Skip to content

Existing ADR Disposition

All 54 baseline records (ADR-000 through ADR-053) are covered below. Status changes are recommendations for decision review. This review makes no edits to accepted ADR bodies or statuses; the incorporated upstream PR #959 amended ADR-049 as described in the update. Proposed ADR-054 through ADR-058 state the replacement scope explicitly.

ADR Proposed disposition Reason
ADR-000: Use Architecture Decision Records Retain Keep decisions versioned and accepted history immutable.
ADR-001: Migrate from AWS/Terraform to Local Docker Compose Clarify with 054/055 Local Docker remains the normal personal-backend path, with actual boundary disclosure.
ADR-002: Wazuh SIEM over Splunk and qRadar Scope to the TechVault pack under 054 Wazuh is TechVault content/integration, not every product profile.
ADR-003: MCP Common Library with Config-Driven Server Generation Clarify with 054/057 Common MCP mechanisms follow optional consumers; explicit grants and process boundary required.
ADR-004: Persistent SSH Session Architecture with Command Queuing Clarify with 057 Persistent sessions need bounded input/output/lifetime and actual cleanup; SSH transport is not host sandboxing.
ADR-005: Docker Compose Profiles for Selective Deployment Clarify with 054/056 Profiles are operator packaging over an admitted graph, not a second topology authority.
ADR-006: Four-Network Segmentation Architecture Scope to the TechVault pack under 054/055 Four networks are TechVault design, not a universal topology or containment proof.
ADR-007: Python CLI as Primary Control Plane Retain with 054 Keep the product-owned CLI; add an installed doctor/lifecycle contract without scenario-pack prerequisites.
ADR-008: Integrated SOC Stack (MISP, TheHive, Cortex, Shuffle, Suricata) Scope to the TechVault pack under 054 SOC clients, initialization, and content remain selected TechVault behavior.
ADR-009: Scenario Engine with YAML Specs and Run Archive Collectors Clarify with 054/056 Keep safe archive/execution mechanisms; portable SDL meaning remains RAES-owned.
ADR-010: SonarCloud for Continuous Code Quality Clarify with 058 Preserve quality checks; passing function complexity or badges is not architecture/live proof.
ADR-011: Notebook-Style Web UI (SvelteKit + FastAPI) Resolve proposed status during migration Useful UI already exists; retain optional operator scope and decide acceptance from implementation evidence.
ADR-012: OpenTelemetry Integration Retain with 054 Generic telemetry transport remains useful; optional stack and research capture policy stay outside tiny core.
ADR-013: Deployment Backend Abstraction Layer Clarify with 054/055 One deployment authority and narrow native interfaces; avoid speculative multi-backend abstraction.
ADR-014: Scenario Description Language (SDL) Propose authority supersession by 054 APTL-local portable language design is historical; RAES supplies public semantics and parsing.
ADR-015: Declarative Experiment Objectives in the SDL Propose authority supersession by 054 RAES owns objective language meaning. Preserve only contract-consuming evaluator behavior.
ADR-016: Workflows, Targetable Sub-Objects, and Leaf Enum Variables in the SDL Propose authority supersession by 054 RAES owns workflows, object targets and variable semantics; no local semantic fork.
ADR-017: SDL Runtime Layer Propose replacement by 054 Resolve stale proposed runtime-layer record against current published RAES contract ownership.
ADR-018: Control Flow Primitives in the SDL Propose authority supersession by 054 Control-flow language primitives belong upstream; backend executes only its supported contract subset.
ADR-019: Suricata stays IDS-only; packet-level prevention via Wazuh active-response Scope to the TechVault pack under 054 Preserve IDS/active-response choice for applicable TechVault profiles.
ADR-020: Wazuh agents run in-process on the target containers; sidecars only for upstream-image carve-outs Scope to the TechVault pack under 054 Preserve exact agent placement where the adopted telemetry profile needs it.
ADR-021: Active-response whitelist enforcement via a standalone iptables AR script Scope to the TechVault pack under 054/055 Retain declared active-response behavior; shared lifecycle code does not own scenario response policy.
ADR-022: MISP-driven Suricata rules via a tag-graduated sync service Scope to the TechVault pack under 054 MISP rule sync is a selected plugin/service, not unconditional backend machinery.
ADR-023: Container Interaction in the Deployment Backend Protocol Clarify with 055 Every interaction must operate on independently verified owned targets, not names alone.
ADR-024: Orchestrator-side purple-team continuity carve-out Scope to the research apparatus under 054/057 Continuity policy must be explicit admitted research policy, not hidden generic mutation.
ADR-025: Strict first-party config schema Clarify with 055 Strict schema validation must be paired with operator authorization; valid data is not a grant.
ADR-026: Advisory CI Vulnerability Scanning Propose partial supersession by 058 Replace blanket advisory platform treatment; retain bounded intentional-target exceptions and advisory posture scores.
ADR-027: Red Team Structured Logging Boundary Retain historical amendment ADR-033 already governs behavioral trace boundary; avoid another attribution/telemetry path.
ADR-028: Runtime-Rendered Service Config Clarify with 055 Use admitted generated artifacts and secure writes; randomize real control credentials.
ADR-029: Control-Plane Secret Handling in Run Data and Local State Clarify with 055/057 Use one private-state boundary, explicit credential grants and accurate possession/revocation claims.
ADR-030: Startup Partial-Readiness Classification Clarify with 055/058 Partial readiness must carry residual-state and retry/cleanup behavior; not success by convenience.
ADR-031: Lab Orchestration Contract Guards Clarify with 055 Preserve contract guards and safe diagnostics; add explicit stage-state/ownership contracts.
ADR-032: Conversation Surface Hardening Clarify with 057 Conversation limits and filtering complement actual provider/MCP process confinement.
ADR-033: Red-Side Behavioural Capture and Non-Contamination Boundary Retain with 057 Keep red-side behavioral evidence separated from evaluator/control state; fix management reachability.
ADR-034: Lab-Managed CA for Verified SOC Stack TLS Retain with 055 Keep verified SOC TLS and CA lifecycle; do not regress to global insecure verification.
ADR-035: Adopt RAES SDL as APTL's Scenario Authoring Surface Clarify with 054/056 RAES adoption survives migration; existing realization supersession remains historical.
ADR-036: Snapshot Endpoint Registry Boundary Clarify with 054 Keep generic snapshot endpoint mechanism; move named TechVault endpoint knowledge.
ADR-037: Docker Compose Backend Cohesion Clarify with 054/055 Keep one cohesive backend, replacing implicit shared mixin state at touched boundaries.
ADR-038: Documentation Style Lint and Published Docs Site Retain with 058 Keep prose/build gates; navigation and claims must match released qualified profiles.
ADR-039: Web Control Plane Authentication and Loopback Exposure Retain with 055 Keep loopback/authentication/CSRF/ticket protections; optional operator UI remains powerful.
ADR-040: Terminal SSH Host-Key Verification Boundary Retain Preserve pinned SSH host identity and failure behavior.
ADR-041: Kali Capture Sidecar Ownership Boundary Retain historical amendment Keep sidecar capture ownership; ADR-042 already refines PTY authenticity.
ADR-042: Sidecar-Owned PTY Master for Kali Transcript Authenticity Retain with 057 Keep independent PTY master; capture admission/loss must invalidate unsupported evidence claims.
ADR-043: Suricata Runtime Config Ownership Boundary Retain Preserve generated/runtime ownership and avoid source-tree mutation by containers.
ADR-044: RAES-Aligned Run Reproducibility Record Clarify with 056/058 Keep reproducibility identities while separating declaration, native proof and scientific interpretation.
ADR-045: Ephemeral Lifecycle Policy Enforcement Clarify with 055 Require owned residual cleanup and crash recovery for every promised lifecycle state.
ADR-046: Dynamic RAES Scenario Realization Clarify with 056 Dynamic realization must match exact admitted concerns; preserve ADR-048/051 history.
ADR-047: RAES Experiment Admission and Trial-Plan Boundary Clarify with 054/056 Keep portable admission and safe bindings; research campaign policy is optional.
ADR-048: APTL Image-Free, Placement-Based Realization Envelope Retain existing partial supersession; clarify 056 ADR-051 permits component routes. Do not restore an image-free-only dogma or ignore exact OS requirements.
ADR-049: Sealed, Disposable Lab Appliance Delivery Boundary Propose narrow partial supersession by 055 Ordinary solo Docker is supported with disclosed limits; stronger sealed participant seat remains opt-in and separately qualified.
ADR-050: Terminal Attempt Archival And Atomic Seal Boundary Retain with 056/058 Keep atomic attempt sealing, terminal-state truth and explicit incomplete evidence.
ADR-051: Component-Level RAES Realization Clarify with 055/056 Keep component-level realization, add authority intersection and scenario-led qualification for all exact claims.
ADR-052: Configured Participant Credential Sourcing Keep proposed; coordinate 055/057 #856 still owns researched configured participant credential sourcing; copying a static value is not revocable delegation.
ADR-053: Pack-Backend Deployment-Serving Interaction Seam Retain with 054/055 Keep installed inert serving-data seam small; entry-point installation grants executable host trust.