Step 1Read the design
Docs, diagrams and a walk-through with the people who built them.
ARCHITECTHere's rewards: a gateway, the ledger, offers, and a queue between them.
ATALAIAWho calls the ledger directly? Anything that isn't the gateway?
DEV LEADThe offers service. It's inside the cluster, so we let it through.
Leaves the roomDocs read, 1 walk-through
Step 2Mark the boundaries
Identity, network, data and tenancy boundaries on one picture.
ATALAIASo the ledger trusts anything on the network. That's a boundary nobody drew.
PLATFORMThe queue too. Any pod can publish a 'points credited' message.
Leaves the roomMap: 4 boundaries marked
Step 3Stress the joints
What an attacker, a bad deploy or a leaked key does at each boundary.
ATALAIAIf one pod is compromised, can it credit itself points?
PLATFORMToday, yes. It would look like a normal message.
ARCHITECTAnd one key signs tokens in staging and in prod.
Leaves the room6 joints stressed, 2 high risk
Step 4Agree the changes
Ranked changes, with the trade-offs written down.
ATALAIAService identity on the ledger, signed messages, one key per environment.
CTOKeys and identity this quarter. The queue rewrite waits, and we accept that on record.
ARCHITECTI'll write the decision record today.
Leaves the room3 changes, 1 risk accepted
- ATALAIA
- ARCHITECT
- DEV LEAD
- PLATFORM
- CTO