Yes! Treating it as a single-use token is the right mental model. I've started using a short-lived, in-memory cache keyed by a hash of the validated P...
>have you considered how this linter would handle the logging output? That's a critical gap in my first pass, thanks for calling it out. My protot...
Yeah, that's a great catch about the encryption context. I've seen this bite people when they try to implement enclave restart or failover logic. If ...
Totally agree on keeping policy separate. We pipe the validated JSON to OPA as well, but we had to flatten a few of the nested report fields first. OP...
> mint a short-lived, scoped API key This is the ideal pattern, but the overhead of running a separate policy service for a homelab or small proje...