merge(milestone): v1.29 Reposplit + Identity Layer Bring-Live to main (release v1.28.6)
Nova Slides Render / render (push) Failing after 22s
Nova Slides Render / render (push) Failing after 22s
---ci--- project: acdl phase: 6 milestone: v1.29 status: complete ---/ci---
This commit is contained in:
@@ -656,4 +656,69 @@ template (raw dict → JSON, no troposphere dep), presents for review
|
||||
(`$PAGER` + resource summary), requires explicit `y/N` approval before
|
||||
`cloudformation deploy --capabilities CAPABILITY_IAM`. `--check` reports
|
||||
prerequisites + IAM policy delta; `--verify` runs the KMS round-trip
|
||||
test. New IAM grants required: `cloudformation:*`, `codeartifact:*`.
|
||||
test. New IAM grants required: `cloudformation:*`, `codeartifact:*`.
|
||||
|
||||
### §12.11 — Platform Ops Reposplit (v1.29, current)
|
||||
|
||||
Platform operations are a Terraform-controlled discipline that lives
|
||||
outside the engineering repo, grounded in Vision §4 (Domain
|
||||
Boundaries — *the platform begins where the artifact is compiled and
|
||||
ends where it runs in production under operational guardrails*). Two
|
||||
repos, two ownership surfaces:
|
||||
|
||||
- **`acdl/acdl` (GitHub)** — engineering. Authors `publish.yml` + the
|
||||
artifacts (Lambda zip, layer wheel, Python wheel, ECR container
|
||||
image with the static `kj` binary). Each tag `v1.29.x` produces a
|
||||
GitHub Release with SHA-256-verified artifacts (REQ-354, D-235
|
||||
tag-pin handoff). Engineering ends at the compiled artifact.
|
||||
- **`nova-platform-ops` (Gitea-private, OPER-PRIV, REQ-359)** —
|
||||
operations. Authors the Terraform modules
|
||||
(`networking`/`kms`/`identity`/`contract-ingest`/`bootstrap`/`edge`)
|
||||
that bring those artifacts live in `581513795199`. Operations begins
|
||||
at the live platform under guardrails. No GitHub mirror; CIAgent has
|
||||
no presence there.
|
||||
|
||||
The handoff between the two repos is the **tag-pin** (D-235):
|
||||
`nova-platform-ops` declares `local.nova_platform_version` +
|
||||
`local.kj_source_sha` and resolves substrates through a single
|
||||
`data.aws_ecr_image.kj_image`.
|
||||
|
||||
**The `kj` substrate (KJ-LOCKSTEP, REQ-371):** `kj` (a compiled Go
|
||||
binary, pinned v0.0.3 in `platform/abac/kj-version.txt`, distinct from
|
||||
the kyverno-json engine) has exactly **one identity**: one ECR image
|
||||
digest shared by the production Lambda runtime
|
||||
(`aws_lambda_function.nova_idp_token_vend.image_uri`) and its
|
||||
defensive Fargate fallback
|
||||
(`aws_ecs_task_definition.kj.container_definitions[0].image`). A
|
||||
`lifecycle.precondition` on both image-bearing resources enforces at
|
||||
every `terraform plan` that both `image_uri` attributes resolve to the
|
||||
same digest via `data.aws_ecr_image.kj_image`. No second pipeline, no
|
||||
second SHA pin (D-238). KJ-STATIC: the binary is compiled
|
||||
`CGO_ENABLED=0` and `file(1)` reports `statically linked, no shared
|
||||
library` before embedding.
|
||||
|
||||
**Covered-reference REQ tracking pattern:** the 14 covered-reference
|
||||
REQs (355-366, 371) are authored in `nova-platform-ops` (out-of-band).
|
||||
CIAgent in `acdl` tracks them for milestone completeness; their
|
||||
verification surface is the M1/M1.5/M2 cutover gates documented in
|
||||
the operator guide. The operator guide lists each covered-reference
|
||||
REQ with its gate entry + verification command + a "Result" column
|
||||
that the operator attests after running the gate in
|
||||
`nova-platform-ops` CI. P6 audit verifies every covered-reference REQ
|
||||
has a non-empty, green Result (grill CF-2/G-5). M1.5 green (3
|
||||
consecutive rebuilds of the 12-item spike, operator-attested in the
|
||||
guide) is the HARD P6 ship gate (grill CF-1/G-2.1).
|
||||
|
||||
**Operator guide pointer:** `docs/operator-guide-platform-ops.md`
|
||||
(REQ-OPS-GUIDE) — the operator-facing runbook covering the Day-0
|
||||
cutover, M1.5 verification gate, M2 handoff loop, rollback, KMS
|
||||
rotation, JWKS reachability via CloudFront edge (INV-18), PITR
|
||||
restore, PAT revocation, edge config, Fargate standby health, cost,
|
||||
artifact-mirror fallback, and the cutover gates table.
|
||||
|
||||
**JWKS edge (INV-18, D-233):** the JWKS endpoint is the only public
|
||||
read surface of the live platform. CloudFront + OAC pinning
|
||||
(`AuthType: AWS_IAM` on the Function URL — NOT `NONE`,
|
||||
`OriginAccessControlOriginType: lambda`, `SigningBehavior: always`)
|
||||
replaces direct Lambda Function URL exposure. Direct Function URL →
|
||||
403; via-CloudFront → 200.
|
||||
Reference in New Issue
Block a user