| OIDC |
OpenID Connect — federation protocol for short-lived tokens, no long-lived credentials |
| ABAC |
Attribute-Based Access Control — access scoped by resource tags + repo identity, not roles |
| CMK |
Customer-Managed Key — per-stack encryption key, 90-day rotation, no shared keys |
| CMDB |
Configuration Management Database — validates change requests for decommission |
| RPO |
Recovery Point Objective — RPO = 0 means evidence is written synchronously, no data loss |
| HITL |
Human-in-the-Loop — deliberate human attestation required for qa/prod/dr environments |
| VCS |
Version Control System — the git hosting platform (GitHub, Gitea, GitLab) |
| NFR |
Non-Functional Requirement — encryption, tagging, observability standards |