audit-core/tests/test_layer_conformance.py
tegwick 4c940d49ae
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Operate scheduled chain-head attestation (AUDIT-WP-0009-T12)
Apply the separate attestor identity, named-ConfigMap RBAC, attest
egress and daily CronJob. Bootstrap an empty chain-head ConfigMap
only because it was absent; drop the placeholder from the apply path
so a later apply cannot overwrite a live head. One-shot job published
a 59-event attestation; mounted readback and receiver write-denial
passed. Offsite copy stays the operator path.

Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
2026-09-15 21:18:17 +02:00

102 lines
3.9 KiB
Python

"""AUDIT-WP-0009-T10. Make the §5 conformance check total rather than vacuous.
`layer.yaml` declares `tooling_contacts: []`, which is true under §5 as
written — audit-core is an Engine and holds no key-cape or OpenBao client. The
companion asks that uncatalogued infrastructure be listed anyway, and a list
nobody checks decays into a list nobody updates. These tests make the claim of
totality mechanical.
"""
from pathlib import Path
import pytest
yaml = pytest.importorskip("yaml")
ROOT = Path(__file__).parents[1]
LAYER = yaml.safe_load((ROOT / "layer.yaml").read_text())
def _listed() -> set[str]:
return {row["id"] for row in LAYER.get("uncatalogued_infrastructure", [])}
def test_the_declaration_states_the_layer_and_role():
assert LAYER["layer"] == "engine"
assert LAYER["role"] == "evidence"
assert LAYER["decision_surfaces_exposed"] == "none"
# §9.4, normative and permanent.
assert LAYER["approval_validity_query"] == "forbidden"
def test_the_evidence_bound_never_claims_occurrence():
bound = LAYER["evidence_bound"]
does_not = " ".join(bound["does_not_prove"]).lower()
assert "ever sent" in does_not
assert "non-occurrence" in does_not
proves = " ".join(bound["proves"]).lower()
# The archive's claim is about records it holds, never about the world.
assert "altered" in proves and "truncated" in proves
assert set(bound["not_claimed"]) >= {"WORM", "object-lock", "archival-custody"}
def test_every_infrastructure_contact_is_listed():
"""The totality claim, checked rather than asserted.
Each probe below names a contact that exists in `deploy/`. When a new one
appears, this fails and the list gets a row — which is the whole point of
the companion's carve-out being total.
"""
listed = _listed()
assert "platform-pg" in listed
assert "state-hub" in listed
assert "kube-apiserver" in listed
assert "forgejo.coulomb.social" in listed
def test_a_new_egress_destination_must_appear_in_the_declaration():
"""Derived from the manifests, so drift fails here rather than at review."""
policies = (ROOT / "deploy" / "networkpolicies.yaml").read_text()
# Namespaces audit-core is permitted to egress to, by name.
for namespace, expected in [("databases", "platform-pg"), ("kube-system", None)]:
assert f"kubernetes.io/metadata.name: {namespace}" in policies
if expected:
assert expected in _listed()
# The attest job's API-server reach is real infrastructure and is declared.
assert "port: 6443" in policies
assert "kube-apiserver" in _listed()
def test_the_registry_pinned_in_deploy_is_declared():
manifests = "".join(
path.read_text() for path in (ROOT / "deploy").glob("*.yaml")
)
for row in LAYER["uncatalogued_infrastructure"]:
if row["id"] == "forgejo.coulomb.social":
break
else:
pytest.fail("registry not declared")
assert "forgejo.coulomb.social" in manifests
# Pinned by digest, never by tag: a mutable tag makes the registry able to
# change what runs without any change here.
images = [
line.strip() for line in manifests.splitlines()
if line.strip().startswith("image:")
]
assert images
assert all("@sha256:" in image for image in images)
assert not any(":latest" in image for image in images)
def test_the_receiver_has_no_api_server_egress():
"""The separation T02 depends on, asserted rather than assumed."""
documents = (ROOT / "deploy" / "networkpolicies.yaml").read_text().split("\n---\n")
receiver = next(d for d in documents if "name: audit-core-egress" in d)
assert "component: receiver" in receiver
assert "6443" not in receiver
attest = next(d for d in documents if "name: audit-core-attest-egress" in d)
assert "component: attest" in attest
assert "6443" in attest
assert "443" in attest
assert "6443" not in receiver
assert "443" not in receiver