fix: complete diagnostic extension remediation

This commit is contained in:
2026-08-04 00:46:44 +02:00
parent 565e93a456
commit 49fa7030a5
6 changed files with 192 additions and 19 deletions
+8 -3
View File
@@ -19,8 +19,8 @@ belongs in the descriptor, this document, a generated `.env.example`, or diagnos
fragment. The client may use only the declared method, path, auth mode, and response-field names.
- `auth: none` sends no credential; `auth: bearer` reads a local file and sends
`Authorization: Bearer <file-content>`; `auth: x-api-key` sends `x-api-key: <file-content>`.
The resolver does not require or read an API-key file for an `auth: none` diagnostic. File
content is never logged or returned.
The resolver, rendered runtime endpoint, and diagnoser do not require or read an API-key file
for an `auth: none` diagnostic. File content is never logged or returned.
## Canonical descriptor additions
@@ -117,6 +117,10 @@ Both returned values must equal the descriptor's DWH database and schema.
with certificate verification; when absent, the native client still requires a valid certificate
chain from the runtime system trust store. Absence never disables TLS verification.
An SSH tunnel changes only the TCP peer to loopback. The forwarded PostgreSQL TLS connection sets
its server name to `<ROLE>_SSH_TARGET_HOST`, so certificate hostname validation remains against the
declared remote target rather than `127.0.0.1`.
For REST, the descriptor above declares the exact ping:
```text
@@ -142,7 +146,8 @@ collection, integer `dimensions`, and `distance` (`cosine`, `l2`, or `inner_prod
`semantic_index.vector_store`.
Their optional `*_TLS_CA_FILE` follows the same verified private-CA-or-system-trust rule as the
DWH diagnostic.
DWH diagnostic. For an SSH tunnel, their TLS server name is likewise the declared vector
`SSH_TARGET_HOST`, not the loopback listener.
For REST, the exact descriptor-declared request is, for example: