Protect digest-pinned packages and refuse partial-inventory pruning
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
codex 2026-09-27 16:00:51 +02:00
parent 3f834b0556
commit 743def17be
5 changed files with 174 additions and 11 deletions

View file

@ -0,0 +1,51 @@
# Activity-core unattended release admission
Owner: ACTIVITY-WP-0041-T03, with RPF-WP-0048-T02 for platform activation.
Status: proposed contract; no credential minted and no automatic sync enabled.
The user authorized implementation; these are enforcement requirements, not a
request to reapprove the existing adoption.
## Required enforcement
Use a dedicated non-admin service principal. Separate producer and reviewer
identities. Public source reads need no repository credential. A general repository
write PAT cannot enforce image-only changes by itself: the executor must validate
the exact before/after commits and authenticated receipts before writing, while
protected branches and required checks prevent bypass. Restrict its repository
membership to the release repository and its ArgoCD role to get/sync the single
`activity-core/activity-core` application. No root sync, application spec updates,
project updates, exec, prune, overrides, secrets or other applications.
The present parent Application pins the child's source revision in the platform
repository. Therefore an app-only ArgoCD sync grant alone cannot perform durable
promotion. Implement a reviewed broker for the single child revision field or a
separately reviewed source-tracking design; do not grant the executor unrestricted
platform repository writes to work around this boundary.
Keep credentials in OpenBao with the existing delivery subsystem; never in Git,
receipts or prompts. Publish the exact subject, repository/branch/path scope,
ArgoCD resource, TTL, revocation and negative-test evidence before admission.
The warden routing catalog currently has no ready release-specific lane. Do not
reuse source-read or package-admin credentials as deployment authority.
## Receipt and failure requirements
Authenticate CI completion against the expected Forgejo repository and full commit;
require the image-build and smoke checks. Bind the independently authenticated
reviewer result to that same commit and actual image digest. Fetch current ArgoCD
health from its authority, with bounded staleness; preserve observations proving
at least 24 healthy hours. Producer-provided booleans are insufficient.
Before promotion retain the exact prior source revision and protect both live and
rollback images in the additive registry inventory. Serialize releases, compare
the current revision before writing, persist state, and recover idempotently after
restart. Reconcile through ArgoCD without pruning. Check deployment readiness,
report sink and schedule invariants. On timeout/failure revert the pinned revision
through the same Git path, reconcile, verify recovery, and stop further promotion
if recovery fails. Store sanitized receipts in the activity-core/State Hub run.
Acceptance must include denied out-of-scope mutation, stale/mismatched/forged
receipts, concurrent release, restart, failed health and successful rollback.
Run destructive failure fixtures in an isolated environment; production must not
be intentionally broken to manufacture proof. Admit only after tests and the
observation gate pass. Access, budget or scope expansion stays a monthly decision.