Skip to content

[CLI-02] Deliver secure authentication, tenant context, device, command, and diagnostics workflows #2

Description

@jaavid

Background

CoreLink is one product across multiple implementation repositories. This work is owned by cli under EPIC-05.

Problem

CLI-02 previously depended on the vague condition supported APIs, which obscured which contract/security gates are needed for implementation versus which are required before a CLI workflow can be advertised as supported.

Goal

Deliver secure authentication, tenant context, device, command and diagnostics workflows with explicit contract provenance, fail-closed authorization and retained Beta evidence.

Parent

  • Primary Product Epic: EPIC-05
  • Backlog ID: CLI-02

Scope

  • Implement authentication and tenant-context selection without unsafe token persistence.
  • Implement supported device, command and diagnostics workflows against version-identifiable contracts.
  • Provide deterministic errors, retries and recovery behavior for supported operations.
  • Distinguish scaffold/prerelease commands from supported CLI surface.
  • Retain conformance evidence against the accepted API/mock/sandbox revision.

Out of Scope

  • Exposing internal/operator-only operations without an accepted public boundary.
  • Treating generated command scaffolding as product support.
  • Publishing stable claims before corresponding contracts and security gates are accepted.

Acceptance Criteria

  • Authentication and tenant context are explicit, least-privilege and safe for local credential handling.
  • Supported device/command/diagnostic operations map to exact accepted contract versions.
  • Disallowed scope/tenant combinations fail closed and cross-tenant access is denied.
  • Expected, error, retry and recovery behavior is deterministic and covered by conformance evidence.
  • Scaffold/prerelease commands are clearly distinguished from supported commands.
  • Runnable examples and documentation identify CLI and API versions.
  • Retained evidence is linked and EPIC-05 exit criteria are measurably advanced.

Dependencies and acceptance state

  • Execution prerequisite: CLI-01 security/public-vs-operator command boundary.
  • Contract inputs: accepted, version-identifiable slices from API-02 for device/telemetry-related workflows and API-03 where partner/operator scope is exposed; additional API contracts must be linked when a command depends on them.
  • Conformance input: MOCK-02/MOCK-03 or an equivalent accepted sandbox path for repeatable positive/failure scenarios before supported Beta claims.
  • Blocks: CLI-03 packaging/release work, DOCS-04 CLI guidance, WEB-03 supported-tool claims and EPIC-05 CLI acceptance.
  • Current dependency state: See the CoreLink Product organization Project.

Planning Metadata

  • Type: Feature
  • Priority snapshot: P1
  • Product milestone snapshot: Beta
  • Domain snapshots: devex, api
  • Area snapshot: package
  • Complexity: L
  • Created in status: Triage
  • Current status and DRI: See the CoreLink Product organization Project.
  • Intended repository labels: type:feature

Definition of Done

  • Acceptance criteria demonstrated.
  • Required conformance/runtime evidence passes on version-identifiable dependencies.
  • Security and tenant boundaries are accepted.
  • Contract compatibility is reconciled.
  • Credential/error/recovery behavior is documented.
  • Package/release implications are reconciled with CLI-03.
  • Pull request(s), dependency versions and retained evidence are linked.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    type:featureUser-visible product capability or outcome

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions