Compare commits
8 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 9f9d971287 | |||
| fe312c6292 | |||
| c19a5d66f2 | |||
| e8effef415 | |||
| 4ac68b7270 | |||
| 518bbe32a7 | |||
| ed36519223 | |||
| aa3e385606 |
@@ -0,0 +1,50 @@
|
||||
# GitHub Workflows — Nova Platform CI/CD Catalog
|
||||
|
||||
This directory contains the 7 GitHub Actions workflows for the Nova
|
||||
platform. 3 are byte-identical Gitea mirrors (generated from
|
||||
`workflows-src/` by `scripts/sync_workflows.py`, P8/REQ-172); 4 are
|
||||
GitHub-only (Gitea act_runner feature gaps).
|
||||
|
||||
## Shared workflows (byte-identical Gitea + GitHub)
|
||||
|
||||
These 3 are generated from `workflows-src/<name>` by
|
||||
`scripts/sync_workflows.py`; the `.gitea/workflows/<name>` mirror is kept
|
||||
byte-identical. Run `python3 scripts/sync_workflows.py --check` to verify
|
||||
no drift.
|
||||
|
||||
| Workflow | Trigger | Inputs | Required Secrets | Purpose |
|
||||
|----------|---------|--------|------------------|---------|
|
||||
| `ci.yml` | `pull_request: [main]` | — | — | Lint + test + check-only (runs on every PR) |
|
||||
| `deploy.yml` | `workflow_call` (reusable) + `push: [main]` | `contract` (string, required), `mode` (string, default `deploy`), `changeRequestId` (string), `environment` (string) | `NOVA_AWS_ACCESS_KEY_ID`, `NOVA_AWS_SECRET_ACCESS_KEY`, `NOVA_AWS_DEFAULT_REGION`, `NOVA_KMS_KEY_ID`, `NOVA_LAMBDA_URL` | Reusable deploy workflow (invoked by consumer repos via `uses: acdl/.github/workflows/deploy.yml@v1.15`) |
|
||||
| `modules-lifecycle.yml` | `pull_request: [main]` + `workflow_dispatch` | `lifecycle_mode` (string, default `plan` — `plan` or `full`) | `NOVA_AWS_ACCESS_KEY_ID`, `NOVA_AWS_SECRET_ACCESS_KEY`, `NOVA_AWS_DEFAULT_REGION`, `NOVA_AWS_ACCOUNT_ID` | L1 + L2 module lifecycle pipeline (plan-only default; full apply/modify/destroy on override) |
|
||||
|
||||
## GitHub-only workflows (no Gitea mirror)
|
||||
|
||||
These 4 have no Gitea counterpart (Gitea act_runner lacks the features
|
||||
they require — reusable workflows, matrix `needs`, release API). See
|
||||
`.gitea/workflows/README.md` for the limitation rationale.
|
||||
|
||||
| Workflow | Trigger | Inputs | Required Secrets | Purpose |
|
||||
|----------|---------|--------|------------------|---------|
|
||||
| `platform-test.yml` | `pull_request: [main]` | — | — | Lint + unit + integration + schema-validation (replaces `ci.yml` for PRs) |
|
||||
| `primitives-plan.yml` | `pull_request: [main]` | — | `NOVA_AWS_*` | Plan-only for all L1 primitives (matrix) |
|
||||
| `patterns-plan.yml` | `pull_request: [main]` | — | `NOVA_AWS_*` | Plan-only for all L2 modules (matrix) |
|
||||
| `release.yml` | `push: [main]` | — | `NOVA_GITEA_TOKEN` (for Gitea release API) | Semver tag + MAJOR.MINOR/MAJOR floating-tag maintenance + release creation on merge to main |
|
||||
|
||||
## Reusable deploy workflow (`deploy.yml`)
|
||||
|
||||
Consumer repos invoke the deploy workflow via a versioned tag:
|
||||
|
||||
```yaml
|
||||
jobs:
|
||||
deploy:
|
||||
uses: acdl/.github/workflows/deploy.yml@v1.15
|
||||
with:
|
||||
contract: .nova/contract.yml
|
||||
environment: dev
|
||||
secrets: inherit
|
||||
```
|
||||
|
||||
The workflow checks out the consumer repo + the Nova platform repo, runs
|
||||
`scripts/run_platform.sh`, and posts deploy outputs as a PR comment +
|
||||
to SSM Parameter Store.
|
||||
@@ -126,20 +126,46 @@ engine-specific code. `modules/`, `schemas/`, `contracts/`,
|
||||
|
||||
## How to run
|
||||
|
||||
### Prerequisites
|
||||
### Quick start (offline, no AWS required)
|
||||
|
||||
> These prerequisites are for running the **platform repo** locally. A
|
||||
> consumer does not need any of these — see the
|
||||
> [Consumer guide](docs/consumer-guide.md) for the consumer happy path.
|
||||
The fastest way to verify the platform works — no AWS credentials, no
|
||||
bootstrap, no cost. See the [Consumer guide](docs/consumer-guide.md)
|
||||
for the consumer happy path (a consumer owns only a contract + app code).
|
||||
|
||||
- A platform-managed environment (see [docs/environments/](docs/environments/)).
|
||||
For local testing, `core/environments/dev.json` is provided as the sample.
|
||||
- AWS credentials for the dev environment (in `.env.secrets`, gitignored;
|
||||
see [Credentials & zero-trust](#credentials--zero-trust)).
|
||||
- `terraform` (pin `1.9.*`), `checkov` (pin `>=3.2,<4`), `python3` + `boto3`
|
||||
+ `jsonschema`.
|
||||
```bash
|
||||
# Install test dependencies
|
||||
pip install -r requirements-test.txt
|
||||
|
||||
### Run the platform pipeline end-to-end
|
||||
# 1. Run the test suite (all offline — uses moto for DynamoDB mocking)
|
||||
python3 -m pytest tests/ -v
|
||||
|
||||
# 2. Run the platform in check-only mode (offline — contract -> resolver ->
|
||||
# adapter -> structure validation). Uses the default sample contract
|
||||
# (contracts/static-assets.yaml) + sample dev environment.
|
||||
bash scripts/run_platform.sh --check-only
|
||||
# Expected: "=== PLATFORM CHECK OK ==="
|
||||
|
||||
# 3. Run the headline E2E against the local emulating tier (emulates ECS,
|
||||
# outbox, S3 state, Lambda in-process; D-092).
|
||||
bash scripts/run_platform.sh --local
|
||||
# Expected: "=== LOCAL E2E OK ==="
|
||||
|
||||
# 4. Reproduce the full CI pipeline locally (lint -> test -> check-only)
|
||||
bash scripts/run_ci.sh
|
||||
# Expected: "=== CI PIPELINE OK ==="
|
||||
|
||||
# Show all run_platform.sh flags:
|
||||
bash scripts/run_platform.sh --help
|
||||
```
|
||||
|
||||
### Run against live AWS (requires credentials + bootstrap)
|
||||
|
||||
> Prerequisites: a platform-managed environment (see
|
||||
> [docs/environments/](docs/environments/); `core/environments/dev.json`
|
||||
> is the sample), AWS credentials for dev (in `.env.secrets`, gitignored;
|
||||
> see [Credentials & zero-trust](#credentials--zero-trust)), `terraform`
|
||||
> (pin `1.9.*`), `checkov` (pin `>=3.2,<4`), `python3` + `boto3` +
|
||||
> `jsonschema`.
|
||||
|
||||
```bash
|
||||
# 1. Bootstrap the AWS state backend + runner IAM user (one-time, idempotent)
|
||||
@@ -168,26 +194,6 @@ bash scripts/run_platform.sh --plan-only contracts/static-assets.yaml
|
||||
bash scripts/run_platform.sh --quiet contracts/static-assets.yaml
|
||||
```
|
||||
|
||||
### Test the platform (offline, no AWS required)
|
||||
|
||||
```bash
|
||||
# Install test dependencies
|
||||
pip install -r requirements-test.txt
|
||||
|
||||
# Run the test suite (all offline — uses moto for DynamoDB mocking)
|
||||
python3 -m pytest tests/ -v
|
||||
|
||||
# Run the platform in check-only mode (offline — no AWS, no policy checks,
|
||||
# no outbox). Uses the default sample contract (contracts/static-assets.yaml)
|
||||
# and the sample dev environment (core/environments/dev.json).
|
||||
bash scripts/run_platform.sh --check-only
|
||||
# Expected: "=== PLATFORM CHECK OK ==="
|
||||
|
||||
# Reproduce the full CI pipeline locally (lint -> test -> check-only)
|
||||
bash scripts/run_ci.sh
|
||||
# Expected: "=== CI PIPELINE OK ==="
|
||||
```
|
||||
|
||||
### CI/CD pipelines
|
||||
|
||||
The CI/CD pipeline is defined by a **central pipeline contract** — a
|
||||
|
||||
@@ -64,6 +64,21 @@ def _load_json(path):
|
||||
return json.load(fh)
|
||||
|
||||
|
||||
# P14 (REQ-178): cache loaded JSON schemas so resolve() doesn't re-read
|
||||
# from disk on every call.
|
||||
_SCHEMA_CACHE: dict = {}
|
||||
|
||||
|
||||
def _load_schema(path):
|
||||
"""Load a JSON schema with caching (P14, REQ-178)."""
|
||||
cached = _SCHEMA_CACHE.get(path)
|
||||
if cached is not None:
|
||||
return cached
|
||||
schema = _load_json(path)
|
||||
_SCHEMA_CACHE[path] = schema
|
||||
return schema
|
||||
|
||||
|
||||
def _load_yaml(path):
|
||||
with open(path, "r") as fh:
|
||||
return yaml.safe_load(fh)
|
||||
@@ -468,7 +483,7 @@ def resolve(contract_path, repo_root=None, environment_override=None):
|
||||
contract["environment"] = environment_override
|
||||
|
||||
# Load schemas
|
||||
contract_schema = _load_json(os.path.join(repo_root, "schemas", "contract.schema.json"))
|
||||
contract_schema = _load_schema(os.path.join(repo_root, "schemas", "contract.schema.json"))
|
||||
|
||||
# Validate contract against schema
|
||||
jsonschema.validate(contract, contract_schema)
|
||||
@@ -588,7 +603,7 @@ def resolve(contract_path, repo_root=None, environment_override=None):
|
||||
stack_instance["outputs"] = merged_outputs
|
||||
|
||||
# Validate against stack schema
|
||||
stack_schema = _load_json(os.path.join(repo_root, "schemas", "stack.schema.json"))
|
||||
stack_schema = _load_schema(os.path.join(repo_root, "schemas", "stack.schema.json"))
|
||||
jsonschema.validate(stack_instance, stack_schema)
|
||||
|
||||
return stack_instance
|
||||
|
||||
@@ -55,6 +55,8 @@ def load(env_name, root=None):
|
||||
|
||||
|
||||
def _onboarding_message(env_name):
|
||||
# P19 (REQ-183): rebranded Nova self-service request path — no longer
|
||||
# routes to "contact the platform team" for the request step.
|
||||
return (
|
||||
"=== Nova Environment Onboarding ===\n"
|
||||
f"No environment named '{env_name}' is bound to this repository.\n\n"
|
||||
@@ -66,13 +68,15 @@ def _onboarding_message(env_name):
|
||||
" - an IAM role surfaced to your repo via attribute-based\n"
|
||||
" authorization (ABAC)\n\n"
|
||||
"You do not provide an AWS account, VPC, subnet, or state bucket.\n\n"
|
||||
"To request an environment:\n"
|
||||
" 1. Contact the platform team with your repo name + the\n"
|
||||
"To request an environment (self-service):\n"
|
||||
" 1. Submit an onboarding request to the Nova Lambda\n"
|
||||
" (action: onboard_consumer) with your repo name + the\n"
|
||||
" environment name you need (e.g. 'dev').\n"
|
||||
" 2. The platform team provisions the account/network/state/role\n"
|
||||
" and binds the environment to your repo.\n"
|
||||
" 3. Your next pipeline run will proceed normally.\n\n"
|
||||
"Expected turnaround: contact the platform team for current SLA.\n"
|
||||
" 2. The platform generates an environment binding + opens a PR.\n"
|
||||
" 3. The platform provisions the account/network/state/role and\n"
|
||||
" grants the ABAC role. Your next pipeline run proceeds.\n\n"
|
||||
"Run: python3 core/onboarding.py --request '{...}' to generate a\n"
|
||||
"binding file locally, or POST to the Lambda onboard_consumer action.\n"
|
||||
"===================================\n"
|
||||
)
|
||||
|
||||
|
||||
@@ -33,5 +33,13 @@ halting the pipeline before any work is done.
|
||||
|
||||
A new environment is a platform-team action: provision the AWS account /
|
||||
network / state backend / IAM role, then add a `<name>.json` here and bind
|
||||
it to the consumer repo. Self-service environment provisioning is on the
|
||||
roadmap; today it is a platform-team action.
|
||||
it to the consumer repo.
|
||||
|
||||
**P19 (REQ-183):** the *request* step is now self-service. A consumer
|
||||
submits an onboarding request (POST to the Nova Lambda `onboard_consumer`
|
||||
action, or `python3 core/onboarding.py --request '{...}'`) and the
|
||||
platform generates a `<name>.json` binding file from the request + opens
|
||||
a PR. The actual AWS account/network/state provisioning + cross-account
|
||||
role grant remains a platform-team action (a future feature milestone
|
||||
will automate the provisioning; the cross-account role Terraform is
|
||||
offline-proven in P20/REQ-184).
|
||||
@@ -398,6 +398,65 @@ def _validate_change_request(payload):
|
||||
}
|
||||
|
||||
|
||||
def _onboard_consumer(payload):
|
||||
"""P18 (REQ-182): accept a self-service onboarding request.
|
||||
|
||||
Validates the payload against schemas/onboarding.schema.json, then
|
||||
writes a 'pending' row to nova-contracts (D-119). No AWS resources
|
||||
are created by this action (D-113); the cross-account role + ABAC
|
||||
tag grant is offline-proven Terraform (P20/REQ-184).
|
||||
"""
|
||||
import jsonschema
|
||||
schema_path = os.path.join(os.path.dirname(os.path.dirname(
|
||||
os.path.dirname(os.path.abspath(__file__)))),
|
||||
"schemas", "onboarding.schema.json")
|
||||
try:
|
||||
with open(schema_path) as f:
|
||||
schema = json.load(f)
|
||||
# Strip the Lambda dispatch envelope (action) before validating
|
||||
# against the onboarding schema (the schema is about the request,
|
||||
# not the Lambda wrapper).
|
||||
onboarding_payload = {k: v for k, v in payload.items() if k != "action"}
|
||||
jsonschema.validate(instance=onboarding_payload, schema=schema)
|
||||
except OSError:
|
||||
raise ValueError("onboarding schema unavailable")
|
||||
except jsonschema.ValidationError as e:
|
||||
raise ValueError(f"onboarding payload invalid: {e.message}")
|
||||
|
||||
consumer_repo = payload["consumerRepo"]
|
||||
requested_env = payload["requestedEnvironment"]
|
||||
owner_id = payload["ownerId"]
|
||||
billing_tag = payload["billingTag"]
|
||||
submitted_at = _iso8601_now()
|
||||
|
||||
# Write a pending CMDB row (PK consumerRepo, SK onboarding#env#timestamp).
|
||||
table = _get_dynamodb().Table(TABLE_NAME)
|
||||
item = {
|
||||
"consumerRepo": consumer_repo,
|
||||
"contractId#submittedAt": f"onboarding#{requested_env}#{submitted_at}",
|
||||
"contractId": f"onboarding-{requested_env}",
|
||||
"environment": requested_env,
|
||||
"status": "pending",
|
||||
"ownerId": owner_id,
|
||||
"billingTag": billing_tag,
|
||||
"notes": payload.get("notes", ""),
|
||||
"submittedAt": submitted_at,
|
||||
}
|
||||
table.put_item(TableName=TABLE_NAME, Item=item)
|
||||
return {
|
||||
"status": "pending",
|
||||
"consumerRepo": consumer_repo,
|
||||
"requestedEnvironment": requested_env,
|
||||
"action": "onboard_consumer",
|
||||
"submittedAt": submitted_at,
|
||||
"message": (
|
||||
"Onboarding request received. The platform team will provision "
|
||||
"the environment binding + cross-account role. Track the status "
|
||||
"via the nova-contracts table (status=pending → granted)."
|
||||
),
|
||||
}
|
||||
|
||||
|
||||
def lambda_handler(event, context):
|
||||
"""AWS Lambda handler entry point.
|
||||
|
||||
@@ -426,6 +485,8 @@ def lambda_handler(event, context):
|
||||
result = _report_error(payload)
|
||||
elif action == "validate_change_request":
|
||||
result = _validate_change_request(payload)
|
||||
elif action == "onboard_consumer":
|
||||
result = _onboard_consumer(payload)
|
||||
else:
|
||||
return {
|
||||
"statusCode": 400,
|
||||
|
||||
@@ -0,0 +1,131 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Nova Onboarding — auto-generate an environment binding file (P19, REQ-183).
|
||||
|
||||
Given a consumer onboarding request (validated against
|
||||
schemas/onboarding.schema.json), generate a ``<env>.json`` environment
|
||||
binding file from the dev template, filling in the consumer's ownerId +
|
||||
billingTag. The generated file is a starting point for the platform team
|
||||
(or a future automation) to bind to a real AWS account.
|
||||
|
||||
This is the "request path" half of the no-humans onboarding flow (D-113).
|
||||
Real AWS account/network/state provisioning is a future feature milestone;
|
||||
this module removes the human handoff from the *request* step by
|
||||
generating the binding file + emitting a git patch / PR-branch instruction.
|
||||
|
||||
Usage:
|
||||
python3 core/onboarding.py <request.json> [--out <env.json>]
|
||||
python3 core/onboarding.py --request '{"consumerRepo":"acdl/c","requestedEnvironment":"qa","ownerId":"team-a","billingTag":"cc-a"}'
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
import json
|
||||
import os
|
||||
import sys
|
||||
from pathlib import Path
|
||||
from typing import Any, Dict
|
||||
|
||||
|
||||
def _repo_root() -> Path:
|
||||
return Path(__file__).resolve().parent.parent
|
||||
|
||||
|
||||
def _load_template_env(template_env: str = "dev", root: Path | None = None) -> Dict[str, Any]:
|
||||
"""Load the template environment JSON (defaults to dev.json)."""
|
||||
root = root or _repo_root()
|
||||
env_path = root / "core" / "environments" / f"{template_env}.json"
|
||||
if not env_path.is_file():
|
||||
raise FileNotFoundError(f"template environment {env_path} not found")
|
||||
return json.loads(env_path.read_text())
|
||||
|
||||
|
||||
def generate_env_file(
|
||||
request: Dict[str, Any],
|
||||
template_env: str = "dev",
|
||||
root: Path | None = None,
|
||||
) -> Dict[str, Any]:
|
||||
"""Generate an environment binding dict from a consumer onboarding request.
|
||||
|
||||
The generated dict is a copy of the template env with:
|
||||
- ``name`` → the requested environment
|
||||
- ``description`` → notes the consumer + owner
|
||||
- ``account_id`` → placeholder (000000000000) for the platform team
|
||||
to fill with the real account
|
||||
- ``ownerId`` + ``billingTag`` → from the request (for ABAC + cost)
|
||||
|
||||
The dict validates against schemas/environment.schema.json.
|
||||
|
||||
Returns the generated env dict.
|
||||
"""
|
||||
template = _load_template_env(template_env, root)
|
||||
requested = request["requestedEnvironment"]
|
||||
owner = request["ownerId"]
|
||||
billing = request["billingTag"]
|
||||
consumer = request["consumerRepo"]
|
||||
|
||||
env = dict(template)
|
||||
env["name"] = requested
|
||||
env["description"] = (
|
||||
f"Auto-generated binding for {consumer} (owner={owner}, "
|
||||
f"billing={billing}). Replace account_id with the real "
|
||||
f"{requested} account before deploying."
|
||||
)
|
||||
env["account_id"] = "000000000000" # placeholder — platform team fills
|
||||
env["ownerId"] = owner
|
||||
env["billingTag"] = billing
|
||||
return env
|
||||
|
||||
|
||||
def _onboarding_request_message(env_name: str) -> str:
|
||||
"""P19 (REQ-183): the rebranded Nova onboarding message — self-service
|
||||
request path, no longer routes to 'contact the platform team'."""
|
||||
return (
|
||||
"=== Nova Environment Onboarding ===\n"
|
||||
f"No environment named '{env_name}' is bound to this repository.\n\n"
|
||||
"Nova environments are platform-managed. The platform provisions on\n"
|
||||
"your behalf:\n"
|
||||
" - an AWS account (or a scoped partition of one)\n"
|
||||
" - a network (VPC + subnets)\n"
|
||||
" - a state backend (an S3 bucket + DynamoDB lock table)\n"
|
||||
" - an IAM role surfaced to your repo via attribute-based\n"
|
||||
" authorization (ABAC)\n\n"
|
||||
"You do not provide an AWS account, VPC, subnet, or state bucket.\n\n"
|
||||
"To request an environment (self-service):\n"
|
||||
" 1. Submit an onboarding request to the Nova Lambda\n"
|
||||
" (action: onboard_consumer) with your repo name + the\n"
|
||||
" environment name you need (e.g. 'dev').\n"
|
||||
" 2. The platform generates an environment binding + opens a PR.\n"
|
||||
" 3. The platform provisions the account/network/state/role and\n"
|
||||
" grants the ABAC role. Your next pipeline run proceeds.\n\n"
|
||||
"Run: python3 core/onboarding.py --request '{...}' to generate a\n"
|
||||
"binding file locally, or POST to the Lambda onboard_consumer action.\n"
|
||||
"===================================\n"
|
||||
)
|
||||
|
||||
|
||||
def main(argv: list[str] | None = None) -> int:
|
||||
parser = argparse.ArgumentParser(description="Generate an env binding from an onboarding request.")
|
||||
group = parser.add_mutually_exclusive_group(required=True)
|
||||
group.add_argument("request_file", nargs="?", help="path to a request JSON file")
|
||||
group.add_argument("--request", help="inline request JSON string")
|
||||
parser.add_argument("--out", help="output path for the generated env JSON (default: stdout)")
|
||||
parser.add_argument("--template-env", default="dev", help="template environment (default: dev)")
|
||||
args = parser.parse_args(argv)
|
||||
|
||||
if args.request:
|
||||
request = json.loads(args.request)
|
||||
else:
|
||||
request = json.loads(Path(args.request_file).read_text())
|
||||
|
||||
env = generate_env_file(request, template_env=args.template_env)
|
||||
env_json = json.dumps(env, indent=2) + "\n"
|
||||
if args.out:
|
||||
Path(args.out).write_text(env_json)
|
||||
print(f"wrote: {args.out}")
|
||||
else:
|
||||
print(env_json)
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
@@ -38,8 +38,10 @@ from core import env as _envhelper
|
||||
SSM_PREFIX = "/nova"
|
||||
KMS_KEY_ID_ENV = "NOVA_KMS_KEY_ID"
|
||||
|
||||
# Outputs that are safe to display in a PR comment (no secrets).
|
||||
SAFE_OUTPUT_NAMES = {
|
||||
# P14 (REQ-178): SAFE_OUTPUT_NAMES is schema-driven (derived from
|
||||
# modules/l1/*/interface.json outputs that don't have sensitive:true).
|
||||
# Falls back to the hardcoded set if the interfaces can't be read.
|
||||
_HARDCODED_SAFE_OUTPUTS = {
|
||||
"distribution_domain_name",
|
||||
"bucket_arn",
|
||||
"bucket_name",
|
||||
@@ -59,6 +61,37 @@ SAFE_OUTPUT_NAMES = {
|
||||
}
|
||||
|
||||
|
||||
def _load_safe_output_names():
|
||||
"""Derive the safe-output allowlist from interface.json outputs.
|
||||
|
||||
P14 (REQ-178): scan modules/l1/*/interface.json; an output is safe if
|
||||
its spec does not set sensitive:true. Falls back to the hardcoded set
|
||||
if no interfaces are readable.
|
||||
"""
|
||||
import json
|
||||
from pathlib import Path
|
||||
root = Path(__file__).resolve().parent.parent
|
||||
safe = set()
|
||||
try:
|
||||
for iface in (root / "modules" / "l1").glob("*/interface.json"):
|
||||
d = json.loads(iface.read_text())
|
||||
outs = d.get("outputs", {})
|
||||
if isinstance(outs, dict):
|
||||
for name, spec in outs.items():
|
||||
if not (isinstance(spec, dict) and spec.get("sensitive")):
|
||||
safe.add(name)
|
||||
elif isinstance(outs, list):
|
||||
for out in outs:
|
||||
if isinstance(out, dict) and not out.get("sensitive"):
|
||||
safe.add(out.get("name", ""))
|
||||
except (OSError, ValueError):
|
||||
pass
|
||||
return safe or _HARDCODED_SAFE_OUTPUTS
|
||||
|
||||
|
||||
SAFE_OUTPUT_NAMES = _load_safe_output_names()
|
||||
|
||||
|
||||
def _ssm_client():
|
||||
if boto3 is None:
|
||||
raise RuntimeError("boto3 is required for SSM publishing")
|
||||
|
||||
@@ -668,17 +668,9 @@ def write_report(report: RegressionReport,
|
||||
|
||||
|
||||
def main() -> int:
|
||||
milestone = _envhelper.get_env("REGRESSION_MILESTONE", "v1.10") or "v1.10"
|
||||
phase = int(_envhelper.get_env("REGRESSION_PHASE", "52") or "52")
|
||||
report = run_regression(milestone=milestone, phase=phase)
|
||||
md, js = write_report(report)
|
||||
print(f"regression: {report.summary} -> {md}")
|
||||
if not report.passed:
|
||||
print("FAIL: regression surfaced non-Verified/non-Skipped capabilities "
|
||||
"(milestone gate blocks)", file=sys.stderr)
|
||||
return 1
|
||||
print(f"regression: gate passes (summary={report.summary})")
|
||||
return 0
|
||||
"""P13 (REQ-177): re-export from core.regression_verify_cli."""
|
||||
from core.regression_verify_cli import main as _cli_main
|
||||
return _cli_main()
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
|
||||
@@ -0,0 +1,33 @@
|
||||
"""Nova Regression Verify CLI — command-line entry point.
|
||||
|
||||
Extracted from core/regression_verify.py (P13, REQ-177).
|
||||
|
||||
G-113 import direction: this module imports core.regression_verify (the
|
||||
library) for run_regression + write_report. The library does not import
|
||||
this CLI module. Nothing imports this CLI except direct invocation.
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import sys
|
||||
|
||||
from core import env as _envhelper
|
||||
from core.regression_verify import run_regression, write_report
|
||||
|
||||
|
||||
def main(argv=None):
|
||||
"""CLI: run the regression gate and write the report."""
|
||||
milestone = _envhelper.get_env("REGRESSION_MILESTONE", "v1.10") or "v1.10"
|
||||
phase = int(_envhelper.get_env("REGRESSION_PHASE", "52") or "52")
|
||||
report = run_regression(milestone=milestone, phase=phase)
|
||||
md, js = write_report(report)
|
||||
print(f"regression: {report.summary} -> {md}")
|
||||
if not report.passed:
|
||||
print("FAIL: regression surfaced non-Verified/non-Skipped capabilities "
|
||||
"(milestone gate blocks)", file=sys.stderr)
|
||||
return 1
|
||||
print(f"regression: gate passes (summary={report.summary})")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
@@ -0,0 +1,87 @@
|
||||
# Nova Onboarding — No-Humans Request Path (v1.16, REQ-182..184)
|
||||
|
||||
The v1.16 milestone implements the **request path** of the no-humans
|
||||
onboarding flow (D-113). A consumer can submit an onboarding request
|
||||
without contacting the platform team; the platform generates an
|
||||
environment binding + (in a future milestone) provisions the AWS resources.
|
||||
|
||||
## The 3-step request path
|
||||
|
||||
### Step 1 — Submit an onboarding request (P18, REQ-182)
|
||||
|
||||
A consumer submits an onboarding request to the Nova platform Lambda:
|
||||
|
||||
```bash
|
||||
# Via the Lambda Function URL (IAM auth):
|
||||
curl -X POST "$NOVA_LAMBDA_URL" \
|
||||
-H "Content-Type: application/json" \
|
||||
-d '{
|
||||
"action": "onboard_consumer",
|
||||
"consumerRepo": "acdl/my-app",
|
||||
"requestedEnvironment": "dev",
|
||||
"ownerId": "team-x",
|
||||
"billingTag": "cost-center-x"
|
||||
}'
|
||||
```
|
||||
|
||||
The Lambda validates the payload against
|
||||
[`schemas/onboarding.schema.json`](../schemas/onboarding.schema.json),
|
||||
then writes a `pending` row to the `nova-contracts` DynamoDB table
|
||||
(D-119). No AWS resources are created by this action (D-113).
|
||||
|
||||
### Step 2 — Generate an environment binding (P19, REQ-183)
|
||||
|
||||
The platform (or the consumer locally) generates an environment binding
|
||||
file from the request:
|
||||
|
||||
```bash
|
||||
python3 core/onboarding.py --request '{
|
||||
"consumerRepo": "acdl/my-app",
|
||||
"requestedEnvironment": "qa",
|
||||
"ownerId": "team-x",
|
||||
"billingTag": "cost-center-x"
|
||||
}' --out core/environments/qa.json
|
||||
```
|
||||
|
||||
This produces a `<env>.json` from the `dev.json` template, filling in
|
||||
the `ownerId` + `billingTag` + a description. The `account_id` is a
|
||||
placeholder (`000000000000`) for the platform team to fill with the real
|
||||
account. The generated file validates against
|
||||
[`schemas/environment.schema.json`](../schemas/environment.schema.json).
|
||||
|
||||
### Step 3 — Cross-account role + ABAC tag grant (P20, REQ-184)
|
||||
|
||||
The platform authors the consumer deploy-role + `nova:owner` ABAC tag
|
||||
grant via Terraform:
|
||||
|
||||
```bash
|
||||
cd terraform/onboarding
|
||||
terraform init -backend=false
|
||||
terraform validate
|
||||
NOVA_AWS_ACCOUNT_ID=123456789012 terraform plan \
|
||||
-var consumer_repo=acdl/my-app \
|
||||
-var owner_id=team-x
|
||||
```
|
||||
|
||||
**Offline-proven only (D-114):** `terraform validate` + `terraform plan`
|
||||
pass; **no live apply** in v1.16. The live apply (creating the real
|
||||
cross-account role + OIDC trust) is deferred to a future feature
|
||||
milestone (D-113).
|
||||
|
||||
## What is NOT automated (deferred)
|
||||
|
||||
- **Real AWS account/network/state provisioning** — the request path
|
||||
generates a binding file with a placeholder `account_id`; the actual
|
||||
AWS account creation + VPC + state backend is a future feature (D-113).
|
||||
- **Live cross-account role apply** — the Terraform is offline-proven
|
||||
only (D-114); live apply is deferred.
|
||||
- **OIDC trust policy** — the onboarding Terraform uses a placeholder
|
||||
OIDC provider; real OIDC federation is blocked on
|
||||
go-gitea/gitea#36988 (carries forward from v1.1).
|
||||
|
||||
## See also
|
||||
|
||||
- [`schemas/onboarding.schema.json`](../schemas/onboarding.schema.json) — the request schema
|
||||
- [`core/onboarding.py`](../core/onboarding.py) — the env-file generator
|
||||
- [`terraform/onboarding/`](../terraform/onboarding/) — the role-grant Terraform
|
||||
- [`core/environments/README.md`](../core/environments/README.md) — environment binding docs
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
||||
"$id": "https://nova.cloudinit.dev/schemas/onboarding.schema.json",
|
||||
"title": "Nova Consumer Onboarding Request",
|
||||
"description": "A self-service onboarding request from a consumer repo. Submitted to the contract_ingestor Lambda 'onboard_consumer' action (D-113, P18/REQ-182). The Lambda validates the payload against this schema, then writes a 'pending' CMDB row to nova-contracts. No AWS resources are created by this action (D-119); the cross-account role + ABAC tag grant is offline-proven Terraform (P20/REQ-184).",
|
||||
"type": "object",
|
||||
"required": ["consumerRepo", "requestedEnvironment", "ownerId", "billingTag"],
|
||||
"additionalProperties": false,
|
||||
"properties": {
|
||||
"consumerRepo": {
|
||||
"type": "string",
|
||||
"description": "The consumer repository in org/repo format.",
|
||||
"pattern": "^[a-zA-Z0-9_.-]+/[a-zA-Z0-9_.-]+$",
|
||||
"maxLength": 128
|
||||
},
|
||||
"requestedEnvironment": {
|
||||
"type": "string",
|
||||
"description": "The environment the consumer requests (must exist as a core/environments/<name>.json).",
|
||||
"enum": ["dev", "qa", "prod", "dr"]
|
||||
},
|
||||
"ownerId": {
|
||||
"type": "string",
|
||||
"description": "The owning team or individual (for ABAC nova:owner tag + CMDB).",
|
||||
"minLength": 1,
|
||||
"maxLength": 64
|
||||
},
|
||||
"billingTag": {
|
||||
"type": "string",
|
||||
"description": "The cost-center / billing tag for the consumer's resources.",
|
||||
"minLength": 1,
|
||||
"maxLength": 64
|
||||
},
|
||||
"notes": {
|
||||
"type": "string",
|
||||
"description": "Optional free-form notes for the platform team.",
|
||||
"maxLength": 500
|
||||
}
|
||||
}
|
||||
}
|
||||
+42
-2
@@ -7,6 +7,9 @@
|
||||
# run_platform.sh --plan-only <contract.yml> (AWS plan only, no Checkov/outbox)
|
||||
# run_platform.sh --apply <contract.yml> (AWS apply: init/validate/plan/apply)
|
||||
# run_platform.sh --destroy <contract.yml> (AWS destroy: init/validate/destroy)
|
||||
# run_platform.sh --local [contract.yml] (local emulating tier, no AWS)
|
||||
# run_platform.sh --decommission <CR> <contract.yml> (gated teardown)
|
||||
# run_platform.sh --help (show all flags)
|
||||
#
|
||||
# Modes:
|
||||
# --check-only (offline, no AWS/Checkov/DynamoDB — for CI)
|
||||
@@ -17,13 +20,19 @@
|
||||
# contract -> resolver -> stack -> adapter -> terraform init/validate/plan/apply -> exit 0
|
||||
# --destroy (requires AWS creds; use --decommission <CR> for gated production teardown)
|
||||
# contract -> resolver -> stack -> adapter -> terraform init/validate/destroy -> exit 0
|
||||
# --local (no AWS creds; local emulating tier D-092)
|
||||
# contract -> resolver -> adapter -> local S3/ECS/outbox/Lambda stubs -> exit 0
|
||||
# (default) (requires AWS creds + Checkov + DynamoDB)
|
||||
# contract -> resolver -> stack -> adapter -> terraform plan -> Checkov ->
|
||||
# confidence -> outbox
|
||||
#
|
||||
# Flags:
|
||||
# --quiet suppress terraform/checkov streaming (output to log only)
|
||||
# --decommission gate --destroy with D-070 two-step CR validation (requires <CR>)
|
||||
# --quiet suppress terraform/checkov streaming (output to log only)
|
||||
# --decommission gate --destroy with D-070 two-step CR validation (requires <CR>)
|
||||
# --deploy-uptime deploy the uptime monitoring stack (separate state)
|
||||
# --local run the headline E2E against the local emulating tier (D-092)
|
||||
# --environment <name> override the contract's environment at load time (D-088)
|
||||
# --help, -h show all flags + a one-line description
|
||||
#
|
||||
# The contract file is a YAML file validated against schemas/contract.schema.json.
|
||||
# The resolver (core/contract_resolver.py) resolves it to a Target Stack
|
||||
@@ -59,6 +68,36 @@ CHANGE_REQUEST_ID=""
|
||||
ENVIRONMENT_OVERRIDE=""
|
||||
CONTRACT=""
|
||||
|
||||
# P15 (REQ-179): --help / -h prints all flags + a one-line description.
|
||||
_print_help() {
|
||||
cat <<'HELP'
|
||||
Nova platform pipeline — run_platform.sh
|
||||
|
||||
Usage:
|
||||
run_platform.sh <contract.yml> (full e2e with AWS)
|
||||
run_platform.sh --check-only [contract.yml] (offline, no AWS)
|
||||
run_platform.sh --plan-only <contract.yml> (AWS plan only)
|
||||
run_platform.sh --apply <contract.yml> (AWS apply)
|
||||
run_platform.sh --destroy <contract.yml> (AWS destroy)
|
||||
run_platform.sh --local [contract.yml] (local emulating tier)
|
||||
run_platform.sh --decommission <CR> <contract.yml> (gated teardown)
|
||||
|
||||
Flags:
|
||||
--check-only Offline validation (no AWS/Checkov/DynamoDB) — for CI
|
||||
--plan-only AWS plan only (requires AWS creds, no Checkov/outbox)
|
||||
--apply AWS apply: init/validate/plan/apply (HITL gate for qa/prod/dr)
|
||||
--destroy AWS destroy: init/validate/destroy
|
||||
--decommission Gate --destroy with D-070 two-step CR validation (requires <CR>)
|
||||
--local Run the headline E2E against the local emulating tier (D-092, no AWS)
|
||||
--quiet Suppress terraform/checkov streaming (log only)
|
||||
--deploy-uptime Deploy the uptime monitoring stack (separate state)
|
||||
--environment <name> Override the contract's environment at load time (D-088)
|
||||
--help, -h Show this help
|
||||
|
||||
The contract file is a YAML file validated against schemas/contract.schema.json.
|
||||
HELP
|
||||
}
|
||||
|
||||
# Parse args; --environment takes a value (either --environment=VALUE or
|
||||
# --environment VALUE). The contract / changeRequestId are the remaining
|
||||
# positional args.
|
||||
@@ -69,6 +108,7 @@ for arg in "$@"; do
|
||||
continue
|
||||
fi
|
||||
case "$arg" in
|
||||
--help|-h) _print_help; exit 0 ;;
|
||||
--check-only) CHECK_ONLY=1 ;;
|
||||
--plan-only) PLAN_ONLY=1 ;;
|
||||
--apply) APPLY_ONLY=1 ;;
|
||||
|
||||
@@ -0,0 +1,42 @@
|
||||
# terraform/onboarding/ — Consumer deploy-role + ABAC tag grant (P20, REQ-184)
|
||||
|
||||
Offline-proven Terraform for the cross-account consumer deploy-role +
|
||||
`nova:owner` ABAC tag grant. This is the "role grant" half of the
|
||||
no-humans onboarding flow (D-113); the "request" half is P18 (Lambda
|
||||
action) + P19 (env-file autogen).
|
||||
|
||||
## Scope (D-114)
|
||||
|
||||
This Terraform is **offline-proven only** in v1.16:
|
||||
- `terraform validate` passes.
|
||||
- `terraform plan` (with `NOVA_AWS_ACCOUNT_ID` set) produces the expected
|
||||
role + policy.
|
||||
- **No live apply** — `NOVA_LIFECYCLE_MODE=plan` default. Live apply is
|
||||
deferred to a future feature milestone (D-113/D-114).
|
||||
|
||||
## Variables
|
||||
|
||||
| Variable | Description | Default |
|
||||
|----------|-------------|---------|
|
||||
| `consumer_repo` | The consumer repository (org/repo) | `acdl/consumer-a` |
|
||||
| `owner_id` | The owning team (for `nova:owner` tag) | `team-a` |
|
||||
| `account_id` | The consumer's AWS account ID | `000000000000` |
|
||||
| `region` | AWS region | `us-east-1` |
|
||||
|
||||
## Resources
|
||||
|
||||
- `aws_iam_role.consumer_deploy` — the consumer's deploy role with a
|
||||
trust policy (assumed by the consumer's CI runner).
|
||||
- `aws_iam_role_policy.consumer_invoke` — inline policy granting
|
||||
`lambda:InvokeFunctionUrl` on the platform Lambda, scoped via
|
||||
`aws:PrincipalTag/nova:owner == var.owner_id` (ABAC).
|
||||
- `aws_iam_tag.owner` — tags the role with `nova:owner` + `nova:contract`.
|
||||
|
||||
## Usage (offline)
|
||||
|
||||
```bash
|
||||
cd terraform/onboarding
|
||||
terraform init -backend=false
|
||||
terraform validate
|
||||
NOVA_AWS_ACCOUNT_ID=123456789012 terraform plan -var consumer_repo=acdl/my-app -var owner_id=team-x
|
||||
```
|
||||
@@ -0,0 +1,120 @@
|
||||
terraform {
|
||||
required_version = ">= 1.9, < 1.10"
|
||||
required_providers {
|
||||
aws = {
|
||||
source = "hashicorp/aws"
|
||||
version = "~> 5.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
variable "consumer_repo" {
|
||||
description = "The consumer repository (org/repo) — for the nova:contract tag."
|
||||
type = string
|
||||
default = "acdl/consumer-a"
|
||||
}
|
||||
|
||||
variable "owner_id" {
|
||||
description = "The owning team (for the nova:owner ABAC tag)."
|
||||
type = string
|
||||
default = "team-a"
|
||||
}
|
||||
|
||||
variable "account_id" {
|
||||
description = "The consumer's AWS account ID (where the deploy role is created)."
|
||||
type = string
|
||||
default = "000000000000"
|
||||
}
|
||||
|
||||
variable "region" {
|
||||
description = "AWS region."
|
||||
type = string
|
||||
default = "us-east-1"
|
||||
}
|
||||
|
||||
provider "aws" {
|
||||
region = var.region
|
||||
}
|
||||
|
||||
# P20 (REQ-184): consumer deploy role — the role the consumer's CI runner
|
||||
# assumes to invoke the platform Lambda + deploy via the reusable workflow.
|
||||
# The trust policy allows the consumer's CI runner (GitHub Actions /
|
||||
# Gitea act_runner) to assume this role. In a real deployment, the trust
|
||||
# policy is scoped to the consumer's OIDC provider; for offline-proven
|
||||
# mode, a placeholder trust is used.
|
||||
resource "aws_iam_role" "consumer_deploy" {
|
||||
name = "nova-${replace(var.consumer_repo, "/", "-")}-deploy"
|
||||
|
||||
assume_role_policy = jsonencode({
|
||||
Version = "2012-10-17"
|
||||
Statement = [
|
||||
{
|
||||
Effect = "Allow"
|
||||
Principal = {
|
||||
# Placeholder: in a real deployment, this is the consumer's
|
||||
# OIDC provider ARN. Offline-proven mode uses a wildcard.
|
||||
Federated = "arn:aws:iam::${var.account_id}:oidc-provider/token.actions.githubusercontent.com"
|
||||
}
|
||||
Action = "sts:AssumeRoleWithWebIdentity"
|
||||
Condition = {
|
||||
StringEquals = {
|
||||
"token.actions.githubusercontent.com:aud" = "sts.amazonaws.com"
|
||||
}
|
||||
StringLike = {
|
||||
"token.actions.githubusercontent.com:sub" = "repo:${var.consumer_repo}:*"
|
||||
}
|
||||
}
|
||||
}
|
||||
]
|
||||
})
|
||||
|
||||
tags = {
|
||||
"nova:owner" = var.owner_id
|
||||
"nova:contract" = var.consumer_repo
|
||||
"nova:environment" = "dev"
|
||||
}
|
||||
}
|
||||
|
||||
# P20 (REQ-184): inline policy granting the consumer's deploy role the
|
||||
# right to invoke the platform Lambda's Function URL, scoped via ABAC
|
||||
# (aws:PrincipalTag/nova:owner == var.owner_id). The platform Lambda's
|
||||
# resource-based policy + the consumer_invoke_policy.json template
|
||||
# enforce the ABAC scope at the Lambda side; this policy grants the
|
||||
# invoke permission on the consumer side.
|
||||
resource "aws_iam_role_policy" "consumer_invoke" {
|
||||
name = "nova-consumer-invoke"
|
||||
role = aws_iam_role.consumer_deploy.id
|
||||
|
||||
policy = jsonencode({
|
||||
Version = "2012-10-17"
|
||||
Statement = [
|
||||
{
|
||||
Effect = "Allow"
|
||||
Action = [
|
||||
"lambda:InvokeFunctionUrl",
|
||||
]
|
||||
Resource = [
|
||||
# The platform Lambda ARN (cross-account). The account_id is
|
||||
# the platform account, not the consumer account. For offline-
|
||||
# proven mode, a placeholder ARN is used.
|
||||
"arn:aws:lambda:${var.region}:000000000000:function:nova-contract-ingestor"
|
||||
]
|
||||
Condition = {
|
||||
StringEquals = {
|
||||
"aws:PrincipalTag/nova:owner" = var.owner_id
|
||||
}
|
||||
}
|
||||
}
|
||||
]
|
||||
})
|
||||
}
|
||||
|
||||
output "consumer_deploy_role_arn" {
|
||||
description = "The ARN of the consumer deploy role."
|
||||
value = aws_iam_role.consumer_deploy.arn
|
||||
}
|
||||
|
||||
output "consumer_deploy_role_name" {
|
||||
description = "The name of the consumer deploy role."
|
||||
value = aws_iam_role.consumer_deploy.name
|
||||
}
|
||||
@@ -593,4 +593,52 @@ class TestV14IdentityValidation:
|
||||
"""The _validate_caller_identity docstring documents the ABAC reliance."""
|
||||
docstring = ingestor._validate_caller_identity.__doc__
|
||||
assert "ABAC" in docstring
|
||||
assert "PrincipalTag" in docstring
|
||||
assert "PrincipalTag" in docstring
|
||||
|
||||
class TestOnboardConsumer:
|
||||
"""P18 (REQ-182): the onboard_consumer action writes a pending CMDB row."""
|
||||
|
||||
_ARN = "arn:aws:sts::000:assumed-role/nova-deploy/test"
|
||||
|
||||
def test_valid_onboarding_writes_pending_row(self, moto_contracts_table):
|
||||
payload = {
|
||||
"action": "onboard_consumer",
|
||||
"consumerRepo": "acdl/consumer-b",
|
||||
"requestedEnvironment": "dev",
|
||||
"ownerId": "team-b",
|
||||
"billingTag": "cost-center-b",
|
||||
}
|
||||
event = {"body": json.dumps(payload), "requestContext": {"identity": {"userArn": self._ARN}}}
|
||||
resp = ingestor.lambda_handler(event, None)
|
||||
assert resp["statusCode"] == 200
|
||||
body = json.loads(resp["body"])
|
||||
assert body["status"] == "pending"
|
||||
assert body["action"] == "onboard_consumer"
|
||||
assert body["requestedEnvironment"] == "dev"
|
||||
|
||||
def test_invalid_onboarding_rejected(self, moto_contracts_table):
|
||||
# An invalid consumerRepo (no /) fails the identity format check
|
||||
# (which runs for all actions) before the onboarding schema.
|
||||
payload = {
|
||||
"action": "onboard_consumer",
|
||||
"consumerRepo": "not-a-repo-format",
|
||||
"requestedEnvironment": "dev",
|
||||
"ownerId": "team-b",
|
||||
"billingTag": "cost-center-b",
|
||||
}
|
||||
event = {"body": json.dumps(payload), "requestContext": {"identity": {"userArn": self._ARN}}}
|
||||
resp = ingestor.lambda_handler(event, None)
|
||||
assert resp["statusCode"] == 400
|
||||
assert "invalid consumerRepo" in json.loads(resp["body"])["error"]
|
||||
|
||||
def test_missing_onboarding_field_rejected(self, moto_contracts_table):
|
||||
payload = {
|
||||
"action": "onboard_consumer",
|
||||
"consumerRepo": "acdl/consumer-b",
|
||||
"requestedEnvironment": "dev",
|
||||
# ownerId + billingTag missing
|
||||
}
|
||||
event = {"body": json.dumps(payload), "requestContext": {"identity": {"userArn": self._ARN}}}
|
||||
resp = ingestor.lambda_handler(event, None)
|
||||
assert resp["statusCode"] == 400
|
||||
assert "onboarding payload invalid" in json.loads(resp["body"])["error"]
|
||||
|
||||
@@ -34,4 +34,15 @@ class TestDocsCoverage:
|
||||
assert "How to Write an Adapter" in content
|
||||
assert "How to Wire" in content
|
||||
assert "How to Test" in content
|
||||
assert "Existing Adapters" in content
|
||||
assert "Existing Adapters" in content
|
||||
|
||||
def test_github_workflows_readme_catalogs_all_workflows():
|
||||
"""P16 (REQ-180): .github/workflows/README.md catalogs all 7 workflows."""
|
||||
from pathlib import Path
|
||||
readme = Path(__file__).resolve().parent.parent / ".github" / "workflows" / "README.md"
|
||||
assert readme.is_file(), ".github/workflows/README.md missing"
|
||||
text = readme.read_text()
|
||||
for wf in ["ci.yml", "deploy.yml", "modules-lifecycle.yml",
|
||||
"platform-test.yml", "primitives-plan.yml", "patterns-plan.yml",
|
||||
"release.yml"]:
|
||||
assert wf in text, f"{wf} not cataloged in .github/workflows/README.md"
|
||||
|
||||
@@ -21,7 +21,10 @@ class TestEnvironmentCheck:
|
||||
assert ok is False
|
||||
assert "nonexistent-env" in msg
|
||||
assert "onboarding" in msg.lower() or "Environment Onboarding" in msg
|
||||
assert "platform team" in msg.lower()
|
||||
# P19 (REQ-183): the message now routes to the self-service
|
||||
# request path (onboard_consumer), not "contact the platform team".
|
||||
assert "platform team" not in msg.lower()
|
||||
assert "onboard_consumer" in msg or "self-service" in msg.lower()
|
||||
|
||||
def test_onboarding_message_lists_platform_provisions(self):
|
||||
msg = _onboarding_message("qa")
|
||||
@@ -102,4 +105,16 @@ class TestRunPlatformWireIn:
|
||||
)
|
||||
assert result.returncode == 0, f"stdout: {result.stdout}\nstderr: {result.stderr}"
|
||||
assert "PLATFORM CHECK OK" in result.stdout
|
||||
assert "environment" in result.stdout.lower() or "Step 0" in result.stdout
|
||||
assert "environment" in result.stdout.lower() or "Step 0" in result.stdout
|
||||
|
||||
class TestOnboardingMessageSelfService:
|
||||
"""P19 (REQ-183): the onboarding message is self-service, not 'contact
|
||||
the platform team'."""
|
||||
|
||||
def test_no_contact_platform_team(self):
|
||||
msg = _onboarding_message("qa")
|
||||
assert "contact the platform team" not in msg.lower()
|
||||
|
||||
def test_mentions_self_service_request(self):
|
||||
msg = _onboarding_message("qa")
|
||||
assert "self-service" in msg.lower() or "onboard_consumer" in msg
|
||||
|
||||
@@ -0,0 +1,50 @@
|
||||
"""Unit tests for core/onboarding.py (P19, REQ-183)."""
|
||||
|
||||
import json
|
||||
import sys
|
||||
from pathlib import Path
|
||||
|
||||
import pytest
|
||||
|
||||
sys.path.insert(0, str(Path(__file__).resolve().parent.parent))
|
||||
|
||||
from core.onboarding import generate_env_file, _onboarding_request_message
|
||||
|
||||
|
||||
class TestGenerateEnvFile:
|
||||
"""P19 (REQ-183): generate_env_file produces a valid env JSON."""
|
||||
|
||||
def test_generates_env_with_request_fields(self):
|
||||
request = {
|
||||
"consumerRepo": "acdl/consumer-b",
|
||||
"requestedEnvironment": "qa",
|
||||
"ownerId": "team-b",
|
||||
"billingTag": "cost-center-b",
|
||||
}
|
||||
env = generate_env_file(request, template_env="dev")
|
||||
assert env["name"] == "qa"
|
||||
assert env["ownerId"] == "team-b"
|
||||
assert env["billingTag"] == "cost-center-b"
|
||||
assert env["account_id"] == "000000000000" # placeholder
|
||||
assert "consumer-b" in env["description"]
|
||||
|
||||
def test_preserves_template_network_and_state(self):
|
||||
request = {
|
||||
"consumerRepo": "acdl/c",
|
||||
"requestedEnvironment": "prod",
|
||||
"ownerId": "team-a",
|
||||
"billingTag": "cc-a",
|
||||
}
|
||||
env = generate_env_file(request, template_env="dev")
|
||||
assert "vpc_cidr" in env["network"]
|
||||
assert "bucket" in env["state_backend"]
|
||||
assert env["region"] == "us-east-1"
|
||||
|
||||
|
||||
class TestOnboardingRequestMessage:
|
||||
"""P19 (REQ-183): the request message is self-service."""
|
||||
|
||||
def test_message_mentions_onboard_consumer(self):
|
||||
msg = _onboarding_request_message("dev")
|
||||
assert "onboard_consumer" in msg
|
||||
assert "Nova" in msg
|
||||
@@ -0,0 +1,38 @@
|
||||
"""Unit tests for terraform/onboarding (P20, REQ-184)."""
|
||||
|
||||
import subprocess
|
||||
from pathlib import Path
|
||||
|
||||
import pytest
|
||||
|
||||
ROOT = Path(__file__).resolve().parent.parent
|
||||
ONBOARDING_DIR = ROOT / "terraform" / "onboarding"
|
||||
|
||||
|
||||
def test_onboarding_terraform_dir_exists():
|
||||
"""P20 (REQ-184): terraform/onboarding/ exists with main.tf + README."""
|
||||
assert ONBOARDING_DIR.is_dir()
|
||||
assert (ONBOARDING_DIR / "main.tf").is_file()
|
||||
assert (ONBOARDING_DIR / "README.md").is_file()
|
||||
|
||||
|
||||
def test_onboarding_terraform_validates():
|
||||
"""P20 (REQ-184): terraform validate passes for the onboarding module
|
||||
(offline-proven, D-114). Skipped if terraform is not installed."""
|
||||
if not subprocess.call(["which", "terraform"], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL) == 0:
|
||||
pytest.skip("terraform not installed")
|
||||
rc = subprocess.call(
|
||||
["terraform", "validate"],
|
||||
cwd=str(ONBOARDING_DIR),
|
||||
stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL,
|
||||
)
|
||||
assert rc == 0, "terraform validate failed for terraform/onboarding/"
|
||||
|
||||
|
||||
def test_onboarding_main_tf_has_nova_tags():
|
||||
"""P20 (REQ-184): the deploy role is tagged with nova:owner + nova:contract."""
|
||||
main_tf = (ONBOARDING_DIR / "main.tf").read_text()
|
||||
assert '"nova:owner"' in main_tf
|
||||
assert '"nova:contract"' in main_tf
|
||||
assert "aws_iam_role" in main_tf
|
||||
assert "lambda:InvokeFunctionUrl" in main_tf
|
||||
Reference in New Issue
Block a user