Implement signed release admission and durable rollback coordinator
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 3s
Build and Publish Container Image / build-and-push (push) Successful in 1m32s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
tegwick 2026-09-27 16:39:29 +02:00
parent a122b1a5a4
commit 22935955cc
10 changed files with 810 additions and 59 deletions

View file

@ -150,3 +150,22 @@ scoped source/sync broker: ArgoCD Core offers no API-server token lane, and a
Kubernetes Application patch grant cannot restrict fields. Concrete enforcement
contract is platform docs/activity-core-release-admission.md. Authenticated
receipts and automatic rollback proof remain required; no broad token is admitted.
## Broker core and isolated recovery proof — 2026-09-27
Implemented Ed25519 receipt verification with trusted role/principal bindings,
independent producer/reviewer keys, exact commit/manifest/image bindings, mandatory
CI contexts, freshness, 24-hour signed observation and live/rollback retention
coverage. Shared image policy remains the admission gate. Fixed mutation builders
restrict platform edits to the child revision and ArgoCD operations to selective
root/child sync without pruning. SQLite serializes releases and records signed
receipts plus transitions; publication intent precedes external calls. Isolated
fixtures prove restart, lost publication responses, failed-health rollback and
failed rollback holding the release lock. No production authority is inferred.
See docs/release-broker.md for implemented behavior and exact remaining work:
authenticated Git/ArgoCD adapter, custody/admission, real attestation issuers and
continuous observer, Temporal dispatch and isolated transport/rollback proof.
The broker is disabled by default and not connected to live credentials or a
production schedule. Current deployed revision and healthy-soak clock are unchanged.
T03 stays progress; the full unattended acceptance is not complete.