Eyedbase Architecture & Identity Foundation
Eyedbase serves as the authoritative Centralized Identity Provider and Zero-Trust Authentication Enclave for the SpreadKnowledge AI stack portfolio. It is designed to eliminate passwords, prevent credential harvesting, and provide deterministic machine-to-machine (M2M) authorization across autonomous agent swarms.
Core Architectural Commitments
1. Asymmetric Cryptography: Eyedbase strictly rejects passwords. Every human credential uses FIDO2 WebAuthn asymmetric public-key cryptography bound to hardware security enclaves.
2. Dual-Write Compatibility (DFG-001): During the enterprise transition from legacy architectures to the unified SPA shell, authentication helpers dual-write to both window.__WIDGET_CONFIG__ and window.__SK_CONFIG__.
3. Fail-Closed Session Leases: Downstream APIs enforce 300-second maximum token lifetimes. Revoked credentials fail closed immediately.
4. Zero TrueNAS Storage (TNSB-001): All database backings run on dedicated physical ESXi NVMe block storage (LINDEBPSGPRD501 (172.16.31.181:5432)). TrueNAS and QNAP appliances are 100% prohibited.