Skip to content

Observability & Audit (COMP-009): M2 deferrals — audit taxonomy registry, provider conformance suite, audit hash chain #992

Description

@toddysm

Context

Observability & Audit Service (COMP-009) M1 is implemented — tracker #692 is closed and OBS-IMPL-001..017 (#675–#691) are all merged: four telemetry pipelines + the read-back API, alert-rule DSL loader/matcher, collector-config merge/validation, and the SSE log tail all landed. On 2026-08-28 the registry was corrected Designed → Implemented. The items below remain open per design/components/observability-audit-service/todos.md.

What's missing

  • TODO-004: Audit-event taxonomy registry — a canonical union of eventName values across components for documentation and the alert-rule editor
  • TODO-005: Conformance test suite for LogQueryProvider and MetricsQueryProvider adapters
  • TODO-006: Cryptographic hash chain over audit rows for tamper-evidence — M2+ (v1 relies on append-only DDL + the audit_retention role)

Design references

  • design/components/observability-audit-service/design.md
  • design/components/observability-audit-service/todos.md

Acceptance criteria

  • Taxonomy registry published and referenced by the alert-rule editor
  • Provider conformance suite running in CI
  • Hash-chain design decided (implement or formally defer with rationale)

Filed 2026-08-28 during status reconciliation of design/architecture/components.md.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions