Skip to content

Add agent runtime identity and credential isolation ADRs - #31

Draft
sfloess wants to merge 2 commits into
mainfrom
agent/identity-profile-separation
Draft

Add agent runtime identity and credential isolation ADRs#31
sfloess wants to merge 2 commits into
mainfrom
agent/identity-profile-separation

Conversation

@sfloess

@sfloess sfloess commented Aug 8, 2026

Copy link
Copy Markdown
Member

Adds the architectural decisions for sharing agent runtime infrastructure while strictly separating organizational identity, profiles, credentials, provider/model policy, and resource access.

ADRs

  • ADR-0021: Agent Runtime Identity and Profile Separation
  • ADR-0022: Provider Credential and Model Policy Isolation

LDAP/FreeIPA/OIDC remain implementation choices; the architectural requirement is identity isolation.

The intent is to support the same agent infrastructure for Red Hat and personal FlossWare contexts without allowing credentials, models, repositories, MCP endpoints, or policy to cross organizational boundaries.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant