Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
3.1 KiB
Activity-core unattended release admission
Owner: ACTIVITY-WP-0041-T03, with RPF-WP-0048-T02 for platform activation. Status: proposed contract; no credential minted and no automatic sync enabled. The user authorized implementation; these are enforcement requirements, not a request to reapprove the existing adoption.
Required enforcement
Use a dedicated non-admin service principal. Separate producer and reviewer
identities. Public source reads need no repository credential. A general repository
write PAT cannot enforce image-only changes by itself: the executor must validate
the exact before/after commits and authenticated receipts before writing, while
protected branches and required checks prevent bypass. Restrict its repository
membership to the release repository and its ArgoCD role to get/sync the single
activity-core/activity-core application. No root sync, application spec updates,
project updates, exec, prune, overrides, secrets or other applications.
The present parent Application pins the child's source revision in the platform repository. Therefore an app-only ArgoCD sync grant alone cannot perform durable promotion. Implement a reviewed broker for the single child revision field or a separately reviewed source-tracking design; do not grant the executor unrestricted platform repository writes to work around this boundary.
Keep credentials in OpenBao with the existing delivery subsystem; never in Git, receipts or prompts. Publish the exact subject, repository/branch/path scope, ArgoCD resource, TTL, revocation and negative-test evidence before admission. The warden routing catalog currently has no ready release-specific lane. Do not reuse source-read or package-admin credentials as deployment authority.
Receipt and failure requirements
Authenticate CI completion against the expected Forgejo repository and full commit; require the image-build and smoke checks. Bind the independently authenticated reviewer result to that same commit and actual image digest. Fetch current ArgoCD health from its authority, with bounded staleness; preserve observations proving at least 24 healthy hours. Producer-provided booleans are insufficient.
Before promotion retain the exact prior source revision and protect both live and rollback images in the additive registry inventory. Serialize releases, compare the current revision before writing, persist state, and recover idempotently after restart. Reconcile through ArgoCD without pruning. Check deployment readiness, report sink and schedule invariants. On timeout/failure revert the pinned revision through the same Git path, reconcile, verify recovery, and stop further promotion if recovery fails. Store sanitized receipts in the activity-core/State Hub run.
Acceptance must include denied out-of-scope mutation, stale/mismatched/forged receipts, concurrent release, restart, failed health and successful rollback. Run destructive failure fixtures in an isolated environment; production must not be intentionally broken to manufacture proof. Admit only after tests and the observation gate pass. Access, budget or scope expansion stays a monthly decision.