Skip to content

spike: Analyze DXP IAM/OpenFGA event gaps and eventing boundaries #367

Description

@hellsontime

Problem

DXP IAM publishes enriched CloudEvents to GCP Pub/Sub. OpenFGA changes outside
the instrumented IAM workflows may not produce events and are reported to reach
Hyperspace only through periodic reconciliation.

The available inputs are the DXP IAM source, a DXP eventing overview and
stakeholder notes. We do not have access to the Hyperspace implementation or
the private golang-dxp/eventing source, so behavior on those sides cannot be
verified in this spike.

Questions

  • Which OpenFGA write paths in the available IAM source do not produce events?
  • Where should event generation and IAM data enrichment occur?
  • Which tenant, entity and OIDC identity fields does Hyperspace require?
  • Where is the current IAM implementation coupled to DXP and GCP?
  • Which parts can form a reusable Platform Mesh boundary, and which conclusions
    require confirmation from the Hyperspace or golang-dxp/eventing owners?

Result

Parent epic: #323

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

Status
Blocked/Waiting
Status
Todo

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions