the issue
Roadmap calls for a standing **design test** in `SECURITY.md`: prefer controls that **remove capability** over friction-only mitigations (rate limits, observe-only DNS). No documented criterion for prioritizing DNS enforcement, credential scoping, and containment vs throttling.
## Affected docs
- `docs/design/SECURITY.md` (primary)
- `docs/guides/DEVELOPER_GUIDE.md` (link from security section)
- ADR candidate if governance wants formal status
## Suggested change
1. Add section **"Impossible vs tedious"** with decision rubric and examples (DNS enforce mode, credential binding, circuit breaker vs turn caps only).
2. Checklist for PR reviewers on security-sensitive changes.
3. Cross-link behavioral circuit breaker and emergency containment drafts.
4. Run `mise //docs:sync` after edit.
## Other information
- Lightweight doc issue; no runtime code required.
- Aligns with ADR-009 security posture themes.
Beitragsleitfaden
Rechercherichtung
Beginne mit docs/design/SECURITY.md und der Zero Trust-Kontrollprüfung in ROADMAP.md und sieh dir anschließend docs/guides/DEVELOPER_GUIDE.md nach dem Link zum Sicherheitsabschnitt an. Füge die Rubrik „Unmöglich vs. mühsam“, die Prüfer-Checkliste, Beispiele und Querverweise auf die Entwürfe zum verhaltensbasierten Circuit Breaker und zur Notfall-Eindämmung hinzu; führe zum Abschluss mise //docs:sync aus.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Bereich
- documentation, security
- Issue-Typ
- Dokumentation
- Schwierigkeit
- 2/5
- Geschätzter Aufwand
- 1-2 Tage
- Aktivitätsstatus
- Ruhig
- Klarheit
- Klar beschrieben
- Anfängerfreundlichkeit
- 75/100