feat(policy): netkingdom maturity-gated publication-scope policy
Token scope is now bound to package maturity, gated on netkingdom's own maturity: - maturity-build -> gitea-wide, maturity-test -> org-wide, maturity-prod -> repo-scoped (scope narrows as stakes rise; broad tokens only for low-stakes build artifacts) - the graduated table is DORMANT until netkingdom reaches production grade; until then every lane clamps to repo-scope, injected as NPM_AUTH_TOKEN (fail-safe) - token env-var name signals blast radius: NPM_AUTH_TOKEN (repo default), NPM_AUTH_COULOMB_TOKEN (org), NPM_AUTH_GITEA_TOKEN (gitea), NPM_AUTH_WHYNOT_TOKEN (npm scope, defined but unused), NPM_AUTH_WHYNOTDESIGN (explicit repo) netkingdom is at maturity-build today, so whynot-design resolves to repo-scope / NPM_AUTH_TOKEN. Flip netkingdom_maturity to maturity-prod to activate graduation. - policies/netkingdom-publication-scope.yaml: the policy data + gate - publication_policy.py: load + resolve (clamp/active, env naming, override) - exec delivery injects under the resolved env-var name (was fixed SE_NPM_TOKEN) - catalog lane carries delivery_config.npm.maturity - new CLI: `secrets-engine policy publication <lane>` - docs/publication-scope-policy.md; tests for clamp, graduation, naming, override Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
parent
f87f4e5e4d
commit
5b48033bce
11 changed files with 394 additions and 9 deletions
|
|
@ -83,8 +83,11 @@ chmod +x "$WORK/npm-wrapped.sh"
|
|||
secrets-engine exec --catalog whynot-design-npm-publish -- "$WORK/npm-wrapped.sh"
|
||||
|
||||
echo
|
||||
echo "### policy binding: which scope/token-env did the lane resolve to?"
|
||||
secrets-engine policy publication whynot-design-npm-publish | sed 's/^/ /'
|
||||
|
||||
echo "### confirm parent shell never held the token"
|
||||
echo " SE_NPM_TOKEN in parent: '${SE_NPM_TOKEN:-<unset>}'"
|
||||
echo " NPM_AUTH_TOKEN in parent: '${NPM_AUTH_TOKEN:-<unset>}'"
|
||||
echo " NPM_CONFIG_USERCONFIG in parent: '${NPM_CONFIG_USERCONFIG:-<unset>}'"
|
||||
echo
|
||||
echo "### DONE — npm publish (dry-run) ran with the token injected by secrets-engine."
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue