Skip to content

QHx MLS Label Format Definition

Kubernetes allows string key-value pairs (labels and annotations) to be associated with Kubernetes resources. This specification defines a set of labels which can be used to classify arbitrary Kubernetes resources in terms for information classification and compartmentalisation purposes as part of a Multi-Level Security (MLS) architecture.

Kubernetes labels are string key-value pairs which are indexed and searchable. Kubernetes annotations also string key-value pairs, but are not indexed and searchable.

This specification uses Kubernetes labels rather than annotations, enabling MLS data to be used to query for Kubernetes resources.

All labels defined in this document have key names of the form:

mls.qhx.dev/<name>

The following Kubernetes labels are defined:

KeySummary
mls.qhx.dev/levelClassification Level
mls.qhx.dev/relReleasability
mls.qhx.dev/compartmentCompartment

The mls.qhx.dev/level label denotes an information security classification level. The value is a level descriptor. A level descriptor is a string which has the following structure (in ABNF):

LEVEL_DESCRIPTOR = CLASSIFICATION_NAMESPACE ":" CLASSIFICATION_LEVEL
CLASSIFICATION_NAMESPACE = NATIONAL_CLASSIFICATION_NAMESPACE / NON_NATIONAL_CLASSIFICATION_NAMESPACE
NATIONAL_CLASSIFICATION_NAMESPACE = 2ALPHA # ISO 3166-2 country code (lowercase)
NON_NATIONAL_CLASSIFICATION_NAMESPACE = NSCHAR / 3*NSCHAR # 2-character namespaces reserved for ISO 3166-2
NSCHAR = %61-7A / DIGIT / "-" / "." # Lowercase only
CLASSIFICATION_LEVEL = TOKEN
TOKEN = 1*TCHAR
TCHAR = NSCHAR / ":"

The meaning of a level descriptor is determined by the classification namespace it begins with. Classification namespaces are either national or non-national. If a classification scheme is used solely or primarily by a single nation-state, a national classification namespace can be used to designate a classification within that nation-state’s framework. A non-national classification namespace is more suitable for a classification scheme shared between multiple nation-states or used by non-governmental entities.

Reference classification namespaces are defined in Annex A.

The mls.qhx.dev/rel label defines an information security releasability designation. The value is a releasability descriptor. A releasability descriptor is a string which has the following structure (in ABNF):

REL_DESCRIPTOR = [*(REL_ENTITY_REF "," [SP]) REL_ENTITY_REF]
REL_ENTITY_REF = REL_ENTITY_NAMESPACE_REF / REL_ENTITY_SPECIFIC_REF
REL_ENTITY_NAMESPACE_REF = CLASSIFICATION_NAMESPACE
REL_ENTITY_SPECIFIC_REF = CLASSIFICATION_NAMESPACE ":" TOKEN

A releasability label is a comma-separated list of entity references. An entity reference can either be a reference to an entire namespace or to a subselector designating some subentity within it. The structure and meaning of subselectors, and the meaning of a reference to an entire namespace, is defined by the specification for that namespace.

The mls.qhx.dev/compartment label denotes an information security compartment. The value is a compartment descriptor. A compartment descriptor is a string which has the following structure (in ABNF):

COMPARTMENT_DESCRIPTOR = CLASSIFICATION_NAMESPACE ":" COMPARTMENT_NAME
COMPARTMENT_NAME = TOKEN

The namespace labelling scheme is shared with classification levels.

Annex A: Reference Classification Namespaces

Section titled “Annex A: Reference Classification Namespaces”

This annex defines the semantics of specific classification namespaces.

The us namespace has the following syntax (in ABNF) under it:

LEVEL_DESCRIPTOR = "us" ":" US_CLASSIFICATION_TOKEN [":" SUBCLASSIFICATION]
US_CLASSIFICATION_TOKEN = UNCLASSIFIED / CONFIDENTIAL / SECRET / TOP_SECRET / TOP_SECRET_SCI
UNCLASSIFIED = "u"
CONFIDENTIAL = "c"
SECRET = "s"
TOP_SECRET = "ts"
TOP_SECRET_SCI = "ts-sci"
SUBCLASSIFICATION = TOKEN ## Reserved for future use

A reference to the us namespace as a whole in a releasability descriptor is considered a reference to the U.S. as a whole. No subselectors for releasability descriptors are currently defined.

A level descriptor may have more fine grained structure beneath the top level coarse classifications. No subclassifications are currently defined and this syntax is reserved for future use. Implementations MUST reject labels using such syntax.

The following shows a YAML fragment showing how the descriptor formats defined above may be used in a Kubernetes labelling context.

labels:
qhx.dev/level: "us:s" # US SECRET
qhx.dev/rel: "us,uk,ca,au,nz" # Releasability to FVEY
qhx.dev/compartment: "us:quantum" # US Compartment "QUANTUM"