Problem
DXP IAM publishes enriched CloudEvents to GCP Pub/Sub. OpenFGA changes outside
the instrumented IAM workflows may not produce events and are reported to reach
Hyperspace only through periodic reconciliation.
The available inputs are the DXP IAM source, a DXP eventing overview and
stakeholder notes. We do not have access to the Hyperspace implementation or
the private golang-dxp/eventing source, so behavior on those sides cannot be
verified in this spike.
Questions
- Which OpenFGA write paths in the available IAM source do not produce events?
- Where should event generation and IAM data enrichment occur?
- Which tenant, entity and OIDC identity fields does Hyperspace require?
- Where is the current IAM implementation coupled to DXP and GCP?
- Which parts can form a reusable Platform Mesh boundary, and which conclusions
require confirmation from the Hyperspace or golang-dxp/eventing owners?
Result
Parent epic: #323
Problem
DXP IAM publishes enriched CloudEvents to GCP Pub/Sub. OpenFGA changes outside
the instrumented IAM workflows may not produce events and are reported to reach
Hyperspace only through periodic reconciliation.
The available inputs are the DXP IAM source, a DXP eventing overview and
stakeholder notes. We do not have access to the Hyperspace implementation or
the private
golang-dxp/eventingsource, so behavior on those sides cannot beverified in this spike.
Questions
require confirmation from the Hyperspace or
golang-dxp/eventingowners?Result
Parent epic: #323