Skip to content

docs(revamp-F): rewrite security.md, refresh use-cases.md - #200

Merged
Pal Lakatos-Toth (pallakatos) merged 1 commit into
devfrom
docs/wave-f-security
May 4, 2026
Merged

Pal Lakatos-Toth (pallakatos) merged 1 commit into
devfrom
docs/wave-f-security

Conversation

@pallakatos

Copy link
Copy Markdown
Collaborator

Wave F of the docs revamp — the security narrative.

docs/security.md rewritten end to end:

  • Opens with four headline guarantees stated up front.
  • Nine-layer model with one short section per layer (infra, OS, pod isolation incl. Kata, container hardening, seccomp, network, inference safety, AGT governance, mesh, CI gates).
  • Removed stale "Phase 1 protocol-layer controls" framing and incorrect counts ("26 vendored patches" → there are 8).
  • "What we do not defend against" section names the four classes of threat AzureClaw cannot stop (per the user's "no fluff, no BS" ask).

docs/use-cases.md surgical edits — CRD list corrected (TrustGraph in, ClawPairing out), runtime tier table replaced with a single shipping/deferred status table.

docs/upstream-alignment.md left intact — already accurate.

Wave F of the v1.0 docs revamp - the security narrative.

docs/security.md (rewritten from 443 lines):
- Opens with 'the headline guarantees' - 4 properties stated up
  front so a security reviewer can decide in 30 seconds whether
  to keep reading.
- 'The nine layers' - one short subsection per layer (Azure infra,
  node OS, pod isolation incl. optional Kata + SEV-SNP, container
  hardening, seccomp, network segmentation, inference safety,
  AGT governance, mesh, CI gates).
- Replaced stale references throughout - removed 'Phase 1 protocol-
  layer controls' framing, removed '26 vendored AgentMesh patches'
  count (real number is 8), removed 'PR #44' callout. The current
  number of allowed/blocked syscalls (219/28) and CRD names are
  retained because they remain accurate.
- 'What we do NOT defend against' section - explicitly names the
  four classes of threat AzureClaw cannot stop (compromised model
  provider, compromised cluster operator without Kata, compromised
  CI/supply chain, prompt injection that the model 'wins'). Honesty
  was an explicit ask from the user ('no fluff, no BS').
- Cross-links updated to point at the post-Wave-A locations.

docs/use-cases.md (surgical edits):
- CRD list corrected: TrustGraph included, ClawPairing removed (it
  is internal and was never user-facing).
- Runtime tier table replaced with a single status table showing all
  7 first-class adapters shipping + BYO + SemanticKernel deferred.
  No more confusing 'Tier-1 vs Tier-2' framing.
- 'Phase 2' historical phrasing replaced with 'v1.0'.
- One stale 'any Tier-1 image' diagram caption updated.

docs/upstream-alignment.md - left intact. It was already accurate
and well-structured; no edits needed in this wave.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pallakatos
Pal Lakatos-Toth (pallakatos) merged commit 4ff1025 into dev May 4, 2026
18 checks passed
@pallakatos
Pal Lakatos-Toth (pallakatos) deleted the docs/wave-f-security branch May 4, 2026 21:48
Pal Lakatos-Toth (pallakatos) added a commit that referenced this pull request May 12, 2026
Wave F of the v1.0 docs revamp - the security narrative.

docs/security.md (rewritten from 443 lines):
- Opens with 'the headline guarantees' - 4 properties stated up
  front so a security reviewer can decide in 30 seconds whether
  to keep reading.
- 'The nine layers' - one short subsection per layer (Azure infra,
  node OS, pod isolation incl. optional Kata + SEV-SNP, container
  hardening, seccomp, network segmentation, inference safety,
  AGT governance, mesh, CI gates).
- Replaced stale references throughout - removed 'Phase 1 protocol-
  layer controls' framing, removed '26 vendored AgentMesh patches'
  count (real number is 8), removed 'PR #44' callout. The current
  number of allowed/blocked syscalls (219/28) and CRD names are
  retained because they remain accurate.
- 'What we do NOT defend against' section - explicitly names the
  four classes of threat AzureClaw cannot stop (compromised model
  provider, compromised cluster operator without Kata, compromised
  CI/supply chain, prompt injection that the model 'wins'). Honesty
  was an explicit ask from the user ('no fluff, no BS').
- Cross-links updated to point at the post-Wave-A locations.

docs/use-cases.md (surgical edits):
- CRD list corrected: TrustGraph included, ClawPairing removed (it
  is internal and was never user-facing).
- Runtime tier table replaced with a single status table showing all
  7 first-class adapters shipping + BYO + SemanticKernel deferred.
  No more confusing 'Tier-1 vs Tier-2' framing.
- 'Phase 2' historical phrasing replaced with 'v1.0'.
- One stale 'any Tier-1 image' diagram caption updated.

docs/upstream-alignment.md - left intact. It was already accurate
and well-structured; no edits needed in this wave.

Co-authored-by: Pal Lakatos-Toth <pallakatos@github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant