Claude/phase d3 mtls handshake and header rewrite scenarios - #81
Merged
hyperpolymath merged 6 commits intoAug 11, 2026
Merged
Conversation
Phase D-2 (PR #14) left two cost surfaces folded into the "exact route allow (proxy 200)" scenario: the Phase A contract-header construction in Proxy.build_backend_headers/1, and the transport-level mTLS handshake. A baseline collected from D-2 would have attributed both to the proxy-200 number, so a regression in either would only show up as an aggregate slowdown -- the comparator couldn't tell us which leg moved. Phase D-3 (this change, hyperpolymath/standards#99 sub-deliverable) pulls each into its own Benchee scenario so D-4 baseline collection attributes them independently: * "trust-header rewrite (Proxy.build_backend_headers)" - direct call to a new @doc false Proxy.__benchmark_build_backend_headers__/1 seam over the existing private build_backend_headers/1. No policy lookup, no Gateway.call/2 pipeline, no network I/O. Isolates the cost surface the Phase A contract invariant lives on: the gateway sets X-Trust-Level / X-Request-ID as authoritative values that shadow any client-supplied header, and the cost of building that final header map is what this scenario measures. * "mTLS handshake (test CA)" - raw :ssl acceptor + :ssl.connect/4 + immediate :ssl.close/1, using a test CA chain generated in-memory at bench startup via :public_key.pkix_test_data/1. Each iteration is one fresh handshake (verify_peer + cert chain validation + key exchange) closed before any application bytes are exchanged. Bounds the connection-spike SLO Phase E rollout has to budget for. Why in-memory rather than reusing the committed Phase B fixture in test/fixtures/mtls/: the fixture ships only *.crt files -- *.key is gitignored at the repo root. Reusing the committed certs would require committing the matching keys (or carving a fixture exception in .gitignore), which the estate security posture prefers we don't do for a bench fixture. The chain shape (test CA -> server peer + test CA -> client peer, verify_peer enforced) is identical to Phase B's fixture; only the key material differs, and it never touches disk. bench/baseline.json gains the two new scenario keys (both TODO; the _status stays "scaffold-placeholder" because D-3 still doesn't collect real numbers -- D-4 does, via the `perf: rebaseline` ritual in docs/perf-contract.md). _schema_version bumps 0.1.0 -> 0.2.0 to signal the shape change to anyone diffing the file or running compare.exs against an older results.json. docs/perf-contract.md moves both items from "Out of scope" to in scope, adds them to the scenarios table and the targets table, and re-anchors the remaining out-of-scope list on D-4 (baseline collection), Phase E (historical dashboard), and a possible follow-up amortised-handshake scenario if D-4 numbers show the proxy-200 + handshake bracket is loose. Phase D-3 is the last harness-shape change before D-4 collection: scenario keys are now stable, the comparator's per-scenario diff stays correctly keyed across the flip from scaffold to active. Unblocks: standards#99 D-4 (real baseline collection + gate arming) and, downstream, the remaining items in section 1.1 of boj-server's docs/integration/hcg-tier2-rollout-runbook.md. Refs hyperpolymath/standards#91 Refs hyperpolymath/standards#99 Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
…over-keep-alive)
Closes the bracket scenarios 3 + 5 left loose: per-iteration cost is
(handshake + N * request) / N which approximates the per-request cost
the Phase E rollout sees once the handshake is amortised across a
kept-alive pool.
Adds:
- bench/gateway_latency.exs: scenario 6
"mTLS amortised (test CA, N requests over kept-alive)" plus a
dedicated kept-alive acceptor on port 19_879 running an echo loop
(separate listener from scenario 5 so its close-on-handshake shape
doesn't kill the kept-alive connection). N=16; payload is a tiny
8-byte ASCII frame.
- bench/baseline.json: new scenario key with TODO placeholders;
_schema_version bumped to 0.3.0-scaffold.
- docs/perf-contract.md: scenarios table + targets table now list six
scenarios; the previously deferred amortised follow-up is moved
out of "Out of scope" into in-scope.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…write-scenarios Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
hyperpolymath
deleted the
claude/phase-d3-mtls-handshake-and-header-rewrite-scenarios
branch
August 11, 2026 23:28
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #
Type of change
How has this been verified?
Checklist
git commit -S).SPDX-License-Identifier(code/configMPL-2.0,prose
CC-BY-SA-4.0); I did not relicense existing files.Notes for reviewers
Summary by Gitar
trust-header rewritescenario isolatingProxy.build_backend_headers/1overheadmTLS handshakeandmTLS amortised(N=16 kept-alive) scenarios using an in-memory test CA chainProxy.__benchmark_build_backend_headers__/1as a@doc falsehook for latency measurementdocs/perf-contract.mdto Phase D-3 status, reflecting the six total benchmark scenariosThis will update automatically on new commits.