Repository navigation
docs(revamp-F): rewrite security.md, refresh use-cases.md - #200
Merged
Merged
Conversation
Wave F of the v1.0 docs revamp - the security narrative. docs/security.md (rewritten from 443 lines): - Opens with 'the headline guarantees' - 4 properties stated up front so a security reviewer can decide in 30 seconds whether to keep reading. - 'The nine layers' - one short subsection per layer (Azure infra, node OS, pod isolation incl. optional Kata + SEV-SNP, container hardening, seccomp, network segmentation, inference safety, AGT governance, mesh, CI gates). - Replaced stale references throughout - removed 'Phase 1 protocol- layer controls' framing, removed '26 vendored AgentMesh patches' count (real number is 8), removed 'PR #44' callout. The current number of allowed/blocked syscalls (219/28) and CRD names are retained because they remain accurate. - 'What we do NOT defend against' section - explicitly names the four classes of threat AzureClaw cannot stop (compromised model provider, compromised cluster operator without Kata, compromised CI/supply chain, prompt injection that the model 'wins'). Honesty was an explicit ask from the user ('no fluff, no BS'). - Cross-links updated to point at the post-Wave-A locations. docs/use-cases.md (surgical edits): - CRD list corrected: TrustGraph included, ClawPairing removed (it is internal and was never user-facing). - Runtime tier table replaced with a single status table showing all 7 first-class adapters shipping + BYO + SemanticKernel deferred. No more confusing 'Tier-1 vs Tier-2' framing. - 'Phase 2' historical phrasing replaced with 'v1.0'. - One stale 'any Tier-1 image' diagram caption updated. docs/upstream-alignment.md - left intact. It was already accurate and well-structured; no edits needed in this wave. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Pal Lakatos-Toth (pallakatos)
added a commit
that referenced
this pull request
May 12, 2026
Wave F of the v1.0 docs revamp - the security narrative. docs/security.md (rewritten from 443 lines): - Opens with 'the headline guarantees' - 4 properties stated up front so a security reviewer can decide in 30 seconds whether to keep reading. - 'The nine layers' - one short subsection per layer (Azure infra, node OS, pod isolation incl. optional Kata + SEV-SNP, container hardening, seccomp, network segmentation, inference safety, AGT governance, mesh, CI gates). - Replaced stale references throughout - removed 'Phase 1 protocol- layer controls' framing, removed '26 vendored AgentMesh patches' count (real number is 8), removed 'PR #44' callout. The current number of allowed/blocked syscalls (219/28) and CRD names are retained because they remain accurate. - 'What we do NOT defend against' section - explicitly names the four classes of threat AzureClaw cannot stop (compromised model provider, compromised cluster operator without Kata, compromised CI/supply chain, prompt injection that the model 'wins'). Honesty was an explicit ask from the user ('no fluff, no BS'). - Cross-links updated to point at the post-Wave-A locations. docs/use-cases.md (surgical edits): - CRD list corrected: TrustGraph included, ClawPairing removed (it is internal and was never user-facing). - Runtime tier table replaced with a single status table showing all 7 first-class adapters shipping + BYO + SemanticKernel deferred. No more confusing 'Tier-1 vs Tier-2' framing. - 'Phase 2' historical phrasing replaced with 'v1.0'. - One stale 'any Tier-1 image' diagram caption updated. docs/upstream-alignment.md - left intact. It was already accurate and well-structured; no edits needed in this wave. Co-authored-by: Pal Lakatos-Toth <pallakatos@github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Wave F of the docs revamp — the security narrative.
docs/security.mdrewritten end to end:docs/use-cases.mdsurgical edits — CRD list corrected (TrustGraphin,ClawPairingout), runtime tier table replaced with a single shipping/deferred status table.docs/upstream-alignment.mdleft intact — already accurate.