Skip to content

Add firewall hit counter evidence gates#1671

Open
yanziwei wants to merge 1 commit into
UnitOneAI:mainfrom
yanziwei:improve/firewall-hit-counter-evidence
Open

Add firewall hit counter evidence gates#1671
yanziwei wants to merge 1 commit into
UnitOneAI:mainfrom
yanziwei:improve/firewall-hit-counter-evidence

Conversation

@yanziwei
Copy link
Copy Markdown

@yanziwei yanziwei commented Jun 7, 2026

Summary

  • add hit-counter freshness evidence requirements to firewall-review unused rule detection
  • require counter baseline, uptime/policy install, failover/reset history, flow-log cross-checks, and owner/ticket evidence
  • add an Unused Rule Evidence output table with evidence quality and disposition fields

Validation

  • git diff --check
  • Markdown fence-balance check
  • marker checks for hit-counter, Counter Baseline, Unused Rule Evidence, and failover/reset history

Notes

This keeps the change scoped to the existing unused-rule section. It does not overlap with broader effective-rule or egress-filtering work.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant