QHx MLS Label Format Definition
Introduction
Section titled “Introduction”Kubernetes allows string key-value pairs (labels and annotations) to be associated with Kubernetes resources. This specification defines a set of labels which can be used to classify arbitrary Kubernetes resources in terms for information classification and compartmentalisation purposes as part of a Multi-Level Security (MLS) architecture.
Kubernetes labels are string key-value pairs which are indexed and searchable. Kubernetes annotations also string key-value pairs, but are not indexed and searchable.
This specification uses Kubernetes labels rather than annotations, enabling MLS data to be used to query for Kubernetes resources.
Specification
Section titled “Specification”All labels defined in this document have key names of the form:
mls.qhx.dev/<name>
The following Kubernetes labels are defined:
| Key | Summary |
|---|---|
| mls.qhx.dev/level | Classification Level |
| mls.qhx.dev/rel | Releasability |
| mls.qhx.dev/compartment | Compartment |
Labels
Section titled “Labels”The mls.qhx.dev/level label denotes an information security classification
level. The value is a level descriptor. A level descriptor is a string which
has the following structure (in ABNF):
LEVEL_DESCRIPTOR = CLASSIFICATION_NAMESPACE ":" CLASSIFICATION_LEVEL
CLASSIFICATION_NAMESPACE = NATIONAL_CLASSIFICATION_NAMESPACE / NON_NATIONAL_CLASSIFICATION_NAMESPACENATIONAL_CLASSIFICATION_NAMESPACE = 2ALPHA # ISO 3166-2 country code (lowercase)NON_NATIONAL_CLASSIFICATION_NAMESPACE = NSCHAR / 3*NSCHAR # 2-character namespaces reserved for ISO 3166-2
NSCHAR = %61-7A / DIGIT / "-" / "." # Lowercase only
CLASSIFICATION_LEVEL = TOKENTOKEN = 1*TCHARTCHAR = NSCHAR / ":"The meaning of a level descriptor is determined by the classification namespace it begins with. Classification namespaces are either national or non-national. If a classification scheme is used solely or primarily by a single nation-state, a national classification namespace can be used to designate a classification within that nation-state’s framework. A non-national classification namespace is more suitable for a classification scheme shared between multiple nation-states or used by non-governmental entities.
Reference classification namespaces are defined in Annex A.
The mls.qhx.dev/rel label defines an information security releasability
designation. The value is a releasability descriptor. A releasability
descriptor is a string which has the following structure (in ABNF):
REL_DESCRIPTOR = [*(REL_ENTITY_REF "," [SP]) REL_ENTITY_REF]REL_ENTITY_REF = REL_ENTITY_NAMESPACE_REF / REL_ENTITY_SPECIFIC_REFREL_ENTITY_NAMESPACE_REF = CLASSIFICATION_NAMESPACEREL_ENTITY_SPECIFIC_REF = CLASSIFICATION_NAMESPACE ":" TOKENA releasability label is a comma-separated list of entity references. An entity reference can either be a reference to an entire namespace or to a subselector designating some subentity within it. The structure and meaning of subselectors, and the meaning of a reference to an entire namespace, is defined by the specification for that namespace.
compartment
Section titled “compartment”The mls.qhx.dev/compartment label denotes an information security compartment.
The value is a compartment descriptor. A compartment descriptor is a string
which has the following structure (in ABNF):
COMPARTMENT_DESCRIPTOR = CLASSIFICATION_NAMESPACE ":" COMPARTMENT_NAMECOMPARTMENT_NAME = TOKENThe namespace labelling scheme is shared with classification levels.
Annex A: Reference Classification Namespaces
Section titled “Annex A: Reference Classification Namespaces”This annex defines the semantics of specific classification namespaces.
National Classification Namespace: us
Section titled “National Classification Namespace: us”The us namespace has the following syntax (in ABNF) under it:
LEVEL_DESCRIPTOR = "us" ":" US_CLASSIFICATION_TOKEN [":" SUBCLASSIFICATION]
US_CLASSIFICATION_TOKEN = UNCLASSIFIED / CONFIDENTIAL / SECRET / TOP_SECRET / TOP_SECRET_SCI UNCLASSIFIED = "u"
CONFIDENTIAL = "c" SECRET = "s" TOP_SECRET = "ts" TOP_SECRET_SCI = "ts-sci"
SUBCLASSIFICATION = TOKEN ## Reserved for future useA reference to the us namespace as a whole in a releasability descriptor is
considered a reference to the U.S. as a whole. No subselectors for
releasability descriptors are currently defined.
A level descriptor may have more fine grained structure beneath the top level coarse classifications. No subclassifications are currently defined and this syntax is reserved for future use. Implementations MUST reject labels using such syntax.
Appendix B: Examples
Section titled “Appendix B: Examples”The following shows a YAML fragment showing how the descriptor formats defined above may be used in a Kubernetes labelling context.
labels: qhx.dev/level: "us:s" # US SECRET qhx.dev/rel: "us,uk,ca,au,nz" # Releasability to FVEY qhx.dev/compartment: "us:quantum" # US Compartment "QUANTUM"