mirror of
https://github.com/rcourtman/Pulse.git
synced 2026-09-11 22:12:23 +00:00
ddc480ff3c
User on a cloud model saw 'redacted by policy' everywhere. Root cause: the default classification (classifyResourceSensitivity) treated every VM, container, pod, k8s workload, and docker service as 'Sensitive', which redacts their hostname/IP/alias/path for cloud models. For Pulse's homelab/SMB audience that crippled the cloud Assistant — a workload named 'grafana' isn't a secret, and its private LAN IP isn't either. Recalibrate: compute workloads classify as 'Internal' (cloud-summary, no redaction) so cloud models can see their names/IPs. Escalation to Sensitive/Restricted is by tag (database, backup, customer-data, secret, ...) or by genuinely sensitive TYPE: storage/data-at-rest (storage, PBS, Ceph, physical-disk, network-share, network, k8s PV/PVC/StorageClass), configuration (docker-config, k8s-configmap), and security (k8s RBAC, secrets, PMG). Secrets and PMG stay Restricted; the tag-based escalation is unchanged. Tests: new TestRefreshPolicyMetadata_PlainComputeWorkloadsAreInternalNotRedacted + TestComputeWorkloadPolicyIsInternalUnlessEscalated lock it in. ~13 AI-subsystem redaction tests that assumed plain compute = Sensitive updated to tag their fixtures so they still exercise redaction on a genuinely-sensitive resource (no assertions weakened). Contract: unified-resources Extension Points documents the recalibrated classification. internal/ai/... + internal/unifiedresources/... green.