Implement scoped Git Argo transport and gap-sensitive health observer
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Build and Publish Container Image / build-and-push (push) Failing after 1m22s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
tegwick 2026-09-27 17:03:06 +02:00
parent 22935955cc
commit 0ae5e84e7b
6 changed files with 512 additions and 11 deletions

View file

@ -169,3 +169,25 @@ continuous observer, Temporal dispatch and isolated transport/rollback proof.
The broker is disabled by default and not connected to live credentials or a
production schedule. Current deployed revision and healthy-soak clock are unchanged.
T03 stays progress; the full unattended acceptance is not complete.
## Transport adapter and sampled health observer — 2026-09-27
Implemented the fixed Git/ArgoCD adapter: exact source/hash verification, static
Kustomization restriction, one-field child revision commits, non-force publication,
remote-tip recovery after lost responses, cluster UID binding, resourceVersion/spec
CAS, selective sync and deployment health checks. A bounded report/schedule probe
remains a required trusted integration. Implemented persistent health sampling with
90-second maximum gaps, revision/failure reset, clock-regression invalidation and
24-hour attestation refusal unless the complete sample interval exists.
Tests use disposable real Git repositories and simulated Kubernetes responses.
The broker completes failed-health rollback through the real Git adapter; tests
cover lost push responses, concurrent publication, source tampering, wrong cluster,
foreign Argo operations and observer restart/gaps. Latest focused suite: 48 passed;
full affected suite before the final cluster-binding test: 75 passed. CI includes
all these tests. No production credentials or activation were introduced.
T03 remains progress for admitted identity/custody, authenticated isolated Kubernetes
verification, real build/review/retention issuers, production invariant probes,
Temporal observer/dispatcher registration and evidence sinks. The implemented
observer cannot retroactively assert the earlier soak interval. See docs/release-broker.md.