Parent: #130
Map Kuadrant connection.* (downstream TLS/mTLS state) onto PPE. Full attribute-by-attribute analysis: 00133 mapping doc (PR #131), section "Connection attributes".
Approach: alias connection.mtls to caller_workload.attestor == "mtls" (a verified client certificate — not plain server-auth TLS); raw TLS state only bridgeable if the host injects it; certificates/digests have no PPE equivalent.
Acceptance (tiered testing — doc "Testing strategy"):
Parent: #130
Map Kuadrant
connection.*(downstream TLS/mTLS state) onto PPE. Full attribute-by-attribute analysis: 00133 mapping doc (PR #131), section "Connection attributes".Approach: alias
connection.mtlstocaller_workload.attestor == "mtls"(a verified client certificate — not plain server-auth TLS); raw TLS state only bridgeable if the host injects it; certificates/digests have no PPE equivalent.Acceptance (tiered testing — doc "Testing strategy"):
connection.mtlsresolves viaattestor == "mtls", not conflated with plain TLS.connection.*attribute, Gap rows (SNI,tls_version,*_certificate, digest) recorded as expected divergence.ppe-pdp-diffcases cover the boolean-vs-attestor-string model and the missing-data fail-open case for unmapped TLS fields.