Compare commits
5 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 78688b968c | |||
| 7e98debd70 | |||
| 255cde5002 | |||
| 2cc76f4f94 | |||
| 9acf23926d |
@@ -1,22 +1,22 @@
|
|||||||
{
|
{
|
||||||
"phase": 3,
|
"phase": 4,
|
||||||
"stage": "complete",
|
"stage": "complete",
|
||||||
"milestone": "v1.25",
|
"milestone": "v1.25",
|
||||||
"phase_role": "execution",
|
"phase_role": "execution",
|
||||||
"attempts": 0,
|
"attempts": 0,
|
||||||
"updated_at": "2026-08-12T17:30:00Z",
|
"updated_at": "2026-08-12T17:45:00Z",
|
||||||
"project": "acdl",
|
"project": "acdl",
|
||||||
"milestone_complete": false,
|
"milestone_complete": false,
|
||||||
"tag_line": "v1.24.x",
|
"tag_line": "v1.24.x",
|
||||||
"tag": "v1.24.3",
|
"tag": "v1.24.4",
|
||||||
"next_tag": "v1.24.4",
|
"next_tag": "v1.24.5",
|
||||||
"release": {
|
"release": {
|
||||||
"forge": "gitea",
|
"forge": "gitea",
|
||||||
"releases_created": true,
|
"releases_created": true,
|
||||||
"release_ids": {"v1.24.0": 640, "v1.24.1": 641, "v1.24.2": 642, "v1.24.3": 643},
|
"release_ids": {"v1.24.0": 640, "v1.24.1": 641, "v1.24.2": 642, "v1.24.3": 643, "v1.24.4": 644},
|
||||||
"phase_release_id": 643
|
"phase_release_id": 644
|
||||||
},
|
},
|
||||||
"requirements": ["REQ-291", "REQ-292", "REQ-293", "REQ-294", "REQ-295", "REQ-296", "REQ-297", "REQ-298", "REQ-299", "REQ-300", "REQ-301", "REQ-302", "REQ-303", "REQ-308", "REQ-309"],
|
"requirements": ["REQ-291", "REQ-292", "REQ-293", "REQ-294", "REQ-295", "REQ-296", "REQ-297", "REQ-298", "REQ-299", "REQ-300", "REQ-301", "REQ-302", "REQ-303", "REQ-304", "REQ-305", "REQ-306", "REQ-307", "REQ-308", "REQ-309"],
|
||||||
"tests": {"total": 88, "passed": 88, "skipped": 11, "failed": 0},
|
"tests": {"total": 170, "passed": 170, "skipped": 23, "failed": 0, "preexisting_flaky": "test_metrics_emitters.py::test_attestation_event_emission (fails on main, unrelated to v1.25)"},
|
||||||
"notes": "v1.25 P3 (plan-JSON+meta+pipeline) complete. Tag v1.24.3 (gitea release id 643). 4 requirements (REQ-300..303). 5 plan-JSON+meta policies. run_platform.sh Step 5b wired. Phase 03 branch deleted. Next: P4 regression-gate policies + docs."
|
"notes": "v1.25 P4 (regression-gate+docs) complete. Tag v1.24.4 (gitea release id 644). 4 requirements (REQ-304..307). 3 regression policies + adapter/STANDARDS/METRICS/schemas docs. Phase 04 branch deleted. All 19 requirements now implemented. Next: P5 final review+audit+milestone ship."
|
||||||
}
|
}
|
||||||
@@ -18,7 +18,7 @@
|
|||||||
"all": [
|
"all": [
|
||||||
{
|
{
|
||||||
"check": {
|
"check": {
|
||||||
"id": "{{ to_string(@) }}"
|
"id": "(regex_match('^[a-z][a-z0-9-]{2,5}$', @))"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
|
|||||||
+45
-2
@@ -533,7 +533,7 @@ if command -v kj >/dev/null 2>&1; then
|
|||||||
if [ -f "$TF_DIR/tfplan" ]; then
|
if [ -f "$TF_DIR/tfplan" ]; then
|
||||||
terraform -chdir="$TF_DIR" show -json tfplan > "$WORK/tfshow.json" 2>/dev/null || true
|
terraform -chdir="$TF_DIR" show -json tfplan > "$WORK/tfshow.json" 2>/dev/null || true
|
||||||
if [ -s "$WORK/tfshow.json" ]; then
|
if [ -s "$WORK/tfshow.json" ]; then
|
||||||
python3 - <<'PY' > "$WORK/kj-pcr.json" 2>"$WORK/kj.err" || echo "[]"
|
python3 - "$WORK/tfshow.json" "$CONTRACT_ID" <<'PY' > "$WORK/kj-pcr.json" 2>"$WORK/kj.err" || echo "[]"
|
||||||
import json, sys
|
import json, sys
|
||||||
from pathlib import Path
|
from pathlib import Path
|
||||||
sys.path.insert(0, ".")
|
sys.path.insert(0, ".")
|
||||||
@@ -541,10 +541,11 @@ import importlib.util
|
|||||||
_spec = importlib.util.spec_from_file_location("kj_engine", "adapters/kyverno-json/kyverno_json_engine.py")
|
_spec = importlib.util.spec_from_file_location("kj_engine", "adapters/kyverno-json/kyverno_json_engine.py")
|
||||||
_mod = importlib.util.module_from_spec(_spec)
|
_mod = importlib.util.module_from_spec(_spec)
|
||||||
_spec.loader.exec_module(_mod)
|
_spec.loader.exec_module(_mod)
|
||||||
|
_payload_path, _contract_id = sys.argv[1], sys.argv[2]
|
||||||
eng = _mod.KyvernoJsonEngine()
|
eng = _mod.KyvernoJsonEngine()
|
||||||
if not eng.is_configured():
|
if not eng.is_configured():
|
||||||
print("[]"); sys.exit(0)
|
print("[]"); sys.exit(0)
|
||||||
out = eng.evaluate(json.load(open("$WORK/tfshow.json")), Path("adapters/kyverno-json/policies/plan-json"), "$CONTRACT_ID")
|
out = eng.evaluate(json.load(open(_payload_path)), Path("adapters/kyverno-json/policies/plan-json"), _contract_id)
|
||||||
print(json.dumps(out))
|
print(json.dumps(out))
|
||||||
PY
|
PY
|
||||||
if [ -s "$WORK/kj-pcr.json" ]; then
|
if [ -s "$WORK/kj-pcr.json" ]; then
|
||||||
@@ -571,6 +572,48 @@ else
|
|||||||
fi
|
fi
|
||||||
echo ""
|
echo ""
|
||||||
|
|
||||||
|
# ============================================================================
|
||||||
|
# Step 5c: kyverno-json meta-policies over the merged PCR list (v1.25, REQ-303)
|
||||||
|
# ============================================================================
|
||||||
|
# After Step 5b merges the Checkov/Wiz + kj plan-JSON PCRs into pcr.json, run
|
||||||
|
# the meta-policies (block-on-any-critical, tagging-rules-agree) over the
|
||||||
|
# merged list. The meta-policy PCRs are appended to pcr.json before the
|
||||||
|
# confidence signal runs. The confidence_signal.py PENALTY["critical"]: None
|
||||||
|
# hard-override stays as defense-in-depth behind this declarative rule
|
||||||
|
# (D-119). Skips gracefully when kj is absent (D-120).
|
||||||
|
if command -v kj >/dev/null 2>&1 && [ -s "$WORK/pcr.json" ]; then
|
||||||
|
echo "=== Step 5c: kyverno-json meta-policies over the merged PCR list ==="
|
||||||
|
python3 - "$WORK/pcr.json" "$CONTRACT_ID" <<'PY' > "$WORK/meta-pcr.json" 2>"$WORK/meta.err" || echo "[]"
|
||||||
|
import json, sys
|
||||||
|
from pathlib import Path
|
||||||
|
sys.path.insert(0, ".")
|
||||||
|
import importlib.util
|
||||||
|
_spec = importlib.util.spec_from_file_location("kj_engine", "adapters/kyverno-json/kyverno_json_engine.py")
|
||||||
|
_mod = importlib.util.module_from_spec(_spec)
|
||||||
|
_spec.loader.exec_module(_mod)
|
||||||
|
eng = _mod.KyvernoJsonEngine()
|
||||||
|
if not eng.is_configured():
|
||||||
|
print("[]"); sys.exit(0)
|
||||||
|
pcrs = json.load(open(sys.argv[1]))
|
||||||
|
out = eng.evaluate(pcrs, Path("adapters/kyverno-json/policies/meta"), sys.argv[2])
|
||||||
|
print(json.dumps(out))
|
||||||
|
PY
|
||||||
|
if [ -s "$WORK/meta-pcr.json" ]; then
|
||||||
|
python3 -c "
|
||||||
|
import json
|
||||||
|
merged = json.load(open('$WORK/pcr.json'))
|
||||||
|
meta = json.load(open('$WORK/meta-pcr.json'))
|
||||||
|
json.dump(merged + meta, open('$WORK/pcr.json', 'w'))
|
||||||
|
print(f'meta-policies: {len(meta)} meta-PCRs appended; total PCR list now {len(merged)+len(meta)}')
|
||||||
|
"
|
||||||
|
else
|
||||||
|
echo "kyverno-json meta-policies produced no output; proceeding with the merged list only"
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
echo "=== Step 5c: kj not installed or no merged PCR list; skipping meta-policies (D-120) ==="
|
||||||
|
fi
|
||||||
|
echo ""
|
||||||
|
|
||||||
echo "=== Step 7: confidence signal compute ==="
|
echo "=== Step 7: confidence signal compute ==="
|
||||||
python3 <<PY > "$WORK/signal.json" || fail "confidence signal failed"
|
python3 <<PY > "$WORK/signal.json" || fail "confidence signal failed"
|
||||||
import json
|
import json
|
||||||
|
|||||||
@@ -27,6 +27,11 @@ class TestStep5bKyvernoJsonWiring:
|
|||||||
assert "Step 5b: kyverno-json plan-JSON policies" in s, \
|
assert "Step 5b: kyverno-json plan-JSON policies" in s, \
|
||||||
"run_platform.sh must have a Step 5b kyverno-json block (REQ-301)"
|
"run_platform.sh must have a Step 5b kyverno-json block (REQ-301)"
|
||||||
|
|
||||||
|
def test_step_5c_meta_block_present(self):
|
||||||
|
s = _read_script()
|
||||||
|
assert "Step 5c: kyverno-json meta-policies over the merged PCR list" in s, \
|
||||||
|
"run_platform.sh must have a Step 5c meta-policy block (REQ-303, P1-1 fix)"
|
||||||
|
|
||||||
def test_kj_scan_invocation_present(self):
|
def test_kj_scan_invocation_present(self):
|
||||||
s = _read_script()
|
s = _read_script()
|
||||||
assert "adapters/kyverno-json/policies/plan-json" in s, \
|
assert "adapters/kyverno-json/policies/plan-json" in s, \
|
||||||
|
|||||||
Reference in New Issue
Block a user