feat(policy): netkingdom maturity-gated publication-scope policy

Token scope is now bound to package maturity, gated on netkingdom's own maturity:
- maturity-build -> gitea-wide, maturity-test -> org-wide, maturity-prod -> repo-scoped
  (scope narrows as stakes rise; broad tokens only for low-stakes build artifacts)
- the graduated table is DORMANT until netkingdom reaches production grade; until
  then every lane clamps to repo-scope, injected as NPM_AUTH_TOKEN (fail-safe)
- token env-var name signals blast radius: NPM_AUTH_TOKEN (repo default),
  NPM_AUTH_COULOMB_TOKEN (org), NPM_AUTH_GITEA_TOKEN (gitea), NPM_AUTH_WHYNOT_TOKEN
  (npm scope, defined but unused), NPM_AUTH_WHYNOTDESIGN (explicit repo)

netkingdom is at maturity-build today, so whynot-design resolves to repo-scope /
NPM_AUTH_TOKEN. Flip netkingdom_maturity to maturity-prod to activate graduation.

- policies/netkingdom-publication-scope.yaml: the policy data + gate
- publication_policy.py: load + resolve (clamp/active, env naming, override)
- exec delivery injects under the resolved env-var name (was fixed SE_NPM_TOKEN)
- catalog lane carries delivery_config.npm.maturity
- new CLI: `secrets-engine policy publication <lane>`
- docs/publication-scope-policy.md; tests for clamp, graduation, naming, override

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-06-28 13:14:46 +02:00
parent f87f4e5e4d
commit 5b48033bce
11 changed files with 394 additions and 9 deletions

View file

@ -12,11 +12,11 @@ def test_registry_authkey_strips_scheme_and_trails_slash():
def test_npm_userconfig_writes_registry_and_token_ref_not_value():
registry = "https://gitea.coulomb.social/api/packages/coulomb/npm/"
with _npm_userconfig(registry, "@whynot") as path:
with _npm_userconfig(registry, "@whynot", "NPM_AUTH_TOKEN") as path:
body = path.read_text()
assert f"@whynot:registry={registry}" in body
# token is referenced via env expansion, never written literally
assert "${SE_NPM_TOKEN}" in body
assert "${NPM_AUTH_TOKEN}" in body
assert "//gitea.coulomb.social/api/packages/coulomb/npm/:_authToken" in body
# file is mode 0600
assert (path.stat().st_mode & 0o077) == 0

View file

@ -0,0 +1,54 @@
from dataclasses import replace
import pytest
from secrets_engine.config import repo_root
from secrets_engine.errors import PolicyGuardError
from secrets_engine.publication_policy import PublicationPolicy, resolve
def _policy():
return PublicationPolicy.load(repo_root() / "policies")
def test_netkingdom_is_build_and_dormant():
p = _policy()
assert p.netkingdom_maturity == "maturity-build"
assert p.production_grade is False
def test_dormant_clamps_to_repo_and_default_token_env():
p = _policy()
r = resolve(p, org="coulomb", repo="whynot-design", npm_scope="@whynot",
package_maturity="maturity-build")
assert r.effective_scope == "repo"
assert r.token_env == "NPM_AUTH_TOKEN"
assert r.clamped is True # build->gitea would be broader; clamped down
assert r.active is False
def test_active_graduated_scoping_when_production_grade():
p = replace(_policy(), netkingdom_maturity="maturity-prod")
build = resolve(p, org="coulomb", repo="whynot-design", npm_scope="@whynot",
package_maturity="maturity-build")
test = resolve(p, org="coulomb", repo="whynot-design", npm_scope="@whynot",
package_maturity="maturity-test")
prod = resolve(p, org="coulomb", repo="whynot-design", npm_scope="@whynot",
package_maturity="maturity-prod")
assert (build.effective_scope, build.token_env) == ("gitea", "NPM_AUTH_GITEA_TOKEN")
assert (test.effective_scope, test.token_env) == ("org", "NPM_AUTH_COULOMB_TOKEN")
assert (prod.effective_scope, prod.token_env) == ("repo", "NPM_AUTH_TOKEN")
assert build.active is True and build.clamped is False
def test_token_env_override_wins():
p = _policy()
r = resolve(p, org="coulomb", repo="whynot-design", npm_scope="@whynot",
package_maturity="maturity-build", token_env_override="NPM_AUTH_WHYNOTDESIGN")
assert r.token_env == "NPM_AUTH_WHYNOTDESIGN"
def test_invalid_maturity_rejected():
p = _policy()
with pytest.raises(PolicyGuardError):
resolve(p, org="coulomb", repo="x", npm_scope="@y", package_maturity="maturity-ga")