Parent: #130
Map Kuadrant source.* (downstream client network + mesh identity) onto PPE. Full attribute-by-attribute analysis: 00133 mapping doc (PR #131), section "Source attributes".
Approach: alias source.principal to caller_workload.spiffe_id once the host populates WorkloadIdentity from peer_identity; bridge client IP via custom.*; mesh fields have no PPE equivalent.
Acceptance (tiered testing — doc "Testing strategy"):
Parent: #130
Map Kuadrant
source.*(downstream client network + mesh identity) onto PPE. Full attribute-by-attribute analysis: 00133 mapping doc (PR #131), section "Source attributes".Approach: alias
source.principaltocaller_workload.spiffe_idonce the host populatesWorkloadIdentityfrompeer_identity; bridge client IP viacustom.*; mesh fields have no PPE equivalent.Acceptance (tiered testing — doc "Testing strategy"):
source.principalresolves to the SPIFFE id when peer identity is populated.source.*attribute, Gap rows (port,service,labels,certificate) recorded as expected divergence.ppe-pdp-diffcases cover the SPIFFE-vs-raw-principal model difference and the missing-data fail-open case for unmappedsource.*.