Protect digest-pinned packages and refuse partial-inventory pruning
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
parent
3f834b0556
commit
743def17be
5 changed files with 174 additions and 11 deletions
51
docs/activity-core-release-admission.md
Normal file
51
docs/activity-core-release-admission.md
Normal file
|
|
@ -0,0 +1,51 @@
|
|||
# Activity-core unattended release admission
|
||||
|
||||
Owner: ACTIVITY-WP-0041-T03, with RPF-WP-0048-T02 for platform activation.
|
||||
Status: proposed contract; no credential minted and no automatic sync enabled.
|
||||
The user authorized implementation; these are enforcement requirements, not a
|
||||
request to reapprove the existing adoption.
|
||||
|
||||
## Required enforcement
|
||||
|
||||
Use a dedicated non-admin service principal. Separate producer and reviewer
|
||||
identities. Public source reads need no repository credential. A general repository
|
||||
write PAT cannot enforce image-only changes by itself: the executor must validate
|
||||
the exact before/after commits and authenticated receipts before writing, while
|
||||
protected branches and required checks prevent bypass. Restrict its repository
|
||||
membership to the release repository and its ArgoCD role to get/sync the single
|
||||
`activity-core/activity-core` application. No root sync, application spec updates,
|
||||
project updates, exec, prune, overrides, secrets or other applications.
|
||||
|
||||
The present parent Application pins the child's source revision in the platform
|
||||
repository. Therefore an app-only ArgoCD sync grant alone cannot perform durable
|
||||
promotion. Implement a reviewed broker for the single child revision field or a
|
||||
separately reviewed source-tracking design; do not grant the executor unrestricted
|
||||
platform repository writes to work around this boundary.
|
||||
|
||||
Keep credentials in OpenBao with the existing delivery subsystem; never in Git,
|
||||
receipts or prompts. Publish the exact subject, repository/branch/path scope,
|
||||
ArgoCD resource, TTL, revocation and negative-test evidence before admission.
|
||||
The warden routing catalog currently has no ready release-specific lane. Do not
|
||||
reuse source-read or package-admin credentials as deployment authority.
|
||||
|
||||
## Receipt and failure requirements
|
||||
|
||||
Authenticate CI completion against the expected Forgejo repository and full commit;
|
||||
require the image-build and smoke checks. Bind the independently authenticated
|
||||
reviewer result to that same commit and actual image digest. Fetch current ArgoCD
|
||||
health from its authority, with bounded staleness; preserve observations proving
|
||||
at least 24 healthy hours. Producer-provided booleans are insufficient.
|
||||
|
||||
Before promotion retain the exact prior source revision and protect both live and
|
||||
rollback images in the additive registry inventory. Serialize releases, compare
|
||||
the current revision before writing, persist state, and recover idempotently after
|
||||
restart. Reconcile through ArgoCD without pruning. Check deployment readiness,
|
||||
report sink and schedule invariants. On timeout/failure revert the pinned revision
|
||||
through the same Git path, reconcile, verify recovery, and stop further promotion
|
||||
if recovery fails. Store sanitized receipts in the activity-core/State Hub run.
|
||||
|
||||
Acceptance must include denied out-of-scope mutation, stale/mismatched/forged
|
||||
receipts, concurrent release, restart, failed health and successful rollback.
|
||||
Run destructive failure fixtures in an isolated environment; production must not
|
||||
be intentionally broken to manufacture proof. Admit only after tests and the
|
||||
observation gate pass. Access, budget or scope expansion stays a monthly decision.
|
||||
Loading…
Add table
Add a link
Reference in a new issue