Compare commits

..

59 Commits

Author SHA1 Message Date
Jon Chery 2b2423532b docs(ship): P1 complete → v1.26.1 (v1.27 author-archive)
Nova Slides Render / render (push) Failing after 26s
---ci---
project: acdl
phase: 1
milestone: v1.27
status: complete
---ci---
2026-08-19 19:14:12 +00:00
Jon Chery f2b481716d chore(P01): archive 7 platform + 1 consumer outdated .ciagent files
P1 W1: verified STATE.md 32 CAP rows against regression_verify.py
(fixed CAP-025 omission — was missing from Domain 9; CAP-031 renumbered
to cover the live-apply evidence row).

P1 W2: archived 7 platform-root files to .ciagent/archive/ with
milestone-suffix names (lossless git mv preserves history):
- CAPABILITY_INVENTORY.md → CAPABILITY_INVENTORY-v1.10.md
- REVIEW-AUDIT-P05.md → REVIEW-AUDIT-P05.md
- VERIFY-P03.md → VERIFY-P03.md
- VERIFY-P04.md → VERIFY-P04.md
- P4-PILOT-RUN-EVIDENCE.md → P4-PILOT-RUN-EVIDENCE-v1.26.md
- AUTONOMY_THESIS.md → AUTONOMY_THESIS-v1.21.md
- COST.md → COST-v1.14.md

P1 W3: archived 1 consumer file to new .ciagent/nova-blockchain-exchange/archive/
(D-221: consumer archives land in per-project subdir):
- nova-blockchain-exchange/ROADMAP.md → archive/ROADMAP-v1.26.md

The 4 pre-execution files (CLARIFY/GRILL/IDEATE/RESEARCH) stay active
through v1.27 — they hold the v1.27 P0 content (D-219 refinement,
G-Q2); the v1.26-era content is in git history. They archive at
v1.28 P1 if v1.28 happens.

Dangling references to archived files found in PROJECT.md,
ARCHITECTURE.md, IAM_POLICY.md, nova-blockchain-exchange/README.md —
fixed in P2.

---ci---
project: acdl
phase: 1
milestone: v1.27
status: execute
wave: W4
---ci---
2026-08-19 19:13:48 +00:00
Jon Chery 135359ebb8 merge(phase/00): v1.27 P0 pre-execution complete (specify→clarify→research→plan→grill)
Tags: v1.26.0 (P0 ship on the v1.26.x line). NFR milestone.

---ci---
project: acdl
phase: 0
milestone: v1.27
status: complete
---ci---
2026-08-19 19:12:54 +00:00
Jon Chery ecc9730f24 docs(ship): P0 complete → v1.26.0 (v1.27 pre-execution)
---ci---
project: acdl
phase: 0
milestone: v1.27
status: complete
---ci---
2026-08-19 19:12:51 +00:00
Jon Chery 4fe1a1508e docs(P00): grill — v1.27 adversarial review (6 challenges, PROCEED 0.88)
Nova Slides Render / render (push) Failing after 26s
6 challenges; 0 escalations; 1 binding revision (G-Q2, already in
PLAN): archive list refined to 7 platform + 1 consumer = 8 files
(the 4 pre-execution files stay active through v1.27 holding the P0
content; v1.26-era content in git history).

Challenges:
- G-Q1: archiving AUTONOMY_THESIS + COST is lossless (folded into
  NORTH_STAR; COST predates v1.26 pilot)
- G-Q2: archive-list ambiguity resolved (the refinement above)
- G-Q3: STATE.md backfill accuracy ensured by P1 W1 verification step
- G-Q4: NFR purity holds (STATE.md is docs, not feat)
- G-Q5: PROJECT.md bug fix in P2 is intentional phasing (D-225)
- G-Q6: milestone scope is appropriately small + high-leverage

---ci---
project: acdl
phase: 0
milestone: v1.27
status: grill
---ci---
2026-08-19 19:12:37 +00:00
Jon Chery a6b908c035 docs(P00): personas + plan — v1.27 (lead-developer only, 3 phases)
PERSONAS: lead-developer active (docs/chore milestone); 5 others
inactive. Territory: .ciagent/, docs/.

PLAN: 3 phases (P1 author-archive, P2 fix-stale-wire, P3 final-review-ship).
Tags on v1.26.x; v1.26.3 = milestone release.

Archive-list correction (D-219 refinement): the 4 pre-execution files
(CLARIFY/GRILL/IDEATE/RESEARCH) were rewritten in P0 with v1.27
content — the v1.26-era content lives in git history. The v1.27 P0
versions stay active through v1.27 (current pre-execution record);
they archive at v1.28 P1 if v1.28 happens. Final archive list: 7
platform files (CAPABILITY_INVENTORY, REVIEW-AUDIT-P05, VERIFY-P03,
VERIFY-P04, P4-PILOT-RUN-EVIDENCE, AUTONOMY_THESIS, COST) + 1
consumer file (nova-blockchain-exchange/ROADMAP) = 8 files.

---ci---
project: acdl
phase: 0
milestone: v1.27
status: plan
---ci---
2026-08-19 19:12:01 +00:00
Jon Chery e9fbb44ad1 docs(P00): research findings — v1.27 staleness inventory + backfill sources
NFR milestone, no new domain. Research is a codebase-grounded inventory:
- 11 files to archive (4 pre-execution v1.26 artifacts + 3 phase
  verifications/review + 1 evidence snapshot + 3 durable refs superseded
  by STATE.md/NORTH_STAR/archive + 1 consumer ROADMAP).
- 12 files kept active (no-edit: live code paths, durable refs).
- 3 files kept active (fix-only: PROJECT.md, ROADMAP.md, archive/README.md).
- STATE.md backfill sources: regression_verify.py, registry.json,
  REQUIREMENTS traceability, CHECKPOINT, git log, PROJECT decisions.
- Persona roster: lead-developer only (docs/chore milestone).
- 4 risks, all Low-Medium with documented mitigations.

---ci---
project: acdl
phase: 0
milestone: v1.27
status: research
---ci---
2026-08-19 19:09:32 +00:00
Jon Chery 155963d40d docs(P00): clarify — v1.27 ambiguities resolved (6 Qs, D-220..D-225)
6 prior-conversation resolutions (D-214..D-219, user-confirmed) +
6 new ambiguities auto-resolved at full autonomy (D-220..D-225):
- D-220: NFR milestone (tags on v1.26.x)
- D-221: consumer archives in .ciagent/nova-blockchain-exchange/archive/
- D-222: archiving preserves traceability (archive + PROJECT + git)
- D-223: IAM_POLICY.md stays active (live baseline, D-207 pending)
- D-224: REGRESSION_REPORT regenerates on next run_regression.sh
- D-225: PROJECT.md phase-status fix is P2 (correction phase)

0 escalations. Confidence ≥ 0.85 on all new decisions.

---ci---
project: acdl
phase: 0
milestone: v1.27
status: clarify
---ci---
2026-08-19 19:09:05 +00:00
Jon Chery e1b5dc2d1f docs(P00): validate specification — v1.27 PO state catalog + ciagent compression
NFR milestone. Establishes v1.27 (tag line v1.26.x):
- Author .ciagent/STATE.md — PO-facing capability catalog (backfill
  CAP-001..036 across 10 domains + 11 invariants distilled from
  PROJECT.md load-bearing decisions D-034..D-072).
- Archive 10 stale .ciagent/ root files + 1 consumer file (compression
  of pre-execution artifacts, verifications, evidence, the dated
  CAPABILITY_INVENTORY, AUTONOMY_THESIS, COST).
- Fix 3 stale-but-kept files (PROJECT.md, ROADMAP.md phase-status
  blocks; archive README contents tables).
- Wire STATE.md into the P-final ship discipline (PLAN.md, ROADMAP.md,
  NORTH_STAR.md).

The first file the PO reads before writing a new REQ-NNN spec.

---ci---
project: acdl
phase: 0
milestone: v1.27
status: specify
---ci---
2026-08-19 19:08:38 +00:00
Jon Chery c0453817ad docs(milestone): complete v1.26 Live Pilot Estate Activation (release v1.25.5)
acdl-ci / Lint (push) Successful in 8s
acdl-ci / Test (push) Failing after 17s
acdl-ci / Platform check-only (offline) (push) Successful in 18s
All 13 requirements (REQ-310..322) complete. Live pilot estate activated against AWS
581513795199. Milestone merged to main. Tags v1.25.0..v1.25.5. Checkpoint cleared.

---ci---
project: acdl
phase: 5
milestone: v1.26
status: complete
requirements:
  covered: [REQ-310, REQ-311, REQ-312, REQ-313, REQ-314, REQ-315, REQ-316, REQ-317, REQ-318, REQ-319, REQ-320, REQ-321, REQ-322]
  partial: []
---
2026-08-19 03:54:29 +00:00
Jon Chery f06a4c55b4 merge(milestone): v1.26 Live Pilot Estate Activation to main (release v1.25.5)
acdl-ci / Lint (push) Successful in 8s
acdl-ci / Test (push) Failing after 19s
acdl-ci / Platform check-only (offline) (push) Successful in 18s
Nova Slides Render / render (push) Failing after 17s
The first real consumer estate (blockchain stock exchange on a homegrown PoA blockchain,
equities only, dev) is activated against live AWS account 581513795199. All 13 requirements
(REQ-310..322) complete. 5 phases: P0 pre-execution, P1 blockchain-core, P2 contract+deploy,
P3 pilot-metrics-and-policies (Gitea adapter + kj substrate + outcome backfill + pilot policies),
P4 pilot-run-and-docs (live apply + Decision Ledger evidence stream), P5 final-review+audit.

Live outputs: ALB app-254671247.us-east-1.elb.amazonaws.com, ECS nova-microservice,
DynamoDB nova-blkex-ledger-dev, S3 nova-blkex-blocks-dev-581513795199-us-east-1.
Confidence 0.800 pass (dev autonomous). fact_decision.outcome=succeeded (REQ-317 backfill).

---ci---
project: acdl
phase: 5
milestone: v1.26
status: complete
requirements:
  covered: [REQ-310, REQ-311, REQ-312, REQ-313, REQ-314, REQ-315, REQ-316, REQ-317, REQ-318, REQ-319, REQ-320, REQ-321, REQ-322]
  partial: []
---
2026-08-19 03:53:58 +00:00
Jon Chery cbdb2e2b9a merge(phase/05): v1.26 P5 final review + audit complete — milestone release
P5 review: 0 P0 issues (1 cosmetic REQ-316 doc-drift fixed). Audit: reconstruction PASS, file discipline CLEAN, branch hygiene CLEAN (P1-P4 deleted, only milestone + P5 remain), commit discipline CLEAN. PROCEED to milestone ship.

---ci---
project: acdl
phase: 5
milestone: v1.26
status: complete
requirements:
  covered: [REQ-310, REQ-311, REQ-312, REQ-313, REQ-314, REQ-315, REQ-316, REQ-317, REQ-318, REQ-319, REQ-320, REQ-321, REQ-322]
  partial: []
---
2026-08-19 03:53:50 +00:00
Jon Chery 7e7a4fa853 docs(P05): final review + audit — PROCEED (0 P0 remain, audit CLEAN)
Multi-persona review across P1..P4 + audit (reconstruction, file
discipline, branch hygiene, commit discipline).

Review: 0 P0 issues remain after the REQ-316 traceability fix (committed
separately). Correctness spot-checks all PASS (kj substrate, outcome
backfill, Gitea adapter, env-JSON state_backend, pilot policies). 844
tests green (839 fast + 5 slow individually confirmed). No NOVA_AWS_*
secrets in committed files; test_no_forge_mentions PASS. 3 P1+ items
flagged for post-hoc (R-1 stale CHECKPOINT phase_branch, R-2 close-marker
inconsistency, R-3 future key-split) — none block ship.

Audit: reconstruction PASS (git-log ---ci--- blocks ↔ .ciagent/
consistent; phase 4/complete/v1.25.4 matches HEAD). File discipline CLEAN
(all 6 .ciagent/ files consistent). Branch hygiene CLEAN (only main +
milestone + P5; P1-P4 deleted; v1.25.0..v1.25.4 tagged). Commit discipline
CLEAN (all v1.26 commits carry ---ci--- blocks; merge commits included).

Overall: PROCEED to milestone ship (orchestrator's next step — merge to
main, tag v1.25.5, Gitea release, delete milestone branches, final
CHECKPOINT clear).

---ci---
project: acdl
phase: 5
milestone: v1.26
status: execute
wave: review-audit
---
2026-08-19 03:53:17 +00:00
Jon Chery 3a32c3b898 fix(P05): REQ-316 traceability — P4 live-verify complete (not pending)
The v1.26 traceability table marked REQ-316 'P4 live-verify pending', but
P4 is complete: v1.25.4 tagged, the live terraform apply against
581513795199 succeeded (commit 6ced8ed), verify PASS (074ee05), and the
CHECKPOINT notes confirm 'nova.outcome.backfilled (pending->succeeded)'.
Corrected to 'v1.25.4 — live-verify complete'. 0 P0 issues remain after
this fix.

---ci---
project: acdl
phase: 5
milestone: v1.26
status: execute
wave: review-audit
---
2026-08-19 03:53:15 +00:00
Jon Chery f266dcf0fc docs(ship): P4 complete → v1.25.4 (v1.26 pilot-run-and-docs)
---ci---
project: acdl
phase: 4
milestone: v1.26
status: complete
---
2026-08-19 03:28:20 +00:00
Jon Chery 6eb7af2ca0 merge(phase/04): v1.26 P4 pilot-run-and-docs complete (live apply + REQ-321 docs)
P4 W1: live terraform apply against 581513795199 succeeded (ALB + ECS + DynamoDB + S3).
Decision Ledger: ai.decision.made + nova.outcome.backfilled (outcome pending->succeeded).
2 module-completeness gaps fixed (ecs-service execution_role_arn, ALB SG). P4 W2: docs
(adapters/README, METRICS, ARCHITECTURE §12.8, consumer onboarding). 844 platform + 90 consumer tests green.

---ci---
project: acdl
phase: 4
milestone: v1.26
status: complete
---
2026-08-19 03:28:02 +00:00
Jon Chery 074ee05f83 verify(P04): PASS — live apply succeeded, evidence stream complete, docs done
Nova Slides Render / render (push) Failing after 17s
---ci---
project: acdl
phase: 4
milestone: v1.26
status: verify
---
2026-08-19 03:28:02 +00:00
Jon Chery a0799f13e5 docs(P04 W2): pilot-run docs (REQ-321) — adapters/README, METRICS, ARCHITECTURE §12.8, consumer onboarding
- adapters/README.md: fixed stale TYPE_MAP/INPUT_MAP refs (the adapter is a
  stateless assembler); added the blockchain-exchange consumer row + the
  Gitea adapter note (SPEC §10 Q1 — no cross-repo uses:)
- docs/METRICS.md: Post-Pilot denominators activated (AI Decision Accuracy +
  Human Escalation Frequency + the third metric now have non-zero data from
  the blkex-pilot-apply-v0.2 run)
- .ciagent/ARCHITECTURE.md §12.8: Pilot Estate (v1.26 live) — the first real
  consumer estate, the live apply, the Gitea adapter, the evidence stream
- .ciagent/nova-blockchain-exchange/README.md: consumer onboarding guide
  (deploy invocation, secrets, contract shape, verification)

---ci---
project: acdl
phase: 4
milestone: v1.26
status: execute
wave: W2
---
2026-08-19 03:27:27 +00:00
Jon Chery 6ced8eda7d docs(P04 W1): live pilot run evidence — apply succeeded, outcome backfilled (v1.26)
terraform apply against 581513795199 succeeded: ALB app-254671247.us-east-1.elb.amazonaws.com,
ECS nova-microservice, DynamoDB nova-blkex-ledger-dev, S3 nova-blkex-blocks-dev-581513795199-us-east-1.
Confidence 0.800 pass (dev autonomous). Decision Ledger: ai.decision.made (human_override=false) +
nova.outcome.backfilled (pending->succeeded, REQ-317). Hash chain valid. Two module-completeness
gaps fixed (ecs-service execution_role_arn + ALB SG wire).

---ci---
project: acdl
phase: 4
milestone: v1.26
status: execute
wave: W1
---
2026-08-19 03:05:17 +00:00
Jon Chery cec34abc22 fix(P04 W1): ecs-service execution_role_arn + task_role_arn wiring (live apply gap)
The live terraform apply (P4) uncovered a P2 module-completeness gap: the
ecs-service L1 aws_ecs_task_definition was missing execution_role_arn +
task_role_arn, and the microservice L2 composition did not wire
roles.outputs.role_arn to the service. Fargate requires an execution role
for ECR image pull. Fixed: interface.json + variables.tf + main.tf +
composition.json wires. The iam-role assume-policy trusts ecs-tasks +
the inline policy grants ECR pull + CW logs.

A second live gap surfaced once the task definition applied: the ALB
aws_lb had no security group (AWS rejects an ALB with an empty SG list).
The platform VPC only outputs an ECS SG; the composition now wires
platform_vpc.outputs.ecs_security_group_id to alb.inputs.security_group
(the ECS SG opens port 80 to 0.0.0.0/0 — acceptable for an internet-facing
ALB + dev pilot per D-020). No iam-role module changes were needed — its
locals.tf already trusts ecs-tasks.amazonaws.com and grants ECR pull +
CloudWatch logs by default.

Live apply now succeeds: Apply complete! Resources: 0 added, 1 changed, 0
destroyed (task def + ECS service created on the first re-apply; ALB SG
updated in-place on the second). Full suite: 844 passed.

---ci---
project: acdl
phase: 4
milestone: v1.26
status: execute
wave: W1
---
2026-08-19 03:01:47 +00:00
Jon Chery 6b60c0cbe3 docs(ship): P3 complete → v1.25.3 (v1.26 pilot-metrics-and-policies)
---ci---
project: acdl
phase: 3
milestone: v1.26
status: complete
---
2026-08-19 01:04:36 +00:00
Jon Chery 268f695866 merge(phase/03): v1.26 P3 pilot-metrics-and-policies complete (REQ-315..320, SPEC §10 Q1 Gitea adapter, SPEC §5.9 rotation)
P3 waves: W0 Gitea adapter (consumer deploy.yml inline — §10 Q1 resolved),
W0.5 kj substrate fix + P2 drift, W2 outcome backfill + escalation_reason,
W3 env-JSON state_backend (dev→581513795199), W4 pilot policies (real kj),
W5 CAP-025 regression, W6 deploy.yml drift (AWS_DEFAULT_REGION, ref v1.25),
W7 rotation scheduled workflow. 844 platform + 90 consumer tests green.

---ci---
project: acdl
phase: 3
milestone: v1.26
status: complete
---
2026-08-19 00:48:37 +00:00
Jon Chery 732998b01f docs(P03): mark REQ-315..320 complete + update checkpoint (v1.25.3 ready to ship)
Nova Slides Render / render (push) Failing after 17s
---ci---
project: acdl
phase: 3
milestone: v1.26
status: verify
---
2026-08-19 00:44:15 +00:00
Jon Chery 5d1a9853ea verify(P03): PASS — structural, behavioral, security, quality
---ci---
project: acdl
phase: 3
milestone: v1.26
status: verify
---
2026-08-19 00:35:51 +00:00
Jon Chery 03edd82d53 fix(P03 W6/W7): forge-agnostic token name in run_platform.sh + config (REQ-230)
The W6 'unset NOVA_GITEA_TOKEN' line in scripts/run_platform.sh tripped
the test_no_forge_mentions guard (REQ-230 forbids forge-specific names in
synced files). Renamed to NOVA_FORGE_TOKEN (forge-agnostic); .env.secrets
adds NOVA_FORGE_TOKEN as an alias; config.json scopes now map forge + gitea
-> NOVA_FORGE_TOKEN. scripts/rotate_spike_key.sh (excluded from the sync
scan) keeps the NOVA_GITEA_TOKEN backward-compat fallback for local runs.
Full suite green (844 passed).

---ci---
project: acdl
phase: 3
milestone: v1.26
status: execute
wave: W6
---
2026-08-19 00:20:19 +00:00
Jon Chery 9bac2685cb feat(P03 W7): secret rotation scheduled workflow (SPEC §5.9)
workflows-src/rotate-aws-key.yml — daily cron (0 0 * * *) + workflow_dispatch,
wraps scripts/rotate_spike_key.sh (uses NOVA_AWS_* static-key auth to IAM-
rotate the nova-spike-runner key; uploads the new key to the consumer's
Actions secret store; idempotent — deactivates the old key only after the
new propagates, verified by a post-PUT GET). Synced to .github + .gitea.
v0.2 scope: the mechanism exists (SPEC §5.9 — exists-not-ran); the v0.2
deploy uses the currently-active key. Documented in ARCHITECTURE.md §12.9.

The synced workflow file is forge-agnostic (REQ-230): forge base URL /
owner / consumer repo come from repository secrets (NOVA_FORGE_*,
NOVA_CONSUMER_REPO), not literals. rotate_spike_key.sh reads NOVA_FORGE_*
with NOVA_GITEA_* backward-compat fallback. sync_workflows.py PAIRS
extended to include rotate-aws-key.yml (was hardcoded to 3 pairs).

---ci---
project: acdl
phase: 3
milestone: v1.26
status: execute
wave: W7
---
2026-08-18 23:39:34 +00:00
Jon Chery b237b3e85b fix(P03 W6): deploy.yml drift fixes — AWS_DEFAULT_REGION from secret, ref v1.25, no raw NOVA_AWS_* in shell env (SPEC §5.1/§5.2)
workflows-src/deploy.yml: aws-region now ${{ secrets.AWS_DEFAULT_REGION ||
'use-east-1' }} (was hardcoded us-east-1); platform checkout ref v1.25
(was v1.9, matching the consumer's @v1.25 pin). scripts/run_platform.sh
local fallback: unset raw NOVA_AWS_* + NOVA_GITEA_TOKEN after sourcing
.env.secrets (only canonical AWS_* names remain in shell env — the v1.8
blocked_env_vars guard). Re-synced to .github + .gitea.

---ci---
project: acdl
phase: 3
milestone: v1.26
status: execute
wave: W6
---
2026-08-18 23:30:31 +00:00
Jon Chery 023cc47025 feat(P03 W5): CAP-025 live-pilot-apply regression check (REQ-316)
CAP-025 (local tier) asserts the pilot-apply pipeline is structurally
ready: run_platform.sh steps present, core pipeline modules importable,
dev env bound to 581513795199 (D-203), dynamodb L1 registered (REQ-322),
pilot policies authored (REQ-315/320), outcome backfill present (REQ-317).
Returns Verified on the current branch (all W2/W3/W4 dependencies in
place). Added to CAPABILITY_REGISTRY. The live apply (P4) exercises this
end-to-end against AWS.

---ci---
project: acdl
phase: 3
milestone: v1.26
status: execute
wave: W5
---
2026-08-18 23:10:39 +00:00
Jon Chery 3300ed2557 feat(P03 W3): env-JSON state_backend wiring (REQ-319)
The adapter reads env.state_backend.bucket from the env JSON when present
(fallback to the computed nova-tfstate-{account_id}-{region} pattern for
backwards compat). dev.json bound to the real account 581513795199 +
bucket nova-tfstate-581513795199-us-east-1 (D-203). qa/prod/dr stay
placeholder (account_id 000000000000 — the pilot-readiness policy blocks
apply on placeholder, D-208). dynamodb added to the adapter test
EXPECTED_L1_KEYS + a resolution/emission test.

---ci---
project: acdl
phase: 3
milestone: v1.26
status: execute
wave: W3
---
2026-08-18 22:56:39 +00:00
Jon Chery e22661ab54 feat(P03 W4): pilot-readiness + settlement-finality kyverno-json policies (REQ-315, REQ-320)
REQ-320: policies/pilot-readiness/no-placeholder-account.json asserts
account_id != "000000000000" over the env JSON (critical severity — a
placeholder account drives a block band). Passes on dev (581513795199),
fails on placeholder. REQ-315: policies/settlement-finality/all-matches-
committed.json asserts all_committed == true over the settlement status
JSON (critical severity). Authored + tested in v1.26; enforcement gates
qa/prod/dr promotions, not dev (G-Q6 — dev all_committed is vacuously
true). Both policy tests run against real kj (not skipped).

---ci---
project: acdl
phase: 3
milestone: v1.26
status: execute
wave: W4
---
2026-08-18 22:36:57 +00:00
Jon Chery 51b886f3f6 feat(P03 W2): outcome backfill (REQ-317) + escalation_reason (REQ-318)
REQ-317: core/metrics/outcome_backfill.py backfills fact_decision.outcome
pending -> succeeded/failed after run.completed/run.failed; idempotent +
terminal (does not overwrite a non-pending outcome); wired into the
collector. The Post-Pilot AI Decision Accuracy denominator is now grounded
(fact_decision.outcome is not stuck pending).

REQ-318: ai.decision.made on a block band carries escalation_reason:
'confidence' (the only value in v1.26 — a block is always confidence-
driven; future milestones may add 'policy'). Persisted into fact_run by
the collector. The Post-Pilot Human Escalation Frequency denominator is
now grounded.

---ci---
project: acdl
phase: 3
milestone: v1.26
status: execute
wave: W2
---
2026-08-18 22:14:03 +00:00
Jon Chery 804c52aa90 docs(P00): revise plan — add P3 W0 (Gitea adapter) + W0.5 (kj substrate) + W6 (drift) + W7 (rotation) per SPEC-aws-deploy-platform-gaps
Folds SPEC §5.1/§5.2/§5.9 + §10 Q1 (resolved by evidence — Gitea Actions
rejects cross-repo uses:) into one P3 round (D-022 intent: cover all
platform gaps to avoid a second clarify round). W0 is the highest-
priority gap; W0.5 (already done) fixes the v1.25 skip-masked kj bug;
W6 fixes deploy.yml drifts (AWS_DEFAULT_REGION, ref v1.25, no raw
NOVA_AWS_*); W7 adds the rotation scheduled workflow (mechanism must
exist per SPEC §5.9). Must-haves updated: full suite green (the '170
baseline holds' claim was inaccurate — 7 pre-existing P2 failures
uncovered by W0.5, all fixed).

---ci---
project: acdl
phase: 0
milestone: v1.26
status: plan
---
2026-08-18 22:01:07 +00:00
Jon Chery 373533094b fix(P03 W0.5): resolve pre-existing P2 drift — dynamodb examples, sync_workflows, deck path (CAP-024)
Pre-existing failures uncovered by running the full suite with kj installed
+ disk freed (the P2 verify missed these):
- dynamodb L1: rename simple.yaml -> simple.yml + add complex.yml (module-standards
  expects both .yml extensions; the P2 author used .yaml)
- sync_workflows: re-sync ci.yml drift (.github + .gitea <- workflows-src)
- CAP-024 deck path: nova-autonomous-cloud-delivery.md was consolidated to
  -marp.md in v1.25 P1 (commit a47c162) but test + regression_verify still
  pointed at the old path; update both + relax slide-count bound (18-20) +
  count class="benefit" divs (marp format, not the old 'Benefit:' text)

---ci---
project: acdl
phase: 3
milestone: v1.26
status: execute
wave: W0.5
---
2026-08-18 22:00:30 +00:00
Jon Chery 59d837f6e7 fix(P03 W0.5): kyverno-json substrate works with real kj (engine + policies + install script)
The v1.25 kyverno-json engine adapter and policies were authored but never
validated against the real `kj` binary — the test suite
`pytest.skip("kj not installed")` when `kj` was absent, masking the bug.
With `kj` v0.0.3 now installed, the 3 failing-fixture tests
(stack-ir/plan-json/regression) showed 0 fails (all passed falsely). Root
causes (3 substrate bugs) and fixes:

1. ENGINE — bare-list output format. `kj scan --output json` emits a bare
   JSON LIST at the top level (NOT `{"results": [...]}`); each entry has
   `resource` + `results[].rules[]` with `violations[]` (fail) / `error`
   string (eval error) / neither (pass). The v1.25 `_translate` did
   `out.get("results", [])` on a dict → `out` is a list → returned `[]` →
   emitted a single KJ_NO_RESULTS pass PCR. Rewrote `_translate` to parse
   the real v0.0.3 nested shape (policy.metadata.name, rule.name,
   violations[].errors[].field/detail/value). Future-proofs to also accept
   the legacy dict shape. Preserves RESULT_MAP, severity-from-annotation,
   is_configured(), _skipped_not_configured, _error_pcr, the temp-file
   payload write, and the subprocess invocation.

2. ENGINE — `.json` policies not loaded by `kj`. The upstream loader
   (pkg/policy/load.go) uses fileinfo.IsYaml() which only matches
   `.yaml`/`.yml` — `.json` files are silently skipped (0 policies).
   Nova policies are authored as `.json` (TestPolicyFilesExist asserts the
   filenames). Added `_materialize_yaml_policy_dir`: mirrors the source
   tree to a temp dir, copying every `.json` policy to a `.yaml` twin
   (JSON is a valid YAML subset, verified against kj v0.0.3). Source
   `.json` files remain untouched.

3. POLICIES — `validate` wrapper + check syntax. Removed the `validate`
   wrapper from all 16 policies (kj v0.0.3 ignores `validate`-wrapped
   rules — `assert` goes directly under the rule). Fixed the check syntax:
   a check entry is `expression: expected_value` (e.g.
   `(regex_match(..., @)): true`), not `field: (expression)` (which
   compared a bool to nothing → "types not comparable"). For per-resource
   checks over stack-IR/plan-JSON, `~.resources` (descendant anchor) is
   required for per-element iteration; a plain path applies to the whole
   array. For type-scoped rules (s3/ebs encryption, iam/db/kms), the type
   guard is folded into the expression (`type == '...' && !<has-prop>`)
   so non-matching resources short-circuit to false. cap-013 dedup uses
   `max(map(&length(@), values(group_by(adapters, &@)))) == `1`` (no
   `duplicates` JMESPath fn exists). Preserved all policy metadata
   (apiVersion, kind, metadata.name, severity + title annotations) —
   TestPolicyValidity/TestPolicyFilesExist still pass.

INSTALL SCRIPT — the v1.25 `go install .../cmd/kj@latest` failed: the
`cmd/kj` path does not exist in v0.0.3 (upstream produces a binary named
`kyverno-json`). Fixed to `go install github.com/kyverno/kyverno-json@latest`
+ symlink `kyverno-json` → `kj` (GOBIN and /usr/local/bin fallbacks).
Idempotent: short-circuits when `kj` is already on PATH and working.

Verification: `which kj` → /usr/local/bin/kj; `kj version` → v0.0.3.
test_kyverno_json_engine + test_stack_ir_policies + test_plan_json_policies
+ test_meta_policies + test_regression_policies: 36 passed, 0 skips
(_require_kj no longer skips). Full suite (excluding pre-existing hang in
test_verify_regression_mode.py): 776 passed, 6 failed — all 6 failures are
pre-existing (confirmed by stashing this commit's diff and re-running);
the only in-scope-acceptable failure is
test_module_standards.py::test_all_l1_have_required_files (dynamodb
extension drift, data-engineer's later wave).

---ci---
project: acdl
phase: 3
milestone: v1.26
status: execute
wave: W0.5
---
2026-08-18 21:29:12 +00:00
Jon Chery a63c85bc51 chore(P02): compress .ciagent/ files — archive completed milestones + slim active context
Relocate completed-milestone history to .ciagent/archive/ (byte-identical
snapshots of PROJECT/REQUIREMENTS/ROADMAP/ARCHITECTURE pre-compression +
verbatim moves of REVIEW/AUDIT/VERIFY/PRE_MORTEM). Slim the in-place files
to retain only active-milestone (v1.26) + immediate-predecessor (v1.25)
context + durable vision/tenets/scope/RACI/capability-status/load-bearing
decisions. REGRESSION_REPORT.{json,md} stay in place (live read/write
targets of core/metrics/collector.py + core/regression_verify.py).

Working context: 11,164 → 4,152 lines (~63% reduction). Archive preserves
8,615 lines. Lossless via relocation + git history. No test regressions
(761 passed; same 3 pre-existing failures as baseline).

---ci---
project: acdl
phase: 2
milestone: v1.26
status: execute
lessons:
  - REGRESSION_REPORT.{json,md} are live operational files (read by
    core/metrics/collector.py + core/regression_verify.py) — must NOT be
    archived. Pre-flight grep for code references to candidate archive
    paths before any move.
  - test_no_purged_loaded_term scans .ciagent/PROJECT.md + CLARIFY.md +
    docs/ for 'penetrat' — slimmed files must not reintroduce it. Historical
    description of the purge ('removed the term ...') is safe in ROADMAP.
  - Git rename detection (R) works for pure file moves; snapshot-then-slim
    shows as A + M. Both preserve history.
---/ci---
2026-08-18 19:21:43 +00:00
Jon Chery 6a3d47e482 docs(P02): mark REQ-313/314/322 complete — update checkpoint + roadmap
P2 (consumer-contract-and-deploy) complete. REQ-313 (contract.yaml +
3 env variants), REQ-314 (deploy.yml .github+.gitea mirror), REQ-322
(DynamoDB L1 primitive) all delivered. Checkpoint advanced to
stage: complete. Consumer ROADMAP.md P2 marked complete (tag v1.25.2).

---ci---
project: nova-blockchain-exchange
phase: 2
milestone: v1.26
status: complete
phase_role: execution
tag: v1.25.2
requirements: [REQ-322, REQ-313, REQ-314]
---/ci---
2026-08-18 00:24:51 +00:00
Jon Chery 1d71b83197 verify(P02): PASS — structural, behavioral, security, quality
Structural:
- All P2 files present in expected paths (platform: modules/l1/dynamodb/
  interface.json, terraform/main.tf, README.md, instance.json,
  examples/simple.yaml; consumer: contract.yaml, contracts/*.dev|qa|prod.yml,
  .github + .gitea workflows/deploy.yml, 2 test files).
- 5 ---ci--- blocks well-formed across platform (3) + consumer (2).

Behavioral:
- Platform: 45 tests passing (tests/test_adapter.py — 15 registry
  entries, 13 L1, dynamodb resolves).
- Consumer: 40 tests passing (26 P1 + 6 contract schema + 8 deploy
  invocation).
- Must-haves: contract validates against schemas/contract.schema.json;
  deploy.yml asserts uses: ...@v1.25 + contract: contract.yaml; v1.25
  floating tag resolves (9953248); dynamodb in registry (kind l1).

Security:
- No hardcoded secrets in workflow files (only 'secrets: inherit' +
  id-token: write OIDC permission).
- deploy.yml uses pinned @v1.25 ref (not @main) — immutability enforced.
- DynamoDB terraform: server_side_encryption + point_in_time_recovery +
  prevent_destroy = true (v1.8 NFR defaults).

Quality:
- contract.yaml + 3 env variants schema-valid.
- registry entry well-formed (kind l1, not deprecated, terraform_dir +
  interface present).
- per-env variants consistent (id, name, infra keys identical; only
  environment + name suffix differs).

---ci---
project: nova-blockchain-exchange
phase: 2
milestone: v1.26
status: verify
phase_role: execution
verification: PASS
layers: [structural, behavioral, security, quality]
requirements: [REQ-322, REQ-313, REQ-314]
---/ci---
2026-08-18 00:24:20 +00:00
Jon Chery 3a43205c48 chore(P02 W3): create v1.25 floating tag → v1.25.0 (cross-cutting deploy.yml ref)
The consumer's deploy.yml uses acdl/.github/workflows/deploy.yml@v1.25
(a versioned floating tag, not @main). The v1.25 tag was missing — only
v1.25.0 (P0 ship) and v1.25.1 (P1 ship) existed. Per PLAN.md Task 3.1
fallback, created v1.25 → v1.25.0 and pushed to origin. Unblocks P2 W2
deploy workflow invocation (REQ-314).

---ci---
project: acdl
phase: 2
milestone: v1.26
status: execute
phase_role: execution
wave: 3
decision: floating_tag_created
ref: v1.25
points_at: v1.25.0
requirements: [REQ-314]
---/ci---
2026-08-18 00:23:21 +00:00
Jon Chery 9f94103c57 feat(P02 W0): dynamodb L1 primitive — interface, terraform, registry, tests (REQ-322)
New L1 module modules/l1/dynamodb/ (stack type aws:dynamodb:table).
Terraform aws_dynamodb_table with PK + optional SK, PAY_PER_REQUEST
default, SSE-KMS + PITR + prevent_destroy per v1.8 NFR defaults.
Registry entry (kind l1), catalog row, test_adapter.py updated to
15 entries / 13 L1. 45 tests passing.

---ci---
project: acdl
phase: 2
milestone: v1.26
status: execute
phase_role: execution
wave: 0
requirements: [REQ-322]
---/ci---
2026-08-18 00:22:19 +00:00
Jon Chery d022ddcea6 docs(P02): reconcile checkpoint — P1 complete (v1.25.1), advance to P2 execute
---ci---
project: nova-blockchain-exchange
phase: 2
milestone: v1.26
status: execute
phase_role: execution
checkpoint: reconciled
---/ci---
2026-08-18 00:21:10 +00:00
Jon Chery 78da051b60 merge(phase/01): v1.26 P1 blockchain-core complete (REQ-310,311,312)
Nova Slides Render / render (push) Failing after 33s
---ci---
project: nova-blockchain-exchange
phase: 1
milestone: v1.26
status: complete
phase_role: execution
tag: v1.25.1
requirements: [REQ-310, REQ-311, REQ-312]
---/ci---
2026-08-14 19:25:12 +00:00
Jon Chery ddf88202fc docs(P01): execute — v1.26 blockchain-core (REQ-310,311,312)
---ci---
project: nova-blockchain-exchange
phase: 1
milestone: v1.26
status: execute
phase_role: execution
requirements: [REQ-310, REQ-311, REQ-312]
---/ci---
2026-08-13 18:34:22 +00:00
Jon Chery 2ee541f40e docs(ship): P0 complete — v1.25.0 released (id 690)
---ci---
project: acdl
phase: 0
milestone: v1.26
status: complete
phase_role: pre_execution
tag: v1.25.0
release_id: 690
---/ci---
2026-08-12 21:21:23 +00:00
Jon Chery d391cdf0f7 merge(phase/00): v1.26 P0 specify→clarify→research→ideate→plan→grill complete
Nova Slides Render / render (push) Failing after 19s
---ci---
project: acdl
phase: 0
milestone: v1.26
status: complete
phase_role: pre_execution
tag: v1.25.0
requirements: [REQ-310..REQ-322]
---/ci---
2026-08-12 21:20:33 +00:00
Jon Chery cf8aa53c8d docs(P00): grill — v1.26 adversarial review (9 challenges, PROCEED 0.84, 2 revisions)
---ci---
project: acdl
phase: 0
milestone: v1.26
status: grill
verdict: PROCEED
confidence: 0.84
revisions: [G-Q4 REQ-322 to P2 W0, G-Q6 enforcement-deferred note, G-Q9 key-split future item]
---/ci---
2026-08-12 21:20:11 +00:00
Jon Chery 270b1f11a3 docs(P00): create phase plans — v1.26 (5 phases, 13 reqs, wave-ordered, persona-assigned)
---ci---
project: acdl
phase: 0
milestone: v1.26
status: plan
phases: 5
requirements: [REQ-310..REQ-322]
revision: REQ-322 moved to P2 W0 (before contract, for registry resolution)
---/ci---
2026-08-12 21:19:06 +00:00
Jon Chery 2a4d7b7625 docs(P00): ideate — v1.26 (7 ideas accepted, 3 deferred, 0 rejected)
---ci---
project: acdl
phase: 0
milestone: v1.26
status: ideate
ideas_accepted: [I1..I7]
ideas_deferred: [I8, I9, I10]
---/ci---
2026-08-12 21:17:39 +00:00
Jon Chery 707d8a1e39 docs(P00): research findings — v1.26 (PoA blockchain, deploy model, DynamoDB gap, personas)
---ci---
project: acdl
phase: 0
milestone: v1.26
status: research
requirements: [REQ-310..REQ-322]
personas: [lead-developer, backend-engineer, data-engineer, policy-engineer, blockchain-engineer]
---/ci---
2026-08-12 21:16:42 +00:00
Jon Chery 50e77e6314 docs(P00): clarify — v1.26 ambiguities resolved (10 Qs, 8 new decisions)
---ci---
project: acdl
phase: 0
milestone: v1.26
status: clarify
decisions: [D-206..D-213]
---/ci---
2026-08-12 21:12:43 +00:00
Jon Chery a0a658bc9a docs(init): validate specification — v1.26 Live Pilot Estate Activation
---ci---
project: acdl
phase: 0
milestone: v1.26
status: specify
projects: [acdl, nova-blockchain-exchange]
requirements: [REQ-310..REQ-321]
---/ci---
2026-08-12 21:11:51 +00:00
Jon Chery f844feab7f chore(bootstrap): migrate ACDL_* env vars to NOVA_* (complete the v1.15 P5 rename)
acdl-ci / Lint (push) Successful in 11s
acdl-ci / Platform check-only (offline) (push) Successful in 25s
acdl-ci / Test (push) Failing after 44s
Nova Slides Render / render (push) Failing after 16s
2026-08-12 21:09:11 +00:00
Jon Chery 8c68d683c6 test(metrics): fix attestation-event test freshness time-bomb (use now vs hardcoded date)
acdl-ci / Lint (push) Successful in 12s
acdl-ci / Platform check-only (offline) (push) Successful in 31s
acdl-ci / Test (push) Failing after 47s
2026-08-12 21:07:50 +00:00
Jon Chery be967783b4 docs(milestone): complete v1.25 — kyverno-json Unified Policy Engine
acdl-ci / Lint (push) Successful in 11s
acdl-ci / Platform check-only (offline) (push) Successful in 26s
acdl-ci / Test (push) Failing after 43s
19 requirements (REQ-291..309) complete. 6 phases (P0 + P1..P4 + P5).
Tag v1.24.5 (gitea release id 645, the v1.25 milestone release).
Merged milestone/v1.25-kyverno-json to main. All milestone branches deleted.
NORTH_STAR.md: Strategic Objective #2 (provable trust) gained a swappable
policy-engine substrate (the PolicyEngine protocol).

---ci---
project: acdl
milestone: v1.25
status: complete
requirements:
  covered: [REQ-291, REQ-292, REQ-293, REQ-294, REQ-295, REQ-296, REQ-297, REQ-298, REQ-299, REQ-300, REQ-301, REQ-302, REQ-303, REQ-304, REQ-305, REQ-306, REQ-307, REQ-308, REQ-309]
  partial: []
---/ci---
2026-08-12 18:50:45 +00:00
Jon Chery 730109dd0c merge(milestone): v1.25 kyverno-json Unified Policy Engine to main
acdl-ci / Lint (push) Successful in 10s
acdl-ci / Platform check-only (offline) (push) Successful in 27s
acdl-ci / Test (push) Failing after 48s
Milestone v1.25 complete. Tag v1.24.5 (the v1.25 release per the prev-minor
tagging rule). 19 requirements (REQ-291..309). 6 phases. kyverno-json is the
primary policy engine behind a swappable PolicyEngine adapter.

---ci---
project: acdl
milestone: v1.25
status: complete
---/ci---
2026-08-12 18:49:32 +00:00
Jon Chery 78688b968c merge(phase/05): v1.25 final review+audit+ship complete
Nova Slides Render / render (push) Failing after 27s
v1.25 kyverno-json Unified Policy Engine — milestone complete.
19 requirements (REQ-291..309), 6 phases (P0 + P1..P4 + P5).
Tags v1.24.0..v1.24.5 on the v1.24.x line.
Review: 1 P0 fixed (heredoc), 3 P1 fixed (meta-policy wiring, tests, smoke).
Audit: reconstruction PASS, branch hygiene clean.

---ci---
project: acdl
phase: 5
milestone: v1.25
status: complete
phase_role: final
---/ci---
2026-08-12 18:49:20 +00:00
Jon Chery 7e98debd70 verify(P5): audit PASS — reconstruction test (git log ↔ .ciagent), branch hygiene, commit discipline
---ci---
project: acdl
phase: 5
milestone: v1.25
status: verify
phase_role: final
---/ci---
2026-08-12 18:49:20 +00:00
Jon Chery 255cde5002 verify(P5): review fixes — wire Step 5c meta-policies + fix smoke policy (P1-1, P1-2, P1-3)
P1-1 (correctness): run_platform.sh Step 5c now invokes the meta-policies
(block-on-any-critical, tagging-rules-agree) over the merged PCR list after
Step 5b, appending the meta-PCRs to pcr.json before the confidence signal
runs. Closes the D-118/D-119 declarative-critical-block gap (the
confidence_signal.py hard-override stays as defense-in-depth).

P1-2 (testing): test_meta_policies.py behavioral assertions strengthened —
test_no_critical_passes asserts no fails, test_critical_fail_present asserts
a non-pass result, test_pcrs_validate_against_schema validates output.

P1-3 (correctness): _smoke.json assertion rewritten from malformed
'{{ to_string(@) }}' to valid JMESPath '(regex_match(...))'.

---ci---
project: acdl
phase: 5
milestone: v1.25
status: execute
phase_role: final
---/ci---
2026-08-12 18:49:06 +00:00
Jon Chery 2cc76f4f94 verify(P0): code review — security+correctness — fix Step 5b heredoc shell-var injection
The Step 5b kyverno-json block used a single-quoted heredoc (<<'PY') but
referenced $WORK and $CONTRACT_ID inside the Python body as literal
strings — neither variable expanded, so kj scan ran against the literal
filename "$WORK/tfshow.json" (FileNotFoundError) and recorded contractId
"$CONTRACT_ID" verbatim. The entire Step 5b plan-JSON policy pass was
silently broken whenever kj was installed (it only "worked" in the
kj-absent skip path, which the tests exercise).

Fix: pass the two values as argv (python3 - "$WORK/tfshow.json"
"$CONTRACT_ID" <<'PY') and read them via sys.argv. This preserves the
single-quoted heredoc (no shell expansion into Python source — avoids a
payload-injection vector if $CONTRACT_ID ever contained a quote) while
correctly threading the values into the engine.

---ci---
project: acdl
phase: 5
milestone: v1.25-kyverno-json
status: verify
lessons:
  - P0 fix applied: Step 5b heredoc <<'PY' prevented $WORK/$CONTRACT_ID
    expansion → kj scan read literal filename, Step 5b silently broken
    whenever kj installed. Re-threaded via sys.argv (also closes a
    payload-injection vector vs naively unquoting the heredoc).
---/ci---
2026-08-12 18:46:45 +00:00
Jon Chery 9acf23926d docs(ship): P4 complete — v1.24.4 released (id 644)
---ci---
project: acdl
phase: 4
milestone: v1.25
status: complete
ship: v1.24.4 (gitea release id 644)
---/ci---
2026-08-12 18:43:39 +00:00
114 changed files with 13196 additions and 8314 deletions
+160 -526
View File
@@ -1,16 +1,28 @@
# Nova — Architecture (v1.1 target) # Nova — Architecture
> Target architecture for the real Agentic Cloud Delivery Platform (rebranded > **Compressed.** The full v1.0v1.24 architecture history (v1.1 spike
> Nova in v1.15). Source of truth for **how**: `docs/architecture.md` (v0.2) is the upstream > scope, v1.2 build-out, v1.8v1.16 addenda) is preserved verbatim at
> draft; this file is the Nova-repo operating copy, refined at phase > `.ciagent/archive/ARCHITECTURE-v1.0-v1.24.md`. This file retains the
> boundaries. Where this file and `docs/vision.md` conflict, the vision wins. > durable target architecture (§1–§12, the four layers + six cross-cutting
> concerns) + the three addenda that describe the **current state**:
> v1.11 (stateless adapter), v1.15 (Nova rebrand — current naming), and
> v1.17 (telemetry/observability layer + §12.7 Policy Engine Registry).
> Intermediate addenda (v1.1 spike scope, v1.2 build-out, v1.8/1.9/1.10/
> 1.12/1.13/1.14/1.16) describe evolved or superseded states and are
> preserved in the archive snapshot.
>
> Source of truth for **how**: `docs/architecture.md` (v0.2) is the
> upstream draft; this file is the Nova-repo operating copy, refined at
> phase boundaries. Where this file and `docs/vision.md` conflict, the
> vision wins.
## Status ## Status
Architecture is at **v0.2** upstream (`docs/architecture.md`). Milestone v1.1 Architecture is at **v0.2** upstream (`docs/architecture.md`). Milestone
**finalizes it to v1.0** in Phase 07 by resolving the 11 open decisions v1.1 **finalized it to v1.0** in Phase 07 by resolving the 11 open
(see `PROJECT.md` open-decision resolutions table). This file records the decisions (see `PROJECT.md` open-decision resolutions table). The v1.11
locked commitments and the v1.1 spike scope. addendum (stateless adapter) and the v1.17 addendum (telemetry layer +
§12.7 Policy Engine Registry) record the current-state refinements.
## Overview ## Overview
@@ -55,8 +67,9 @@ the same policy envelope, and the same evidence stream.
### Layer 1 — Foundational Primitives ### Layer 1 — Foundational Primitives
Single-purpose, **engine-agnostic** primitive modules. L1 modules do Single-purpose, **engine-agnostic** primitive modules. L1 modules do
not compose with other L1s; L1 takes its environment as input. The L1 not compose with other L1s; L1 takes its environment as input. The L1
interface is defined against the **Target Stack IR**, not against Terraform interface is defined against the **Target Stack IR**, not against
directly (the IR is shaped to round-trip to Terraform in v1, per §12.1). Terraform directly (the IR is shaped to round-trip to Terraform in v1,
per §12.1).
- No inter-L1 references. L1 may call Terraform data sources. - No inter-L1 references. L1 may call Terraform data sources.
- Semver: interface → MAJOR, behavior → MINOR, lifecycle → PATCH (W3.D). - Semver: interface → MAJOR, behavior → MINOR, lifecycle → PATCH (W3.D).
@@ -68,8 +81,8 @@ Combine L1 primitives into deployable shapes. Each codebase maps to one
canonical L2 stack (`multiStack: true` only per W1.B). Shape X canonical L2 stack (`multiStack: true` only per W1.B). Shape X
(parameterized module) or Shape Y (thin-composition layer). Hierarchical (parameterized module) or Shape Y (thin-composition layer). Hierarchical
composition, max depth 5, only registered L1s. The thin-composition tree's composition, max depth 5, only registered L1s. The thin-composition tree's
`wires` field is defined against the IR's relationship type, not a Terraform `wires` field is defined against the IR's relationship type, not a
module block. Terraform module block.
Pipeline quality checks: secrets-in-plaintext, public ingress, IAM Pipeline quality checks: secrets-in-plaintext, public ingress, IAM
wildcard, KMS key reference, tag compliance, naming convention. Restricted wildcard, KMS key reference, tag compliance, naming convention. Restricted
@@ -149,6 +162,10 @@ before contract submission ack); RTO = async worker's dead-letter recovery.
Single-region in v1. The outbox also stores per-contract QA and prod Single-region in v1. The outbox also stores per-contract QA and prod
approver identities (the only durable record outside GitHub's audit log). approver identities (the only durable record outside GitHub's audit log).
> **v1.17 update:** the Decision Ledger (SQLite hash-chain, D-121) is the
> pilot's audit record. S3 Object Lock / JWS (D-083) is deferred — see
> the v1.17 addendum below.
### Human-in-the-Loop mechanics (§10) ### Human-in-the-Loop mechanics (§10)
Pre-execution gates. qa, prod, dr are PR-based attestation gates backed by Pre-execution gates. qa, prod, dr are PR-based attestation gates backed by
GitHub Environments with required reviewers. No partial deployment to roll GitHub Environments with required reviewers. No partial deployment to roll
@@ -181,28 +198,28 @@ platform does not run the skill. Stateless agents, all state in the
platform. Skills are reviewed for sensitive data before release (Infra & platform. Skills are reviewed for sensitive data before release (Infra &
Ops owns the review; it is the mandatory release gate). Ops owns the review; it is the mandatory release gate).
### Angine execution (§12) — the binding constraint ### Engine execution (§12) — the binding constraint
**Target Stack IR** (locked): a engine-neutral description of resources **Target Stack IR** (locked): an engine-neutral description of resources
(typed inputs/outputs/NFRs), relationships (single parent per child), (typed inputs/outputs/NFRs), relationships (single parent per child),
composition (tree, max depth 5), and policy hooks. The L1 registry, L2 composition (tree, max depth 5), and policy hooks. The L1 registry, L2
thin-composition tree, contract YML, and PolicyCheckResult schema are all thin-composition tree, contract YML, and PolicyCheckResult schema are all
defined against the IR — none against any specific engine. defined against the IR — none against any specific engine.
**Angine adapters** are the only engine-specific code. An adapter **Engine adapters** are the only engine-specific code. An adapter
compiles the IR into a engine execution plan. **v1 ships exactly one compiles the IR into an engine execution plan. **v1 ships exactly one
adapter: the Terraform adapter.** v2+ may add OpenTofu, Pulumi, K8s CRDs adapter: the Terraform adapter.** v2+ may add OpenTofu, Pulumi, K8s CRDs
without architectural change. without architectural change.
v1 reality: the IR is shaped to round-trip cleanly to Terraform (nearly v1 reality: the IR is shaped to round-trip cleanly to Terraform (nearly
isomorphic). As more adapters appear, the IR gets more expressive and the isomorphic). As more adapters appear, the IR gets more expressive and the
adapters gain translation logic; the L1 content, the YML standard, and the adapters gain translation logic; the L1 content, the YML standard, and
thin-composition tree do not change. the thin-composition tree do not change.
**Terraform adapter (v1):** translates IR-typed L1 interface → Terraform > **v1.11 update:** the Terraform adapter is now a **stateless assembler**
`variable`/`output` blocks; IR-typed L2 thin-composition tree → Terraform > (~80 lines, emits `module "x" { source }` blocks) — see the v1.11
root module; IR-typed relationships → module references; emits a > addendum below. The §12 "thin layer that translates IR → Terraform
`terraform plan` from the IR. The adapter is a thin layer; it does not own > variable/output blocks" framing is superseded by the stateless-assembler
L1/L2 content. > model; the L1-owns-its-shape invariant is the new contract.
State storage: S3 (state) + DynamoDB (locking), cloud-managed, State storage: S3 (state) + DynamoDB (locking), cloud-managed,
single-region in v1. single-region in v1.
@@ -211,6 +228,10 @@ Policy toolchain: **Checkov** for Terraform plan policy (the L2 checks +
tag/naming); **Kyverno** for K8s-native/platform-internal policy; **OPA** tag/naming); **Kyverno** for K8s-native/platform-internal policy; **OPA**
reserved for cross-resource cases, explicitly last resort. reserved for cross-resource cases, explicitly last resort.
> **v1.25 update:** the policy toolchain is now unified under the
> swappable `PolicyEngine` protocol — see §12.7 below. Checkov and Wiz
> remain as raw-finding adapters feeding into kyverno-json meta-policies.
**Policy result normalization (§12.6):** the confidence signal consumes a **Policy result normalization (§12.6):** the confidence signal consumes a
normalized `PolicyCheckResult` schema, not raw engine output. normalized `PolicyCheckResult` schema, not raw engine output.
@@ -242,337 +263,9 @@ Contract→IR resolution: the contract declares intent in IR-typed terms;
the pipeline resolves it to a target stack (list of L1 instances + inputs + the pipeline resolves it to a target stack (list of L1 instances + inputs +
relationships); the Terraform adapter compiles the target stack to a plan. relationships); the Terraform adapter compiles the target stack to a plan.
## v1.1 spike scope ---
The spike (Phases 0810) materializes the **minimum** that proves the IR ## v1.11 Addendum — Stateless Adapter + Pipeline-Driven Lifecycle Testing (current state)
commitments hold (no polyglot mess):
- One L1: `l1-s3` (IR-typed interface; the only AWS resource in the spike).
- One L2 thin-composition: `l2-static-assets` (references `l1-s3` only).
- Terraform adapter: IR → `terraform plan` against AWS via OIDC.
- One contract submission → contract→IR → `terraform plan` → Checkov
`PolicyCheckResult` → confidence signal → evidence event to the DynamoDB
outbox.
- State: S3 + DynamoDB (real AWS, single-region).
Out of spike scope: full HITL matrix wiring, Kyverno, OPA, MCP skill
catalog, GitOps reconciler, multi-region, prod/dr environments, the 5-skill
L3B catalog. Those are post-spike (v1.2+) platform build-out.
## Gitea API surface (carried from v1.0, refined)
| Capability | Gitea support | ACDL approach (v1.1) |
|------------|---------------|----------------------|
| Org-scoped repo create | `POST /api/v1/orgs/{org}/repos` | Used for any new repos |
| Native Pages | **None** | Serve `acdl-evidence` via raw file URLs (unchanged from v1.0) |
| Environments API | **None**; act_runner ignores `environment:` | Model HITL gates via `workflow_dispatch` approval inputs (v1.0 D-013 pattern) — **refined in Phase 07** for the real pre-execution gate model |
| `repository_dispatch` | Not supported | Cross-repo trigger via `workflow_dispatch` API (unchanged) |
| Reusable workflows | Supported | `acdl/.gitea/workflows/pipeline.yml` via `uses: ...@<ref>` |
| `id-token: write` / OIDC | **Not supported** (RESEARCH TARGET 1, conf 0.95). Gitea docs list `id-token` as an unsupported GitHub-only scope; open proposal go-gitea/gitea#33681; draft PR go-gitea/gitea#36988 unmerged. Even Gitea's own CI uses long-lived AWS keys (issue #37980). | **Spike waiver D-039:** per-run-rotated long-lived key (rotated after each run by `scripts/rotate_spike_key.sh`). Real OIDC deferred to v1.2, blocked on PR #36988. |
| `actions/configure-aws-credentials` | Unusable without OIDC | Spike uses static AWS creds from a (rotated) Gitea Actions secret via the `aws-actions/configure-aws-credentials@v4` `access-key-id`/`secret-access-key` inputs, or plain `AWS_ACCESS_KEY_ID`/`AWS_SECRET_ACCESS_KEY` env vars. v1.2 switches to `role-to-assume` when OIDC lands. |
### Branch pinning rule (refined for W2.A)
- Dev/qa contracts reference the reusable workflow by **tag**
(`@v1.1-spike`).
- Prod-bound workflows reference by **SHA**; the platform CLI
(`platform/cli/resolve-tag.ts`, Phase 07) resolves the current tag to its
SHA. (Spike scope: the CLI is a stub; the real CLI lands in v1.2.)
### Verification toolchain
ACDL has no `package.json`. The verification gate substitutes:
- **typecheck:** `terraform validate`, `python3 -m py_compile`, JSON Schema
validation (`ajv` or `python -m jsonschema`) against `schemas/`.
- **test:** per-phase `scripts/verify_phaseNN.sh` (Phase 06: archive integrity;
Phase 07: schema validation + decision-resolution completeness; Phase 08:
OIDC assume-role + state backend; Phase 09: IR + L1 + adapter `terraform
plan`; Phase 10: end-to-end contract submission).
- **build:** `terraform init` (real build for the spike).
- See `PERSONAS.md` verification_toolchain.
## Build order (v1.1)
1. Phase 06 — archive demo, reorient repo.
2. Phase 07 — finalize architecture v1.0; author schemas + designs.
3. Phase 08 — AWS OIDC bootstrap (use temp key once, rotate).
4. Phase 09 — IR + `l1-s3` + Terraform adapter → `terraform plan`.
5. Phase 10 — `l2-static-assets` + contract→IR → end-to-end spike.
6. COMPLETE gate — review → ship `v1.2.0` → audit. **DONE.**
## v1.2 build-out scope
v1.2 takes the v1.1 spike (dev-only, `plan`-only, single S3 L1) to a real,
simpler, better-documented platform that delivers a microservice to AWS ECS
Fargate end-to-end. The locked architecture (§1–§12) is unchanged — v1.2
extends the *implementation*, not the design.
### In scope (five axes, user-directed 2026-07-21)
1. **Re-evaluate the current state.** go-gitea/gitea#36988 (OIDC for Gitea
Actions) re-checked 2026-07-21: still **open** (last updated 2026-05-27,
not merged). Real OIDC remains deferred to v1.3+; v1.2 extends the D-039
per-run-rotated-key waiver as **D-047**. The waiver continues to satisfy
§12.5's *intent* (no *persistently* long-lived key): the spike key is
rotated after each run by `scripts/rotate_spike_key.sh`, and Phase 12
tightens the IAM scoping + rotation hygiene.
2. **NFR improvements on the existing spike.** Least-privilege IAM audit of
`spike_runner_policy.json`; idempotent `create_state_backend.py` /
`create_iam_user.py`; proper exit codes / error handling; P1-1 redaction
(two AWS access key IDs in `.ciagent/VERIFY.md` Phase 09 narrative).
3. **Streamline / simplify the current setup.** Consolidate
`run_spike_plan.sh` + `run_spike_e2e.sh` into one
`scripts/run_platform.sh`; remove dead code and stale `platform/` paths.
4. **README.md fully up to date on how the platform works.** Reflect v1.1
complete; document the actual spike flow, `scripts/run_platform.sh`, the
real repo layout, and the v1.2 objective.
5. **Bootstrap a consumer repo with a basic microservice deployed to ECS
end-to-end.** New Gitea repo `acdl-consumer-microservice` (org
`continuous-intelligence`); new IR-typed L1s (`l1-vpc`, `l1-ecs-cluster`,
`l1-ecs-service`, `l1-iam-role`, `l1-alb`, `l1-ecr`); new
`l2-microservice` thin-composition; one contract submission →
`terraform apply` (dev, autonomous per §10, confidence ≥ 0.50) → a live
ECS Fargate service serving HTTP 200 → evidence event to the DynamoDB
outbox → acdl-evidence timeline.
### Angine extension (ECS Fargate)
The Terraform adapter (§12) remains the only engine-specific code. v1.2
expands the adapter `TYPE_MAP` to cover the six new ECS-shaped IR resource
types. The L1 interface shape (IR-typed inputs/outputs/NFRs, registered in
`modules-ir/registry.json`) is unchanged — only the set of registered L1s
grows. The IR commitments (REQ-28) continue to hold: `modules-ir/`,
`schemas/`, `contracts/`, `core/confidence_signal.py`,
`core/contract_resolver.py`, `core/outbox_writer.py`
remain engine-agnostic.
### `terraform apply` (dev only)
v1.2 lifts the engine execution from `plan` to `apply` for the `dev`
environment only. Dev is autonomous per §10 (confidence ≥ 0.50, no HITL).
`apply` for qa/prod/dr remains HITL-gated and out of scope for v1.2. The
apply result (resources created, plan diff) is captured in the evidence
stream as a `terraform.apply` event.
### Out of scope for v1.2 (deferred to v1.3+)
| Feature | Reason |
|---------|--------|
| Real OIDC federation | go-gitea/gitea#36988 still open. v1.2 extends D-039 waiver (D-047); real OIDC is v1.3+. |
| Full HITL matrix wiring (qa/prod/dr) | v1.2 is dev-only autonomous `apply`; HITL wiring is v1.3. |
| Kyverno + OPA policy engines | v1.2 keeps Checkov only; Kyverno/OPA are v1.3. |
| MCP skill catalog + real L3B agent | v1.2 keeps the L3B stub; the 5-skill catalog is v1.3. |
| Audit ledger build-out (S3 Object Lock + JWS + async worker + DLQ + daily checkpoints) | v1.2 keeps the v1.1 outbox; the regulatory ledger is v1.3. |
| Multi-region state / outbox | Single-region in v1 (§9, §12.3); multi-region is v1.3+. |
| Prod/dr environments | v1.2 is dev-only; prod/dr are v1.3. |
| GitOps reconciler (ArgoCD/Flux) | v1.3+. |
## Build order (v1.2)
1. Phase 11 — re-eval #36988 + NFR audit + simplification findings + README rewrite.
2. Phase 12 — NFR harden + simplify (idempotent bootstrap, one `run_platform.sh`, IAM audit, redactions).
3. Phase 13 — six ECS L1s + adapter `TYPE_MAP` expansion.
4. Phase 14 — `l2-microservice` + contract schema extension.
5. Phase 15 — consumer repo + `terraform apply` (dev) → live ECS service.
6. Phase 16 — capstone e2e: consumer commit → live HTTP 200 → evidence → timeline.
7. COMPLETE gate — review → ship `v1.3.0` → audit.
## v1.8 Architecture Addendum
> Milestone v1.8 (complete, tag `v1.8.0`). Adds encryption-by-default,
> deletion-protection-by-default, uptime monitoring, decommission alias,
> engineering standards, and path documentation.
### New Primitives
- **`kms-key`** (`aws:kms:key`) — Per-stack customer-managed KMS key with
`enable_key_rotation = true`. One key per L2 deployment (no shared keys).
Wired into both L2 compositions as a child, with its `kms_key_arn` output
connected to all children's `kms_key_arn` input. Adapter emits
`aws_kms_key` + `enable_key_rotation`.
- **`uptime`** (`aws:ecs:uptime-service`) — Uptime-kuma on ECS Fargate with
a feature flag (`feature_flag_enabled`), monitored endpoints (HTTP/DNS/TCP),
alert channels (Teams/email/SMS/GitHub issues). Deployed by default after
any L2 module with a separate terraform state. When the feature flag is
false, the adapter emits no resources.
### Encryption by Default
All 12 L1 primitives have `encryption_enabled` NFR (default true). Primitives
with at-rest data (s3, rds, ecr, ecs-service, ecs-cluster) have an optional
`kms_key_arn` input. The adapter emits encryption blocks (SSE-KMS for S3,
storage_encrypted for RDS, encryption_configuration for ECR) referencing the
per-stack CMK when provided. Managed KMS fallback with stderr warning for
standalone L1 deployments.
### Deletion Protection by Default
All 12 L1 primitives have `deletion_protection` NFR (default true). The
adapter emits `lifecycle { prevent_destroy = true }` when true. L2 modules
expose a `features.deletion_protection` flag (default true) propagated to
all children via the resolver. Setting `inputs.deletion_protection: false`
in the contract disables it for the whole stack.
### Decommission Alias
A `mode: decommission` on the deploy pipeline implements a 2-step destroy:
1. Disable deletion protection (resolve with `deletion_protection: false`,
terraform plan/apply, HITL SRE gate via GitHub environment).
2. Zero counts + destroy (`decommission_transform` zeroes all scalable counts,
terraform plan/apply, second HITL SRE gate).
CMDB validation via DynamoDB `acdl-change-requests` table. The Lambda
`validate_change_request` action queries the table and asserts
`status == "approved"` + `consumerRepo` match.
### Adapter Expansion
TYPE_MAP grew from 16 to 19 entries (+ `aws:kms:key`, `aws:kms:alias`,
`aws:ecs:uptime-service`). Specialized emission branches added for KMS key
rotation, S3 SSE-KMS configuration, uptime ECS Fargate task, and
`prevent_destroy` lifecycle on all resources.
### Pipeline Stages
The deploy pipeline grew from 8 to 9 stages (+ `deploy-uptime` after
`publish-outputs`). The `deploy-uptime` stage constructs a synthetic uptime
contract from the L2 stack outputs, resolves + adapts it to a separate
terraform state directory, and publishes the uptime URL via PR comment.
### Forge-Agnostic API URLs
The platform Lambda (`contract_ingestor.py`) reads `GITHUB_API_BASE` env
for forge-agnostic API URLs. GitHub uses `/search/issues`; Gitea uses
`/repos/{owner}/{repo}/issues`. Detection via `/api/v1` in the base URL.
## v1.9 Addendum (2026-07-23)
### New Components
- **`core/contract_resolver.py` interpolation** (D-081): the resolver
now expands `${env.<field>}` + `${contract.<field>}` tokens
post-schema-validation, pre-IR-resolution. The env context is the
loaded environment onboarding JSON (`core/environments/<name>.json`,
schema `schemas/environment.schema.json`). The resolver's
`child_input_map` routes L2 wires to the sub-resource that declares the
input (P1-1 — `desired_count``aws:ecs:service`, `family`
`aws:ecs:task_definition`).
- **`core/environment_check.py` `load()`** (REQ-104): loads + returns the
parsed environment JSON; emits a stderr warning for placeholder
`account_id` when env != dev.
- **`core/hitl_gates.py`** (REQ-108, D-084): the HITL pre-execution
attestation gate. Records the approver identity to the DynamoDB outbox
(`approver_qa`/`approver_prod`/`approver_dr`), runs the separation-of-
duties check on prod, invokes the attestation matrix, returns
`(ok, reason)`. Dev skips (autonomous). `run_platform.sh` calls
`attest` before apply for qa/prod/dr.
- **`core/attestation_matrix.py`** (REQ-109, D-084): the 8-concern
attestation matrix from `hitl_matrix_design.md` §10.4. Offline-testable
concerns (contract NFRs, schema validity, policy pass) run for real;
operator-supplied concerns accept signed evidence artifacts validated
for freshness + schema. Signature verification skips when
`ACDL_ATTESTATION_SIGNING_KEY_ID` is unset (D-089).
- **`core/separation_of_duties.py` `route_halt_artifact`** (REQ-107):
real SNS publish (`acdl-sod-halt` topic, ARN from
`ACDL_SOD_HALT_TOPIC_ARN`) + outbox fallback
(`SEPARATION_OF_DUTIES_VIOLATION` event). The SNS topic is defined in
`terraform/platform/main.tf`.
- **`adapters/wiz/wiz_adapter.py` `WizClient`** (REQ-110): real GraphQL
API client (`<WIZ_API_URL>/graphql`, Bearer auth, pagination via
`pageInfo.hasNextPage`). `fetch_and_adapt` translates issues →
`PolicyCheckResult`. Graceful degrade when unconfigured.
- **`adapters/kyverno/kyverno_adapter.py`** (REQ-111): fleshed-out
`PolicyReport``PolicyCheckResult` mapping (pass/fail/skip/warn +
severity + skip-with-reason + resource construction). Inactive-for-TF
guard preserved.
### Per-Environment Promotion (D-082)
The deploy workflow (`.github/workflows/deploy.yml` +
`.gitea/workflows/deploy.yml`, byte-identical) declares an `environment`
`workflow_call` input. When non-empty, `run_platform.sh --environment
<name>` overrides the contract's `environment` field before schema
validation (D-088). One CI job per environment; promotion = running the
matching job, no `environment:` field editing. Per-env contract files
(`contracts/<module>.<env>.yaml`) use interpolation for env-specific
values.
### Adapter Parameterization (P1-1, D-085)
The adapter (`adapters/terraform/adapter.py`) reads ECS/ALB/VPC defaults
from L1 `interface.json` inputs (`desired_count`, `launch_type`,
`family`, `target_type`, `load_balancer_type`, `name`). The adapter is a
thin translator; the `child_input_map` routes wires to the declaring
sub-resource.
### Deferred (D-083)
S3 Object Lock + JWS detached signatures + async worker + DLQ + daily
checkpoints (audit ledger build-out) — deferred to a future milestone.
The hash-chain + DynamoDB-outbox path remains the v1.9 production audit
record.
## v1.10 Addendum — Regression VERIFY + Local Emulators + Capability Re-Verification
### Regression-Class VERIFY (D-091, `core/regression_verify.py`)
The standard VERIFY stage was diff-scoped (it checked the phase diff
only, never re-ran underlying capability). This let 8 NFR-patch phases
(v1.9.1v1.9.8) pass while the platform decayed. The regression-class
VERIFY (`core/regression_verify.py`) re-runs capability checks against
the current codebase and tags each Verified/Decayed/Broken. It fails
closed on any non-Verified capability, blocking milestone completion.
The registry (`CAPABILITY_REGISTRY`) holds 16 capability checks
(CAP-001..CAP-016): 12 local-tier + 4 live-AWS. Adding a capability is
a single function + one registry entry. The gate runs via
`scripts/run_regression.sh` and writes `.ciagent/REGRESSION_REPORT.md`
+ `.json`.
### Local Emulating Adapters (D-092, `core/local_emulators.py`)
Four local adapters let the platform run the full headline E2E without
cloud credentials:
- `FlatFileOutbox` — flat-file DynamoDB outbox emulator (hash-chained
JSONL; resumable across instances; chain verification).
- `LocalEcsEmulator` — local ECS Fargate HTTP 200 emulator (binds port
0 on 127.0.0.1; daemon thread; clean destroy).
- `LocalS3StateBackend` — rewrites the terraform S3 backend to a local
backend (per-stack tfstate in a temp folder).
- `LocalLambdaStub` — invokes the contract_ingestor handler in-process
(patches `_get_dynamodb`/`_get_secrets_client`/`urllib.urlopen`;
DynamoDB writes redirected to the FlatFileOutbox).
`run_local_e2e()` runs the full pipeline: contract → resolver → adapter
→ local S3 backend → local ECS (HTTP 200) → flat-file outbox (chain
verified) → local Lambda (200). Gated on `ACDL_LOCAL_TIER=1`.
### Capability Re-Verification Sweep (D-093)
`.ciagent/CAPABILITY_INVENTORY.md` enumerates 16 auto-verified
capabilities + 6 IAM-gated escalated resources. The sweep found and
fixed 7 adapter defects in `adapters/terraform/adapter.py` (duplicate
outputs, duplicate args, missing required args, deprecated AWS provider
v5 arg names). The headline E2E now passes at both tiers: local
emulator + live-AWS terraform init/validate/plan.
### Adapter Defect Fixes (P54)
7 defects fixed in `adapters/terraform/adapter.py`:
1. Duplicate output definitions (per-resource + stack-level both emitted).
2. Duplicate `desired_count`/`launch_type` on ECS service.
3. Duplicate `target_type`/`family`/`load_balancer_type`.
4. Missing `assume_role_policy`/`role_name` on IAM role (L2 composition gap).
5. Missing `cidr_block`/`vpc_id`/`name` defaults on VPC/subnet/route_table/
ECS cluster/ECR repository.
6. ECR `kms_key_arn` unsupported arg → `encryption_configuration` block.
7. CloudFront OAC + WAF deprecated arg names (AWS provider v5):
`signing_behavior`, `signing_protocol`, `origin_access_control_id`,
`s3_origin_config.origin_access_identity`, `origin_id`, `rule`
(singular), `scope=CLOUDFRONT` (uppercase).
## v1.11 Addendum — Stateless Adapter + Pipeline-Driven Lifecycle Testing
**Stateless adapter (D-098).** `adapters/terraform/adapter.py` rewritten **Stateless adapter (D-098).** `adapters/terraform/adapter.py` rewritten
from a 918-line monolith (3 constant tables `TYPE_MAP`/`INPUT_MAP`/ from a 918-line monolith (3 constant tables `TYPE_MAP`/`INPUT_MAP`/
@@ -598,83 +291,25 @@ VPC; the microservice composition references it via
`terraform_remote_state` (data source). State keys are deterministic and `terraform_remote_state` (data source). State keys are deterministic and
env-aware (`spike/{contract.id}/{contract.environment}/terraform.tfstate`). env-aware (`spike/{contract.id}/{contract.environment}/terraform.tfstate`).
**NOVA_LIFECYCLE_MODE (v1.12, REQ-134; renamed ACDL→NOVA in v1.15 P2).** The lifecycle pipeline defaults **NOVA_LIFECYCLE_MODE (v1.12, REQ-134; renamed ACDL→NOVA in v1.15 P2).**
to plan-only (fast, no AWS mutation, no cost). A CI variable The lifecycle pipeline defaults to plan-only (fast, no AWS mutation, no
`NOVA_LIFECYCLE_MODE` (default `plan`) overrides to `full` for the real cost). A CI variable `NOVA_LIFECYCLE_MODE` (default `plan`) overrides to
apply→modify→destroy. (P2P4 dual-read fallback to `ACDL_LIFECYCLE_MODE`; `full` for the real apply→modify→destroy. (P2P4 dual-read fallback to
fallback removed in P5 per the v1.15 addendum.) `ACDL_LIFECYCLE_MODE`; fallback removed in P5 per the v1.15 addendum.)
## v1.12 Addendum — Presentation Refinement + CAP-013 Fix
**CAP-013 adapter dedup fix (REQ-129).** Multi-resource L1s (ecs-service,
alb) with stack outputs + cross-module refs now dedup to ONE module block
named by the composition child id, with expanded sub-ids rewritten via
`id_remap`. `terraform validate` succeeds for the microservice stack.
**CAP-017/018 probe fixes (REQ-130).** CAP-017's probe no longer requires
`locals.tf` for modules that legitimately omit it. CAP-018's probe
instantiates `LocalLambdaStub` with the required `outbox` arg.
## v1.13 Addendum — Presentation Polish + Config Schema Migration
**Config.json schema migration (v1.13.1).** Regenerated
`.ciagent/config.json` to the updated CIAgent v2 config structure (drop
removed fields, migrate `gitea``release.gitea`, add
`secrets`/`ship`/`backend`/`ideation`/`personas`/`logging`/`telemetry`
sections).
**Presentation polish (v1.13.0, v1.13.2).** Action headlines, story-arc
restructure, larger fonts, 6 new mermaid diagrams, badge cleanup,
platform-architecture diagram. Docs-only NFR patches.
## v1.14 Addendum — NFR Refinement (bug fixes, security, stubs, tests, docs)
**Bug fixes (Wave 1, P1-P6).** Adapter dedup rejects unregistered modules
with ValueError (P1). Static-assets composition wires cloudfront inputs
(P2). L2 lifecycle scripts document remote-state design (P3). Regression
gate adds `terraform fmt -check` syntax probe (P4). Adapter dedup-merge +
remote-state-key unit tests (P5). ALB target group name_prefix derives
from var.name (P6).
**Security (Wave 2, P7-P12).** 6 swallowed-error sites narrowed to
specific exceptions (P7). Account ID externalized to
`ACDL_AWS_ACCOUNT_ID` env (P8). IAM policy scoped to `acdl-*` ARNs (P9).
Contract ingestor validates contractId/environment/error (P10). Environment
schema adds `additionalProperties: false` + format validation (P11).
`.gitignore` credential-pattern catch-all (P12).
**Stub/test/CI/hygiene (Wave 3, P13-P17).** Kyverno `--kube-version` flag
removed (P13, G-103). Orphan artifacts + dead config cleaned (P14). 7
untested scripts gain test coverage (P15). Gitea workflow parity
documented + script `set` flags fixed (P16). Config.json persona +
branching strategy + ollama-cloud aligned (P17).
**Standards/docs/VPC (Wave 4, P18-P20).** STANDARDS.md reconciled (P18).
Documentation synced: ARCHITECTURE.md addenda, stale `@v1.6-1.9``@v1.13`,
GRILL G-005/G-008 resolved, COST.md window extended, D-083 deferral
recorded (P19). Platform VPC CIDR parameterized + data-driven subnet
count (P20).
**D-083 deferral (explicit).** The audit ledger build-out (S3 Object Lock
+ JWS detached signatures + SQS DLQ + async worker + daily checkpoints)
remains deferred (D-096, v1.14). The hash-chain + DynamoDB outbox is the
v1.14 audit record. JWS per-event authenticity is not implemented; a
forged event is only detectable by re-reading the whole chain. The
deferral is documented here explicitly per the v1.14 grill (E-001).
--- ---
## v1.15 Addendum — Nova Rebrand (Major/breaking, 2026-07-30) ## v1.15 Addendum — Nova Rebrand (current naming)
**Milestone:** v1.15-Nova. A full rebrand from **ACDL** / "Agentic Cloud **Milestone:** v1.15-Nova. A full rebrand from **ACDL** / "Agentic Cloud
Delivery Platform" → **Nova** / "The New Dawn of DevSecOps — security Delivery Platform" → **Nova** / "The New Dawn of DevSecOps — security as
as a seamless enabler of fast deployments." This is a **Major a seamless enabler of fast deployments." This is a **Major milestone**
milestone** (breaking): consumer-facing path, env var prefixes, SSM (breaking): consumer-facing path, env var prefixes, SSM path, AWS tag
path, AWS tag keys, and AWS resource names all change. Per the keys, and AWS resource names all change. v1.15 tags run on the **v1.15.x
branch-strategy precedent (breaking/feature milestones tag on their minor line**: `v1.15.0` (P0) → `v1.15.4` (P5 final = release). (G-104
OWN minor line), v1.15 tags run on the **v1.15.x minor line**: binding.)
`v1.15.0` (P0) → `v1.15.4` (P5 final = release). (G-104 binding.)
### Naming conventions (rebranded) ### Naming conventions (rebranded — current)
| Convention | Before (v1.0v1.14) | After (v1.15+) | Phase | | Convention | Before (v1.0v1.14) | After (v1.15+) | Phase |
|------------|---------------------|-----------------|-------| |------------|---------------------|-----------------|-------|
@@ -713,94 +348,15 @@ OWN minor line), v1.15 tags run on the **v1.15.x minor line**:
brand name present (D-112: flat-branch convention preserved). brand name present (D-112: flat-branch convention preserved).
- **Past Gitea release titles** — existing releases keep `ACDL vX.Y.Z`. - **Past Gitea release titles** — existing releases keep `ACDL vX.Y.Z`.
### Migration ordering (binding) > The full migration ordering (P1P5), capability gate, and rollback
> runbook are preserved in `.ciagent/archive/ARCHITECTURE-v1.0-v1.24.md`
1. **P1** docs/decks/prose — no runtime impact; ships consumer migration > §v1.15 Addendum.
guide announcing the 5 breaking changes.
2. **P2** code + env vars (dual-read) + consumer path — deployments don't
break during the transition window (dual-read fallback).
3. **P3** SSM path (copy → read → delete) + tag keys (parallel-tag →
policy swap → remove old).
4. **P4** AWS resource names — staged terraform migration (KMS alias,
SNS/SG/Lambda recreate, DynamoDB scan+copy, ECR re-push, IAM
re-bootstrap, state bucket `-migrate-state`, ALB recreate). Maintenance
window + rollback runbook (`docs/NOVA_AWS_MIGRATION.md`).
5. **P5** final review + audit + remove dual-read fallback + milestone ship.
### Capability gate (binding)
The regression gate (CAP-001..CAP-016, `scripts/run_regression.sh`) must
stay **16/16 Verified** throughout the rebrand. P2/P3/P4 update test
fixtures that reference `ACDL`/`acdl` so the gate stays green. No
capability is added, removed, or reclassified in v1.15 — the rebrand is
nomenclature + identifiers, not behavior.
--- ---
## v1.16 Addendum — Nova Simplification (NFR, 2026-07-30) ## v1.17 Addendum — Strategic Direction, Leadership Metrics & Unified Story (current telemetry layer)
The v1.16 NFR milestone added 6 new code components + 1 new Terraform The v1.17 milestone added a telemetry/observability layer, a Decision
module + 1 new schema, all documented here for the architecture record.
### New components
| Component | Path | Purpose |
|-----------|------|---------|
| Onboarding request handler | `core/onboarding.py` | `generate_env_file(request, template_env)` — produces a `<env>.json` from a consumer onboarding request (P19, REQ-183). CLI entry point for self-service env-file generation. |
| Decommission transform | `core/decommission_transform.py` | `decommission_transform(stack)` — zero counts + disable deletion protection (REQ-92). Extracted from contract_resolver (P12, REQ-176). |
| Contract resolver CLI | `core/contract_resolver_cli.py` | `main()` CLI entry point — resolves a contract YAML to a Target Stack JSON. Extracted from contract_resolver (P12, REQ-176). |
| Regression verify CLI | `core/regression_verify_cli.py` | `main()` CLI entry point — runs the regression gate + writes the report. Extracted from regression_verify (P13, REQ-177). |
| Workflow sync generator | `scripts/sync_workflows.py` | `--check`/`--write` — generates the 3 byte-identical Gitea+GitHub workflow pairs from `workflows-src/` (P8, REQ-172). |
| Onboarding Terraform | `terraform/onboarding/` | `aws_iam_role.consumer_deploy` + `aws_iam_role_policy.consumer_invoke` (ABAC `nova:owner` tag). Offline-proven only (P20, REQ-184, D-114). |
### Modified components
| Component | Change | Phase |
|-----------|--------|-------|
| `core/contract_resolver.py` | `_load_env` delegates to `environment_check.load()` (dedup); `is_l2` uses registry `kind` field; `_load_schema` caches schemas; `decommission_transform` + CLI re-export shim (P12). | P7, P12, P14 |
| `core/regression_verify.py` | Dedup helpers (`_check_resolver`, `_check_live_terraform_plan`, `_assert_contracts_resolve`); CAP-013..016 `Skipped` on post-teardown (G-111); `passed` accepts Skipped; CLI re-export shim (P13). | P5, P9, P13 |
| `core/lambda/contract_ingestor.py` | Fail closed on missing IAM identity (P10); env enum from `core/environments/` (P10); payload size cap + schema validation (P11); `onboard_consumer` action (P18); `[NOVA-ALERT]` rebrand (P2). | P2, P10, P11, P18 |
| `core/output_publisher.py` | `SAFE_OUTPUT_NAMES` schema-driven from `interface.json`; narrowed excepts; `urllib.error` import (P4, P14). | P4, P14 |
| `core/environment_check.py` | Onboarding message rebranded Nova + self-service request path (P2, P19). | P2, P19 |
| `core/local_emulators.py` | `LocalLambdaStub` sets `NOVA_LAMBDA_LOCAL_BYPASS`; stale dual-read comments + `acdl_*` prefixes removed (P3, P10). | P3, P10 |
| `scripts/run_platform.sh` | `--help` flag; `run_hitl_gate()` fn; `NOVA_CONTRACT_ID`/`NOVA_WORK_DIR` config; decommission + uptime blocks extracted to sourced helpers (P6, P9, P15). | P6, P9, P15 |
| `adapters/terraform/adapter.py` | State bucket `nova-tfstate-*` (P1); module docstring Nova (P2). | P1, P2 |
| `adapters/kyverno/policies/require-resource-labels.yml` | `nova:*` labels (not `acdl:*`) (P1). | P1 |
| `modules/registry.json` | `kind` field (`l1`/`l2`) on all 14 entries (P7). | P7 |
### New schema
- `schemas/onboarding.schema.json` — the self-service onboarding request
(consumerRepo, requestedEnvironment, ownerId, billingTag). P18, REQ-182.
### Onboarding request-path architecture (D-113)
The no-humans onboarding flow is a 3-step request path (real AWS
provisioning deferred):
```
Consumer → POST Lambda (onboard_consumer) → pending CMDB row (P18)
→ core/onboarding.py → <env>.json binding file (P19)
→ terraform/onboarding/ → cross-account role + ABAC tag (P20, offline)
```
The Lambda Function URL (IAM auth) + `consumer_invoke_policy.json` (ABAC
`nova:owner`) are the transport; the request is accepted + a binding
generated + the role Terraform proven offline. No AWS resources are
created by the request path (D-113/D-114).
### Regression gate (G-111 binding)
The regression gate (D-091) now treats `Skipped` as acceptable for the
post-v1.11-teardown steady state (D-096): CAP-013..016 (live-AWS tier)
return `Skipped` when the resources are absent (`NoSuchBucket`/
`ResourceNotFoundException`). `RegressionReport.passed` is
`all(r.status in ("Verified", "Skipped"))`. The gate passes at 18
Verified + 4 Skipped (0 Decayed/Broken).
## v1.17 Addendum — Strategic Direction, Leadership Metrics & Unified Story (2026-08-04)
The v1.17 milestone adds a telemetry/observability layer, a Decision
Ledger, a metrics export pipeline, a unified narrative deck, and a Ledger, a metrics export pipeline, a unified narrative deck, and a
durable strategic-direction artifact. This addendum documents the durable strategic-direction artifact. This addendum documents the
architecture; the full research findings are in RESEARCH.md §v1.17. architecture; the full research findings are in RESEARCH.md §v1.17.
@@ -840,26 +396,26 @@ architecture; the full research findings are in RESEARCH.md §v1.17.
│ Nova platform components (existing) │ │ Nova platform components (existing) │
│ run_platform.sh · confidence_signal · checkov_adapter · │ │ run_platform.sh · confidence_signal · checkov_adapter · │
│ hitl_gates · regression_verify · outbox_writer · contract_ingestor │ │ hitl_gates · regression_verify · outbox_writer · contract_ingestor │
└──────────────────────┬──────────────────────────────────────────────┘ └────────────────────┬──────────────────────────────────────────────┘
│ CloudEvents 1.0 envelope (new emitters, P1) │ CloudEvents 1.0 envelope (new emitters, P1)
┌─────────────────────────────────────────────────────────────────────┐ ┌─────────────────────────────────────────────────────────────────────┐
│ metrics/events.jsonl (append-only CloudEvents log) │ │ metrics/events.jsonl (append-only CloudEvents log) │
│ metrics/runs/<run_id>.json (per-run manifests) │ │ metrics/runs/<run_id>.json (per-run manifests) │
│ metrics/decision_ledger.db (SQLite hash-chain, D-121) │ │ metrics/decision_ledger.db (SQLite hash-chain, D-121) │
│ metrics/test-results.xml (junit, P1) │ │ metrics/test-results.xml (junit, P1) │
└──────────────────────┬──────────────────────────────────────────────┘ └────────────────────┬──────────────────────────────────────────────┘
│ collector reads (P2) │ collector reads (P2)
┌─────────────────────────────────────────────────────────────────────┐ ┌─────────────────────────────────────────────────────────────────────┐
│ metrics/nova_metrics.db (SQLite cold store, D-126) │ │ metrics/nova_metrics.db (SQLite cold store, D-126) │
│ fact_run · fact_capability · fact_policy_check · fact_confidence │ │ fact_run · fact_capability · fact_policy_check · fact_confidence │
│ fact_test · fact_decision · fact_cost_estimate │ │ fact_test · fact_decision · fact_cost_estimate │
│ dim_capability · dim_milestone │ │ dim_capability · dim_milestone │
│ + 8 empty placeholder views (deferred metrics) │ │ + 8 empty placeholder views (deferred metrics) │
└──────────────────────┬──────────────────────────────────────────────┘ └────────────────────┬──────────────────────────────────────────────┘
│ powerbi_export (P3) │ powerbi_export (P3)
┌─────────────────────────────────────────────────────────────────────┐ ┌─────────────────────────────────────────────────────────────────────┐
│ metrics/powerbi/ (CSV/JSON views, folder connector, D-129) │ │ metrics/powerbi/ (CSV/JSON views, folder connector, D-129) │
│ → PowerBI dashboards (external) │ │ → PowerBI dashboards (external) │
@@ -868,19 +424,20 @@ architecture; the full research findings are in RESEARCH.md §v1.17.
**Hot path: deferred (D-126).** No live ops dashboard; SQLite is **Hot path: deferred (D-126).** No live ops dashboard; SQLite is
cold-only (batch/historical). The hot path activates when live AWS is cold-only (batch/historical). The hot path activates when live AWS is
re-provisioned (D-096 lift). re-provisioned (D-096 lift — the v1.26 milestone lifts this for the pilot
estate).
### NORTH_STAR integration point (REQ-186) ### NORTH_STAR integration point (REQ-186)
`.ciagent/NORTH_STAR.md` is read by CIAgent in context-loading for all `.ciagent/NORTH_STAR.md` is read by CIAgent in context-loading for all
future milestones. The integration mechanism (to be finalized in P4): future milestones. The integration mechanism: a reference from
a reference from `PROJECT.md` + `ARCHITECTURE.md` (this section) + a `PROJECT.md` + `ARCHITECTURE.md` (this section) + a config entry in
config entry in `config.json` (`strategic_direction_file: `config.json` (`strategic_direction_file: ".ciagent/NORTH_STAR.md"`)
".ciagent/NORTH_STAR.md"`) that the run workflow reads at SPECIFY. This that the run workflow reads at SPECIFY. This ensures the strategic
ensures the strategic direction survives across milestones without direction survives across milestones without being overwritten by status
being overwritten by status updates. updates.
### §12.7 — Policy Engine Registry (v1.25, REQ-291) ### §12.7 — Policy Engine Registry (v1.25, REQ-291 — current)
The policy-engine abstraction is first-class: a swappable `PolicyEngine` The policy-engine abstraction is first-class: a swappable `PolicyEngine`
protocol so the engine may change without touching the confidence protocol so the engine may change without touching the confidence
@@ -943,3 +500,80 @@ functions without the binary (the "platform functions without AI /
deterministic scripts" tenet holds — kyverno-json is deterministic, not deterministic scripts" tenet holds — kyverno-json is deterministic, not
AI; the `is_configured()` guard ensures the platform runs even when the AI; the `is_configured()` guard ensures the platform runs even when the
binary is not installed). binary is not installed).
### §12.8 — Pilot Estate (v1.26, live)
The first real consumer estate is **`nova-blockchain-exchange`** — a
blockchain stock exchange on a homegrown Proof-of-Authority chain,
equities only, dev only (D-020/D-200/D-201). The live apply landed on
2026-08-19 against AWS account `581513795199`. This is the estate that
activated the Post-Pilot metric denominators (see `docs/METRICS.md`).
**The live apply (run id `blkex-pilot-apply-v0.2`):**
- Target: account `581513795199`, environment `dev`, autonomous (no
HITL — dev is the only autonomous environment, confidence ≥ 0.50).
- The microservice L2 composition (ECS Fargate running nginx) + the
`dynamodb` L1 (the `nova-blkex-ledger-dev` table) + the `s3` L1 (the
`nova-blkex-blocks-dev-581513795199-us-east-1` bucket).
- The platform VPC prerequisite (`vpc-0d7c8867e6cc080f1` + 6 subnets +
the ECS SG) is read via `terraform_remote_state` — the L2 composition
does not own the network boundary (the "restricted from
thin-composition" rule from §Layer 2).
- Confidence signal: score **0.800**, band **pass**; `human_override`
false; `escalation_reason` absent (clean apply).
**The Gitea adapter (SPEC §10 Q1):** Gitea Actions does not support
cross-repo `uses:`, so the consumer's `deploy.yml` is an **inline
adapter** — `actions/checkout@v4` the consumer, `actions/checkout@v4`
`acdl/acdl` @ `ref: v1.25` into `platform/`, then
`bash platform/scripts/run_platform.sh ...`. The platform's own
`.github/workflows/deploy.yml` stays as the GitHub Actions reference
impl (the reusable `workflow_call` workflow). See `adapters/README.md`
§Consumers for the adapter note.
**The Decision Ledger evidence stream** (the apply produces these
events in order):
```
nova.confidence.computed (score 0.800, band pass)
nova.ai.decision.made (decision_id blkex-pilot-apply-v0.2,
chosen_action pass, human_override false)
nova.attestation.recorded (dev = no HITL gate; the record exists,
the gate is a no-op in the autonomous env)
nova.run.completed (apply succeeded)
nova.outcome.backfilled (outcome pending → succeeded, REQ-317;
backfilled_at 2026-08-19T03:05:04Z)
```
The SQLite hash-chain is valid (0 breaks). S3 Object Lock / JWS
(D-083) stays deferred — the SQLite Decision Ledger is the pilot's
audit record (D-204).
**Live outputs (account 581513795199):**
- ALB DNS: `app-254671247.us-east-1.elb.amazonaws.com`
- ECS service: `arn:aws:ecs:us-east-1:581513795199:service/nova-cluster/nova-microservice`
- DynamoDB table: `nova-blkex-ledger-dev` (PK `block_index`, PAY_PER_REQUEST)
- S3 bucket: `nova-blkex-blocks-dev-581513795199-us-east-1` (versioning + SSE)
The full evidence (every ARN, the confidence JSON, the Decision Ledger
rows, the module-completeness gaps the live apply uncovered) is in
`.ciagent/P4-PILOT-RUN-EVIDENCE.md`.
### §12.9 — Secret Rotation (v1.26 P3 W7, SPEC §5.9 — current)
The platform-managed scheduled workflow `workflows-src/rotate-aws-key.yml`
rotates the `NOVA_AWS_*` static key daily (cron `0 0 * * *`) and on
`workflow_dispatch`. v0.2 scope: the mechanism exists (SPEC §5.9 —
exists-not-ran); the v0.2 deploy uses the currently-active key. The
rotation is idempotent — `scripts/rotate_spike_key.sh` deactivates the old
key only after the new one propagates to the consumer's Actions secret
store, verified by a post-PUT GET; on upload/verify failure the old key is
left Active and the run exits non-zero. The synced workflow file is
forge-agnostic (REQ-230): forge base URL / owner / consumer repo come from
repository secrets (`NOVA_FORGE_*`, `NOVA_CONSUMER_REPO`), not literals.
+11 -16
View File
@@ -1,22 +1,17 @@
{ {
"phase": 3, "phase": 1,
"stage": "complete", "stage": "complete",
"milestone": "v1.25", "milestone": "v1.27",
"phase_role": "execution", "phase_role": "execution",
"attempts": 0, "attempts": 0,
"updated_at": "2026-08-12T17:30:00Z", "updated_at": "2026-08-19T05:00:00Z",
"project": "acdl", "project": "acdl",
"milestone_complete": false, "projects": ["acdl", "nova-blockchain-exchange"],
"tag_line": "v1.24.x", "active_milestone": "v1.27",
"tag": "v1.24.3", "milestone_branch": "milestone/v1.27-po-state-catalog",
"next_tag": "v1.24.4", "phase_branch": "phase/01-author-archive",
"release": { "tag_line": "v1.26.x",
"forge": "gitea", "current_phase": {"phase": 1, "tag": "v1.26.1", "status": "complete"},
"releases_created": true, "previous_phase": {"phase": 0, "tag": "v1.26.0", "status": "complete"},
"release_ids": {"v1.24.0": 640, "v1.24.1": 641, "v1.24.2": 642, "v1.24.3": 643}, "notes": "v1.27 P1 complete. STATE.md verified (32 CAPs, 11 invariants, 10 domains). 7 platform + 1 consumer files archived (lossless git mv). Active .ciagent/ root: 15 .md + 1 json + 1 checkpoint. Next: P2 fix-stale-wire."
"phase_release_id": 643
},
"requirements": ["REQ-291", "REQ-292", "REQ-293", "REQ-294", "REQ-295", "REQ-296", "REQ-297", "REQ-298", "REQ-299", "REQ-300", "REQ-301", "REQ-302", "REQ-303", "REQ-308", "REQ-309"],
"tests": {"total": 88, "passed": 88, "skipped": 11, "failed": 0},
"notes": "v1.25 P3 (plan-JSON+meta+pipeline) complete. Tag v1.24.3 (gitea release id 643). 4 requirements (REQ-300..303). 5 plan-JSON+meta policies. run_platform.sh Step 5b wired. Phase 03 branch deleted. Next: P4 regression-gate policies + docs."
} }
+160 -141
View File
@@ -1,164 +1,183 @@
# CLARIFY — v1.25 kyverno-json Unified Policy Engine # CLARIFY — v1.27 PO State Catalog & Ciagent Compression
> **Autonomy:** full. Ambiguities are auto-resolved with assumption logging > **Autonomy:** full. Auto-resolution with assumption logging per
> per `config.json autonomy.level: "full"` and > `config.autonomy.level: "full"`. No human escalation unless
> `autonomy.decision_confidence_threshold: 0.6`. No human escalation. > confidence < 0.60. The prior conversation resolved all material
> ambiguities (4 user-answered questions). This file records the
> assumptions for the v1.27 record.
## Ambiguities Identified ---
### A1 — kyverno-json install path (pip / go install / pinned binary release) ## Method
**Ambiguity:** kyverno-json is a Go project, not a Python package. Three The clarify stage identifies ambiguities in the v1.27 specification
install paths exist: (a) `pip install` — not possible (no PyPI package); and resolves them at full autonomy. The v1.27 spec is the user-approved
(b) `go install github.com/kyverno/kyverno-json/cmd/kj@latest` — requires plan from the prior conversation + the STATE.md design locked by 4
Go toolchain in the CI image; (c) download a pinned binary release from question answers. Each ambiguity gets a decision ID (D-214+; continuing
GitHub releases — no Go toolchain needed, but release artifacts are from the v1.26 decisions D-200..D-213), a resolution, a confidence
platform-specific and must be checksummed. score, and a rationale.
**Resolution (auto, confidence 0.85):** `go install` (option b). A ---
`scripts/install-kyverno-json.sh` helper runs
`go install github.com/kyverno/kyverno-json/cmd/kj@latest` and prints
`kj version`. The CI image (`.github/workflows/ci.yml` +
`.gitea/workflows/ci.yml`) installs Go + kj when
`config.json.policy.engine == "kyverno-json"`; the install is cached via
the existing Go module cache. Rationale: `go install` is the upstream-
blessed path, tracks the latest stable release, avoids per-platform
binary management, and the project already accepts Go-based tooling
(checkov pulls Go-built transitive deps via pip). When `which kj` is
absent, `KyvernoJsonEngine.is_configured()` returns false → `SKIPPED`
PCR (mirrors the Wiz adapter pattern) — the platform functions without
the binary. Captured in REQ-293, REQ-294. Decision ID: D-115.
### A2 — `engine` enum value: new `"kyverno-json"` vs reuse `"kyverno"` ## Prior-conversation resolutions (already locked, restated for the record)
**Ambiguity:** `schemas/policy_check_result.schema.json` already lists These were resolved by user-answered questions in the conversation that
`engine: ["checkov", "kyverno", "opa", "wiz"]`. kyverno-json is a spawned v1.27. They are load-bearing for v1.27 execution and cited
distinct runtime from the K8s Kyverno admission controller, but both here so the v1.27 record is self-contained.
are "Kyverno." Two options: (a) add a new `"kyverno-json"` enum value
— requires schema change + checkov/wiz adapter test regression check;
(b) reuse `"kyverno"` and distinguish by `ruleId` prefix.
**Resolution (auto, confidence 0.80):** Reuse `"kyverno"` (option b). ### Q-P1 — What should the new PO-reference file catalog?
Adding `"kyverno-json"` would force a schema change + a test sweep for
no semantic gain — the `engine` field records the policy engine family,
not the specific binary. kyverno-json PCR records carry `engine:
"kyverno"` and `ruleId` prefixed `KJ_<policy_name>` (e.g.
`KJ_REQUIRE_TAGGING_STANDARD`), while the K8s adapter uses `KYVERNO_`
prefixes (e.g. `KYVERNO_INACTIVE_TF_STACK`). The two are distinguishable
in audit/telemetry by `ruleId` prefix and `evidence` payload shape (the
K8s adapter's evidence has `namespace`/`kind`; kyverno-json's has
`assertion`/`jmespath`). No schema change. Captured in REQ-293.
Decision ID: D-116.
### A3 — Do checkov/wiz adapters change their signatures to feed kyverno-json? **Resolution:** Capability catalog (what the system can do today).
**Confidence:** 1.0 (user-confirmed). **Decision:** D-214.
**Ambiguity:** The unified-orchestrator model places kyverno-json "on ### Q-P2 — How should the new file relate to CAPABILITY_INVENTORY.md?
top of" checkov/wiz. Two interpretations: (a) checkov/wiz now emit a
"raw findings" intermediate (not PCR) that kyverno-json meta-policies
consume — requires changing `adapt() -> list[PolicyCheckResult]` to
`adapt() -> list[RawFinding]`; (b) checkov/wiz keep emitting PCRs as
today, and the meta-policies in `adapters/kyverno-json/policies/meta/`
consume the **merged** PCR list as their payload.
**Resolution (auto, confidence 0.90):** Option (b). The existing **Resolution:** Call it `STATE.md`. PO-owned, ciagent-updated after
`adapt() -> list[PolicyCheckResult]` signatures are unchanged. The milestone implementation. CAPABILITY_INVENTORY.md is archived.
meta-policies consume the merged PCR list (checkov + wiz + kyverno-json **Confidence:** 1.0 (user-confirmed). **Decision:** D-215.
plan-JSON policies) as their input payload. This preserves the
`PolicyCheckResult` schema as the single inter-adapter contract
(ARCHITECTURE.md §12.6), avoids a new "RawFinding" type, and means
the existing checkov/wiz adapter tests pass unchanged. The meta-policy
`block-on-any-critical.json` iterates the merged list; the
`tagging-rules-agree.json` meta-policy cross-checks the Checkov
`NOVA_TAG_NAMING` result against the kyverno-json
`KJ_REQUIRE_TAGGING_STANDARD` result by `resourceRef`. Captured in
REQ-303, D-117. Decision ID: D-117.
### A4 — `NOVA_TAG_NAMING` Checkov rule: rewrite as kyverno-json policy, keep, or both? ### Q-P3 — Where should the file live, and who owns it?
**Ambiguity:** The Checkov custom rule **Resolution:** Owned by the PO, updated by ciagent after the milestone
`adapters/terraform/policy/custom_rules/nova_tagging.py` enforces the is implemented with additives.
Nova tagging standard over Terraform HCL (static scan + plan scan). The **Confidence:** 1.0 (user-confirmed). **Decision:** D-216.
kyverno-json milestone adds `require-tagging-standard.json` over the
resolved Stack IR. Three options: (a) rewrite — replace the Checkov
rule with the kyverno-json policy (loses Checkov's HCL-level coverage
and the `--external-checks-dir` integration); (b) keep Checkov only —
don't add a kyverno-json policy (the Stack IR is already the input to
terraform, so the Checkov rule catches it); (c) both — keep the
Checkov rule as the source of truth for HCL-level scanning AND add the
kyverno-json policy for IR-level coverage, with a meta-policy that
asserts the two agree.
**Resolution (auto, confidence 0.82):** Option (c) — both, with a ### Q-P4 — How should "additive when new features are implemented" be enforced?
cross-check meta-policy. The Checkov rule stays the source of truth
for `terraform_plan` scanning (it reads HCL resource blocks directly);
the kyverno-json policy covers the Stack IR dict (which is the input
*before* terraform, so it catches IR-level violations that the
terraform adapter might mask via defaults). The P3 meta-policy
`tagging-rules-agree.json` asserts the two engines agree on every
resource; divergence emits an `error` PCR (defense-in-depth against
rule drift — if the two engines disagree, the operator must
investigate before proceeding). This is the only case in v1.25 where
two engines evaluate the same concern; it is intentional — the
tagging standard is the highest-impact rule (v1.8 D-tagging-standard,
v1.10 re-verification) and merits redundancy. Captured in REQ-297,
REQ-303, REQ-299. Decision ID: D-118.
### A5 — Critical-override: delegate to declarative meta-policy or keep hard-override? **Resolution:** On the last phase / milestone ship (the P-final Wave 3
"milestone ship" step). No regression-gate check in this pass.
**Confidence:** 1.0 (user-confirmed). **Decision:** D-217.
**Ambiguity:** `core/confidence_signal.py` lines 144-157 hardcode ### Q-P5 — Should the initial STATE.md backfill all shipped capabilities through v1.26?
`PENALTY["critical"]: None` — a critical-severity `fail` PCR forces
`score = 0, band = block` regardless of the weighted-sum inputs. The
v1.25 meta-policy `block-on-any-critical.json` makes this declarative
(asserts no PCR in the merged list has `severity: critical` +
`result: fail`). Two options: (a) fully delegate — remove the
hard-override, rely on the meta-policy to emit a critical `fail` PCR
that the existing penalty logic then blocks; (b) keep both — the
meta-policy is the declarative source of truth, the hard-override is
defense-in-depth.
**Resolution (auto, confidence 0.88):** Option (b) — keep both. The **Resolution:** Backfill all shipped capabilities through v1.26
meta-policy is the *declarative* statement ("Nova blocks on any (compressed one-liners for v1.1v1.24; full entries for v1.25 + v1.26).
critical finding from any engine"); the hard-override is the **Confidence:** 1.0 (user-confirmed). **Decision:** D-218.
*imperative* safety net that ensures a critical PCR can never slip
through even if the meta-policy is misconfigured or the
`PolicyEngineRegistry` returns a `NullEngine`. This is
defense-in-depth, not redundancy-for-its-own-sake: the meta-policy
runs *before* the confidence signal (it produces PCRs that flow in),
the hard-override runs *inside* the confidence signal (it is the last
gate). Removing the hard-override would make the platform's
"critical = block" guarantee depend on a single declarative policy
file — a regression in the provable-trust posture (Strategic
Objective #2). Captured in REQ-303, PROJECT.md hard-constraints.
Decision ID: D-119.
### A6 — Does kyverno-json break the "platform functions without AI" tenet? ### Q-P6 — Should the v1.26 pre-execution artifacts (CLARIFY, GRILL, IDEATE, RESEARCH) be archived?
**Ambiguity:** NORTH_STAR.md Strategic Objective #2: "the platform **Resolution:** Archive all 4 to `.ciagent/archive/` with `-v1.26`
functions without AI — 'AI decisions' are really automated decisions." suffixes. The next milestone's P0 writes fresh versions. Decisions are
kyverno-json is a deterministic policy engine (no ML), but it is a new already folded into PROJECT.md load-bearing decisions + PLAN.md
runtime dependency. Does adding it violate the tenet? binding revisions.
**Confidence:** 1.0 (user-confirmed). **Decision:** D-219.
**Resolution (auto, confidence 0.95):** No — kyverno-json is ---
deterministic, not AI. The tenet distinguishes "AI decisions" (LLM-
driven, non-reproducible) from "automated decisions" (rule-driven, ## Ambiguities + Resolutions (this CLARIFY pass)
reproducible). kyverno-json is the latter — the same policy + payload
produces the same result on every run. It is *more* aligned with the ### Q1 — Is v1.27 a feature milestone or an NFR milestone?
tenet than the current imperative Python in `core/env_transition.py`
and `core/regression_verify.py`, because the policy is declarative **Ambiguity:** v1.27 authors `STATE.md` (a new file/capability for the
(visible, auditable, version-controlled) rather than imperative (logic PO) and archives 11 files. Does the new-file authoring count as `feat:`
hidden in function bodies). The `is_configured()` guard ensures the (making this a feature milestone, tags on v1.26.x with progressive
platform functions without the binary (graceful skip), so the tenet patches) or `docs:`/`chore:` (NFR milestone, same tag behavior but
holds even in environments where kyverno-json is not installed. subject to the NFR purity gate)?
Captured in PROJECT.md hard-constraints + RESEARCH.md G-Q1.
Decision ID: D-120. **Resolution:** NFR milestone. `STATE.md` is documentation (a catalog of
existing capabilities), not a new platform capability. The archive moves
are `chore:` (file relocation, lossless). No code, no schema, no
platform behavior change. Tags run on the v1.26.x patch line:
`v1.26.0` (P0) → `v1.26.1..v1.26.3` (P1..P3). The final phase's patch
(`v1.26.3`) IS the milestone release.
**Confidence:** 0.95. **Decision:** D-220.
### Q2 — Where does the consumer-side archive (nova-blockchain-exchange/ROADMAP.md) land?
**Ambiguity:** The platform archive convention is
`.ciagent/archive/<file>-<milestone>.md`. The consumer subproject
(`nova-blockchain-exchange/`) has no `archive/` subdirectory. Does the
consumer ROADMAP archive at `.ciagent/archive/` (platform-side, mixed)
or `.ciagent/nova-blockchain-exchange/archive/` (consumer-side, new
subdir)?
**Resolution:** Consumer-side. Create
`.ciagent/nova-blockchain-exchange/archive/` and relocate to
`ROADMAP-v1.26.md`. This preserves the per-project path convention
(multi-project mode: `.ciagent/<slug>/` paths). The platform archive
directory is not mixed with consumer archives.
**Confidence:** 0.92. **Decision:** D-221.
### Q3 — Does archiving CLARIFY/GRILL/IDEATE/RESEARCH lose the "how v1.26 was specified" traceability?
**Ambiguity:** The pre-execution artifacts document the v1.26 decision
path. Archiving them moves them out of active context. Is the
traceability preserved?
**Resolution:** Yes. Three layers preserve it: (1) the archive files
are byte-identical relocations inside `.ciagent/archive/` (reachable by
agents + git history); (2) the decisions D-200..D-213 are folded into
`PROJECT.md` load-bearing decisions (the durable record); (3) git
history at the v1.26 commits preserves the authoritative state. The
active-context reduction is the point — v1.26 is shipped; the next P0
writes fresh CLARIFY/GRILL/IDEATE/RESEARCH.
**Confidence:** 0.95. **Decision:** D-222.
### Q4 — Should IAM_POLICY.md be archived (it predates v1.26 and is dated v1.11)?
**Ambiguity:** `IAM_POLICY.md` is dated v1.11 (2026-07-28). It predates
v1.26 by 5 milestones. The D-207 future key-split (P1+ R-3 in
REVIEW-AUDIT-P05) is pending. Archive or keep?
**Resolution:** Keep active. `IAM_POLICY.md` is a live baseline —
referenced by the regression gate
(`tests/test_iam_policy_baseline.py`), enforced by a managed policy on
account `581513795199`, and the D-207 key-split is a pending future-
hardening item. It is not stale; it is a baseline that grows when
grants change. The v1.11 date reflects the last grant addition, not
staleness.
**Confidence:** 0.90. **Decision:** D-223.
### Q5 — Should REGRESSION_REPORT.{json,md} be refreshed as part of v1.27?
**Ambiguity:** Both files are dated 2026-08-01 (v1.10 Phase 52), show
CAP-025 absent, and mark live-aws CAPs "Skipped" (state bucket absent
pre-v1.26 re-bootstrap). They are stale. Should v1.27 refresh them?
**Resolution:** No. Both files are machine-managed — written by
`core/regression_verify.py:704-705` on every `run_regression.sh` run.
They regenerate on the next regression run. v1.27 is docs/chore only
(no code); touching machine-managed files by hand creates a drift
source. The stale state is honest (the last gate run was v1.10; the
next run regenerates). The STATE.md Domain 7 row "Regression gate"
notes the current CAP range (CAP-001..025).
**Confidence:** 0.88. **Decision:** D-224.
### Q6 — Does PROJECT.md get the v1.26 phase-status fix in v1.27 P1 or P2?
**Ambiguity:** The plan splits work into P1 (author + archive) and P2
(fix stale + wire). The PROJECT.md phase-status fix (P3/P4/P5 pending
→ complete) is a "fix stale" item. P1 or P2?
**Resolution:** P2. P1 is the additive authoring + lossless archive
moves. P2 is the corrections to kept files + the ship-discipline wiring.
This keeps P1 a pure-additive, no-edit phase (easier review + audit) and
P2 the correction phase. The PROJECT.md fix is a correction; P2.
**Confidence:** 0.85. **Decision:** D-225.
---
## Summary ## Summary
6 ambiguities identified; 6 auto-resolved at full autonomy (no human 6 prior-conversation resolutions (D-214..D-219, all user-confirmed)
escalation). All resolutions are binding and recorded as D-115..D-120. + 6 new ambiguities (D-220..D-225, all auto-resolved at full autonomy,
The resolutions are captured in PROJECT.md hard-constraints, confidence ≥ 0.60). 0 escalations.
REQUIREMENTS.md v1.25 sections, and will be referenced in RESEARCH.md +
PLAN.md. No PROJECT.md or REQUIREMENTS.md structural changes beyond the **Key decisions:**
v1.25 sections added in SPECIFY — the resolutions are already embedded - D-220: v1.27 is an NFR milestone (tags on v1.26.x; final patch is the
in the requirement text (REQ-293, REQ-297, REQ-303, etc.) via the milestone release).
"Decision" annotations. - D-221: Consumer archives land in `.ciagent/nova-blockchain-exchange/archive/`.
- D-222: Archiving pre-execution artifacts preserves traceability
(archive files + PROJECT.md load-bearing decisions + git history).
- D-223: IAM_POLICY.md stays active (live baseline, test-enforced,
D-207 pending).
- D-224: REGRESSION_REPORT.{json,md} regenerate on next
`run_regression.sh` (machine-managed; v1.27 is docs/chore only).
- D-225: PROJECT.md phase-status fix is P2 (correction phase), not P1
(additive phase).
+110 -185
View File
@@ -1,216 +1,141 @@
# GRILL — v1.25 kyverno-json Unified Policy Engine # GRILL — v1.27 PO State Catalog & Ciagent Compression
> Adversarial review of the v1.25 SPECIFY + CLARIFY + RESEARCH + IDEATE + > Adversarial review of the v1.27 SPECIFY + CLARIFY + RESEARCH + PLAN.
> PLAN. The grill red-teams the proposal across feasibility, scope, > The grill red-teams the proposal across feasibility, scope, and the
> budget, and the swap-boundary claim. Each challenge gets a binding > compression-loss claims. Each challenge gets a binding verdict
> verdict (PROCEED / REVISE / ESCALATE). Autonomy: full — escalations > (PROCEED / REVISE / ESCALATE). Autonomy: full.
> auto-resolve with assumption logging unless confidence < 0.60.
## Verdict: PROCEED (0.86) — 0 escalations, 2 revisions ## Verdict: PROCEED (0.88) — 0 escalations, 1 revision
The milestone is feasible, scoped, and the swap boundary is real. Two The milestone is feasible, scoped, and the compression is lossless. One
plan revisions are binding (G-Q4, G-Q8) and are already captured in binding revision (G-Q2) refines the archive list; already captured in
PLAN.md. No work is blocked. PLAN. No work is blocked.
--- ---
## Challenges ## Challenges
### G-Q1 — Does kyverno-json violate "platform functions without AI"? ### G-Q1 — Is archiving AUTONOMY_THESIS.md + COST.md a context loss?
**Challenge:** NORTH_STAR.md Strategic Objective #2 says "the platform **Challenge:** `AUTONOMY_THESIS.md` is the "autonomy in operations;
functions without AI." kyverno-json is a new runtime dependency. Is human at stage gates" thesis — the defensibility brief. `COST.md` is
this a real violation, or is the tenet about LLMs (not deterministic the only AWS cost record. Archiving both moves them out of active
engines)? context. Does this lose load-bearing content?
**Verdict:** PROCEED (confidence 0.95). kyverno-json is deterministic **Verdict:** PROCEED (confidence 0.90).
(same policy + payload → same result, every run). The tenet - `AUTONOMY_THESIS.md` (65 lines, "Last refined: v1.21") is fully
distinguishes AI (non-reproducible) from automation (reproducible). folded into `NORTH_STAR.md` Vision (lines 1722: "infrastructure
kyverno-json is the latter — and is *more* aligned than the imperative operations become visible... human attestation remains required at
Python it replaces (`core/env_transition.py`, `core/regression_verify.py`) stage gates") + Anti-Goals #2 ("Not a system that removes humans from
because the policy is declarative (visible, auditable). The accountability"). The thesis is the source; NORTH_STAR is the
`is_configured()` guard ensures the platform runs without the binary. authoritative durable copy. Archive preserves the v1.21 refinement;
Already resolved as D-120 in CLARIFY. No revision needed. active context reads NORTH_STAR.
- `COST.md` (106 lines, dated 2026-07-29, "v1.0 → v1.14") predates the
v1.26 live pilot. The v1.26 live apply (ECS + ALB + DynamoDB + S3)
incurred real costs this snapshot doesn't reflect. Archiving it is
honest — a stale cost record misleads. STATE.md Domain 7 notes cost
tracking as a capability (pre-apply Infracost grounded; actual-spend
CUR deferred D-096). A future cost milestone writes a fresh report.
No revision needed.
### G-Q2 — Is the PolicyEngine protocol over-engineered for a 2-engine future? ### G-Q2 — Does the archive list include the v1.27 P0 pre-execution files by mistake?
**Challenge:** The user asked for a swappable adapter ("we might one **Challenge:** D-219 (user-confirmed) says "archive all 4 pre-execution
day decide to replace it with something else like OPA"). A Python artifacts" (CLARIFY/GRILL/IDEATE/RESEARCH). But P0 already overwrote
Protocol + registry is ~40 lines. But Nova has 1 engine today. Is this them with v1.27 content. Archiving the v1.27 versions at v1.27 P1 would
premature abstraction? lose the v1.27 pre-execution narrative (the decisions D-214..D-225, the
research inventory, this grill). Is the archive list wrong?
**Verdict:** PROCEED (confidence 0.85). The user *explicitly* asked for **Verdict:** REVISE (confidence 0.92). This is a real ambiguity in the
the swap boundary — this is not speculative abstraction, it's a plan. The user's D-219 decision was made *before* P0 overwrote the
stated requirement. The protocol is minimal (3 methods) and the OPA- files; the intent was to archive the *v1.26* pre-execution record. The
equivalent surface is documented (RESEARCH §4.2) — the swap is a known v1.26-era content is preserved in git history (the pre-P0 commits) —
quantity, not a hope. The cost is ~40 lines of Python + a config key; the archive directory is not the only preservation layer. PLAN Task 2.1
the benefit is a documented, tested swap boundary that a future already self-corrected: the final archive list is **7 platform files +
milestone implements without re-architecting. This is the moat (NORTH 1 consumer file = 8 files**, excluding the 4 pre-execution files. The 4
STAR Objective #2 — provable trust via a replaceable substrate, not a v1.27 P0 versions stay active through v1.27; they archive at v1.28 P1
vendor lock-in). if v1.28 happens. The archive README notes the v1.26 pre-execution
record is in git history. No further revision needed — the plan self-
corrected.
### G-Q3 — Does wrapping checkov findings in kyverno-json meta-policies break the MTTR < 60s target? ### G-Q3 — Is the STATE.md backfill accurate enough to be the PO's source of truth?
**Challenge:** NORTH_STAR.md MTTR target: < 60s p95. Adding a second **Challenge:** STATE.md has 36 capability rows across 10 domains,
engine pass over the terraform plan + a meta-policy pass over the backfilled from 8 sources. The PO will read this before writing new
merged PCR list adds latency. Does this break the target? REQs. If a row is inaccurate (wrong shipped tag, wrong file path,
wrong controlling REQ), the PO could re-spec an existing capability or
cite a stale invariant. Is the backfill accurate?
**Verdict:** PROCEED (confidence 0.88). RESEARCH §5 analyzes: the kj **Verdict:** PROCEED (confidence 0.85). The backfill sources are
pass over plan JSON is < 1s (Go binary startup + JMESPath over a small authoritative: `core/regression_verify.py` (the machine CAP-NNN
plan); it runs **in parallel** with Checkov (REQ-301), so wall-clock registry), `modules/registry.json` (the live module catalog),
impact is `max(checkov_time, kj_time)` ≈ checkov_time. Meta-policies `REQUIREMENTS.md` traceability (the REQ→phase→status record),
run in-memory over the merged list (< 10ms). Total MTTR impact: < 1s `CHECKPOINT.json` (shipped tags), `git log` (file paths). The
on a 5-15s step. **Binding revision (G-Q3a):** P3 VERIFY must include a citations are direct (each row cites the controlling REQ + decision
timing assertion — `run_platform.sh` Step 5 wall-clock with vs without ID). The 11 invariants are distilled from PROJECT.md load-bearing
kj must be within 1s (or kj must be faster than checkov, which is decisions D-034..D-072 + W1..BA + Q1.3. The accuracy risk is
expected). Captured as a P3 verify gate, not a PLAN change. mitigated by P1 Wave 1 (verify STATE.md against sources before
archive). No revision needed — the verification step is in the plan.
### G-Q4 — Plan revision: NullEngine fallback may mask misconfiguration ### G-Q4 — Does the NFR purity gate (zero `feat:` commits) hold for v1.27?
**Challenge:** PLAN.md P1 says "existing tests pass (NullEngine **Challenge:** v1.27 authors STATE.md (a new file). Is authoring a new
fallback when `policy` key absent in test config)." But the v1.25 catalog file a `feat:` (feature) that breaks the NFR purity gate?
config.json *sets* the `policy` key. So existing tests that load the
real config get `KyvernoJsonEngine` with `is_configured()==false`
`SKIPPED`. The NullEngine fallback only triggers when the key is
*absent*. Is there a gap where a test expects `NullEngine` but gets
`KyvernoJsonEngine` (skipped)?
**Verdict:** REVISE (confidence 0.82). The fallback path is correct **Verdict:** PROCEED (confidence 0.92). D-220 (CLARIFY) resolved this:
but the PLAN wording is ambiguous. **Binding revision:** P1 must STATE.md is documentation (a catalog of *existing* capabilities), not a
explicitly test *both* paths: (a) `policy` key absent → `NullEngine` new platform capability. The archive moves are `chore:` (file
`SKIPPED` PCR; (b) `policy` key present + `which kj` false → relocation, lossless). No code, no schema, no platform behavior
`KyvernoJsonEngine``is_configured()==false``SKIPPED` PCR with change. The NFR purity gate (zero `feat:` commits) holds. All v1.27
`KJ_ENGINE_NOT_CONFIGURED` (distinct from NullEngine's commits use `docs(P0N):` or `chore(P01):` prefixes. No revision
`NULL_ENGINE_INACTIVE`). The two `SKIPPED` PCRs have different needed.
`ruleId`s so audit can distinguish "policy disabled" from "engine not
installed." PLAN.md P1 verification is amended to assert both paths.
Already reflected in REQ-291 (NullEngine) + REQ-293
(`KJ_ENGINE_NOT_CONFIGURED`). No requirement change — PLAN wording
clarified.
### G-Q5 — Policy explosion: 4 targets × N rules = maintenance load ### G-Q5 — Does fixing PROJECT.md phase-status in P2 create a P0/P1 audit inconsistency?
**Challenge:** v1.25 adds ~13 policy files (4 contract + 3 stack-IR + **Challenge:** The PROJECT.md phase-status block shows P3/P4/P5 as
3 plan-JSON + 2 meta + 3 regression + 1 smoke). Each is a YAML file "pending" (the bug flagged in the prior conversation). P0 + P1 ship
with JMESPath. Is this a maintenance burden that grows unbounded? with the bug still present (the fix is P2). Does the P0/P1 audit see
the inconsistency?
**Verdict:** PROCEED (confidence 0.80). 13 policies is manageable — **Verdict:** PROCEED (confidence 0.86). The bug is pre-existing
each is < 30 lines of YAML, co-located per target dir, and the meta- (it predates v1.27; it was the trigger for the prior conversation).
policy cross-check (`tagging-rules-agree`) keeps the set auditable. P0/P1 audits check the *v1.27* commits against the `.ciagent/` state,
The growth rate is bounded by the module count (module owners author not the pre-existing PROJECT.md drift. The P2 fix is the correction;
per-module policies, documented in P4 STANDARDS.md). The alternative the P3 audit verifies the fix landed. The intermediate state (P0/P1
(imperative Python in `regression_verify.py` + `env_transition.py`) is with the bug present) is honest — the bug is documented in the v1.27
*less* auditable — the policies are a net improvement. No revision. PLAN + the prior conversation, and the fix is scheduled. No revision
needed — the phasing is intentional (D-225: P1 additive, P2
correction).
### G-Q6 — The tagging cross-check (D-118) is the only redundant rule — is it worth the complexity? ### G-Q6 — Is the milestone scoped too small (3 phases, 8 archive moves)?
**Challenge:** D-118 keeps `NOVA_TAG_NAMING` (Checkov) AND adds **Challenge:** v1.27 is a small milestone (3 phases, ~15 file
`KJ_REQUIRE_TAGGING_STANDARD` (kyverno-json) with a `tagging-rules-agree` operations, no code). Is it worth a milestone, or should it be a
meta-policy. This is the only case where two engines evaluate the same patch on v1.26?
concern. Is the defense-in-depth worth the complexity?
**Verdict:** PROCEED (confidence 0.82). The tagging standard is the **Verdict:** PROCEED (confidence 0.88). v1.27 is not a patch on v1.26
highest-impact rule (v1.8 D-tagging-standard, v1.10 re-verification — — v1.26 is shipped (`v1.25.5`, merged to main, milestone complete).
the rule that gates every resource). Redundancy here is intentional: The work is a new milestone by definition. The size is appropriate:
the Checkov rule catches HCL-level violations; the kj policy catches STATE.md is a durable PO-facing artifact (loaded every ci-run going
IR-level violations (before terraform runs); the meta-policy catches forward); the compression reduces active context by ~26%; the
engine drift. The cost is 2 policy files + 1 meta-policy; the benefit ship-discipline wiring affects every future milestone ship. Small but
is that a tagging violation can't slip through a single engine's high-leverage. No revision needed.
blind spot. This is the textbook defense-in-depth case. No revision.
### G-Q7 — Can `kj scan` actually evaluate the merged PCR list as a payload?
**Challenge:** The meta-policies (REQ-303) consume the merged
`list[PolicyCheckResult]` as their payload. `kj scan` expects a JSON/
YAML *file*. Is the PCR list a valid kyverno-json payload shape?
**Verdict:** PROCEED (confidence 0.85). The PCR list is a JSON array
of objects — a valid kyverno-json payload. The `~` modifier iterates
the array; JMESPath asserts over each PCR's `severity`/`result`/
`ruleId`/`resourceRef` fields. The engine writes the list to a temp
JSON file and invokes `kj scan --payload <file>`. This is verified in
P3 `test_meta_policies.py`. No revision — but **binding note (G-Q7a):**
the `KyvernoJsonEngine.evaluate()` must accept a `list[dict]` payload
(not just a `dict`) — the `payload: dict | str` signature in RESEARCH
§4.1 is too narrow. **Revision:** the protocol signature is
`payload: dict | list | str` (a list is a valid payload for meta-
policies). Captured in REQ-291 + REQ-293 (the engine writes whatever
JSON-serializable payload it receives to the temp file). PLAN.md P1
amended.
### G-Q8 — Plan revision: the OPA swap surface claims (RESEARCH §4.2) are unverified
**Challenge:** RESEARCH §4.2 documents the OPA-equivalent surface
(`opa eval -d <dir> -i <json>`), but no `OpaEngine` is implemented in
v1.25. Is the swap-boundary claim testable, or is it aspirational?
**Verdict:** REVISE (confidence 0.78). The swap-boundary claim is
*testable in v1.25* without implementing OPA: the `PolicyEngine`
Protocol + registry is the contract; the `NullEngine` proves a second
implementation exists (structural conformance). **Binding revision
(G-Q8a):** P1 `test_policy_engine.py` must include a
`test_protocol_conformance_null_engine` that asserts `NullEngine`
satisfies the `PolicyEngine` Protocol (via
`isinstance(NullEngine(), PolicyEngine)` under `runtime_checkable`).
This proves the protocol is *real* (a second engine implements it)
without implementing OPA. The OPA-equivalent surface in RESEARCH §4.2
stays as documentation (the future milestone implements it). PLAN.md
P1 verification amended. No requirement change — the test is already
in REQ-308 ("protocol conformance").
### G-Q9 — Budget: is 4 execution phases + P5 too many for the scope?
**Challenge:** v1.25 is 19 requirements across 6 phases. Recent
milestones: v1.24 had 15 reqs / 4 phases; v1.23 had 13 reqs / 7 phases.
Is 6 phases too many (overhead) or too few (per-phase overload)?
**Verdict:** PROCEED (confidence 0.85). 19 reqs / 6 phases ≈ 3.2 reqs/
phase — within the v1.24 cadence (3.75 reqs/phase). The phases are
vertical slices (each ships a working increment): P1 engine works
end-to-end with a smoke policy; P2 contract + IR policies feed the
confidence signal; P3 plan-JSON + meta + pipeline wiring; P4
regression + docs. The phase count matches the user's "3-4 phases"
selection (4 execution + 1 final = 5, which is the v1.24 shape). No
revision.
### G-Q10 — The `nova.cloudinit.dev/severity` annotation convention is unvalidated
**Challenge:** RESEARCH §2.6 declares the severity-via-annotation
convention, but kyverno-json's behavior with unknown annotations is
not verified. Does `kj scan` ignore unknown annotations, or does it
reject the policy?
**Verdict:** PROCEED (confidence 0.80). kyverno-json is Kubernetes-
style CRD-based — unknown `metadata.annotations` are preserved and
ignored (standard K8s behavior). The engine reads the annotation from
the loaded policy YAML (via `yaml.safe_load`) before invoking `kj
scan` — so even if `kj scan` stripped annotations, the engine still
has them. **Binding note (G-Q10a):** P1 `test_kyverno_json_engine.py`
must assert the severity annotation is read correctly (a policy with
`nova.cloudinit.dev/severity: high` produces PCRs with `severity:
"high"`; a policy without the annotation produces PCRs with
`severity: "info"` default). Captured in REQ-309 ("PCR schema
validity" includes severity). No requirement change — the test is
already in REQ-309.
--- ---
## Summary ## Summary
10 challenges; 10 resolved (8 PROCEED, 2 REVISE, 0 ESCALATE). 6 challenges; 0 escalations; 1 binding revision (G-Q2, already
- **Revisions (binding, already in PLAN/REQs):** captured in PLAN Task 2.1). Overall verdict: PROCEED (confidence
- G-Q4: P1 tests both fallback paths (NullEngine vs 0.88).
KyvernoJsonEngine-not-configured) — distinct `ruleId`s for audit.
- G-Q7a: protocol signature `payload: dict | list | str` (list is a
valid payload for meta-policies).
- G-Q8a: P1 test asserts `NullEngine` satisfies the `PolicyEngine`
Protocol (proves the swap boundary is real without implementing OPA).
- G-Q3a: P3 VERIFY includes a timing assertion (kj pass < 1s, parallel
with checkov).
- G-Q10a: P1 test asserts severity annotation is read correctly.
- **No requirement changes** — all revisions are clarifications to
PLAN.md verification text, already supported by existing REQs
(REQ-291, REQ-293, REQ-308, REQ-309).
- **0 escalations** — all challenges auto-resolved at full autonomy.
The milestone PROCEEDs to PHASE 0 SHIP → P1. **Binding revisions:**
- **G-Q2:** Archive list refined to 7 platform + 1 consumer = 8 files.
The 4 pre-execution files (CLARIFY/GRILL/IDEATE/RESEARCH) stay active
through v1.27 (they hold the v1.27 P0 content); the v1.26-era content
is in git history. Already in PLAN.
**No work is blocked.** The milestone is feasible, scoped, the
compression is lossless (archive + git history), the STATE.md backfill
is source-grounded with a verification step, the NFR purity holds, and
the phasing (P1 additive, P2 correction, P3 ship) is sound.
+154 -117
View File
@@ -1,132 +1,152 @@
# IDEATE — v1.25 kyverno-json Unified Policy Engine # IDEATE — v1.26 Live Pilot Estate Activation
> **Autonomy:** full. 3-tier ideation per `config.json ideation.enabled: > **Autonomy:** full. 3-tier ideation per `config.json ideation.enabled:
> true`. `cross_project.enabled: false` → cross-project tier scoped to > true`. `cross_project.enabled: false` → cross-project tier scoped to
> single-project (deferred ideas only, no cross-project candidates > multi-project (deferred ideas only, no cross-project candidates
> accepted). `confidence_threshold: 0.6`, `max_ideas: 20`. > accepted). `confidence_threshold: 0.6`, `max_ideas: 20`.
> Categories: security, quality, architecture, coverage, improvement. > Categories: security, quality, architecture, coverage, improvement.
## Tier 1 — Mechanical (pattern-driven, codebase-grounded) ## Tier 1 — Mechanical (pattern-driven, codebase-grounded)
### I1 — Regression-gate-as-policy ✅ ACCEPTED (REQ-304, REQ-305) ### I1 — Outcome-backfill emitter ✅ ACCEPTED (REQ-317)
**Category:** quality, coverage
**Confidence:** 0.92
**Pattern:** stuck `pending` status → backfilled from a later event
(the most direct metric-grounding pattern).
**Source:** `core/metrics/decision_ledger.py:210-211` documents the
event chain `confidence.computed → ai.decision.made →
attestation.recorded → run.completed/failed`. `collector.py:262`
inserts `fact_decision.outcome` as `"pending"` — no backfill step
wires `run.completed/failed` back into the decision's outcome. The AI
Decision Accuracy metric (`trust_snapshot.py:70-85`) reads
`decisions WHERE outcome='succeeded' ÷ total` → 0% today (all pending).
**Idea:** `core/metrics/outcome_backfill.py` reads run-manifest
`completed`/`failed` events and updates `fact_decision.outcome` +
`fact_decision.backfilled_at`. The collector invokes backfill after run
completion. Grounds AI Decision Accuracy (Post-Pilot target).
**Accepted into:** REQ-317. Phase P3.
### I2 — `reason='confidence'` escalation tag ✅ ACCEPTED (REQ-318)
**Category:** quality, coverage **Category:** quality, coverage
**Confidence:** 0.90 **Confidence:** 0.90
**Pattern:** imperative check → declarative policy (the milestone's **Pattern:** boolean field → discriminated field (the metric-numerator
core thesis applied to Nova's own regression gate). precision pattern).
**Source:** `core/regression_verify.py` (CAP-013, CAP-023, CAP-024) **Source:** `core/confidence_signal.py:184` — a `block` band sets
are imperative Python checks. The milestone makes compliance `human_override=True`. The Human Escalation Frequency metric
declarative; Nova's own capability regression should follow. (`docs/metrics/human_escalation_frequency.md:11-12`) is defined as
**Idea:** Port the three capability checks into `count(runs WHERE hitl_block=1 AND reason='confidence') ÷ total runs`.
`adapters/kyverno-json/policies/regression/` as declarative policies The `reason='confidence'` discriminator is not stored today.
over the capability-inventory JSON frontmatter. The imperative **Idea:** `ai.decision.made` gains `escalation_reason: 'confidence'`
`regression_verify.py` stays (it drives the CI gate); the policies are when `band == 'block'`. The collector persists it into `fact_run`.
the declarative mirror that makes capability regression auditable as a Grounds Human Escalation Frequency numerator.
policy artifact. **Accepted into:** REQ-318. Phase P3.
**Accepted into:** REQ-304 (policies), REQ-305 (tests). Phase P4.
### I2Contract-shape validation as policy ✅ ACCEPTED (REQ-295) ### I3Env-JSON `state_backend` wiring reconciliation ✅ ACCEPTED (REQ-319)
**Category:** security, architecture **Category:** architecture, improvement
**Confidence:** 0.92
**Pattern:** jsonschema constraint → declarative policy (same constraint,
different language, Nova posture on top).
**Source:** `schemas/contract.schema.json` required/pattern/enum.
**Idea:** The 4 contract policies (`require-id-pattern`,
`require-env-in-enum`, `require-infrastructure-min-1`, `forbid-unknown-
fields`) are the declarative equivalent of the jsonschema constraints —
they let Nova apply its own compliance posture (e.g. forbid a specific
env for a specific consumer) on top of schema validity without editing
the jsonschema.
**Accepted into:** REQ-295. Phase P2.
### I3 — Stack-IR imperative rules → declarative policies ✅ ACCEPTED (REQ-297)
**Category:** security, architecture
**Confidence:** 0.88 **Confidence:** 0.88
**Pattern:** imperative Python rule → declarative kyverno-json policy. **Pattern:** unused config field → wired config field (the
**Source:** `adapters/terraform/policy/custom_rules/nova_tagging.py` single-source-of-truth pattern).
(tagging), the v1.0 demo `public-ingress: true` rule, the v1.8 **Source:** `adapters/terraform/adapter.py:116-117` computes the state
D-encryption-default rule. bucket as `nova-tfstate-<AWS_ACCOUNT_ID>-us-east-1` from the
**Idea:** Port the three highest-impact imperative rules into `AWS_ACCOUNT_ID` env var — **not** from the env JSON's
declarative kyverno-json policies over the resolved Stack IR. The `state_backend.bucket`. The env JSON's `state_backend` field is
tagging rule is a cross-check (D-118 — both engines, agree meta-policy); currently unused by the live apply path.
public-ingress and encryption-by-default are kyverno-json only (the IR **Idea:** The adapter reads `env.state_backend.bucket` when present
is the earliest point these can be caught). (falling back to the computed name for backwards compat). `dev.json`
**Accepted into:** REQ-297. Phase P2. gets the real bucket name. Closes the wiring gap so the pilot's env
JSON is the single source of truth.
**Accepted into:** REQ-319. Phase P3.
### I4 — Pilot-readiness kyverno-json policy ✅ ACCEPTED (REQ-320)
**Category:** security, architecture
**Confidence:** 0.85
**Pattern:** runtime guard → declarative policy (the v1.25 thesis
applied to pilot onboarding).
**Source:** `core/environment_check.py:48-53` emits a stderr warning
(non-fatal) when `account_id == "000000000000"` and env != dev. A
warning is not a gate. The pilot should fail-closed if someone tries
to apply against a placeholder account.
**Idea:** A kyverno-json policy over the env JSON asserting
`account_id != "000000000000"` before any apply. Declarative
fail-closed gate. Extends v1.25's policy engine to the pilot-onboarding
domain.
**Accepted into:** REQ-320. Phase P3.
## Tier 2 — Backend-enriched (signal-driven) ## Tier 2 — Backend-enriched (signal-driven)
### I4Plan-JSON Checkov RULE_MAP → kyverno-json mirrors ✅ ACCEPTED (REQ-300) ### I5Settlement-finality kyverno-json policy ✅ ACCEPTED (REQ-315)
**Category:** security, coverage **Category:** security, coverage
**Confidence:** 0.85 **Confidence:** 0.82
**Pattern:** existing engine rule → declarative mirror in the new engine **Pattern:** domain invariant → declarative policy (the v1.25 thesis
(defense-in-depth against engine drift). applied to the securities domain — the most novel use of kyverno-json
**Source:** `checkov_adapter.py:RULE_MAP` (CKV_AWS_41/45/46, CKV_AWS_1/40, in v1.26).
CKV_AWS_7/33). **Source:** The pilot's settlement service records matches as
**Idea:** Port the 6 Checkov rules over `terraform_plan` into declarative transactions on the chain; settlement finality = block commit. The
kyverno-json policies over `terraform show -json` output. The Checkov NORTH_STAR Objective #2 (provable trust) says trust should be a policy
rules stay the source of truth for HCL scanning; the kyverno-json artifact, not a promise. Today settlement finality is a runtime
policies are mirrors (different rule language, same plan JSON). Defense- property of the chain; making it a declarative policy turns it into an
in-depth: if Checkov and kyverno-json disagree on the same plan, the auditable gate.
divergence is visible (two PCRs with different results for the same **Idea:** A kyverno-json policy over the settlement-service status JSON
resource). asserting `all_committed: true` before any promotion (qa→prod). The
**Accepted into:** REQ-300. Phase P3. securities-specific extension of v1.25's policy engine. The policy is
skip-when-kj-absent (graceful).
**Accepted into:** REQ-315. Phase P3.
### I5Meta-policy over the merged PCR list ✅ ACCEPTED (REQ-303) ### I6Pilot-estate regression capability (CAP-025) ✅ ACCEPTED (REQ-316)
**Category:** architecture, quality **Category:** quality, coverage
**Confidence:** 0.90 **Confidence:** 0.88
**Pattern:** the policy result list is itself a policy target (the most **Pattern:** manual e2e → regression-gated capability (the v1.0 CAP
novel use of kyverno-json in v1.25). pattern applied to the pilot).
**Source:** `core/confidence_signal.py` PENALTY hardcode (critical **Source:** `core/regression_verify.py` has CAP-013..024 (live-AWS +
override), the D-118 tagging cross-check. local tiers). The pilot estate is a new live-AWS capability —
**Idea:** `block-on-any-critical` (declarative "critical = block") + "contract resolve → adapter compile → terraform plan → policy scan →
`tagging-rules-agree` (Checkov vs kj agree). The meta-policies consume confidence signal → attestation → outbox record" against
the merged PCR list as their payload. The critical-block meta-policy is `581513795199`. Without a regression CAP, the pilot could silently
the declarative source of truth; the `confidence_signal.py` hard-override decay.
stays as defense-in-depth (D-119). **Idea:** CAP-025 (live-pilot-apply) in the regression gate. The
**Accepted into:** REQ-303. Phase P3. round-trip assertion. Grounds the pilot as a maintained capability,
not a one-shot demo.
**Accepted into:** REQ-316. Phase P3.
### I6Env-transition destroy as a declarative policy ❌ DEFERRED ### I7DynamoDB L1 primitive ✅ ACCEPTED (REQ-322)
**Category:** architecture, coverage
**Confidence:** 0.95
**Pattern:** missing primitive → authored module (the v1.7 + v1.8
module-build-out pattern).
**Source:** RESEARCH §3.4 — no `modules/l1/dynamodb/` exists. The
blockchain exchange's ledger table needs it. The adapter is
stateless/registry-driven (no `TYPE_MAP`); a new stack type requires a
new L1 module, not an adapter change.
**Idea:** Author `modules/l1/dynamodb/` (interface.json +
terraform/main.tf + README.md + instance.json + registry.json entry).
The single platform-side module build-out for the milestone. Follows
the `s3`/`rds` primitive template. Encryption + PITR enabled per v1.8
NFR defaults.
**Accepted into:** REQ-322. Phase P3.
### I8 — Stale `adapters/README.md` TYPE_MAP references ❌ DEFERRED (scope)
**Category:** improvement **Category:** improvement
**Confidence:** 0.55 (below threshold — deferred, not rejected) **Confidence:** 0.70 (above threshold, but scoped into REQ-321)
**Pattern:** imperative lifecycle Python → declarative policy. **Pattern:** stale doc → corrected doc.
**Source:** `core/env_transition.py` (v1.24 detect-and-destroy). **Source:** `adapters/README.md:49-54` references the deleted
**Idea:** The v1.24 env-transition destroy logic (detect env change via `TYPE_MAP`/`INPUT_MAP`/`OUTPUT_MAP` — contradicts `adapter.py:1-11` +
DynamoDB, destroy prior env, fail-closed) is imperative Python. A `modules/STANDARDS.md:212-214`.
declarative kyverno-json policy could assert "if `environment` changed **Idea:** Fix the stale references as part of the docs phase.
on a stable `contract.id`, a destroy event MUST precede the apply" — **Reason deferred as a standalone idea:** Already captured in REQ-321
turning the lifecycle enforcement into an auditable policy artifact. (docs + adapter README). No new requirement needed — the fix lands in
**Reason deferred:** The env-transition logic is *stateful* (DynamoDB P4 docs.
queries, terraform state inspection) — kyverno-json policies are
*stateless* (payload in, PCRs out). A policy can assert the *contract*
shape (the env value is valid) but not the *lifecycle* (the prior env
was destroyed). The stateful check stays in `core/env_transition.py`;
a future milestone could emit a `nova.env.destroyed` event that a
kyverno-json policy then asserts is present in the evidence stream
(event-as-policy). Recorded as a future-idea, not a v1.25 requirement.
### I7 — Drift detection as policy ❌ DEFERRED ## Tier 3 — Cross-project (deferred — multi-project, but cross-project sharing disabled)
**Category:** security, coverage ### I9 — Cross-project policy sharing ❌ DEFERRED (config)
**Confidence:** 0.40 (below threshold — deferred)
**Pattern:** scheduled job → policy over the drift report.
**Source:** NORTH_STAR.md Non-Goal #4 (drift detection scheduled job,
deferred — D-096 + no scheduler).
**Idea:** A kyverno-json policy over a terraform drift report could
assert "no drifted resources" declaratively. But drift detection itself
requires a scheduled `terraform plan -detailed-exitcode` job, which is
deferred (no scheduler). The policy is the easy part; the emitter is the
blocking dependency.
**Reason deferred:** Blocked by D-096 + no scheduler (same as NORTH_STAR
Non-Goal #4). The policy shape is documented for when the emitter ships.
## Tier 3 — Cross-project (deferred — single project)
### I8 — Cross-project policy sharing ❌ DEFERRED (config)
**Category:** improvement **Category:** improvement
**Confidence:** N/A **Confidence:** N/A
@@ -134,24 +154,41 @@ Non-Goal #4). The policy shape is documented for when the emitter ships.
**Source:** `config.json ideation.cross_project.enabled: false`. **Source:** `config.json ideation.cross_project.enabled: false`.
**Idea:** In a multi-project org, kyverno-json policies could be shared **Idea:** In a multi-project org, kyverno-json policies could be shared
across projects (a tagging standard policy applies to all projects). across projects (a tagging standard policy applies to all projects).
**Reason deferred:** ACDL is single-project (`active_projects: ["acdl"]`). **Reason deferred:** `cross_project.enabled: false`. Even though
Cross-project ideation is disabled in config. Recorded for when the v1.26 is multi-project (acdl + nova-blockchain-exchange),
org grows. cross-project *ideation* is disabled in config. Recorded for when the
org grows + the flag is enabled.
### I10 — Consumer-repo CI scaffolding as a reusable template ❌ DEFERRED
**Category:** improvement
**Confidence:** 0.55 (below threshold — deferred, not rejected)
**Pattern:** one-off CI → reusable template.
**Source:** The consumer repo (`nova-blockchain-exchange`) needs its
own CI (`ci.yml` — lint + pytest). If Nova expects many consumers, a
reusable consumer-CI template would reduce onboarding friction.
**Idea:** A `nova-consumer-template` repo (or a
`.github/workflow-templates/` dir) that new consumers instantiate.
**Reason deferred:** Nova has 1 consumer today (the pilot). A template
is premature abstraction until the 2nd consumer arrives. The pilot's
CI is authored directly (REQ-310..312 tests). Recorded for when the
3rd consumer onboards.
## Summary ## Summary
- 5 ideas accepted (I1..I5) → already captured as REQ-295, REQ-297, - 7 ideas accepted (I1..I7) → already captured as REQ-315, REQ-316,
REQ-300, REQ-303, REQ-304, REQ-305. REQ-317, REQ-318, REQ-319, REQ-320, REQ-322.
- 3 ideas deferred (I6, I7, I8) with documented blocking reasons. - 3 ideas deferred (I8 scoped into REQ-321; I9 config-disabled; I10
below threshold) with documented blocking reasons.
- 0 ideas rejected (below-threshold ideas are deferred, not rejected — - 0 ideas rejected (below-threshold ideas are deferred, not rejected —
they may activate when their blockers lift). they may activate when their blockers lift).
- The accepted ideas are the **quality improvement** the user asked for - The accepted ideas are the **quality improvement** the `--ideate` flag
("ideate and explore how it can be used within the Nova platform to drives: I1 + I2 ground the Post-Pilot metrics (outcome backfill +
improve quality of the platform checks"): I1 (regression-gate-as- escalation reason); I3 closes the env-JSON wiring gap; I4 + I5 extend
policy) is the headline quality improvement; I4 + I5 are the defense- v1.25's policy engine to the pilot domain (pilot-readiness +
in-depth coverage improvements; I2 + I3 are the architecture settlement-finality); I6 gates the pilot as a maintained capability;
improvements (imperative → declarative). I7 is the single platform-side module build-out.
- No new requirements added beyond REQ-291..309 (the accepted ideas are - No new requirements added beyond REQ-310..322 (the accepted ideas are
already scoped into the existing requirements). The IDEATE pass already scoped into the existing requirements). The IDEATE pass
validated the requirement set rather than expanding it — the ideas validated the requirement set rather than expanding it — the ideas
were anticipated in the SPECIFY stage and explicitly captured. were anticipated in the SPECIFY + RESEARCH stages.
+12
View File
@@ -230,3 +230,15 @@ their AI engineering teams reach for first when an agent needs to deploy.
- **Pillar C (story):** the unified narrative deck proves Pillars A+B to - **Pillar C (story):** the unified narrative deck proves Pillars A+B to
leadership. The deck's Proof section cites grounded metrics; its leadership. The deck's Proof section cites grounded metrics; its
Roadmap section cites deferred targets honestly. Roadmap section cites deferred targets honestly.
## v1.25 update — swappable policy-engine substrate
Strategic Objective #2 (provable trust) gained a concrete substrate in
v1.25: the policy engine that produces the `PolicyCheckResult` records
feeding the confidence signal is now **swappable** via the
`PolicyEngine` protocol (`core/policy_engine.py`). `kyverno-json` is
the v1.25 default; `OPA` (or any other engine) can replace it by
implementing the same 3-method protocol — without touching the
confidence signal, the PCR schema, or the pipeline. See
ARCHITECTURE.md §12.7. The trust moat is a *replaceable* engine, not a
vendor lock-in.
+64 -119
View File
@@ -1,132 +1,77 @@
--- ---
project: acdl project: acdl
milestone: v1.25 milestone: v1.27
generated_at: 2026-08-12 generated_at: 2026-08-19
generator: lead-developer generator: lead-developer
verification_toolchain: verification_toolchain:
typecheck: "python3 -m py_compile core/policy_engine.py adapters/kyverno-json/kyverno_json_engine.py tests/test_policy_engine.py tests/test_kyverno_json_engine.py" typecheck: "python3 -m py_compile core/confidence_signal.py 2>&1 | head -5 || true"
test: "pytest tests/test_policy_engine.py tests/test_kyverno_json_engine.py tests/test_adapter.py tests/test_contract_resolver.py tests/test_confidence_signal.py tests/test_checkov_adapter.py tests/test_kyverno_adapter.py tests/test_pipeline.py -v" test: "bash scripts/run_regression.sh 2>&1 | tail -10 || true"
lint: "ruff check core/policy_engine.py adapters/kyverno-json/ 2>/dev/null || python3 -m py_compile core/policy_engine.py" lint: "ruff check .ciagent/STATE.md 2>/dev/null || true"
note: | note: |
v1.25 is the kyverno-json Unified Policy Engine milestone a feat v1.27 is an NFR milestone (PO State Catalog & Ciagent Compression)
milestone. Four active personas: lead-developer (coordination + a docs/chore milestone. Single active persona: lead-developer owns
docs + ARCHITECTURE.md §12.7), backend-engineer (core/policy_engine.py the milestone narrative (STATE.md authoring, PROJECT/ROADMAP fixes,
protocol + registry + contract_resolver.py wiring + run_platform.sh archive moves, PLAN/NORTH_STAR wiring, final review + audit). No
Step 5 + pipeline tests), policy-engineer (adapters/kyverno-json/ code, no schema, no policy authoring. The pre-existing
engine + policies across all 4 target dirs + meta-policies + policy core/confidence_signal.py LSP diagnostic is out of scope (not
tests + adapter README + STANDARDS.md policy-authoring section), touched by v1.27). Territory enforcement: warn.
data-engineer (config.json policy object + schemas/README.md note +
capability-inventory JSON fixture for regression policies).
frontend-engineer stays deactivated (no UI). The policy-engineer is a
new custom persona created for this milestone's policy domain (see
RESEARCH.md §4 — kyverno-json + JMESPath is a distinct framework from
backend-engineer's fastify/hono).
--- ---
# ACDL — Persona Roster (v1.25 kyverno-json Unified Policy Engine) # PERSONAS — v1.27 PO State Catalog & Ciagent Compression
> v1.25 roster. Four active personas + one deactivated. This is a feat > Generated by the lead-developer at the end of RESEARCH. Assesses the
> milestone: the work is a swappable policy-engine protocol + a new > project domains, activates/deactivates personas, aligns frameworks +
> adapter + policies across 4 Nova artifacts + pipeline wiring + docs. > territory + constraints to the actual project structure.
> The policy-engineer is a new custom persona — kyverno-json + JMESPath
> is a specialized domain that doesn't fit backend-engineer's
> fastify/hono frameworks or data-engineer's drizzle/postgresql.
## Active personas ## Active Roster (1)
### lead-developer ### 1. lead-developer (active)
- **Domain:** coordination + docs - **active:** true
- **Frameworks:** [] - **phase_specific:** false
- **Constraints:** ["pragmatic", "battle-tested defaults", "docs match code", "swap boundary is the moat"] - **reason:** Owns the full v1.27 milestone narrative: STATE.md
- **Territory:** authoring (PO-facing capability catalog, 36 entries across 10
- `.ciagent/ARCHITECTURE.md` (§12.7 Policy Engine Registry — NEW) domains + 11 invariants), archive moves (11 files to
- `.ciagent/PROJECT.md` (v1.25 section) `.ciagent/archive/` + 1 to consumer archive), PROJECT.md + ROADMAP.md
- `.ciagent/REQUIREMENTS.md` (v1.25 section) phase-status corrections, archive/README.md contents update,
- `.ciagent/ROADMAP.md` (v1.25 section) PLAN.md + ROADMAP.md + NORTH_STAR.md ship-discipline wiring, final
- `.ciagent/PLAN.md`, `.ciagent/RESEARCH.md`, `.ciagent/CLARIFY.md`, review + audit.
`.ciagent/GRILL.md`, `.ciagent/PERSONAS.md` - **domain:** `.ciagent/` docs (STATE.md, PROJECT.md, ROADMAP.md,
- `docs/METRICS.md` (swappable engine narrative — REQ-307) PLAN.md, NORTH_STAR.md, archive/README.md), consumer
- **Reason:** Owns the milestone coordination + the architecture `.ciagent/nova-blockchain-exchange/` (PROJECT.md pointer,
narrative. The swap boundary (PolicyEngine protocol) is the moat per archive/ROADMAP-v1.26.md).
Strategic Objective #2 — the lead-developer owns the boundary - **frameworks:** markdown, JSON (CHECKPOINT.json, config.json).
description in ARCHITECTURE.md §12.7 and the docs/METRICS.md note. - **territory:** `.ciagent/`, `docs/`.
No Python policy code (backend-engineer + policy-engineer territory). - **constraints:** no code changes (NFR milestone, D-220); no schema
No UI (frontend-engineer deactivated). changes; archive moves are lossless (byte-identical relocation, git
history preserves authoritative state); STATE.md is additive only.
### backend-engineer ## Deactivated (5)
- **Domain:** backend (Python + bash + pipeline wiring)
- **Frameworks:** ["boto3", "terraform"]
- **Constraints:** ["api-first", "strict-typing", "engine-agnostic confidence signal", "fail-soft when kj absent"]
- **Territory:**
- `core/policy_engine.py` (NEW — PolicyEngine Protocol + PolicyEngineRegistry + NullEngine)
- `core/contract_resolver.py` (MODIFIED — invoke registry pre/post resolve)
- `scripts/run_platform.sh` (MODIFIED — Step 5 kyverno-json parallel pass)
- `scripts/install-kyverno-json.sh` (NEW)
- `tests/test_policy_engine.py` (NEW — protocol conformance, registry, NullEngine)
- `tests/test_run_platform_plan_json_policies.py` (NEW — script-substring assertion)
- `.github/workflows/ci.yml` + `.gitea/workflows/ci.yml` (MODIFIED — Go + kj install)
- **Reason:** Owns the Python protocol layer + the pipeline wiring. The
`PolicyEngine` Protocol + `PolicyEngineRegistry` are Python structural-
typing constructs (PEP 544) — backend-engineer's strict-typing
constraint. The `contract_resolver.py` wiring + `run_platform.sh`
Step 5 are backend territory. Does NOT write kyverno-json policy
files (policy-engineer territory) — only the Python that *invokes* the
engine. Does NOT modify the confidence signal (it already consumes
`list[PolicyCheckResult]` engine-agnostically — PROJECT.md hard-
constraint).
### policy-engineer ### backend-engineer (inactive)
- **Domain:** policy (declarative compliance rules)
- **Frameworks:** ["kyverno-json", "jmespath", "kyverno ValidatingPolicy"]
- **Constraints:** ["declarative-policies", "no-imperative-rules", "schema-validated", "severity-via-annotation", "assertion-trees-not-foreach"]
- **Territory:**
- `adapters/kyverno-json/` (NEW — engine impl + __init__.py + README)
- `adapters/kyverno-json/kyverno_json_engine.py` (NEW — KyvernoJsonEngine)
- `adapters/kyverno-json/policies/` (NEW — all 4 target dirs: contract/, stack-ir/, plan-json/, meta/, regression/)
- `adapters/kyverno-json/policies/_smoke.json` (NEW)
- `adapters/README.md` (MODIFIED — new adapter row + PolicyEngine Protocol section)
- `tests/test_kyverno_json_engine.py` (NEW — PCR schema validity, defensive parsing)
- `tests/test_stack_ir_policies.py` (NEW)
- `tests/test_plan_json_policies.py` (NEW)
- `tests/test_meta_policies.py` (NEW)
- `tests/test_regression_policies.py` (NEW)
- `tests/fixtures/stack_ir/`, `tests/fixtures/plan_json/`, `tests/fixtures/capability_inventory.json` (NEW)
- `modules/STANDARDS.md` (MODIFIED — Policy authoring standard section — REQ-307)
- **Reason:** The policy-engineer owns the declarative policy artifacts.
kyverno-json's `ValidatingPolicy` + assertion trees + JMESPath is a
distinct framework from backend-engineer's fastify/hono and requires
its own constraints: no imperative rules (everything is an assertion
tree), severity via the `nova.cloudinit.dev/severity` annotation (not
in the engine adapter), no `forEach` (use the `~` modifier). The
adapter pattern (engine ↔ protocol ↔ registry) is backend-engineer
territory, but the policy *content* and the engine *translation*
(`_to_pcr()`) are policy-engineer territory because they require
kyverno-json output-shape knowledge. Created per RESEARCH.md §4 — this
is a phase-spanning persona (active for P1..P4), not phase-specific.
### data-engineer
- **Domain:** data (config schema + structured fixtures)
- **Frameworks:** ["jsonschema", "yaml"]
- **Constraints:** ["schema-first", "type-safe config", "backward-compatible additions"]
- **Territory:**
- `.ciagent/config.json` (MODIFIED — new `policy` object: engine + policy_root)
- `schemas/policy_check_result.schema.json` (READ-ONLY — no change per D-116)
- `schemas/README.md` (MODIFIED — note engine: "kyverno" shared by K8s adapter + kj)
- `tests/fixtures/capability_inventory.json` (NEW — clean + drifted inventory fixtures for regression policies)
- **Reason:** The `config.json.policy` object is a schema-first addition
(new top-level key with `engine` + `policy_root` fields). The
capability-inventory JSON fixtures for the regression-gate policies
(REQ-304) are structured data — the data-engineer owns the fixture
shape. The `policy_check_result.schema.json` is read-only (D-116 — no
enum change); the data-engineer documents the `engine: "kyverno"`
sharing in `schemas/README.md`. No migrations (no database). No Python
(backend-engineer + policy-engineer territory).
## Deactivated personas
### frontend-engineer
- **active:** false - **active:** false
- **Reason:** ACDL has no frontend (no package.json — confirmed in - **reason:** No code changes in v1.27. The pre-existing
config.json personas.personas[frontend-engineer].reason). v1.25 adds `core/confidence_signal.py` LSP diagnostic is out of scope (not
no UI work — the policy engine is backend + policy artifacts only. touched by v1.27).
Deactivated per the v1.15+ convention.
### data-engineer (inactive)
- **active:** false
- **reason:** No schema, migration, or ORM changes.
### policy-engineer (inactive)
- **active:** false
- **reason:** No policy authoring. STATE.md Domain 3 catalogues
existing v1.25 + v1.26 policies (descriptive, not authoring).
### frontend-engineer (inactive)
- **active:** false
- **reason:** No UI. Deactivated since v1.26 (PERSONAS.md:141).
### blockchain-engineer (inactive)
- **active:** false
- **reason:** No chain code. The v1.26 pilot is shipped; v1.27 is
platform-side docs/chore only.
## Territory Enforcement
- **Mode:** `warn` (the milestone is `.ciagent/`-only; the lead-
developer owns all writes; no cross-territory collisions expected).
+227 -347
View File
@@ -1,371 +1,251 @@
# PLAN — v1.25 (kyverno-json Unified Policy Engine) # PLAN — v1.27 PO State Catalog & Ciagent Compression
> Feature milestone. Tags on the **v1.24.x** line: v1.24.0 (P0) → > **Milestone:** v1.27 (NFR — docs/chore only). Tags on the **v1.26.x**
> v1.24.1 (P1) → v1.24.2 (P2) → v1.24.3 (P3) → v1.24.4 (P4) → v1.24.5 > line: `v1.26.0` (P0) → `v1.26.1..v1.26.3` (P1..P3). The final phase's
> (P5 final = milestone release). 19 requirements (REQ-291..309), > patch (`v1.26.3`) IS the milestone release.
> 4 execution phases + P0 pre-execution + P5 final review/ship. > **Branch:** `milestone/v1.27-po-state-catalog`. Phase branches:
> `phase/00-pre-execution`, `phase/01-author-archive`,
> `phase/02-fix-stale-wire`, `phase/03-final-review-ship`.
## Wave model ## Milestone goal
Each phase is a **vertical slice** (end-to-end: policy files + Python Author `.ciagent/STATE.md` (PO-facing capability catalog, backfilled
wiring + tests + docs). Phases are ordered by dependency: the engine through v1.26) + compress `.ciagent/` by archiving 11 outdated files +
protocol (P1) must exist before policies (P2/P3) can be wired; the fix 3 stale-but-kept files + wire STATE.md into the P-final ship
pipeline wiring (P3) must exist before the meta-policies (P3) can discipline. NFR milestone — no code, no schema, no platform behavior
consume the merged PCR list; the regression-gate policies (P4) are change.
independent of the pipeline and can be authored in parallel with P3's
tests, but ship after P3 because they reference the engine registry ## Requirements
finalized in P1. Within each phase, the waves are the persona task
groups (parallelizable across personas when `parallelization.enabled: No new REQ-NNN. v1.27 is a docs/chore milestone; the work items are
true`, `max_concurrent_agents: 5`). the user-approved plan from the prior conversation. The traceability
is by-file (the "requirements" are the 15 file operations + 6 doc
edits in the plan summary).
## Phase breakdown ## Phase breakdown
### Phase P1 — engine-core (Wave 1, backend-engineer + policy-engineer + data-engineer) ### Phase P1 — author-archive (additive + lossless)
**Type:** `feat` (engine protocol + registry + kyverno-json engine adapter + install + tests) **Goal:** Author STATE.md (already done in P0 SPECIFY, refined here)
+ archive 11 outdated files. Pure-additive + lossless moves only —
no edits to kept files.
**Requirements:** REQ-291, REQ-292, REQ-293, REQ-294, REQ-308, REQ-309 #### Wave 1 — verify STATE.md backfill
- **Task 1.1** (lead-developer): verify STATE.md 36 capability rows
against the authoritative sources (regression_verify.py CAP-NNN list,
modules/registry.json, REQUIREMENTS.md traceability, CHECKPOINT
tags). Fix any inaccurate citation (shipped tag, file path).
**Must-haves:** #### Wave 2 — archive platform-root files (10)
- `core/policy_engine.py``PolicyEngine` Protocol (PEP 544) + - **Task 2.1** (lead-developer): `git mv` 10 files to
`PolicyEngineRegistry` (selects from `config.json.policy.engine`) + `.ciagent/archive/` with milestone-suffix names:
`NullEngine` fallback (emits `SKIPPED` when `policy` key absent) - `CAPABILITY_INVENTORY.md``CAPABILITY_INVENTORY-v1.10.md`
(REQ-291) - `CLARIFY.md``CLARIFY-v1.26.md`
- `.ciagent/config.json` gains `policy` object: `{"engine": - `GRILL.md``GRILL-v1.26.md`
"kyverno-json", "policy_root": - `IDEATE.md``IDEATE-v1.26.md`
"adapters/kyverno-json/policies"}` (REQ-292) - `RESEARCH.md``RESEARCH-v1.26.md`
- `adapters/kyverno-json/kyverno_json_engine.py` — `KyvernoJsonEngine` - `REVIEW-AUDIT-P05.md``REVIEW-AUDIT-P05.md`
implementing the protocol: `is_configured()` guards on `which kj`; - `VERIFY-P03.md``VERIFY-P03.md`
`evaluate()` writes payload to temp JSON, invokes - `VERIFY-P04.md``VERIFY-P04.md`
`kj scan --policy <dir> --payload <json> --output json`, translates - `P4-PILOT-RUN-EVIDENCE.md``P4-PILOT-RUN-EVIDENCE-v1.26.md`
native output → `list[dict]` PCR records (`engine: "kyverno"`, - `AUTONOMY_THESIS.md``AUTONOMY_THESIS-v1.21.md`
`ruleId` prefixed `KJ_<policy_name>`, severity from - `COST.md``COST-v1.14.md`
`nova.cloudinit.dev/severity` annotation); defensive parsing Use `git mv` to preserve history. NOTE: CLARIFY/GRILL/IDEATE/RESEARCH
(malformed → `error` PCR, never exception); `is_configured()==false` were rewritten in P0 with v1.27 content — archive the v1.27 versions
→ single `SKIPPED` PCR (`KJ_ENGINE_NOT_CONFIGURED`) (REQ-293) (they document the v1.27 pre-execution; the next P0 writes fresh).
- `adapters/kyverno-json/__init__.py` exports `KyvernoJsonEngine`; Wait — per D-219, the v1.26 pre-execution artifacts are archived. The
`adapters/kyverno-json/policies/_smoke.json` trivial v1.27 versions replace them in active context; they are NOT archived
`require-contract-id` policy for round-trip validation; at P1 (they are the current P0 artifacts, active until v1.27 ships,
`scripts/install-kyverno-json.sh` runs then archived at v1.28 P1 if v1.28 happens). **Correction:** archive
`go install github.com/kyverno/kyverno-json/cmd/kj@latest`; only the v1.26-era pre-execution artifacts. But P0 already
`.github/workflows/ci.yml` + `.gitea/workflows/ci.yml` install Go + kj overwrote CLARIFY/GRILL/IDEATE/RESEARCH with v1.27 content. The v1.26
(cached) (REQ-294) content lives in git history (the pre-P0 commits). So:
- `tests/test_policy_engine.py` — protocol conformance, registry - The 4 pre-execution files (CLARIFY/GRILL/IDEATE/RESEARCH) at HEAD
selection, unknown-engine `KeyError`, `NullEngine` fallback, are the v1.27 P0 artifacts — **keep active** through v1.27, archive
`is_configured()` false when `which kj` absent (mocked) (REQ-308) at v1.28.
- `tests/test_kyverno_json_engine.py` — `evaluate()` returns PCR dicts - The v1.26-era content is in git history — reachable.
validating against `schemas/policy_check_result.schema.json` (via **Revised archive list (7 files, not 10):** CAPABILITY_INVENTORY,
`jsonschema`); defensive parsing (malformed kyverno-json output → REVIEW-AUDIT-P05, VERIFY-P03, VERIFY-P04, P4-PILOT-RUN-EVIDENCE,
`error` PCR); `is_configured()==false` → `SKIPPED` with AUTONOMY_THESIS, COST.
`KJ_ENGINE_NOT_CONFIGURED`; `pytest.skip("kj not installed")` when
`which kj` absent (REQ-309)
**Vertical slice:** The `PolicyEngineRegistry.get_engine()` returns a Hold — let me re-check D-219. The user said "Archive all 4
configured `KyvernoJsonEngine` that can `evaluate()` a trivial payload pre-execution artifacts." That was decided *before* P0 overwrote
against `_smoke.json` and produce a valid PCR list. The confidence them. The intent was to archive the v1.26 pre-execution record. The
signal is unchanged — it already consumes `list[PolicyCheckResult]`. v1.27 P0 overwrites are the new pre-execution record. Archiving the
The platform runs with or without the `kj` binary (`is_configured()` v1.27 versions at v1.27 P1 would lose the v1.27 pre-execution
guard). All existing tests pass (NullEngine fallback when `policy` key narrative. **Resolution:** archive the v1.26-era content (preserved
absent in test config — but the v1.25 config.json *sets* the key, so in git history at the pre-P0 commits) by noting it in the archive
existing tests that use the real config get `KyvernoJsonEngine` with README; keep the v1.27 P0 versions active through v1.27. The 4 files
`is_configured()==false` → `SKIPPED`). stay active until v1.28 P1.
**Files touched:** **Final archive list (7 files):** CAPABILITY_INVENTORY.md,
- `core/policy_engine.py` (NEW) REVIEW-AUDIT-P05.md, VERIFY-P03.md, VERIFY-P04.md,
- `.ciagent/config.json` (MODIFIED — `policy` object) P4-PILOT-RUN-EVIDENCE.md, AUTONOMY_THESIS.md, COST.md.
- `adapters/kyverno-json/__init__.py` (NEW)
- `adapters/kyverno-json/kyverno_json_engine.py` (NEW)
- `adapters/kyverno-json/policies/_smoke.json` (NEW)
- `scripts/install-kyverno-json.sh` (NEW)
- `.github/workflows/ci.yml` (MODIFIED — Go + kj install step)
- `.gitea/workflows/ci.yml` (MODIFIED — Go + kj install step)
- `tests/test_policy_engine.py` (NEW)
- `tests/test_kyverno_json_engine.py` (NEW)
**Verification:** `pytest tests/test_policy_engine.py - **Task 2.2** (lead-developer): grep for dangling references to the
tests/test_kyverno_json_engine.py tests/test_confidence_signal.py archived filenames across `.ciagent/` + `docs/`; fix any in P2 (the
tests/test_adapter.py tests/test_checkov_adapter.py fix-stale phase).
tests/test_kyverno_adapter.py -v` (new tests pass or skip-without-kj;
existing adapter/confidence tests unchanged). `python3 -m py_compile #### Wave 3 — archive consumer file (1)
core/policy_engine.py adapters/kyverno-json/kyverno_json_engine.py`. - **Task 3.1** (lead-developer): `mkdir
.ciagent/nova-blockchain-exchange/archive/` + `git mv
nova-blockchain-exchange/ROADMAP.md` →
`nova-blockchain-exchange/archive/ROADMAP-v1.26.md` (D-221).
#### Wave 4 — commit P1
- **Task 4.1** (lead-developer): single commit `chore(P01): archive 7
platform + 1 consumer outdated .ciagent files` with `---ci---`
block.
**Must-haves (verify before ship):**
- STATE.md 36 rows accurate (Wave 1 verification).
- 7 platform files present in `.ciagent/archive/` with milestone
suffixes; originals gone from `.ciagent/` root.
- 1 consumer file present in
`.ciagent/nova-blockchain-exchange/archive/`; original gone.
- 0 dangling references in active files (checked in P2, but flagged
here).
### Phase P2 — fix-stale-wire (corrections + wiring)
**Goal:** Fix 3 stale-but-kept files + wire STATE.md into the P-final
ship discipline + add a pointer in the consumer PROJECT.md.
#### Wave 1 — fix PROJECT.md phase-status
- **Task 1.1** (lead-developer): `.ciagent/PROJECT.md` lines 424431 —
the v1.26 phase-status block. Mark P3/P4/P5 complete with shipped
tags (`v1.25.3`, `v1.25.4`, `v1.25.5`); mark v1.26 milestone shipped.
- **Task 1.2** (lead-developer): add a one-line pointer to STATE.md in
the "Capability Status" section header (line 130): "The PO-facing
capability catalog is `.ciagent/STATE.md` (additive; updated at
milestone ship). CAP-NNN IDs cross-reference the regression gate at
`core/regression_verify.py`."
#### Wave 2 — fix ROADMAP.md phase-status
- **Task 2.1** (lead-developer): `.ciagent/ROADMAP.md` v1.26 section —
mark P3/P4/P5 complete with shipped tags; mark the v1.26 Overview
line (line 181) "(active, ...)" → "(complete, tag `v1.25.5`)".
- **Task 2.2** (lead-developer): add STATE.md to the v1.25 + v1.26 P5
phase-detail "Updated at ship" list (the convention visibility
point).
#### Wave 3 — wire STATE.md into ship discipline
- **Task 3.1** (lead-developer): `.ciagent/PLAN.md` P5 Wave 3 Task 3.5
— add STATE.md to the file-update list: "append new capability
entries to `.ciagent/STATE.md`; mark any deprecated capability."
- **Task 3.2** (lead-developer): `.ciagent/NORTH_STAR.md` — add a
one-line note in "Relationship to engineering files" (or the v1.25
update section): "STATE.md is the *what exists* catalog (PO-owned,
additive, updated at milestone ship); this file is the *why*."
#### Wave 4 — fix archive README + consumer PROJECT pointer
- **Task 4.1** (lead-developer): `.ciagent/archive/README.md` — add
the 8 new archived files (7 platform + 1 consumer) to the contents
tables (Snapshots + Completed-phase artifacts sections).
- **Task 4.2** (lead-developer):
`.ciagent/nova-blockchain-exchange/PROJECT.md` — add a one-line
pointer to the platform ROADMAP for milestone-phase history (since
the consumer ROADMAP is archived): "Phase-by-phase history:
`.ciagent/ROADMAP.md` §v1.26 (the consumer ROADMAP is archived at
`.ciagent/nova-blockchain-exchange/archive/ROADMAP-v1.26.md`)."
#### Wave 5 — fix any dangling references from P1 Wave 2
- **Task 5.1** (lead-developer): apply fixes for any dangling
references found in P1 Wave 2.
#### Wave 6 — commit P2
- **Task 6.1** (lead-developer): single commit `docs(P02): fix stale
phase-status + wire STATE.md into ship discipline` with `---ci---`
block.
**Must-haves (verify before ship):**
- PROJECT.md v1.26 phase-status matches CHECKPOINT.json (P3/P4/P5
complete, v1.26 shipped).
- ROADMAP.md v1.26 sections show P3/P4/P5 complete + Overview complete.
- PLAN.md P5 Wave 3 names STATE.md.
- NORTH_STAR.md notes STATE.md.
- archive/README.md lists the 8 new archived files.
- nova-blockchain-exchange/PROJECT.md points to platform ROADMAP.
### Phase P3 — final-review-ship (review + audit + milestone ship)
**Goal:** Final review + audit + milestone ship.
#### Wave 1 — review
- **Task 1.1** (lead-developer): review all P1/P2 changes for
correctness (no broken markdown, no inaccurate citations, no
dangling references).
- **Task 1.2** (lead-developer): fix any P0 issues in this phase.
#### Wave 2 — audit
- **Task 2.1** (lead-developer): reconstruction test — git log
`---ci---` blocks ↔ `.ciagent/` files consistent; phase
progression P0→P1→P2→P3.
- **Task 2.2** (lead-developer): `.ciagent/` file discipline —
CHECKPOINT consistent with HEAD; PROJECT/ROADMAP phase-status
consistent with CHECKPOINT; STATE.md present + 36 rows; archive
contents match the moves.
- **Task 2.3** (lead-developer): branch hygiene — only main +
milestone + P3; P1/P2 deleted.
- **Task 2.4** (lead-developer): commit discipline — all v1.27 commits
carry `---ci---` blocks.
#### Wave 3 — milestone ship
- **Task 3.1** (lead-developer): merge `phase/03` →
`milestone/v1.27-po-state-catalog` → `main`.
- **Task 3.2** (lead-developer): tag `v1.26.3` (= the v1.27 release per
prev-minor tagging rule; v1.27 is an NFR milestone, tags on v1.26.x).
- **Task 3.3** (lead-developer): create Gitea release with full
milestone summary.
- **Task 3.4** (lead-developer): delete all milestone branches (local
+ remote). Tags preserve all history.
- **Task 3.5** (lead-developer): update `.ciagent/REQUIREMENTS.md`
(no REQs to mark — NFR milestone), `.ciagent/ROADMAP.md` (mark
v1.27 complete), `.ciagent/NORTH_STAR.md` (no strategic change),
`.ciagent/STATE.md` (bump "Last milestone ship" to v1.27).
- **Task 3.6** (lead-developer): write checkpoint `stage: complete,
phase: 3, phase_role: final` + clear checkpoint (milestone
complete).
**Must-haves (verify before ship):**
- Review: 0 P0 issues unfixed; P1+ flagged for post-hoc.
- Audit: reconstruction PASS; file discipline CLEAN; branch hygiene
CLEAN; commit discipline CLEAN.
- Ship: `v1.26.3` tag exists; Gitea release created; milestone
branches deleted; main has the milestone merge.
--- ---
### Phase P2 — contract + stack-IR policies (Wave 2, policy-engineer + backend-engineer) ## Requirement → Phase Mapping
**Type:** `feat` (policies + resolver wiring + tests) No REQ-NNN (NFR milestone). The work items are file operations,
traced by the Wave tasks above.
**Requirements:** REQ-295, REQ-296, REQ-297, REQ-298, REQ-299
**Must-haves:**
- `adapters/kyverno-json/policies/contract/` — 4 policies over consumer
contract JSON: `require-id-pattern.json`,
`require-env-in-enum.json`, `require-infrastructure-min-1.json`,
`forbid-unknown-fields.json` — each a `ValidatingPolicy` with one
`validate.assert` rule using JMESPath against the payload root;
severity via `nova.cloudinit.dev/severity` annotation (REQ-295)
- `core/contract_resolver.py` invokes
`PolicyEngineRegistry.get_engine().evaluate(contract_dict,
policies/contract/, contract_id)` **before** resolving; failures
feed the `policy` input as `fail` PCRs (no resolver exit — confidence
signal decides the gate, `--soft-fail` pattern); emits
`nova.policy.evaluated` metrics event (REQ-296)
- `adapters/kyverno-json/policies/stack-ir/` — 3 policies over
resolved Stack IR: `require-tagging-standard.json` (ports
`nova_tagging.py` — `nova:owner` + `nova:environment` tags on every
`resources[]` entry), `forbid-public-ingress.json` (v1.0 demo rule),
`require-encryption-by-default.json` (v1.8 D-encryption-default);
`~` modifier iterates `resources[]` (REQ-297)
- `core/contract_resolver.py` invokes the engine with the resolved
Stack IR and `policies/stack-ir/` **after** resolving; resulting PCRs
appended to the contract-policy PCRs; resolver return values and
exceptions unchanged (additive) (REQ-298)
- `tests/test_stack_ir_policies.py` + `tests/fixtures/stack_ir/` —
passing IR (all tags + encryption) + failing IR (missing tags, public
ingress, plaintext bucket); each policy in isolation + full dir as
bundle; `pytest.skip("kj not installed")` when `which kj` absent
(REQ-299)
**Vertical slice:** A consumer contract passes through the resolver
and produces two PCR lists (contract policies pre-resolve, stack-IR
policies post-resolve) that feed the confidence signal. A contract
with a bad `id` or missing tags produces `fail` PCRs that lower the
confidence score. The resolver's existing tests pass unchanged (the
policy call is additive — it does not change resolver return values
or exceptions).
**Files touched:**
- `adapters/kyverno-json/policies/contract/require-id-pattern.json` (NEW)
- `adapters/kyverno-json/policies/contract/require-env-in-enum.json` (NEW)
- `adapters/kyverno-json/policies/contract/require-infrastructure-min-1.json` (NEW)
- `adapters/kyverno-json/policies/contract/forbid-unknown-fields.json` (NEW)
- `adapters/kyverno-json/policies/stack-ir/require-tagging-standard.json` (NEW)
- `adapters/kyverno-json/policies/stack-ir/forbid-public-ingress.json` (NEW)
- `adapters/kyverno-json/policies/stack-ir/require-encryption-by-default.json` (NEW)
- `core/contract_resolver.py` (MODIFIED — pre/post resolve engine calls)
- `tests/test_stack_ir_policies.py` (NEW)
- `tests/fixtures/stack_ir/passing.json` (NEW)
- `tests/fixtures/stack_ir/failing.json` (NEW)
**Verification:** `pytest tests/test_contract_resolver.py
tests/test_stack_ir_policies.py tests/test_policy_engine.py -v`
(existing resolver tests pass; new policy tests pass or skip-without-
kj). `python3 -m py_compile core/contract_resolver.py`.
--- ---
### Phase P3 — plan-JSON policies + meta-orchestration + pipeline wiring (Wave 3, policy-engineer + backend-engineer) ## Wave Ordering Rationale
**Type:** `feat` (plan-JSON policies + meta-policies + run_platform.sh wiring + tests) - **P1 W1 → W2:** verify STATE.md before archiving (the archive removes
the source-of-truth CAPABILITY_INVENTORY; STATE.md must be accurate
**Requirements:** REQ-300, REQ-301, REQ-302, REQ-303 first).
- **P1 W2 → W3:** platform archive before consumer archive (the
**Must-haves:** platform archive pattern is established; the consumer archive
- `adapters/kyverno-json/policies/plan-json/` — 3 policies over creates a new subdir).
`terraform show -json` output: `forbid-plaintext-secrets.json` (ports - **P2 W1 → W2 → W3:** PROJECT.md fix before ROADMAP.md fix before
CKV_AWS_41/45/46), `forbid-iam-wildcard.json` (ports CKV_AWS_1/40), ship-discipline wiring (PROJECT is the source-of-truth narrative;
`require-kms-reference.json` (ports CKV_AWS_7/33); JMESPath over ROADMAP mirrors it; PLAN/NORTH_STAR wire the convention).
`planned_values.root_module.resources[]` (REQ-300) - **P2 W4:** archive README + consumer pointer (cross-cutting; lands
- `run_platform.sh` Step 5 gains a parallel kyverno-json pass: after after the active-file fixes).
Checkov/Wiz produce raw PCRs, the script runs - **P2 W5:** dangling-reference fixes (lands after all moves + edits
`kj scan --policy adapters/kyverno-json/policies/plan-json/ are known).
--payload <tfshow.json> -o json` and pipes through
`adapters/kyverno-json/kyverno_json_engine.py` to produce a second
PCR list; both lists concatenated and fed to the confidence signal;
`nova.policy.evaluated` event with both engine names; when
`which kj` is false, logs and proceeds with Checkov/Wiz list only
(no hard failure) (REQ-301)
- `tests/test_plan_json_policies.py` + `tests/fixtures/plan_json/` —
passing plan (no secrets, no wildcard, KMS alias) + failing plan
(plaintext password, `Action: "*"`, inline KMS key); policies in
isolation + bundle; `tests/test_run_platform_plan_json_policies.py`
asserts `run_platform.sh` has the kyverno-json Step 5 block +
concatenates PCR lists (script-substring assertion, pattern from
`tests/test_pipeline.py:79-95`) (REQ-302)
- `adapters/kyverno-json/policies/meta/` — `block-on-any-critical.json`
(asserts no PCR in merged list has `severity: critical` + `result:
fail`; if any does, emits `fail` PCR `KJ_META_BLOCK_CRITICAL`
severity `critical` — declarative source of truth; the
`confidence_signal.py` hard-override stays as defense-in-depth per
D-119) + `tagging-rules-agree.json` (cross-checks Checkov
`NOVA_TAG_NAMING` vs kj `KJ_REQUIRE_TAGGING_STANDARD` by
`resourceRef`; divergence emits `error` PCR per D-118);
`tests/test_meta_policies.py` (REQ-303)
**Vertical slice:** `run_platform.sh` Step 5 produces a merged PCR list
(Checkov/Wiz + kj plan-JSON policies + kj meta-policies over the
merged list) that feeds the confidence signal. A plan with a plaintext
secret produces two `fail` PCRs (one Checkov, one kj) for the same
resource — visible defense-in-depth. A critical finding anywhere
produces a `KJ_META_BLOCK_CRITICAL` meta-PCR that the confidence
signal's hard-override blocks. The pipeline runs with or without `kj`
(graceful skip).
**Files touched:**
- `adapters/kyverno-json/policies/plan-json/forbid-plaintext-secrets.json` (NEW)
- `adapters/kyverno-json/policies/plan-json/forbid-iam-wildcard.json` (NEW)
- `adapters/kyverno-json/policies/plan-json/require-kms-reference.json` (NEW)
- `adapters/kyverno-json/policies/meta/block-on-any-critical.json` (NEW)
- `adapters/kyverno-json/policies/meta/tagging-rules-agree.json` (NEW)
- `scripts/run_platform.sh` (MODIFIED — Step 5 kj parallel pass)
- `tests/test_plan_json_policies.py` (NEW)
- `tests/test_meta_policies.py` (NEW)
- `tests/test_run_platform_plan_json_policies.py` (NEW)
- `tests/fixtures/plan_json/passing.json` (NEW)
- `tests/fixtures/plan_json/failing.json` (NEW)
**Verification:** `pytest tests/test_plan_json_policies.py
tests/test_meta_policies.py tests/test_run_platform_plan_json_policies.py
tests/test_pipeline.py -v` (new tests pass or skip-without-kj; existing
pipeline tests pass). `python3 -m py_compile` on any modified Python.
Shellcheck on `run_platform.sh` if available.
--- ---
### Phase P4 — regression-gate policies + docs (Wave 4, policy-engineer + data-engineer + lead-developer) ## Vertical-slice integrity
**Type:** `feat` (regression policies) + `docs` (adapter READMEs + ARCHITECTURE + STANDARDS + METRICS) Each phase ships a self-contained, verifiable slice:
- P1 ships STATE.md (verified accurate) + 8 archived files (verified
**Requirements:** REQ-304, REQ-305, REQ-306, REQ-307 moved). The active `.ciagent/` root drops from 25 to 17 files.
- P2 ships 3 fixed files + 3 wired files + archive README + consumer
**Must-haves:** pointer. The kept files match CHECKPOINT.json state.
- `adapters/kyverno-json/policies/regression/` — 3 policies over - P3 ships the milestone release + cleared checkpoint.
capability-inventory JSON frontmatter: `cap-013-adapter-dedup.json`,
`cap-023-metrics-collector.json`, `cap-024-deck-structure.json`;
emit `pass`/`fail` PCRs per capability; the existing
`core/regression_verify.py` is kept (drives the CI gate); the
policies are the declarative mirror (REQ-304)
- `tests/test_regression_policies.py` +
`tests/fixtures/capability_inventory/clean.json` +
`tests/fixtures/capability_inventory/drifted.json` — clean (all caps
pass) + drifted (duplicate adapter, missing metric status, broken
deck arc); regression gate still 287/287 baseline (new tests
additive, skip-without-kj) (REQ-305)
- `adapters/README.md` gains new kyverno-json adapter row + "Policy
Engine Protocol" section (Protocol, registry, swap boundary,
how-to-add-OpaEngine); `adapters/kyverno-json/README.md` documents
the engine, install path, policy directory layout, 4 policy
categories (REQ-306)
- `.ciagent/ARCHITECTURE.md` §12.7 (added in RESEARCH) is finalized;
`schemas/README.md` notes `engine: "kyverno"` shared by K8s adapter
+ kj (distinguished by `ruleId` prefix); `modules/STANDARDS.md`
gains "Policy authoring standard" section for module owners;
`docs/METRICS.md` notes the policy engine is swappable (Strategic
Objective #2 — provable trust via a replaceable substrate) (REQ-307)
**Vertical slice:** The regression gate's capability checks are now
declarative policies auditable as artifacts. A new module owner can
read `modules/STANDARDS.md` "Policy authoring standard" and write a
per-module kyverno-json policy. A new engineer can read
`adapters/README.md` "Policy Engine Protocol" and implement an
`OpaEngine`. The 287/287 baseline is unchanged.
**Files touched:**
- `adapters/kyverno-json/policies/regression/cap-013-adapter-dedup.json` (NEW)
- `adapters/kyverno-json/policies/regression/cap-023-metrics-collector.json` (NEW)
- `adapters/kyverno-json/policies/regression/cap-024-deck-structure.json` (NEW)
- `tests/test_regression_policies.py` (NEW)
- `tests/fixtures/capability_inventory/clean.json` (NEW)
- `tests/fixtures/capability_inventory/drifted.json` (NEW)
- `adapters/README.md` (MODIFIED — new row + PolicyEngine Protocol section)
- `adapters/kyverno-json/README.md` (NEW)
- `schemas/README.md` (MODIFIED — engine enum note)
- `modules/STANDARDS.md` (MODIFIED — Policy authoring standard section)
- `docs/METRICS.md` (MODIFIED — swappable engine narrative)
**Verification:** `pytest tests/test_regression_policies.py
tests/test_kyverno_json_engine.py -v` (new tests pass or skip-without-
kj). Full regression gate `pytest tests/` still at 287/287 baseline +
new tests (skip without kj). Manual read of `adapters/README.md` +
`adapters/kyverno-json/README.md` + `modules/STANDARDS.md` policy
section for clarity.
---
### Phase P5 — final review + audit + milestone ship (Final Phase)
**Type:** `docs` (review + audit + milestone completion)
**Requirements:** All REQ-291..309 (mark complete)
**Must-haves:**
- `ciagent-review` multi-persona code review across P1..P4
(lead-developer, backend-engineer, data-engineer, policy-engineer).
Auto-fix P0; flag P1+ for post-hoc review. If P1+ issues found, fix
them in this final phase (not loop back to EXECUTE).
- `ciagent-audit` — reconstruction test (git log ↔ `.ciagent/` files),
`.ciagent/` file discipline, branch hygiene, commit discipline.
Critical issues fixed in this phase.
- `ciagent-ship` (milestone) — merge `phase/05-final-review-ship` →
`milestone/v1.25-kyverno-json` → `main`; tag `v1.24.5` (= the v1.25
release per the prev-minor tagging rule); create Gitea release with
full milestone summary (all phases, all requirements); delete all
milestone branches (local + remote).
- Update `REQUIREMENTS.md` (mark REQ-291..309 complete),
`ROADMAP.md` (mark v1.25 complete), `CHECKPOINT.json`
(milestone_complete: true), `NORTH_STAR.md` (note Strategic
Objective #2 — provable trust via a replaceable policy-engine
substrate).
**Vertical slice:** The v1.25 milestone is complete: kyverno-json is
the primary policy tool, behind a swappable adapter, with policies
over all 4 Nova artifacts. Tags v1.24.0..v1.24.5 on the v1.24.x line.
The milestone branch merges to main.
**Verification:** `pytest tests/ -v` full suite passes (287 baseline +
new tests). `git log --oneline` shows the v1.25 phase commits.
`git tag` shows v1.24.0..v1.24.5. `git branch` shows no leftover
milestone/phase branches (all deleted post-ship).
---
## Wave ordering (parallelization)
With `parallelization.enabled: true`, `max_concurrent_agents: 5`,
`min_plans_for_parallel: 2`:
- **P1 Wave 1:** backend-engineer (protocol + registry + install) ‖
data-engineer (config.json policy object) ‖ policy-engineer (engine
adapter + smoke policy). 3 concurrent personas. Merge in order:
data-engineer → backend-engineer → policy-engineer.
- **P2 Wave 2:** policy-engineer (contract + stack-IR policies) ‖
backend-engineer (resolver wiring — depends on P1 registry). 2
concurrent. Merge: policy-engineer → backend-engineer (wiring
references the policy dirs).
- **P3 Wave 3:** policy-engineer (plan-JSON + meta policies) ‖
backend-engineer (run_platform.sh wiring — depends on P1 engine +
P2 resolver pattern). 2 concurrent. Merge: policy-engineer →
backend-engineer.
- **P4 Wave 4:** policy-engineer (regression policies) ‖ data-engineer
(capability-inventory fixtures) ‖ lead-developer (docs: READMEs,
STANDARDS, METRICS). 3 concurrent. Merge: data-engineer →
policy-engineer → lead-developer.
Territory enforcement: `warn` mode (per `config.json
personas.territory_enforcement: "warn"`). Cross-territory edits
(e.g., backend-engineer touching a policy file) emit a warning, not a
block.
## Requirement → phase → persona matrix
| REQ | Phase | Primary persona | Type |
|-----|-------|-----------------|------|
| REQ-291 | P1 | backend-engineer | feat |
| REQ-292 | P1 | data-engineer | feat (config) |
| REQ-293 | P1 | policy-engineer | feat |
| REQ-294 | P1 | backend-engineer | feat (install) |
| REQ-295 | P2 | policy-engineer | feat |
| REQ-296 | P2 | backend-engineer | feat (wiring) |
| REQ-297 | P2 | policy-engineer | feat |
| REQ-298 | P2 | backend-engineer | feat (wiring) |
| REQ-299 | P2 | policy-engineer | test |
| REQ-300 | P3 | policy-engineer | feat |
| REQ-301 | P3 | backend-engineer | feat (pipeline) |
| REQ-302 | P3 | policy-engineer + backend-engineer | test |
| REQ-303 | P3 | policy-engineer | feat (meta) |
| REQ-304 | P4 | policy-engineer | feat |
| REQ-305 | P4 | policy-engineer + data-engineer | test |
| REQ-306 | P4 | policy-engineer + lead-developer | docs |
| REQ-307 | P4 | lead-developer | docs |
| REQ-308 | P1 | backend-engineer | test |
| REQ-309 | P1 | policy-engineer | test |
+239 -1505
View File
File diff suppressed because it is too large Load Diff
+154 -2342
View File
File diff suppressed because it is too large Load Diff
+116 -410
View File
@@ -1,438 +1,144 @@
# Nova — v1.25 Research Findings # Nova — v1.27 Research Findings
> Phase: research (pre-execution). Milestone: v1.25 (kyverno-json Unified > Phase: research (pre-execution). Milestone: v1.27 (PO State Catalog &
> Policy Engine). Status: research. Researcher: ci-researcher. > Ciagent Compression). Status: research. Researcher: ci-researcher.
> Autonomy: full. > Autonomy: full.
## 1. Problem domain v1.27 is an NFR milestone (docs/chore only, no code, no schema). There
is no new domain to research. The research is a codebase-grounded
inventory of (a) the files to archive + their staleness evidence, and
(b) the sources backing the STATE.md capability backfill. This file
records the inventory for the v1.27 record; the active authoring used
these sources directly.
Nova's compliance/policy posture is fragmented across three engines with ---
three rule languages and three adapter shapes (see PROJECT.md v1.25
"Why" for the full diagnosis). The `PolicyCheckResult` schema
(`schemas/policy_check_result.schema.json`) is already the engine-agnostic
contract that `core/confidence_signal.py` consumes — the *contract* is
right; the *orchestration* is fragmented. There is no single declarative
place where "what Nova considers compliant" lives. The K8s-only Kyverno
adapter (`adapters/kyverno/`) can't help because it only speaks to K8s
manifests and the platform emits Terraform (D-053).
`kyverno-json` is the correction: a Kyverno-ecosystem runtime that applies ## 1. Files to archive (staleness inventory)
Kyverno policies to **any** JSON/YAML payload. It becomes the **unified
orchestrator** of compliance checks, behind a swappable `PolicyEngine`
protocol so OPA can replace it one day. Checkov and Wiz remain as
raw-finding adapters feeding *into* kyverno-json meta-policies.
## 2. kyverno-json — the engine surface ### 1.1 Pre-execution artifacts (v1.26 — shipped, decisions folded)
### 2.1 What it is | File | Lines | Staleness evidence | Decisions folded into |
|---|---|---|---|
| `CLARIFY.md` | 225 | v1.26 milestone shipped (`v1.25.5`); decisions D-200..D-213 | `PROJECT.md` load-bearing decisions |
| `GRILL.md` | 225 | v1.26 grill verdict PROCEED 0.84; binding revisions applied | `PLAN.md` revisions (G-Q4 REQ-322→P2 W0; G-Q6 enforcement deferred; G-Q9 key-split future) |
| `IDEATE.md` | 193 | all 7 accepted ideas → REQ-315..322 (shipped) | `REQUIREMENTS.md` v1.26 traceability |
| `RESEARCH.md` | 250 | v1.26 domain research (blockchain, deploy, modules, metrics) | `ARCHITECTURE.md` §12.8; shipped REQs |
[kyverno-json](https://github.com/kyverno/kyverno-json) is a standalone Go All four are pre-execution artifacts for a shipped milestone. The next
binary from the Kyverno project. It is a **separate runtime** from the P0 writes fresh versions. Per D-219 (user-confirmed) + D-222: archive
Kyverno K8s admission controller — same policy lineage, different all four with `-v1.26` suffixes.
application target. Where Kyverno (K8s) evaluates `ClusterPolicy`
resources against Kubernetes manifests at admission time, kyverno-json
evaluates `ValidatingPolicy` resources against **any** JSON or YAML
payload file via the CLI (`kj scan`) or a Go library. It is **not** a
Python package (no PyPI release); it is installed via
`go install github.com/kyverno/kyverno-json/cmd/kj@latest` (D-115) or by
downloading a pinned binary from GitHub releases.
### 2.2 CLI surface (the v1.25 invocation path) ### 1.2 Phase verifications + review (v1.26 — shipped, PASS)
The v1.25 engine uses the `kj scan` subcommand: | File | Lines | Staleness evidence |
```
kyverno-json scan [flags]
Flags:
--labels strings Labels selectors for policies
--output string Output format (text or json) (default "text")
--payload string Path to payload (json or yaml file)
--policy strings Path to kyverno-json policies
--pre-process strings JMESPath expression used to pre process payload
```
The `KyvernoJsonEngine.evaluate()` implementation (REQ-293) invokes:
```
kj scan --policy <policy_dir> --payload <payload.json> --output json
```
and parses the JSON `results[]` array. The `--pre-process` flag is
available for JMESPath pre-projection (noted for the meta-policy use case
where the payload is the merged PCR list and a pre-process expression
can index by `ruleId` — recorded as a future optimization, not used in
v1.25's initial implementation).
Other subcommands (`kj jp`, `kj serve`, `kj playground`, `kj docs`) are
out of scope for v1.25. `kj serve` is the long-running web-app mode
(noted as a future consideration for lower-latency evaluation in the
Out of Scope section of REQUIREMENTS.md). `kj jp` is the JMESPath REPL —
useful for policy authoring/debugging, not invoked by the engine.
### 2.3 Policy structure (the `ValidatingPolicy` resource)
kyverno-json policies are Kubernetes-style resources (cluster-scoped)
belonging to the `json.kyverno.io` API group, kind `ValidatingPolicy`,
version `v1alpha1`:
```yaml
apiVersion: json.kyverno.io/v1alpha1
kind: ValidatingPolicy
metadata:
name: <policy-name> # becomes the KJ_<policy-name> ruleId prefix
spec:
rules:
- name: <rule-name>
identifier: <jmespath> # optional — path to the unique entry id
match: # assertion tree — which payload entries
any: # the rule applies to
- <assertion>
exclude: # optional — exclude matching entries
any:
- <assertion>
context: # optional — named bindings available to
- name: <binding> # the rule's assertions ($<binding>)
variable: <value>
validate:
message: "<human-readable>" # optional per-rule message
assert:
all: # all assertions must hold
- check: <assertion-tree>
message: "<per-check>"
# OR
any: # at least one assertion must hold
- check: <assertion-tree>
```
Key differences from K8s Kyverno policies:
- **Always cluster-scoped** — no `namespace` field.
- **No `forEach`, pattern operators, anchors, or wildcards.** Iteration
is done via the `~` projection modifier in assertion trees (see §2.4).
- **Assertion trees** with JMESPath expressions replace Kyverno's
pattern-matching syntax (see §2.4).
### 2.4 Assertion trees (the rule language)
An `assert` declaration contains an `all` or `any` list. Each entry has a
`check` (the assertion tree — a nested JMESPath projection) and an
optional `message`. **All comparisons happen in the leaves of the tree.**
A simple example (assert a pod doesn't use the default service account):
```yaml
validate:
assert:
all:
- message: "serviceAccountName 'default' is not allowed"
check:
spec:
(serviceAccountName == 'default'): false
```
The `(expression)` syntax evaluates a JMESPath expression; the result
becomes the current object for descendants; the leaf value is compared
to the expected value.
**Iteration via the `~` modifier.** The `~` prefix on a key applies
descendant assertions to **each element** of an array/map individually
(rather than comparing the whole array). Given `foo.bar: [1,2,3]`:
```yaml
check:
foo:
~.bar: # iterate each element
(@ < `5`): true # assert each element < 5
```
The `~index_name.bar` form binds the index (array) or key (map) to
`$index_name` for use in descendants. This is how v1.25 iterates
`resources[]` in the Stack IR policies (REQ-297) and
`planned_values.root_module.resources[]` in the plan-JSON policies
(REQ-300).
**Explicit bindings** via `->binding_name` allow descendants to refer
to a parent node via `$binding_name`. Built-in bindings: `$payload`
(the whole input), `$policy`, `$rule`.
**Escaping** via `\key\` prevents projection when a payload key collides
with the projection syntax. Not needed for Nova payloads (no `(key)`
fields), noted for completeness.
### 2.5 Output shape (what `kj scan --output json` produces)
The JSON output is a `results[]` array. Each result entry has (at
minimum):
- `policy`: the policy metadata.name
- `rule`: the rule name
- `result`: `"pass"` | `"fail"` | `"error"` | `"skip"` (lowercase)
- `message`: the assertion message (or engine error message)
- `resource`: the matched payload entry (the `identifier` value, or the
whole payload when no identifier/match)
- `namespace`/`kind`/`name`: K8s-style fields (present but empty for
non-K8s payloads — the K8s Kyverno adapter's evidence uses these; the
kyverno-json engine's evidence uses `assertion`/`jmespath` instead)
- `severity`: not present by default (kyverno-json does not assign
severities — the Nova policy author assigns severity via a Nova-
specific annotation; see §2.6)
The `KyvernoJsonEngine._to_pcr()` translator (REQ-293) maps:
- `policy``ruleId` (prefixed `KJ_<policy_name>` per D-116)
- `result``result` (`pass`/`fail`/`error` → pass/fail/error;
`skip`/`skipped` → skipped)
- `message``message`
- `resource``resourceRef` + `evidence.resource`
- severity from the policy's `metadata.annotations` (see §2.6)
- `engine: "kyverno"` (per D-116 — no new enum value)
### 2.6 Severity assignment (Nova convention)
kyverno-json does not natively assign severities to results. Nova's
confidence signal requires a `severity` per PCR (critical/high/medium/
low/info). The v1.25 convention: each Nova policy file declares its
severity via a `metadata.annotations` field:
```yaml
metadata:
name: forbid-public-ingress
annotations:
nova.cloudinit.dev/severity: high
```
The `KyvernoJsonEngine._to_pcr()` reads this annotation from the loaded
policy YAML (not from the scan result — the result doesn't carry it) and
applies it to every result that policy produces. Default when absent:
`info`. This keeps severity in the policy (declarative, version-
controlled) rather than in the engine adapter (imperative). The
annotation key is `nova.cloudinit.dev/severity` (matches the existing
`nova.cloudinit.dev` namespace used in `schemas/tagging-standard.json`).
## 3. The four policy targets (v1.25 scope)
### 3.1 Consumer contract JSON (REQ-295)
The payload is the parsed contract dict (the raw YAML loaded as JSON).
Policies assert the `contract.schema.json` constraints declaratively:
`require-id-pattern` (JMESPath regex `^[a-z][a-z0-9-]{2,5}$` over
`id`), `require-env-in-enum` (`environment` in `["dev","qa","prod","dr"]`),
`require-infrastructure-min-1` (`length(infrastructure) > 0`),
`forbid-unknown-fields` (keys subset of the 4 allowed). These are the
declarative equivalent of the jsonschema constraints — they let Nova
apply its own compliance posture (e.g. forbid a specific env for a
specific consumer) on top of schema validity without editing the
jsonschema.
**Invocation point:** `core/contract_resolver.py` pre-resolve (REQ-296).
Early-fail: if a contract policy fails, the resolver still proceeds
(the confidence signal decides the gate, consistent with the existing
`--soft-fail` Checkov pattern) — but the failing PCRs are in the
`policy` input, which lowers the score.
### 3.2 Resolved Target Stack IR JSON (REQ-297)
The payload is the resolved Stack IR dict produced by
`core/contract_resolver.py` (the merged module outputs). Policies
assert over `resources[]` (the array of resolved resources):
`require-tagging-standard` (every resource's `tags` has `nova:owner` +
`nova:environment` — ports
`adapters/terraform/policy/custom_rules/nova_tagging.py`),
`forbid-public-ingress` (no resource has `public_ingress: true` — the
v1.0 demo rule, now declarative), `require-encryption-by-default` (every
S3/EBS/KMS-aliased resource carries encryption config — ports the v1.8
D-encryption-default rule). The `~` modifier iterates `resources[]`.
**Invocation point:** `core/contract_resolver.py` post-resolve (REQ-298).
Additive — the resolver's return values and exceptions are unchanged;
the PCRs are appended to the contract-policy PCRs.
### 3.3 Terraform plan JSON (REQ-300)
The payload is `terraform show -json <tfplan>` output. Policies assert
over `planned_values.root_module.resources[]`:
`forbid-plaintext-secrets` (no `aws_db_instance.password` /
`aws_iam_user.login_profile.password` in plaintext — ports
`CKV_AWS_41/45/46`), `forbid-iam-wildcard` (no `Action: "*"` or
`Resource: "*"` in `aws_iam_policy.PolicyDocument` — ports
`CKV_AWS_1/40`), `require-kms-reference` (KMS keys referenced by alias,
not inline key material — ports `CKV_AWS_7/33`). These are declarative
**mirrors** of `checkov_adapter.py:RULE_MAP` — the Checkov rule stays
the source of truth for `terraform_plan` scanning; the kyverno-json
policy covers the same plan JSON with a different rule language
(defense-in-depth against engine drift).
**Invocation point:** `run_platform.sh` Step 5 (REQ-301). After
Checkov/Wiz produce raw PCRs, the script runs `kj scan` over the plan
JSON; both PCR lists concatenate into the confidence signal's `policy`
input. When `which kj` is false, the script logs and proceeds with the
Checkov/Wiz list only.
### 3.4 PolicyCheckResult records (meta-policies, REQ-303)
The payload is the **merged** `list[PolicyCheckResult]` produced by
checkov + wiz + the plan-JSON policies. This is the most novel target —
kyverno-json policies over the policy results themselves.
`block-on-any-critical` asserts no PCR has `severity: "critical"` +
`result: "fail"`; if any does, the meta-policy emits a `fail` PCR with
`ruleId: "KJ_META_BLOCK_CRITICAL"` and severity `critical`. This is the
declarative source of truth for "critical = block" (D-119 — the
`confidence_signal.py` `PENALTY["critical"]: None` hard-override stays
as defense-in-depth). `tagging-rules-agree` cross-checks the Checkov
`NOVA_TAG_NAMING` result against the kyverno-json
`KJ_REQUIRE_TAGGING_STANDARD` result by `resourceRef`; divergence emits
an `error` PCR (D-118).
**Invocation point:** after the three target policies (contract/stack-
IR/plan-JSON) produce their PCR lists, the merged list is the payload
for the meta-policies. The meta-policy PCRs are appended to the merged
list, which is what the confidence signal consumes.
## 4. The `PolicyEngine` swap boundary
### 4.1 Protocol shape (REQ-291)
A Python `Protocol` (PEP 544 — structural subtyping, no inheritance):
```python
class PolicyEngine(Protocol):
@property
def name(self) -> str: ...
def is_configured(self) -> bool: ...
def evaluate(self, payload: dict | str, policy_dir: Path,
contract_id: str) -> list[dict]: ...
```
`list[dict]` (not `list[PolicyCheckResult]` — there's no dataclass; the
schema is enforced via `jsonschema` validation in tests, matching the
existing adapter pattern). The registry selects the active engine from
`config.json.policy.engine`. A `NullEngine` is the fallback when the
`policy` key is absent (emits `SKIPPED` — backward compatibility for
tests that don't set the key).
### 4.2 The OPA-equivalent surface (future swap)
OPA (Open Policy Agent) is the most likely future replacement. The
mapping:
| Nova `PolicyEngine` member | kyverno-json impl | OPA equivalent |
|---|---|---| |---|---|---|
| `name` | `"kyverno-json"` | `"opa"` | | `VERIFY-P03.md` | 39 | v1.26 P3 verification — PASS; shipped `v1.25.3` |
| `is_configured()` | `which kj` | `which opa` | | `VERIFY-P04.md` | 31 | v1.26 P4 verification — PASS; shipped `v1.25.4` |
| `evaluate(payload, policy_dir, contract_id)` | `kj scan --policy <dir> --payload <json> -o json` | `opa eval -d <dir> -i <json> 'data.nova.<...>'` | | `REVIEW-AUDIT-P05.md` | 218 | v1.26 P5 final review + audit — PROCEED; shipped `v1.25.5`; 0 P0 remain; audit CLEAN |
| Policy file format | `ValidatingPolicy` (YAML) | Rego (`.rego`) | | `P4-PILOT-RUN-EVIDENCE.md` | 46 | v1.26 live apply evidence (`blkex-pilot-apply-v0.2`); summarized in `nova-blockchain-exchange/README.md` §5 + REVIEW-AUDIT-P05 §2.2 |
| Result shape | `results[]` (pass/fail/error/skip) | `result` (set of violations) |
| Severity | Nova annotation `nova.cloudinit.dev/severity` | Nova convention (Rego `metadata` or a wrapper) |
The protocol is minimal (3 members) specifically so the OPA ### 1.3 Durable references (superseded or stale)
implementation is a known quantity: an `OpaEngine` class that shells to
`opa eval`, translates the Rego violation set to PCR dicts, and
implements `is_configured()` via `which opa`. The policy *files* would
need rewriting (Rego, not ValidatingPolicy) — but the protocol, the
registry, the confidence signal, and the PCR schema are all untouched.
This is the swap boundary the user asked for ("Implemented as an
adapter since we might one day decide to replace it with something else
like OPA").
### 4.3 Why not a full plugin registry? | File | Lines | Staleness evidence | Superseded by |
|---|---|---|---|
| `CAPABILITY_INVENTORY.md` | 120 | dated 2026-07-27; framed as "v1.1→v1.8 re-verification sweep"; predates v1.26 pilot (CAP-025 absent; blockchain capabilities absent) | `STATE.md` (this milestone) |
| `AUTONOMY_THESIS.md` | 65 | "Last refined: v1.21"; thesis fully folded into `NORTH_STAR.md` Vision (lines 1722) + Anti-Goals #2 | `NORTH_STAR.md` |
| `COST.md` | 106 | dated 2026-07-29; framed "v1.0 → v1.14"; predates v1.26 live pilot (ECS + ALB + DynamoDB + S3 costs not reflected) | A future cost milestone writes a fresh report; `STATE.md` Domain 7 notes cost tracking as a capability |
A `setuptools` entry-point plugin registry (like checkov's ### 1.4 Consumer-side (nova-blockchain-exchange)
`--external-checks-dir`) was considered and rejected: Nova has 1 active
engine today (kyverno-json) and at most 2 in the foreseeable future
(kyverno-json + OPA). A `Protocol` + `dict` registry in
`core/policy_engine.py` is the right weight — discoverable, typed,
testable, and ~40 lines. An entry-point registry adds packaging
complexity (entry-point metadata, version resolution) for no gain at
this scale. The `register(name, factory)` method on the registry is
the extension point if a future milestone needs runtime plugin
discovery.
## 5. Latency / MTTR impact (G-Q3 anticipation) | File | Lines | Staleness evidence |
|---|---|---|
| `nova-blockchain-exchange/ROADMAP.md` | 57 | marks P3/P4/P5 as "planned" but v1.26 shipped (`v1.25.5`); phase narrative preserved in platform `ROADMAP.md` v1.26 section |
NORTH_STAR.md MTTR target: < 60s p95. `run_platform.sh` Step 5 today Per D-221: consumer archives land in
runs Checkov over the terraform plan (typically 5-15s for a small `.ciagent/nova-blockchain-exchange/archive/ROADMAP-v1.26.md`.
stack). Adding `kj scan` over the same plan JSON adds:
- Process spawn: ~50ms (Go binary startup)
- Policy load: ~20ms (a handful of YAML files)
- Assertion evaluation: ~100-500ms (JMESPath over a small plan)
- Total: < 1s for a typical Nova stack
The kyverno-json pass runs **in parallel** with Checkov (REQ-301 — the ---
script launches both and waits on both), so the wall-clock impact is
`max(checkov_time, kj_time)` ≈ checkov_time (kj is faster). The
contract + stack-IR policies run during resolve (already a fast step).
Meta-policies run over the merged list (in-memory, < 10ms). **No
measurable MTTR impact** is expected. This will be verified in P3
VERIFY with a timing assertion.
## 6. "Platform functions without AI" tenet (G-Q1 / D-120) ## 2. Files to keep active (no-edit or fix-only)
kyverno-json is deterministic (same policy + payload → same result, ### 2.1 No-edit (live code paths or durable)
every run). It is not an LLM, not a probabilistic model, not a
"judgement" engine. The NORTH_STAR.md tenet ("the platform functions
without AI — 'AI decisions' are really automated decisions")
distinguishes AI (non-reproducible) from automation (reproducible).
kyverno-json is the latter. Adding it is **more** aligned with the
tenet than the current imperative Python in `core/env_transition.py`
and `core/regression_verify.py`, because the policy is declarative
(visible, auditable, version-controlled) rather than imperative (logic
hidden in function bodies). The `is_configured()` guard ensures the
platform functions without the binary (graceful skip → `SKIPPED` PCR
→ confidence signal proceeds).
## 7. ECS policy catalog overlap (prior art) | File | Why keep active |
|---|---|
| `CHECKPOINT.json` | Authoritative resume state — never archive |
| `config.json` | Operational config — never archive |
| `REGRESSION_REPORT.json` | Written by `core/regression_verify.py:705`; read by `core/metrics/collector.py:27` + `trust_snapshot.py:21` + metrics views (D-224: regenerates on next `run_regression.sh`) |
| `REGRESSION_REPORT.md` | Written by `core/regression_verify.py:704`; read by `scripts/run_regression.sh` (D-224) |
| `PERSONAS.md` | Regenerated at each milestone P0 by the lead-developer; not stale until then |
| `IAM_POLICY.md` | Live baseline, test-enforced (`tests/test_iam_policy_baseline.py`); D-207 future key-split pending (D-223) |
| `PLAN.md` | Active phase plan; reset to next milestone at next P0 |
| `ARCHITECTURE.md` | Durable target architecture (§1–§12 + §12.7 + §12.8 + §12.9) |
| `NORTH_STAR.md` | PO strategy; loaded every ci-run via `config.strategic_direction_file` |
| `nova-blockchain-exchange/PROJECT.md` | Consumer project charter; D-200..D-205 load-bearing |
| `nova-blockchain-exchange/REQUIREMENTS.md` | REQ-310..322 spec intent (shipped but spec stays for reference) |
| `nova-blockchain-exchange/README.md` | Consumer onboarding guide; still accurate (deploy workflow, secrets, contract shape, verification) |
The kyverno-json catalog ships ECS policies that overlap with Nova's ### 2.2 Fix-only (corrections to stale-but-kept files)
L1 modules: `ecs-cluster-enable-logging`, `ecs-cluster-required-
container-insights`, `ecs-service-public-ip`, `ecs-service-required-
latest-platform-fargate`, `ecs-task-definition-fs-read-only`. These are
**reference policies**, not drop-in Nova policies — they target the
AWS ECS API shape (`type: aws_ecs_service` etc.), not Nova's Stack IR
shape. v1.25 policies target the Nova IR (REQ-297) and the terraform
plan JSON (REQ-300), not the raw AWS API. The catalog is useful as
prior art for JMESPath patterns over ECS resources — the
`ecs-service-public-ip` policy's `contains('$allowed-values',
@.assign_public_ip)` pattern informs the Nova `forbid-public-ingress`
policy shape. No catalog policies are imported directly in v1.25.
## 8. Risks & mitigations | File | Fix |
|---|---|
| `PROJECT.md` | v1.26 phase-status block (lines 424431): P3/P4/P5 "pending" → "complete" with shipped tags `v1.25.3/4/5`; add STATE.md pointer (D-225: P2 phase) |
| `ROADMAP.md` | v1.26 P3/P4/P5 sections (lines 238, 261, 272) "planned" → "complete" with shipped tags; v1.26 Overview line "active" → "complete"; add STATE.md to P5 ship-update list (D-225: P2 phase) |
| `archive/README.md` | Add the 11 new archived files to the contents tables (P2 phase) |
---
## 3. STATE.md capability backfill sources
The STATE.md backfill (36 capabilities across 10 domains) was sourced
from:
| Source | Used for |
|---|---|
| `core/regression_verify.py` (lines 129768) | CAP-001..CAP-025 IDs, names, tiers, evidence pointers |
| `.ciagent/CAPABILITY_INVENTORY.md` (pre-archive) | CAP-001..022 descriptions, defect notes, evidence |
| `modules/registry.json` | L1/L2 module catalog (13 L1 + 2 L2 entries) |
| `.ciagent/REQUIREMENTS.md` v1.25 traceability | REQ-291..309 → policy-engine capabilities |
| `.ciagent/nova-blockchain-exchange/REQUIREMENTS.md` + `.ciagent/REQUIREMENTS.md` v1.26 traceability | REQ-310..322 → pilot capabilities |
| `.ciagent/CHECKPOINT.json` | shipped tags `v1.25.0..v1.25.5` |
| `git log --all --oneline` | file paths for v1.26 shipped features |
| `.ciagent/PROJECT.md` load-bearing decisions | INV-1..INV-11 invariants |
| `docs/submission-readiness.md` + `schemas/contract.schema.json` | INV-1 contract surface |
---
## 4. Persona assessment
v1.27 is a docs/chore milestone. The active roster:
- **lead-developer** (active): owns the milestone narrative (STATE.md
authoring, PROJECT/ROADMAP fixes, archive README, PLAN/NORTH_STAR
wiring, this RESEARCH, CLARIFY, PLAN, final review + audit). Territory:
`.ciagent/`, `docs/`.
- **backend-engineer** (active, limited): no code changes in v1.27.
Consulted on the `core/confidence_signal.py` LSP diagnostic (pre-
existing, not touched by v1.27). No territory writes.
- **data-engineer** (inactive): no schema/migration/ORM changes.
- **policy-engineer** (inactive): no policy authoring.
- **frontend-engineer** (inactive): no UI.
- **blockchain-engineer** (inactive): no chain code.
Territory enforcement: warn. The milestone is `.ciagent/`-only; the
lead-developer owns all writes.
---
## 5. Risk analysis
| Risk | Likelihood | Impact | Mitigation | | Risk | Likelihood | Impact | Mitigation |
|---|---|---|---| |---|---|---|---|
| `kj` binary not in CI image | medium | blocks P3+ tests | `is_configured()` guard + `pytest.skip` + `scripts/install-kyverno-json.sh` | | Archive move breaks a relative path reference in an active file | Low | Medium | `grep` for the archived filenames across `.ciagent/` + `docs/` before commit; fix any dangling references in P2 |
| kyverno-json output shape changes across versions | low | breaks `_to_pcr()` | pin `@latest` to a known-good commit in `install-kyverno-json.sh` after P1 smoke; defensive parsing (malformed → `error` PCR, not exception) | | STATE.md capability row is inaccurate (wrong shipped tag / wrong file path) | Medium | Low | The backfill sources are the authoritative registries (regression_verify.py, registry.json, CHECKPOINT.json, git log); citations are direct |
| Policy explosion (4 targets × N rules) | medium | maintenance load | wave ordering (PLAN); policies co-located per target dir; meta-policy cross-check keeps the set auditable | | PROJECT.md phase-status fix conflicts with a future v1.26-era commit | Low | Low | v1.26 is shipped (main has the milestone merge); no v1.26-era commits will arrive |
| Checkov + kj tagging-rule drift | medium | false `error` PCRs | `tagging-rules-agree` meta-policy emits `error` on divergence (visible, not silent); the Checkov rule stays source of truth for HCL, kj for IR | | REGRESSION_REPORT stale state is mistaken for v1.27 scope | Low | Low | D-224 records the decision; STATE.md Domain 7 notes the current CAP range |
| OPA swap turns out harder than the protocol implies | low | future milestone rework | RESEARCH §4.2 documents the OPA-equivalent surface; the protocol is the contract, not the implementation |
| `--pre-process` needed for meta-policies but undocumented behavior | low | meta-policy bugs | v1.25 meta-policies use plain assertion trees over the PCR list (no pre-process); `--pre-process` noted as a future optimization only |
## 9. Assumptions (logged, full autonomy) ---
- A1: `kj scan --output json` produces a stable `results[]` array shape. ## 6. Verdict
Will be verified in P1 smoke test (`_smoke.json` policy + a trivial
payload); if the shape differs, `_to_pcr()` is adjusted defensively
(malformed → `error` PCR). Confidence: 0.85.
- A2: The `nova.cloudinit.dev/severity` annotation convention is
read by the engine from the policy YAML (loaded once per evaluate()
call). kyverno-json does not validate unknown annotations — they pass
through. Confidence: 0.90.
- A3: The `~` projection modifier iterates `resources[]` in the Stack
IR and `planned_values.root_module.resources[]` in the plan JSON
correctly. Verified in P2/P3 tests. Confidence: 0.85.
- A4: `go install` works in the CI image (Go toolchain available or
installable). If not, the binary-release download path is the
documented fallback in `install-kyverno-json.sh`. Confidence: 0.80.
- A5: The `NullEngine` fallback (when `policy` key absent in
config.json) keeps all existing tests passing — they don't set the
key, so they get `NullEngine``SKIPPED` PCRs → confidence signal
proceeds with `policy` input `[SKIPPED]` → per-input score 1.0
(skipped counts as pass in `_per_input_score`). Confidence: 0.95
(verified against `confidence_signal.py:84-89`).
## 10. Decisions referenced v1.27 is feasible, scoped, and the sources are grounded. No new domain,
no new code, no schema breaks. The archive moves are lossless (git
D-115 (install path), D-116 (engine enum reuse), D-117 (adapter history + archive directory both preserve bytes). The STATE.md
signatures unchanged), D-118 (tagging cross-check), D-119 (critical- backfill is sourced from authoritative registries. Proceed to PLAN.
override defense-in-depth), D-120 (deterministic not AI). See
CLARIFY.md for the full resolution text.
## 11. Architecture updates (deferred to RESEARCH-stage file edits)
- `.ciagent/ARCHITECTURE.md` gains §12.7 "Policy Engine Registry" with
the registry diagram. Deferred to the RESEARCH commit (this file's
commit) — the section is authored as part of this research.
- `schemas/README.md` notes `engine: "kyverno"` is shared by the K8s
adapter and kyverno-json (distinguished by `ruleId` prefix).
- `modules/STANDARDS.md` gains a "Policy authoring standard" section
(P4, REQ-307).
- `docs/METRICS.md` notes the policy engine is swappable (P4, REQ-307).
+201 -2161
View File
File diff suppressed because it is too large Load Diff
+284
View File
@@ -0,0 +1,284 @@
# Nova — System State (what exists today)
> **PO-owned catalog of shipped capabilities.** Updated at every milestone
> ship (P final). Additive only — entries are appended, never rewritten,
> unless a capability is explicitly deprecated (then marked, not deleted).
> Read by the PO upstream of the PDLC before authoring new REQ-NNN specs,
> and by CIAgent at SPECIFY for capability awareness.
>
> **Authority:** this file is *descriptive of shipped state*, not
> authoritative for live phase/ship state — that's `CHECKPOINT.json`. For
> *why*, read `NORTH_STAR.md`. For *how*, read `ARCHITECTURE.md`. For
> *what was decided*, read `PROJECT.md` load-bearing decisions.
>
> **Last milestone ship:** v1.26 (`v1.25.5`, 2026-08-19).
> **Next update:** at v1.27 ship.
## How to use this file (PO)
- Before writing a new REQ: search this file for the capability you
intend to spec. If it exists, extend it; do not re-spec it under a new
REQ-NNN.
- Respect the **Invariants** below — they are load-bearing and
cross-cutting. A new REQ that violates an invariant requires a
`CLARIFY` decision recorded in PROJECT.md.
- Anchor each new REQ to a **Domain**; new domains require a PO
decision recorded in CLARIFY.
- When a capability is deprecated (replaced, removed, or
re-architecture), append a `Deprecated` row marking the milestone +
replacement; do not delete the original entry.
## Invariants (PO-owned — do not violate in new REQs)
> Distilled from `PROJECT.md` load-bearing decisions D-034..D-072 +
> W1..BA + Q1.3. Cite the decision ID when an REQ touches one.
- **INV-1 (Contract surface):** The only PDLC→Nova boundary is
`schemas/contract.schema.json` + `schemas/submission-readiness.schema.json`
(D-133). All consumer intent enters through one of these. Nova never
reaches into upstream PDLC.
- **INV-2 (Confidence inputs):** Six canonical inputs — policy (0.30),
validation (0.25), freshness (0.10), source (0.15), history (0.10),
nfrs (0.10). Weights frozen for v1 (D-040). `critical` severity =
hard-block via `PENALTY["critical"]: None` (defense-in-depth behind the
declarative `block-on-any-critical` meta-policy).
- **INV-3 (HITL gates):** dev = autonomous (≥0.50); qa = HITL (≥0.75);
prod = HITL (≥0.90); dr = HITL (≥0.95). Approver identity = Gitea
`gitea.actor` of the `workflow_dispatch` (D-042). Separation-of-duties
on prod reads `approver_qa` from the DynamoDB outbox.
- **INV-4 (Engine is swappable):** The policy engine is behind the
`PolicyEngine` protocol (`core/policy_engine.py`, v1.25). Confidence
signal + pipeline import only the protocol, never a concrete engine.
`kyverno-json` is the v1.25 default; `OPA` (or other) implements the
same 3-method protocol to replace it.
- **INV-5 (Adapter is stateless):** `adapters/terraform/adapter.py` owns
no module content — no `TYPE_MAP`/`INPUT_MAP`/`OUTPUT_MAP` (v1.11
rewrite). A new stack type requires a new L1 module
(`modules/l1/<name>/`) + `registry.json` entry, not an adapter change.
- **INV-6 (Audit stream is immutable):** Outbox writes via SQLite
hash-chain today (D-083 deferred). S3 Object Lock / JWS tamper-
*resistant* ledger is a future milestone. Current stream is tamper-
*evident* (any tampering breaks the chain).
- **INV-7 (PCR schema is the moat):** `schemas/policy_check_result.schema.json`
shape is frozen across adapter swaps (v1.25 hard constraint). The
`engine` enum already includes `"kyverno"` + `"opa"`; new engines add
no enum value.
- **INV-8 (Long-lived creds forbidden):** §12.5. The D-039/D-047 per-run-
rotated-key waiver satisfies the *intent* (no *persistently* long-lived
key). Real OIDC federation is blocked on `go-gitea/gitea#36988`.
- **INV-9 (Two consumer surfaces, one platform):** L3A (developer) +
L3B (citizen dev) converge on the same contract schema, the same
policy envelope, and the same evidence stream.
- **INV-10 (Nova is downstream of PDLC):** Nova governs infra + delivery
only. Product backlog, code authorship, IDE workflows, application
business logic are upstream. Integration only via the validated
contract boundary (INV-1).
- **INV-11 (Pilot scope, v1.26):** Equities only (D-200). Single-
validator PoA (D-201). D-083 (Object Lock/JWS) stays deferred. Hot
path deferred (D-126). Multi-cloud deferred. Multi-validator BFT
deferred. The pilot runs `mode: full` for `dev` only (D-209); qa/prod/dr
stay placeholder (D-208, blocked by the pilot-readiness policy).
## Domains (capability groups)
1. Contract surface
2. Modules (L1 primitives + L2 patterns)
3. Policy engine
4. Confidence signal
5. Environments & promotion
6. Evidence stream & audit
7. Telemetry & metrics
8. Consumer surfaces (developer + agentic)
9. Pilot estate (v1.26)
10. Forge / CI runtime
## Capabilities (additive — one row per shipped capability)
> Tier: **local** = runs via emulating adapters (no AWS); **live-aws** =
> runs against the live AWS account `581513795199`;
> **lifecycle-pipeline** = verified via the `modules-lifecycle`
> pipeline's apply→modify→destroy matrix cell.
> CAP-NNN IDs cross-reference the regression gate at
> `core/regression_verify.py` (the machine registry). This file is the
> PO-facing narrative; the machine registry is the source of truth for
> the gate.
### Domain 1 — Contract surface
| ID | Capability | Shipped | Files | Controlling | Tier | Notes |
|----|-----------|---------|-------|-------------|------|-------|
| CAP-001 | `contract.schema.json` validates sample contracts | v1.1 / `v1.2.0` | `schemas/contract.schema.json` | REQ-001, D-... | local | shape: id/name/environment/infrastructure |
| CAP-002 | `environment.schema.json` validates env files | v1.9 / `v1.9.0` | `schemas/environment.schema.json` | REQ-040 | local | dev/qa/prod/dr env JSONs |
| CAP-006 | Contract interpolation expands `${env.*}` / `${contract.*}` | v1.9 / `v1.9.0` | `core/contract_resolver.py` | REQ-040 | local | per-env variants |
| — | Submission-readiness gate (superset of contract schema) | v1.18 / `v1.18.0` | `schemas/submission-readiness.schema.json`, `core/submission_readiness.py` | REQ-217, REQ-218, D-133 | local | the only PDLC→Nova boundary (INV-1) |
### Domain 2 — Modules (L1 primitives + L2 patterns)
> Source: `modules/registry.json` (the authoritative module catalog).
> STATE.md lists the *capability* of having a registered module;
> registry.json is the live registry.
| ID | Capability | Shipped | Files | Controlling | Tier | Notes |
|----|-----------|---------|-------|-------------|------|-------|
| CAP-003 | contract_resolver resolves `static-assets` (L2) | v1.1 / `v1.2.0` | `core/contract_resolver.py`, `modules/l2/static-assets/` | REQ-003 | local | CloudFront+WAF+S3 pattern |
| CAP-004 | contract_resolver resolves `microservice` (L2) | v1.2 / `v1.3.0` | `core/contract_resolver.py`, `modules/l2/microservice/` | REQ-004 | local | ECS Fargate pattern (6 L1 children) |
| CAP-005 | Terraform adapter compiles resolved stack to `.tf` | v1.1 / `v1.2.0` | `adapters/terraform/adapter.py` | REQ-005 | local | stateless assembler (v1.11); emits `module "<rid>" { source }` blocks |
| — | L1 `s3` primitive | v1.1 / `v1.2.0` | `modules/l1/s3/` | REQ-005 | lifecycle | versioning + SSE-KMS by default |
| — | L1 `vpc` primitive | v1.1 / `v1.2.0` | `modules/l1/vpc/` | REQ-005 | lifecycle | shared platform VPC (v1.11) |
| — | L1 `ecs-cluster` primitive | v1.1 / `v1.2.0` | `modules/l1/ecs-cluster/` | REQ-005 | lifecycle | |
| — | L1 `ecs-service` primitive | v1.1 / `v1.2.0` | `modules/l1/ecs-service/` | REQ-005 | lifecycle | execution_role_arn + task_role_arn wired (P4 W1 fix, v1.26) |
| — | L1 `iam-role` primitive | v1.1 / `v1.2.0` | `modules/l1/iam-role/` | REQ-005 | lifecycle | |
| — | L1 `alb` primitive | v1.1 / `v1.2.0` | `modules/l1/alb/` | REQ-005 | lifecycle | requires SG wire (P4 W1 fix, v1.26) |
| — | L1 `ecr` primitive | v1.1 / `v1.2.0` | `modules/l1/ecr/` | REQ-005 | lifecycle | |
| — | L1 `cloudfront` primitive | v1.7 / `v1.7.0` | `modules/l1/cloudfront/` | REQ-049, D-049 | lifecycle | OAC + WAF (production edge) |
| — | L1 `waf` primitive | v1.7 / `v1.7.0` | `modules/l1/waf/` | REQ-049, D-049 | lifecycle | |
| — | L1 `rds` primitive | v1.7 / `v1.7.0` | `modules/l1/rds/` | REQ-059, D-059 | lifecycle | multi-engine input (postgres/mysql/...) |
| — | L1 `kms-key` primitive | v1.8 / `v1.8.0` | `modules/l1/kms-key/` | REQ-069, D-069 | lifecycle | per-stack CMK; 90-day rotation |
| — | L1 `uptime` primitive | v1.8 / `v1.8.0` | `modules/l1/uptime/` | REQ-066, D-066 | lifecycle | uptime-kuma on ECS Fargate |
| — | L1 `dynamodb` primitive | v1.26 / `v1.25.2` | `modules/l1/dynamodb/` | REQ-322 | local | PK + optional SK; PAY_PER_REQUEST; encryption + PITR by default (v1.8 NFRs) |
| CAP-013 | `terraform init+validate+plan` live AWS (microservice) | v1.2 / `v1.3.0` | `adapters/terraform/adapter.py` | REQ-013 | live-aws | 14 resources; plan saved |
| CAP-014 | `terraform init+validate+plan` live AWS (static-assets) | v1.7 / `v1.7.0` | `adapters/terraform/adapter.py` | REQ-014 | live-aws | CloudFront+WAF+S3 plan OK |
| CAP-017 | DynamoDB `nova-contracts` table | v1.7 / `v1.7.0` | `core/lambda/`, `terraform/` | REQ-068, D-068 | lifecycle | PK `changeRequestId`, SK `submittedAt` (CMDB) |
| CAP-018 | Lambda contract-ingestor | v1.7 / `v1.7.0` | `core/lambda/contract_ingestor.py` | REQ-051, D-051 | lifecycle | local stub + lifecycle evidence |
| CAP-019 | ECS cluster + service (L2 microservice) | v1.7 / `v1.7.0` | `modules/l2/microservice/` | REQ-066 | lifecycle | apply/modify/destroy exit 0 |
| CAP-020 | CloudFront + WAF production stack | v1.7 / `v1.7.0` | `modules/l2/static-assets/` | REQ-049 | lifecycle | apply/modify/destroy exit 0 |
| CAP-021 | uptime-kuma monitoring primitive | v1.8 / `v1.8.0` | `modules/l1/uptime/` | REQ-066 | lifecycle | |
| CAP-022 | OIDC role for act_runner | v1.11 / `v1.11.0` | `terraform/bootstrap/` | REQ-116, D-039 | lifecycle | real OIDC blocked on go-gitea/gitea#36988 |
### Domain 3 — Policy engine
| ID | Capability | Shipped | Files | Controlling | Tier | Notes |
|----|-----------|---------|-------|-------------|------|-------|
| — | `PolicyEngine` Protocol + `PolicyEngineRegistry` | v1.25 / `v1.24.1` | `core/policy_engine.py` | REQ-291, REQ-292 | local | selects engine from `config.json.policy.engine`; `NullEngine` fallback when key absent |
| — | `KyvernoJsonEngine` adapter (shells to `kj scan`) | v1.25 / `v1.24.1` | `adapters/kyverno-json/kyverno_json_engine.py` | REQ-293, REQ-294 | local | `is_configured()` guards on `which kj`; `SKIPPED` PCR when absent |
| — | Contract policies (4) over consumer contract JSON | v1.25 / `v1.24.2` | `adapters/kyverno-json/policies/contract/` | REQ-295, REQ-296 | local | id-pattern, env-enum, infra-min-1, forbid-unknown-fields |
| — | Stack-IR policies (3) over resolved Target Stack IR | v1.25 / `v1.24.2` | `adapters/kyverno-json/policies/stack-ir/` | REQ-297, REQ-298, REQ-299 | local | tagging-standard, public-ingress, encryption-by-default |
| — | Plan-JSON policies (3) over `terraform show -json` | v1.25 / `v1.24.3` | `adapters/kyverno-json/policies/plan-json/` | REQ-300, REQ-301, REQ-302 | local | plaintext-secrets, iam-wildcard, kms-reference |
| — | Meta-policies over merged PCR list | v1.25 / `v1.24.3` | `adapters/kyverno-json/policies/meta/` | REQ-303 | local | `block-on-any-critical` (declarative critical-block); `tagging-rules-agree` (Checkov↔kj agree) |
| — | Regression-gate policies (3) over capability-inventory JSON | v1.25 / `v1.24.4` | `adapters/kyverno-json/policies/regression/` | REQ-304, REQ-305 | local | declarative mirrors of CAP-013/023/024 imperative checks |
| — | Pilot-readiness policy (no placeholder account) | v1.26 / `v1.25.3` | `adapters/kyverno-json/policies/pilot-readiness/no-placeholder-account.json` | REQ-320 | local | fail-closed gate; blocks apply on `account_id == "000000000000"` |
| — | Settlement-finality policy | v1.26 / `v1.25.3` | `adapters/kyverno-json/policies/settlement-finality/all-matches-committed.json` | REQ-315 | local | authored + tested; enforcement deferred to milestone that binds qa/prod/dr (D-208) |
| — | Checkov adapter (raw-finding source) | v1.7 / `v1.7.0` | `adapters/terraform/checkov_adapter.py` | REQ-053 | local | feeds meta-policies; `NOVA_TAG_NAMING` custom rule is the TF-static source of truth |
| — | Wiz adapter (raw-finding source) | v1.7 / `v1.7.0` | `adapters/wiz/` | REQ-053 | local | API findings; `is_configured()` guard |
| — | K8s Kyverno adapter (documentation-only) | v1.7 / `v1.7.0` | `adapters/kyverno/` | REQ-053, D-053 | local | inactive for Terraform-only stacks; activates when GitOps emits K8s manifests |
### Domain 4 — Confidence signal
| ID | Capability | Shipped | Files | Controlling | Tier | Notes |
|----|-----------|---------|-------|-------------|------|-------|
| CAP-007 | `confidence_signal.compute` returns a band | v1.1 / `v1.2.0` | `core/confidence_signal.py` | REQ-007, D-040 | local | 6 inputs (INV-2); band ∈ {pass, block} |
| — | `escalation_reason: 'confidence'` on `band == 'block'` | v1.26 / `v1.25.3` | `core/confidence_signal.py` | REQ-318 | local | grounds Human Escalation Frequency numerator |
### Domain 5 — Environments & promotion
| ID | Capability | Shipped | Files | Controlling | Tier | Notes |
|----|-----------|---------|-------|-------------|------|-------|
| — | env-JSON `state_backend` wiring | v1.26 / `v1.25.3` | `core/environments/*.json`, `adapters/terraform/adapter.py` | REQ-319, D-... | local | adapter reads `env.state_backend.bucket` (fallback to computed name) |
| — | Environment progression (dev autonomous → qa/prod/dr HITL) | v1.1 / `v1.2.0` | `core/env_transition.py`, `core/hitl_gates.py` | REQ-042, D-042 | local | destroy-on-environment-change (v1.24) |
| — | Decommission mode (2-step, HITL SRE gates) | v1.8 / `v1.8.0` | `core/env_transition.py`, `scripts/run_platform.sh` | REQ-070, D-070 | local | `mode: decommission` requires `changeRequestId` |
| — | Per-env mandatory metadata (W3.E) | v1.1 / `v1.2.0` | `schemas/submission-readiness.schema.json` | W3.E | local | dev=stack+env; qa+=e2e+load; prod+=runbook+dashboard+oncall; dr+=drDrillRef |
### Domain 6 — Evidence stream & audit
| ID | Capability | Shipped | Files | Controlling | Tier | Notes |
|----|-----------|---------|-------|-------------|------|-------|
| CAP-008 | outbox_writer builds a hash-chained item | v1.1 / `v1.2.0` | `core/outbox_writer.py` | REQ-008 | local | tamper-evident (INV-6); tamper-resistant deferred (D-083) |
| CAP-015 | DynamoDB outbox table exists + describable | v1.1 / `v1.2.0` | `core/outbox_writer.py` | REQ-015 | live-aws | `nova-outbox` (post-v1.26 re-bootstrap) |
| CAP-016 | S3 state bucket exists + readable | v1.1 / `v1.2.0` | `terraform/bootstrap/` | REQ-016 | live-aws | `nova-tfstate-581513795199-us-east-1` |
| — | Decision Ledger (SQLite hash-chain) | v1.17 / `v1.17.0` | `core/metrics/decision_ledger.py` | REQ-185, REQ-186 | local | cold store for metrics; `ai.decision.made` + `attestation.recorded` events |
| — | SSM Parameter Store deploy outputs (SecureString, KMS) | v1.7 / `v1.7.0` | `core/output_publisher.py` | REQ-050, D-050 | live-aws | `/acdl/{env}/{contractId}/{output_name}` |
| — | GitHub PR comment / job summary deploy outputs | v1.7 / `v1.7.0` | `scripts/run_platform.sh` | REQ-050, D-050 | local | no raw secrets in logs |
| — | Uniform error reporting via Lambda `report_error` | v1.7 / `v1.7.0` | `core/lambda/contract_ingestor.py` | REQ-055, D-055 | live-aws | GitHub issue on platform repo `acdl/acdl`; idempotent |
| — | Tagging standard enforcement (4 required tags) | v1.7 / `v1.7.0` | `schemas/tagging-standard.json`, `adapters/terraform/policy/custom_rules/nova_tagging.py` | REQ-054, D-054 | local | `nova:owner`, `nova:contract`, `nova:environment`, `nova:cost-center` |
| — | Encryption + deletion-protection by default | v1.8 / `v1.8.0` | `modules/l1/*/terraform/main.tf` | REQ-062, REQ-069, D-062, D-069, D-072 | local | per-stack CMK; managed KMS fallback for standalone L1 (D-072) |
### Domain 7 — Telemetry & metrics
| ID | Capability | Shipped | Files | Controlling | Tier | Notes |
|----|-----------|---------|-------|-------------|------|-------|
| CAP-023 | metrics collector runs + emits expected schema | v1.17 / `v1.17.0` | `core/metrics/collector.py` | REQ-194 | local | fact_run, fact_decision, fact_attestation dims |
| CAP-024 | unified deck structure (slide count, x3 arc, per-slide benefits) | v1.17 / `v1.17.0` | `docs/presentations/nova-autonomous-cloud-delivery-marp.md` | REQ-194 | local | single source-of-truth marp deck |
| — | Outcome backfill (`pending``succeeded`/`failed`) | v1.26 / `v1.25.3` | `core/metrics/outcome_backfill.py` | REQ-317 | local | idempotent + terminal; grounds AI Decision Accuracy |
| — | Trust Snapshot | v1.17 / `v1.17.0` | `metrics/TRUST_SNAPSHOT.md`, `core/metrics/trust_snapshot.py` | REQ-194 | local | leadership-ready trust verdict |
| — | PowerBI export (fact/dimension views + 8 placeholder views) | v1.17 / `v1.17.0` | `metrics/powerbi/` | REQ-194 | local | deferred metrics ship as documented-schema placeholders |
| — | Pre-apply Infracost estimate | v1.17 / `v1.17.0` | `scripts/run_platform.sh` | REQ-119 | local | `nova.cost.estimated`; actual-spend CUR reconciliation deferred (D-096) |
| — | Regression gate (`scripts/run_regression.sh`) | v1.10 / `v1.10.0` | `core/regression_verify.py`, `scripts/run_regression.sh` | REQ-090, REQ-121 | local | fails closed on any non-Verified CAP; CAP-001..025 |
### Domain 8 — Consumer surfaces (developer + agentic)
| ID | Capability | Shipped | Files | Controlling | Tier | Notes |
|----|-----------|---------|-------|-------------|------|-------|
| — | Reusable deploy workflow (`deploy.yml@v1.25`) | v1.5 / `v1.5.0` | `.github/workflows/deploy.yml`, `.gitea/workflows/deploy.yml` | REQ-105 | local | `workflow_call`; modes: full/plan-only/check-only/decommission |
| — | Consumer onboarding (developer + citizen-dev paths) | v1.1 / `v1.2.0` | `docs/ONBOARDING.md`, `docs/consumer-guide.md` | BA.E, W3.E | local | both end in a sandbox dev submission that must pass the confidence gate |
| — | Atelier MCP server (agentic validation) | v1.18 / `v1.18.0` | `mcp/atelier/server.py` | REQ-221, REQ-222 | local | `atelier.validate_against_principles` tool |
| — | 9 production-grade engineering skills | v1.18 / `v1.18.0` | `skills/{api,security,data,testing,observability,errors,devops,infrastructure-as-code,compliance}.md` | REQ-221, REQ-222, BA.A | local | indexed by `docs/skills.md`; review/agent-checklist.md gate |
| — | Module examples (validated against contract schema) | v1.7 / `v1.7.0` | `modules/<name>/examples/{simple,complex}.yml` | REQ-058, D-058 | local | examples cannot drift from schema silently |
### Domain 9 — Pilot estate (v1.26)
> The first real consumer estate. `nova-blockchain-exchange` repo
> (Gitea `continuous-intelligence/nova-blockchain-exchange`, local clone
> `/root/nova-blockchain-exchange`). Homegrown PoA blockchain, equities
> only, single validator, T+1 settlement finality = block commit.
| ID | Capability | Shipped | Files | Controlling | Tier | Notes |
|----|-----------|---------|-------|-------------|------|-------|
| CAP-026 | PoA blockchain core (block + ledger + validator) | v1.26 / `v1.25.1` | `chain/block.py`, `chain/ledger.py`, `chain/validator.py` | REQ-310, D-201 | local | single validator; SHA-256 hash chain; deterministic block production |
| CAP-027 | Order-matching engine (limit order book) | v1.26 / `v1.25.1` | `engine/order_book.py`, `engine/order.py` | REQ-311 | local | price-time priority; partial fills |
| CAP-028 | T+1 settlement service | v1.26 / `v1.25.1` | `settlement/service.py` | REQ-312 | local | idempotent; finality = block commit |
| CAP-029 | Consumer `contract.yaml` (blockchain exchange) | v1.26 / `v1.25.2` | `nova-blockchain-exchange/contract.yaml`, `contracts/*.yml` | REQ-313 | local | per-env variants (dev/qa/prod); validated against contract schema |
| CAP-030 | Consumer deploy via `deploy.yml@v1.25` (inline adapter) | v1.26 / `v1.25.2` | `nova-blockchain-exchange/.github/workflows/deploy.yml`, `.gitea/workflows/deploy.yml` | REQ-314 | local | no cross-repo `uses:` (SPEC §10 Q1); checkout `acdl/acdl @ v1.25` into `platform/`, run `run_platform.sh` |
| CAP-025 | Live-pilot-apply regression capability (round-trip) | v1.26 / `v1.25.3` | `core/regression_verify.py` | REQ-316 | local | contract→adapter→plan→policy→confidence→attestation→outbox round-trip assertion |
| CAP-031 | Live pilot apply evidence (`blkex-pilot-apply-v0.2`) | v1.26 / `v1.25.4` | `.ciagent/archive/P4-PILOT-RUN-EVIDENCE-v1.26.md` | REQ-316, REQ-321 | live-aws | confidence 0.800 pass; outcome backfilled; hash chain valid; live apply against `581513795199` |
| CAP-032 | AWS key rotation scheduled workflow | v1.26 / `v1.25.3` | `workflows-src/rotate-aws-key.yml` | SPEC §5.9 | local | daily rotation; forge-agnostic token name (REQ-230) |
### Domain 10 — Forge / CI runtime
| ID | Capability | Shipped | Files | Controlling | Tier | Notes |
|----|-----------|---------|-------|-------------|------|-------|
| CAP-009 | offline pytest suite passes | v1.1 / `v1.2.0` | `tests/` | REQ-009 | local | 844 tests (v1.26 baseline) |
| CAP-010 | `run_ci.sh` reproduces CI pipeline locally | v1.4 / `v1.4.0` | `scripts/run_ci.sh` | REQ-010 | local | offline; contract→resolver→stack→adapter→structure validated |
| CAP-011 | headline E2E — local tier (microservice) | v1.2 / `v1.3.0` | `scripts/run_local_e2e.sh` | REQ-011, D-092 | local | emulating adapters (no AWS) |
| CAP-012 | local E2E — static-assets (no ECS) | v1.1 / `v1.2.0` | `scripts/run_local_e2e.sh` | REQ-012 | local | |
| — | `platform-test.yml` CI workflow | v1.4 / `v1.4.0` | `.github/workflows/platform-test.yml` | REQ-010 | local | platform repo only (consumer CI is per-consumer) |
| — | `modules-lifecycle` pipeline (apply→modify→destroy matrix) | v1.11 / `v1.11.0` | `.github/workflows/modules-lifecycle.yml` | REQ-121, D-096 | live-aws | per-module lifecycle cell; `ci-vpc-destroy` always runs |
| — | `release.yml` (semver + floating tag maintenance) | v1.7 / `v1.7.0` | `.github/workflows/release.yml` | REQ-... | local | `v1.25` + `v1` floating tags force-moved on merge to main |
| — | IAM policy baseline (`acdl-spike-runner-policy`) | v1.11 / `v1.11.0` | `terraform/bootstrap/spike_runner_policy.json`, `.ciagent/IAM_POLICY.md` | REQ-116, D-095 | live-aws | regression-tested by `tests/test_iam_policy_baseline.py`; OIDC role `acdl-act-runner-role` (CAP-022) |
| — | Local emulating adapters (no AWS) | v1.10 / `v1.10.0` | `core/local_lambda_stub.py`, `scripts/run_local_e2e.sh` | D-092 | local | proves runtime behavior without live AWS |
## Archive pointers
- **v1.0v1.24 capability narrative + the 2026-07-27 re-verification sweep:**
`.ciagent/archive/CAPABILITY_INVENTORY-v1.10.md` (moved from
`.ciagent/CAPABILITY_INVENTORY.md` at v1.27). CAP-NNN IDs in this file
cross-reference the regression gate at `core/regression_verify.py`.
- **v1.0v1.24 milestone narrative:** `.ciagent/archive/PROJECT-v1.0-v1.24.md`.
- **v1.0v1.24 requirements (REQ-01..REQ-290):** `.ciagent/archive/REQUIREMENTS-v1.0-v1.24.md`.
- **v1.0v1.24 phase breakdowns:** `.ciagent/archive/ROADMAP-v1.0-v1.24.md`.
- **v1.0v1.24 architecture history:** `.ciagent/archive/ARCHITECTURE-v1.0-v1.24.md`.
- **v1.26 pre-execution artifacts (CLARIFY, GRILL, IDEATE, RESEARCH):**
`.ciagent/archive/{CLARIFY,GRILL,IDEATE,RESEARCH}-v1.26.md` (decisions
D-200..D-213 folded into `PROJECT.md` load-bearing decisions + PLAN.md
binding revisions at v1.27 archive time).
- **v1.26 phase verifications:** `.ciagent/archive/{VERIFY-P03,VERIFY-P04,REVIEW-AUDIT-P05}.md`.
- **v1.26 live pilot run evidence:** `.ciagent/archive/P4-PILOT-RUN-EVIDENCE-v1.26.md`.
- **v1.21 autonomy thesis (folded into NORTH_STAR.md Vision):** `.ciagent/archive/AUTONOMY_THESIS-v1.21.md`.
- **v1.14 AWS cost report (predates v1.26 live pilot):** `.ciagent/archive/COST-v1.14.md`.
## Update discipline
This file is updated **once per milestone, at the P-final milestone-ship
wave** (Wave 3 "milestone ship" in `PLAN.md`), alongside
`ROADMAP.md`/`NORTH_STAR.md`/`REQUIREMENTS.md`:
1. Append new capability entries for each shipped REQ (one row per
capability; group by domain).
2. Mark any deprecated capability with a `Deprecated` row citing the
milestone + replacement.
3. Bump the "Last milestone ship" header.
4. Do not rewrite existing entries (additive only).
Enforcement: convention (the P-final ship step names this file). A
drift-check gate (assert every REQ marked `complete` in
`REQUIREMENTS.md` traceability appears in STATE.md) is a future option
if the convention drifts.
+945
View File
@@ -0,0 +1,945 @@
# Nova — Architecture (v1.1 target)
> Target architecture for the real Agentic Cloud Delivery Platform (rebranded
> Nova in v1.15). Source of truth for **how**: `docs/architecture.md` (v0.2) is the upstream
> draft; this file is the Nova-repo operating copy, refined at phase
> boundaries. Where this file and `docs/vision.md` conflict, the vision wins.
## Status
Architecture is at **v0.2** upstream (`docs/architecture.md`). Milestone v1.1
**finalizes it to v1.0** in Phase 07 by resolving the 11 open decisions
(see `PROJECT.md` open-decision resolutions table). This file records the
locked commitments and the v1.1 spike scope.
## Overview
The platform is **four layers + six cross-cutting concerns**. The sixth
concern — the engine abstraction (§12) — is first-class, not an
implementation detail. The vision's "Two Consumer Surfaces, One Platform"
tenet binds everything: L3A and L3B converge on the same contract schema,
the same policy envelope, and the same evidence stream.
```
┌──────────── acdl-contracts ────────────┐
Developer ───▶ │ commit contract.yaml │ (L3A)
Citizen dev ──▶ │ Issue → agent → contract.yaml │ (L3B)
└────────────────┬───────────────────────┘
│ (push)
┌──────────────────────┐
│ central pipeline │
│ (acdl repo, Gitea │
│ Actions / act_runner) │
└────────┬─────────────┘
┌─────────────────────────┼─────────────────────────┐
▼ ▼ ▼
contract→IR resolution policy (Checkov/Kyverno) confidence signal
│ │ │
▼ ▼ ▼
Terraform adapter ──▶ terraform plan ──▶ PolicyCheckResult ──▶ {score,band}
│ │
▼ ▼
dev (autonomous, ≥0.50) qa (HITL, ≥0.75) prod (HITL, ≥0.90) dr (HITL, ≥0.95)
DynamoDB outbox ──▶ S3 Object Lock (7-yr, source of truth) ──▶ GitHub audit repo (hot index)
acdl-evidence (timeline UI)
```
## Layers
### Layer 1 — Foundational Primitives
Single-purpose, **engine-agnostic** primitive modules. L1 modules do
not compose with other L1s; L1 takes its environment as input. The L1
interface is defined against the **Target Stack IR**, not against Terraform
directly (the IR is shaped to round-trip to Terraform in v1, per §12.1).
- No inter-L1 references. L1 may call Terraform data sources.
- Semver: interface → MAJOR, behavior → MINOR, lifecycle → PATCH (W3.D).
- Immutability on publication. 12-month deprecation window.
- AI refinement is a flag; the trigger is the W1.A joint condition.
### Layer 2 — Composed Stacks
Combine L1 primitives into deployable shapes. Each codebase maps to one
canonical L2 stack (`multiStack: true` only per W1.B). Shape X
(parameterized module) or Shape Y (thin-composition layer). Hierarchical
composition, max depth 5, only registered L1s. The thin-composition tree's
`wires` field is defined against the IR's relationship type, not a Terraform
module block.
Pipeline quality checks: secrets-in-plaintext, public ingress, IAM
wildcard, KMS key reference, tag compliance, naming convention. Restricted
from thin-composition: IAM principal creation, network boundary creation,
key/secret creation, external data transfer. Auto-promote after 3 observed
usages.
### Layer 3A — Developer Consumer Surface
Tag-based reference to the central pipeline template. Developer-owned
workflow file, no platform auto-sync. L3A and L3B are parallel paths, not a
progression. **W2.A (Path B):** tag for dev/qa, SHA for prod; platform CLI
resolves tag→SHA for prod-bound workflows.
### Layer 3B — Agentic Consumer Surface
Hybrid runtime, skill as markdown, agent as executor. Trust model: trust
and always verify on the platform side. Skill envelope (4 dimensions).
Stateless agents, all state in the platform. `profile: agentic` marker
unlocks `naturalLanguageIntent`, `confidenceAtSubmission`, `agentTrace`.
Initial skill catalog (BA.A): web API, worker, scheduled job, static asset,
basic observability bootstrap.
Environment progression:
| Environment | Autonomy | Attester | Gate |
|---|---|---|---|
| dev | Full autonomy (no HITL) | — | Confidence ≥ 0.50, all six inputs present |
| qa | Held for attestation | QA | GitHub Deployment approval + full QA matrix (§10) |
| prod | Held for attestation | SRE | GitHub Deployment approval + full SRE matrix (§10) |
| dr | Held for attestation | SRE | GitHub Deployment approval + dr-drill evidence |
**Staging is removed.** Dev is the only autonomous environment.
## Cross-cutting concerns
### Central pipeline template (§6)
JSON Schema (draft 2020-12) with a thin domain wrapper. Central repo +
generated client libraries. Multi-stage validation: schema → policy → NFR →
confidence. Distributed enrichment. GitOps reconciler (K8s API; cdlc-gitops
state → CRDs) + Terraform execution layer (§12.5). The pipeline emits one
`PolicyCheckResult` per policy rule; the confidence signal consumes them as
one normalized input.
### Contract schema (§7)
Central repo + generated client libraries. Strict fail-fast at schema
stage, multi-stage validation with reason codes from a published
vocabulary. **W3.E:** per-env mandatory inputs —
- dev: `stack`, `environment`
- qa adds: `validation.e2eSuite`, `validation.loadTest`
- prod adds: `runbook`, `dashboard`, `oncall`
- dr adds: `drDrillRef`
- `inputs` always optional; `profile: agentic` fields optional everywhere.
### Confidence signal (§8)
Six canonical inputs, weighted sum with per-input breakdown. Per-env
thresholds: dev ≥ 0.50, qa ≥ 0.75, prod ≥ 0.90, dr ≥ 0.95. Structured output
`{ score, band, perInput, reasonCodes }`. 1-year storage, no retraining in
v1. Halt with explicit reason on missing input.
Policy input = list of `PolicyCheckResult` records (engine-agnostic).
Severity → penalty: critical → hard override to mandatory block; high →
-0.2; medium → -0.05; low → -0.01; info → 0.0. One critical finding
hard-overrides the score regardless of all other inputs.
**BA.B:** thresholds frozen for v1; tuning begins v1.2 (quarterly FP/FN
tracking; override = Infra & Ops + SRE joint sign-off, itself a
confidence-event).
### Audit and evidence stream (§9)
Tiered ledger: **S3 with Object Lock in compliance mode** (cold, source of
truth, 7-year retention) + **GitHub audit repo** (`acdl-evidence`, hot
query index, not part of the chain). Daily checkpoints. Event schema: JWS
detached signature, `prev_event_hash` chain, controlled-vocabulary
`event_type`. Outbox pattern: local durable outbox + async worker.
Outbox database = **DynamoDB**. RPO = 0 (synchronous write to local outbox
before contract submission ack); RTO = async worker's dead-letter recovery.
Single-region in v1. The outbox also stores per-contract QA and prod
approver identities (the only durable record outside GitHub's audit log).
### Human-in-the-Loop mechanics (§10)
Pre-execution gates. qa, prod, dr are PR-based attestation gates backed by
GitHub Environments with required reviewers. No partial deployment to roll
back on rejection (qa, prod); dr is a separate GitHub Deployment against a
separate cluster/region.
Reviewer routing: GitHub CODEOWNERS + Environment required reviewers
(qa → QA; prod → SRE; dr → SRE). CODEOWNERS routes, does not enforce
identity distinctness.
**Separation of duties** (platform-internal, not GitHub-native, not Kyverno
in v1): on dev→qa promotion the platform writes the QA approver's GitHub
identity to the DynamoDB outbox keyed by `contractId`; on qa→prod it reads
the stored QA approver and the new SRE approver; if equal, it blocks, emits
`SEPARATION_OF_DUTIES_VIOLATION`, and routes a halt artifact to SRE on-call.
Full 8-concern attestation matrix (functional, performance, security
posture, contract NFRs, operational readiness, incident response,
capacity/cost, resilience) — see `docs/architecture.md` §10.4.
Timeout: 1 business day = warn + escalate; 2 business days = auto-freeze +
re-submit (linked via `supersedes`). Rejection returns the contract to HELD;
the audit chain is extended, not torn up.
### Agentic stack (§11)
Hybrid runtime: platform-managed control plane + consumer-owned agent.
Versioned, signed skill catalog over MCP. Skill envelope enforced on
invocation and result submission. Consumer-owned skill execution; the
platform does not run the skill. Stateless agents, all state in the
platform. Skills are reviewed for sensitive data before release (Infra &
Ops owns the review; it is the mandatory release gate).
### Angine execution (§12) — the binding constraint
**Target Stack IR** (locked): a engine-neutral description of resources
(typed inputs/outputs/NFRs), relationships (single parent per child),
composition (tree, max depth 5), and policy hooks. The L1 registry, L2
thin-composition tree, contract YML, and PolicyCheckResult schema are all
defined against the IR — none against any specific engine.
**Angine adapters** are the only engine-specific code. An adapter
compiles the IR into a engine execution plan. **v1 ships exactly one
adapter: the Terraform adapter.** v2+ may add OpenTofu, Pulumi, K8s CRDs
without architectural change.
v1 reality: the IR is shaped to round-trip cleanly to Terraform (nearly
isomorphic). As more adapters appear, the IR gets more expressive and the
adapters gain translation logic; the L1 content, the YML standard, and the
thin-composition tree do not change.
**Terraform adapter (v1):** translates IR-typed L1 interface → Terraform
`variable`/`output` blocks; IR-typed L2 thin-composition tree → Terraform
root module; IR-typed relationships → module references; emits a
`terraform plan` from the IR. The adapter is a thin layer; it does not own
L1/L2 content.
State storage: S3 (state) + DynamoDB (locking), cloud-managed,
single-region in v1.
Policy toolchain: **Checkov** for Terraform plan policy (the L2 checks +
tag/naming); **Kyverno** for K8s-native/platform-internal policy; **OPA**
reserved for cross-resource cases, explicitly last resort.
**Policy result normalization (§12.6):** the confidence signal consumes a
normalized `PolicyCheckResult` schema, not raw engine output.
```json
{
"contractId": "uuid",
"evaluatedAt": "ISO-8601",
"engine": "checkov | kyverno | opa",
"ruleId": "CKV_AWS_24 | KYVERNO_NO_PRIVILEGED | ...",
"severity": "critical | high | medium | low | info",
"result": "pass | fail | skipped | error",
"message": "human-readable",
"evidence": { "...engine-specific, opaque to the signal..." },
"resourceRef": "IR-typed resource identifier"
}
```
Execution layer: GitHub/Gitea Actions in the central pipeline repo. State
locking via DynamoDB. **AWS credentials via OIDC federation — long-lived
credentials are forbidden** (§12.5). The platform does not run
`terraform apply` against a developer's workstation; all execution is in
the central pipeline.
Registry maintenance: L1 publication updates the L1 registry in the same
PR. The registry is the IR-typed contract, not a Terraform-specific
variable schema.
Contract→IR resolution: the contract declares intent in IR-typed terms;
the pipeline resolves it to a target stack (list of L1 instances + inputs +
relationships); the Terraform adapter compiles the target stack to a plan.
## v1.1 spike scope
The spike (Phases 0810) materializes the **minimum** that proves the IR
commitments hold (no polyglot mess):
- One L1: `l1-s3` (IR-typed interface; the only AWS resource in the spike).
- One L2 thin-composition: `l2-static-assets` (references `l1-s3` only).
- Terraform adapter: IR → `terraform plan` against AWS via OIDC.
- One contract submission → contract→IR → `terraform plan` → Checkov
`PolicyCheckResult` → confidence signal → evidence event to the DynamoDB
outbox.
- State: S3 + DynamoDB (real AWS, single-region).
Out of spike scope: full HITL matrix wiring, Kyverno, OPA, MCP skill
catalog, GitOps reconciler, multi-region, prod/dr environments, the 5-skill
L3B catalog. Those are post-spike (v1.2+) platform build-out.
## Gitea API surface (carried from v1.0, refined)
| Capability | Gitea support | ACDL approach (v1.1) |
|------------|---------------|----------------------|
| Org-scoped repo create | `POST /api/v1/orgs/{org}/repos` | Used for any new repos |
| Native Pages | **None** | Serve `acdl-evidence` via raw file URLs (unchanged from v1.0) |
| Environments API | **None**; act_runner ignores `environment:` | Model HITL gates via `workflow_dispatch` approval inputs (v1.0 D-013 pattern) — **refined in Phase 07** for the real pre-execution gate model |
| `repository_dispatch` | Not supported | Cross-repo trigger via `workflow_dispatch` API (unchanged) |
| Reusable workflows | Supported | `acdl/.gitea/workflows/pipeline.yml` via `uses: ...@<ref>` |
| `id-token: write` / OIDC | **Not supported** (RESEARCH TARGET 1, conf 0.95). Gitea docs list `id-token` as an unsupported GitHub-only scope; open proposal go-gitea/gitea#33681; draft PR go-gitea/gitea#36988 unmerged. Even Gitea's own CI uses long-lived AWS keys (issue #37980). | **Spike waiver D-039:** per-run-rotated long-lived key (rotated after each run by `scripts/rotate_spike_key.sh`). Real OIDC deferred to v1.2, blocked on PR #36988. |
| `actions/configure-aws-credentials` | Unusable without OIDC | Spike uses static AWS creds from a (rotated) Gitea Actions secret via the `aws-actions/configure-aws-credentials@v4` `access-key-id`/`secret-access-key` inputs, or plain `AWS_ACCESS_KEY_ID`/`AWS_SECRET_ACCESS_KEY` env vars. v1.2 switches to `role-to-assume` when OIDC lands. |
### Branch pinning rule (refined for W2.A)
- Dev/qa contracts reference the reusable workflow by **tag**
(`@v1.1-spike`).
- Prod-bound workflows reference by **SHA**; the platform CLI
(`platform/cli/resolve-tag.ts`, Phase 07) resolves the current tag to its
SHA. (Spike scope: the CLI is a stub; the real CLI lands in v1.2.)
### Verification toolchain
ACDL has no `package.json`. The verification gate substitutes:
- **typecheck:** `terraform validate`, `python3 -m py_compile`, JSON Schema
validation (`ajv` or `python -m jsonschema`) against `schemas/`.
- **test:** per-phase `scripts/verify_phaseNN.sh` (Phase 06: archive integrity;
Phase 07: schema validation + decision-resolution completeness; Phase 08:
OIDC assume-role + state backend; Phase 09: IR + L1 + adapter `terraform
plan`; Phase 10: end-to-end contract submission).
- **build:** `terraform init` (real build for the spike).
- See `PERSONAS.md` verification_toolchain.
## Build order (v1.1)
1. Phase 06 — archive demo, reorient repo.
2. Phase 07 — finalize architecture v1.0; author schemas + designs.
3. Phase 08 — AWS OIDC bootstrap (use temp key once, rotate).
4. Phase 09 — IR + `l1-s3` + Terraform adapter → `terraform plan`.
5. Phase 10 — `l2-static-assets` + contract→IR → end-to-end spike.
6. COMPLETE gate — review → ship `v1.2.0` → audit. **DONE.**
## v1.2 build-out scope
v1.2 takes the v1.1 spike (dev-only, `plan`-only, single S3 L1) to a real,
simpler, better-documented platform that delivers a microservice to AWS ECS
Fargate end-to-end. The locked architecture (§1–§12) is unchanged — v1.2
extends the *implementation*, not the design.
### In scope (five axes, user-directed 2026-07-21)
1. **Re-evaluate the current state.** go-gitea/gitea#36988 (OIDC for Gitea
Actions) re-checked 2026-07-21: still **open** (last updated 2026-05-27,
not merged). Real OIDC remains deferred to v1.3+; v1.2 extends the D-039
per-run-rotated-key waiver as **D-047**. The waiver continues to satisfy
§12.5's *intent* (no *persistently* long-lived key): the spike key is
rotated after each run by `scripts/rotate_spike_key.sh`, and Phase 12
tightens the IAM scoping + rotation hygiene.
2. **NFR improvements on the existing spike.** Least-privilege IAM audit of
`spike_runner_policy.json`; idempotent `create_state_backend.py` /
`create_iam_user.py`; proper exit codes / error handling; P1-1 redaction
(two AWS access key IDs in `.ciagent/VERIFY.md` Phase 09 narrative).
3. **Streamline / simplify the current setup.** Consolidate
`run_spike_plan.sh` + `run_spike_e2e.sh` into one
`scripts/run_platform.sh`; remove dead code and stale `platform/` paths.
4. **README.md fully up to date on how the platform works.** Reflect v1.1
complete; document the actual spike flow, `scripts/run_platform.sh`, the
real repo layout, and the v1.2 objective.
5. **Bootstrap a consumer repo with a basic microservice deployed to ECS
end-to-end.** New Gitea repo `acdl-consumer-microservice` (org
`continuous-intelligence`); new IR-typed L1s (`l1-vpc`, `l1-ecs-cluster`,
`l1-ecs-service`, `l1-iam-role`, `l1-alb`, `l1-ecr`); new
`l2-microservice` thin-composition; one contract submission →
`terraform apply` (dev, autonomous per §10, confidence ≥ 0.50) → a live
ECS Fargate service serving HTTP 200 → evidence event to the DynamoDB
outbox → acdl-evidence timeline.
### Angine extension (ECS Fargate)
The Terraform adapter (§12) remains the only engine-specific code. v1.2
expands the adapter `TYPE_MAP` to cover the six new ECS-shaped IR resource
types. The L1 interface shape (IR-typed inputs/outputs/NFRs, registered in
`modules-ir/registry.json`) is unchanged — only the set of registered L1s
grows. The IR commitments (REQ-28) continue to hold: `modules-ir/`,
`schemas/`, `contracts/`, `core/confidence_signal.py`,
`core/contract_resolver.py`, `core/outbox_writer.py`
remain engine-agnostic.
### `terraform apply` (dev only)
v1.2 lifts the engine execution from `plan` to `apply` for the `dev`
environment only. Dev is autonomous per §10 (confidence ≥ 0.50, no HITL).
`apply` for qa/prod/dr remains HITL-gated and out of scope for v1.2. The
apply result (resources created, plan diff) is captured in the evidence
stream as a `terraform.apply` event.
### Out of scope for v1.2 (deferred to v1.3+)
| Feature | Reason |
|---------|--------|
| Real OIDC federation | go-gitea/gitea#36988 still open. v1.2 extends D-039 waiver (D-047); real OIDC is v1.3+. |
| Full HITL matrix wiring (qa/prod/dr) | v1.2 is dev-only autonomous `apply`; HITL wiring is v1.3. |
| Kyverno + OPA policy engines | v1.2 keeps Checkov only; Kyverno/OPA are v1.3. |
| MCP skill catalog + real L3B agent | v1.2 keeps the L3B stub; the 5-skill catalog is v1.3. |
| Audit ledger build-out (S3 Object Lock + JWS + async worker + DLQ + daily checkpoints) | v1.2 keeps the v1.1 outbox; the regulatory ledger is v1.3. |
| Multi-region state / outbox | Single-region in v1 (§9, §12.3); multi-region is v1.3+. |
| Prod/dr environments | v1.2 is dev-only; prod/dr are v1.3. |
| GitOps reconciler (ArgoCD/Flux) | v1.3+. |
## Build order (v1.2)
1. Phase 11 — re-eval #36988 + NFR audit + simplification findings + README rewrite.
2. Phase 12 — NFR harden + simplify (idempotent bootstrap, one `run_platform.sh`, IAM audit, redactions).
3. Phase 13 — six ECS L1s + adapter `TYPE_MAP` expansion.
4. Phase 14 — `l2-microservice` + contract schema extension.
5. Phase 15 — consumer repo + `terraform apply` (dev) → live ECS service.
6. Phase 16 — capstone e2e: consumer commit → live HTTP 200 → evidence → timeline.
7. COMPLETE gate — review → ship `v1.3.0` → audit.
## v1.8 Architecture Addendum
> Milestone v1.8 (complete, tag `v1.8.0`). Adds encryption-by-default,
> deletion-protection-by-default, uptime monitoring, decommission alias,
> engineering standards, and path documentation.
### New Primitives
- **`kms-key`** (`aws:kms:key`) — Per-stack customer-managed KMS key with
`enable_key_rotation = true`. One key per L2 deployment (no shared keys).
Wired into both L2 compositions as a child, with its `kms_key_arn` output
connected to all children's `kms_key_arn` input. Adapter emits
`aws_kms_key` + `enable_key_rotation`.
- **`uptime`** (`aws:ecs:uptime-service`) — Uptime-kuma on ECS Fargate with
a feature flag (`feature_flag_enabled`), monitored endpoints (HTTP/DNS/TCP),
alert channels (Teams/email/SMS/GitHub issues). Deployed by default after
any L2 module with a separate terraform state. When the feature flag is
false, the adapter emits no resources.
### Encryption by Default
All 12 L1 primitives have `encryption_enabled` NFR (default true). Primitives
with at-rest data (s3, rds, ecr, ecs-service, ecs-cluster) have an optional
`kms_key_arn` input. The adapter emits encryption blocks (SSE-KMS for S3,
storage_encrypted for RDS, encryption_configuration for ECR) referencing the
per-stack CMK when provided. Managed KMS fallback with stderr warning for
standalone L1 deployments.
### Deletion Protection by Default
All 12 L1 primitives have `deletion_protection` NFR (default true). The
adapter emits `lifecycle { prevent_destroy = true }` when true. L2 modules
expose a `features.deletion_protection` flag (default true) propagated to
all children via the resolver. Setting `inputs.deletion_protection: false`
in the contract disables it for the whole stack.
### Decommission Alias
A `mode: decommission` on the deploy pipeline implements a 2-step destroy:
1. Disable deletion protection (resolve with `deletion_protection: false`,
terraform plan/apply, HITL SRE gate via GitHub environment).
2. Zero counts + destroy (`decommission_transform` zeroes all scalable counts,
terraform plan/apply, second HITL SRE gate).
CMDB validation via DynamoDB `acdl-change-requests` table. The Lambda
`validate_change_request` action queries the table and asserts
`status == "approved"` + `consumerRepo` match.
### Adapter Expansion
TYPE_MAP grew from 16 to 19 entries (+ `aws:kms:key`, `aws:kms:alias`,
`aws:ecs:uptime-service`). Specialized emission branches added for KMS key
rotation, S3 SSE-KMS configuration, uptime ECS Fargate task, and
`prevent_destroy` lifecycle on all resources.
### Pipeline Stages
The deploy pipeline grew from 8 to 9 stages (+ `deploy-uptime` after
`publish-outputs`). The `deploy-uptime` stage constructs a synthetic uptime
contract from the L2 stack outputs, resolves + adapts it to a separate
terraform state directory, and publishes the uptime URL via PR comment.
### Forge-Agnostic API URLs
The platform Lambda (`contract_ingestor.py`) reads `GITHUB_API_BASE` env
for forge-agnostic API URLs. GitHub uses `/search/issues`; Gitea uses
`/repos/{owner}/{repo}/issues`. Detection via `/api/v1` in the base URL.
## v1.9 Addendum (2026-07-23)
### New Components
- **`core/contract_resolver.py` interpolation** (D-081): the resolver
now expands `${env.<field>}` + `${contract.<field>}` tokens
post-schema-validation, pre-IR-resolution. The env context is the
loaded environment onboarding JSON (`core/environments/<name>.json`,
schema `schemas/environment.schema.json`). The resolver's
`child_input_map` routes L2 wires to the sub-resource that declares the
input (P1-1 — `desired_count``aws:ecs:service`, `family`
`aws:ecs:task_definition`).
- **`core/environment_check.py` `load()`** (REQ-104): loads + returns the
parsed environment JSON; emits a stderr warning for placeholder
`account_id` when env != dev.
- **`core/hitl_gates.py`** (REQ-108, D-084): the HITL pre-execution
attestation gate. Records the approver identity to the DynamoDB outbox
(`approver_qa`/`approver_prod`/`approver_dr`), runs the separation-of-
duties check on prod, invokes the attestation matrix, returns
`(ok, reason)`. Dev skips (autonomous). `run_platform.sh` calls
`attest` before apply for qa/prod/dr.
- **`core/attestation_matrix.py`** (REQ-109, D-084): the 8-concern
attestation matrix from `hitl_matrix_design.md` §10.4. Offline-testable
concerns (contract NFRs, schema validity, policy pass) run for real;
operator-supplied concerns accept signed evidence artifacts validated
for freshness + schema. Signature verification skips when
`ACDL_ATTESTATION_SIGNING_KEY_ID` is unset (D-089).
- **`core/separation_of_duties.py` `route_halt_artifact`** (REQ-107):
real SNS publish (`acdl-sod-halt` topic, ARN from
`ACDL_SOD_HALT_TOPIC_ARN`) + outbox fallback
(`SEPARATION_OF_DUTIES_VIOLATION` event). The SNS topic is defined in
`terraform/platform/main.tf`.
- **`adapters/wiz/wiz_adapter.py` `WizClient`** (REQ-110): real GraphQL
API client (`<WIZ_API_URL>/graphql`, Bearer auth, pagination via
`pageInfo.hasNextPage`). `fetch_and_adapt` translates issues →
`PolicyCheckResult`. Graceful degrade when unconfigured.
- **`adapters/kyverno/kyverno_adapter.py`** (REQ-111): fleshed-out
`PolicyReport``PolicyCheckResult` mapping (pass/fail/skip/warn +
severity + skip-with-reason + resource construction). Inactive-for-TF
guard preserved.
### Per-Environment Promotion (D-082)
The deploy workflow (`.github/workflows/deploy.yml` +
`.gitea/workflows/deploy.yml`, byte-identical) declares an `environment`
`workflow_call` input. When non-empty, `run_platform.sh --environment
<name>` overrides the contract's `environment` field before schema
validation (D-088). One CI job per environment; promotion = running the
matching job, no `environment:` field editing. Per-env contract files
(`contracts/<module>.<env>.yaml`) use interpolation for env-specific
values.
### Adapter Parameterization (P1-1, D-085)
The adapter (`adapters/terraform/adapter.py`) reads ECS/ALB/VPC defaults
from L1 `interface.json` inputs (`desired_count`, `launch_type`,
`family`, `target_type`, `load_balancer_type`, `name`). The adapter is a
thin translator; the `child_input_map` routes wires to the declaring
sub-resource.
### Deferred (D-083)
S3 Object Lock + JWS detached signatures + async worker + DLQ + daily
checkpoints (audit ledger build-out) — deferred to a future milestone.
The hash-chain + DynamoDB-outbox path remains the v1.9 production audit
record.
## v1.10 Addendum — Regression VERIFY + Local Emulators + Capability Re-Verification
### Regression-Class VERIFY (D-091, `core/regression_verify.py`)
The standard VERIFY stage was diff-scoped (it checked the phase diff
only, never re-ran underlying capability). This let 8 NFR-patch phases
(v1.9.1v1.9.8) pass while the platform decayed. The regression-class
VERIFY (`core/regression_verify.py`) re-runs capability checks against
the current codebase and tags each Verified/Decayed/Broken. It fails
closed on any non-Verified capability, blocking milestone completion.
The registry (`CAPABILITY_REGISTRY`) holds 16 capability checks
(CAP-001..CAP-016): 12 local-tier + 4 live-AWS. Adding a capability is
a single function + one registry entry. The gate runs via
`scripts/run_regression.sh` and writes `.ciagent/REGRESSION_REPORT.md`
+ `.json`.
### Local Emulating Adapters (D-092, `core/local_emulators.py`)
Four local adapters let the platform run the full headline E2E without
cloud credentials:
- `FlatFileOutbox` — flat-file DynamoDB outbox emulator (hash-chained
JSONL; resumable across instances; chain verification).
- `LocalEcsEmulator` — local ECS Fargate HTTP 200 emulator (binds port
0 on 127.0.0.1; daemon thread; clean destroy).
- `LocalS3StateBackend` — rewrites the terraform S3 backend to a local
backend (per-stack tfstate in a temp folder).
- `LocalLambdaStub` — invokes the contract_ingestor handler in-process
(patches `_get_dynamodb`/`_get_secrets_client`/`urllib.urlopen`;
DynamoDB writes redirected to the FlatFileOutbox).
`run_local_e2e()` runs the full pipeline: contract → resolver → adapter
→ local S3 backend → local ECS (HTTP 200) → flat-file outbox (chain
verified) → local Lambda (200). Gated on `ACDL_LOCAL_TIER=1`.
### Capability Re-Verification Sweep (D-093)
`.ciagent/CAPABILITY_INVENTORY.md` enumerates 16 auto-verified
capabilities + 6 IAM-gated escalated resources. The sweep found and
fixed 7 adapter defects in `adapters/terraform/adapter.py` (duplicate
outputs, duplicate args, missing required args, deprecated AWS provider
v5 arg names). The headline E2E now passes at both tiers: local
emulator + live-AWS terraform init/validate/plan.
### Adapter Defect Fixes (P54)
7 defects fixed in `adapters/terraform/adapter.py`:
1. Duplicate output definitions (per-resource + stack-level both emitted).
2. Duplicate `desired_count`/`launch_type` on ECS service.
3. Duplicate `target_type`/`family`/`load_balancer_type`.
4. Missing `assume_role_policy`/`role_name` on IAM role (L2 composition gap).
5. Missing `cidr_block`/`vpc_id`/`name` defaults on VPC/subnet/route_table/
ECS cluster/ECR repository.
6. ECR `kms_key_arn` unsupported arg → `encryption_configuration` block.
7. CloudFront OAC + WAF deprecated arg names (AWS provider v5):
`signing_behavior`, `signing_protocol`, `origin_access_control_id`,
`s3_origin_config.origin_access_identity`, `origin_id`, `rule`
(singular), `scope=CLOUDFRONT` (uppercase).
## v1.11 Addendum — Stateless Adapter + Pipeline-Driven Lifecycle Testing
**Stateless adapter (D-098).** `adapters/terraform/adapter.py` rewritten
from a 918-line monolith (3 constant tables `TYPE_MAP`/`INPUT_MAP`/
`OUTPUT_MAP`, 39 type-specific branches) to a ~80-line stateless assembler.
Each L1 module ships a real `terraform/` module dir
(`versions.tf`/`variables.tf`/`locals.tf`/`main.tf`/`outputs.tf`) owning
its resource shape, nested blocks, and defaults. The adapter reads the
registry, emits a root `main.tf` instantiating each L1 as
`module "x" { source = "..." }` with resolved inputs and wired refs.
**Terraform owns lifecycle (D-101).** `scripts/run_platform.sh` gains
`--apply` and `--destroy` modes. Python never runs terraform.
`scripts/verify_deploy_microservice.py` is deleted.
**Pipeline-driven testing (D-102).** A `modules-lifecycle` pipeline
(Gitea + GitHub, byte-identical) matrix-runs each L1 module's
`examples/{simple,complex}.yml` contracts through apply→modify→destroy
against live AWS. No per-module Python/pytest. The "test" = the pipeline
cell going green.
**Single platform VPC (D-105).** `terraform/platform/main.tf` owns ONE
VPC; the microservice composition references it via
`terraform_remote_state` (data source). State keys are deterministic and
env-aware (`spike/{contract.id}/{contract.environment}/terraform.tfstate`).
**NOVA_LIFECYCLE_MODE (v1.12, REQ-134; renamed ACDL→NOVA in v1.15 P2).** The lifecycle pipeline defaults
to plan-only (fast, no AWS mutation, no cost). A CI variable
`NOVA_LIFECYCLE_MODE` (default `plan`) overrides to `full` for the real
apply→modify→destroy. (P2P4 dual-read fallback to `ACDL_LIFECYCLE_MODE`;
fallback removed in P5 per the v1.15 addendum.)
## v1.12 Addendum — Presentation Refinement + CAP-013 Fix
**CAP-013 adapter dedup fix (REQ-129).** Multi-resource L1s (ecs-service,
alb) with stack outputs + cross-module refs now dedup to ONE module block
named by the composition child id, with expanded sub-ids rewritten via
`id_remap`. `terraform validate` succeeds for the microservice stack.
**CAP-017/018 probe fixes (REQ-130).** CAP-017's probe no longer requires
`locals.tf` for modules that legitimately omit it. CAP-018's probe
instantiates `LocalLambdaStub` with the required `outbox` arg.
## v1.13 Addendum — Presentation Polish + Config Schema Migration
**Config.json schema migration (v1.13.1).** Regenerated
`.ciagent/config.json` to the updated CIAgent v2 config structure (drop
removed fields, migrate `gitea``release.gitea`, add
`secrets`/`ship`/`backend`/`ideation`/`personas`/`logging`/`telemetry`
sections).
**Presentation polish (v1.13.0, v1.13.2).** Action headlines, story-arc
restructure, larger fonts, 6 new mermaid diagrams, badge cleanup,
platform-architecture diagram. Docs-only NFR patches.
## v1.14 Addendum — NFR Refinement (bug fixes, security, stubs, tests, docs)
**Bug fixes (Wave 1, P1-P6).** Adapter dedup rejects unregistered modules
with ValueError (P1). Static-assets composition wires cloudfront inputs
(P2). L2 lifecycle scripts document remote-state design (P3). Regression
gate adds `terraform fmt -check` syntax probe (P4). Adapter dedup-merge +
remote-state-key unit tests (P5). ALB target group name_prefix derives
from var.name (P6).
**Security (Wave 2, P7-P12).** 6 swallowed-error sites narrowed to
specific exceptions (P7). Account ID externalized to
`ACDL_AWS_ACCOUNT_ID` env (P8). IAM policy scoped to `acdl-*` ARNs (P9).
Contract ingestor validates contractId/environment/error (P10). Environment
schema adds `additionalProperties: false` + format validation (P11).
`.gitignore` credential-pattern catch-all (P12).
**Stub/test/CI/hygiene (Wave 3, P13-P17).** Kyverno `--kube-version` flag
removed (P13, G-103). Orphan artifacts + dead config cleaned (P14). 7
untested scripts gain test coverage (P15). Gitea workflow parity
documented + script `set` flags fixed (P16). Config.json persona +
branching strategy + ollama-cloud aligned (P17).
**Standards/docs/VPC (Wave 4, P18-P20).** STANDARDS.md reconciled (P18).
Documentation synced: ARCHITECTURE.md addenda, stale `@v1.6-1.9``@v1.13`,
GRILL G-005/G-008 resolved, COST.md window extended, D-083 deferral
recorded (P19). Platform VPC CIDR parameterized + data-driven subnet
count (P20).
**D-083 deferral (explicit).** The audit ledger build-out (S3 Object Lock
+ JWS detached signatures + SQS DLQ + async worker + daily checkpoints)
remains deferred (D-096, v1.14). The hash-chain + DynamoDB outbox is the
v1.14 audit record. JWS per-event authenticity is not implemented; a
forged event is only detectable by re-reading the whole chain. The
deferral is documented here explicitly per the v1.14 grill (E-001).
---
## v1.15 Addendum — Nova Rebrand (Major/breaking, 2026-07-30)
**Milestone:** v1.15-Nova. A full rebrand from **ACDL** / "Agentic Cloud
Delivery Platform" → **Nova** / "The New Dawn of DevSecOps — security
as a seamless enabler of fast deployments." This is a **Major
milestone** (breaking): consumer-facing path, env var prefixes, SSM
path, AWS tag keys, and AWS resource names all change. Per the
branch-strategy precedent (breaking/feature milestones tag on their
OWN minor line), v1.15 tags run on the **v1.15.x minor line**:
`v1.15.0` (P0) → `v1.15.4` (P5 final = release). (G-104 binding.)
### Naming conventions (rebranded)
| Convention | Before (v1.0v1.14) | After (v1.15+) | Phase |
|------------|---------------------|-----------------|-------|
| Project name | `ACDL` / "Agentic Cloud Delivery Platform" | `Nova` / "The New Dawn of DevSecOps" | P1 |
| Tagline | "Consumers declare intent; the platform delivers safe production deployment through an agentic stack" | (retained) **+** "The New Dawn of DevSecOps — security as a seamless enabler of fast deployments" | P1 |
| Schema `$id` URL | `https://acdl.cloudinit.dev/schemas/...` | `https://nova.cloudinit.dev/schemas/...` | P1 |
| Gitea release title | `ACDL vX.Y.Z` | `Nova vX.Y.Z` | P1 (forward only) |
| Env var prefix | `ACDL_*` (21 vars) | `NOVA_*` (dual-read fallback in P2P4; removed P5) | P2 |
| Env loader | scattered `os.environ.get("ACDL_*")` | centralized `core/env.py` `get_env()` (D-108) | P2 |
| Consumer contract path | `.acdl/contract.yml` | `.nova/contract.yml` | P2 |
| Checkov custom rule file | `acdl_tagging.py` | `nova_tagging.py` | P2 |
| Checkov tag-key enforcement | `acdl:*` (hard) | `nova:*` (warn P2, hard P3) | P2/P3 |
| SSM parameter path | `/acdl/{env}/{contractId}/{output}` | `/nova/{env}/{contractId}/{output}` | P3 |
| AWS tag keys | `acdl:owner|environment|contract|cost-center|ref` | `nova:owner|environment|contract|cost-center|ref` | P3 |
| ABAC session policy match | `acdl:*` tags | `nova:*` tags (parallel-tag period) | P3 |
| DynamoDB tables | `acdl-contracts`, `acdl-change-requests` | `nova-contracts`, `nova-change-requests` (scan+copy) | P4 |
| Lambda (ingestor) | `acdl-contract-ingestor` (role/policy/function) | `nova-contract-ingestor` | P4 |
| Secrets Manager secret | `acdl/github-token` | `nova/github-token` | P4 |
| SNS topic | `acdl-sod-halt` | `nova-sod-halt` | P4 |
| Security group | `acdl-ecs-sg` | `nova-ecs-sg` | P4 |
| KMS alias | `alias/acdl-platform` | `alias/nova-platform` | P4 |
| ECS cluster/service/task | `acdl-microservice` | `nova-microservice` | P4 |
| ECR repo | `acdl-microservice` | `nova-microservice` (re-push) | P4 |
| IAM user/policy | `acdl-spike-runner` (+policy) | `nova-spike-runner` (re-bootstrap) | P4 |
| S3 state bucket | `acdl-tfstate-581513795199-us-east-1` | `nova-tfstate-581513795199-us-east-1` (`-migrate-state`) | P4 |
| ALB name prefix | `acdl-alb` | `nova-alb` | P4 |
| Lambda default table names | `CONTRACTS_TABLE` default `acdl-contracts` | default `nova-contracts` (D-111) | P4 |
### Unchanged conventions (out of scope)
- **S&P Global Energy visual theme** (`sp-theme.json`, deck CSS: #D6002A
red, Akkurat Pro) — client branding, not the Nova product brand (D-107).
- **config.json `release.gitea.repo`** = `acdl` — real Gitea repo name
unchanged (D-105). Doc URLs updated to `nova` for prose only.
- **Git branch/tag naming**`milestone/v*`, `phase/*`, `v*` semver; no
brand name present (D-112: flat-branch convention preserved).
- **Past Gitea release titles** — existing releases keep `ACDL vX.Y.Z`.
### Migration ordering (binding)
1. **P1** docs/decks/prose — no runtime impact; ships consumer migration
guide announcing the 5 breaking changes.
2. **P2** code + env vars (dual-read) + consumer path — deployments don't
break during the transition window (dual-read fallback).
3. **P3** SSM path (copy → read → delete) + tag keys (parallel-tag →
policy swap → remove old).
4. **P4** AWS resource names — staged terraform migration (KMS alias,
SNS/SG/Lambda recreate, DynamoDB scan+copy, ECR re-push, IAM
re-bootstrap, state bucket `-migrate-state`, ALB recreate). Maintenance
window + rollback runbook (`docs/NOVA_AWS_MIGRATION.md`).
5. **P5** final review + audit + remove dual-read fallback + milestone ship.
### Capability gate (binding)
The regression gate (CAP-001..CAP-016, `scripts/run_regression.sh`) must
stay **16/16 Verified** throughout the rebrand. P2/P3/P4 update test
fixtures that reference `ACDL`/`acdl` so the gate stays green. No
capability is added, removed, or reclassified in v1.15 — the rebrand is
nomenclature + identifiers, not behavior.
---
## v1.16 Addendum — Nova Simplification (NFR, 2026-07-30)
The v1.16 NFR milestone added 6 new code components + 1 new Terraform
module + 1 new schema, all documented here for the architecture record.
### New components
| Component | Path | Purpose |
|-----------|------|---------|
| Onboarding request handler | `core/onboarding.py` | `generate_env_file(request, template_env)` — produces a `<env>.json` from a consumer onboarding request (P19, REQ-183). CLI entry point for self-service env-file generation. |
| Decommission transform | `core/decommission_transform.py` | `decommission_transform(stack)` — zero counts + disable deletion protection (REQ-92). Extracted from contract_resolver (P12, REQ-176). |
| Contract resolver CLI | `core/contract_resolver_cli.py` | `main()` CLI entry point — resolves a contract YAML to a Target Stack JSON. Extracted from contract_resolver (P12, REQ-176). |
| Regression verify CLI | `core/regression_verify_cli.py` | `main()` CLI entry point — runs the regression gate + writes the report. Extracted from regression_verify (P13, REQ-177). |
| Workflow sync generator | `scripts/sync_workflows.py` | `--check`/`--write` — generates the 3 byte-identical Gitea+GitHub workflow pairs from `workflows-src/` (P8, REQ-172). |
| Onboarding Terraform | `terraform/onboarding/` | `aws_iam_role.consumer_deploy` + `aws_iam_role_policy.consumer_invoke` (ABAC `nova:owner` tag). Offline-proven only (P20, REQ-184, D-114). |
### Modified components
| Component | Change | Phase |
|-----------|--------|-------|
| `core/contract_resolver.py` | `_load_env` delegates to `environment_check.load()` (dedup); `is_l2` uses registry `kind` field; `_load_schema` caches schemas; `decommission_transform` + CLI re-export shim (P12). | P7, P12, P14 |
| `core/regression_verify.py` | Dedup helpers (`_check_resolver`, `_check_live_terraform_plan`, `_assert_contracts_resolve`); CAP-013..016 `Skipped` on post-teardown (G-111); `passed` accepts Skipped; CLI re-export shim (P13). | P5, P9, P13 |
| `core/lambda/contract_ingestor.py` | Fail closed on missing IAM identity (P10); env enum from `core/environments/` (P10); payload size cap + schema validation (P11); `onboard_consumer` action (P18); `[NOVA-ALERT]` rebrand (P2). | P2, P10, P11, P18 |
| `core/output_publisher.py` | `SAFE_OUTPUT_NAMES` schema-driven from `interface.json`; narrowed excepts; `urllib.error` import (P4, P14). | P4, P14 |
| `core/environment_check.py` | Onboarding message rebranded Nova + self-service request path (P2, P19). | P2, P19 |
| `core/local_emulators.py` | `LocalLambdaStub` sets `NOVA_LAMBDA_LOCAL_BYPASS`; stale dual-read comments + `acdl_*` prefixes removed (P3, P10). | P3, P10 |
| `scripts/run_platform.sh` | `--help` flag; `run_hitl_gate()` fn; `NOVA_CONTRACT_ID`/`NOVA_WORK_DIR` config; decommission + uptime blocks extracted to sourced helpers (P6, P9, P15). | P6, P9, P15 |
| `adapters/terraform/adapter.py` | State bucket `nova-tfstate-*` (P1); module docstring Nova (P2). | P1, P2 |
| `adapters/kyverno/policies/require-resource-labels.yml` | `nova:*` labels (not `acdl:*`) (P1). | P1 |
| `modules/registry.json` | `kind` field (`l1`/`l2`) on all 14 entries (P7). | P7 |
### New schema
- `schemas/onboarding.schema.json` — the self-service onboarding request
(consumerRepo, requestedEnvironment, ownerId, billingTag). P18, REQ-182.
### Onboarding request-path architecture (D-113)
The no-humans onboarding flow is a 3-step request path (real AWS
provisioning deferred):
```
Consumer → POST Lambda (onboard_consumer) → pending CMDB row (P18)
→ core/onboarding.py → <env>.json binding file (P19)
→ terraform/onboarding/ → cross-account role + ABAC tag (P20, offline)
```
The Lambda Function URL (IAM auth) + `consumer_invoke_policy.json` (ABAC
`nova:owner`) are the transport; the request is accepted + a binding
generated + the role Terraform proven offline. No AWS resources are
created by the request path (D-113/D-114).
### Regression gate (G-111 binding)
The regression gate (D-091) now treats `Skipped` as acceptable for the
post-v1.11-teardown steady state (D-096): CAP-013..016 (live-AWS tier)
return `Skipped` when the resources are absent (`NoSuchBucket`/
`ResourceNotFoundException`). `RegressionReport.passed` is
`all(r.status in ("Verified", "Skipped"))`. The gate passes at 18
Verified + 4 Skipped (0 Decayed/Broken).
## v1.17 Addendum — Strategic Direction, Leadership Metrics & Unified Story (2026-08-04)
The v1.17 milestone adds a telemetry/observability layer, a Decision
Ledger, a metrics export pipeline, a unified narrative deck, and a
durable strategic-direction artifact. This addendum documents the
architecture; the full research findings are in RESEARCH.md §v1.17.
### New components
| Component | Path | Purpose |
|-----------|------|---------|
| Event envelope | `core/metrics/event_envelope.py` | CloudEvents 1.0 envelope + `platform.*` semantic conventions (P1, REQ-187) |
| Per-run manifest writer | `core/metrics/run_manifest.py` | Emits `nova.run.started/completed/failed` events + writes `metrics/runs/<run_id>.json` (P1, REQ-187) |
| Decision Ledger (SQLite) | `core/metrics/decision_ledger.py` | Extends `outbox_writer.py` → SQLite append-only hash-chain table; `ai.decision.made` + `attestation.recorded` events + outcome backfill (P1, REQ-188, D-121) |
| Infracost post-processor | `core/metrics/infracost_adapter.py` | Runs Infracost on plan JSON; emits `nova.cost.estimated{delta_usd}` (P1, REQ-187, D-120) |
| Metrics collector | `core/metrics/collector.py` | Reads all grounded signals (files + events) → SQLite cold store at `metrics/nova_metrics.db` (P2, REQ-189) |
| PowerBI export | `core/metrics/powerbi_export.py` | Emits CSV/JSON views to `metrics/powerbi/` (fact + dim + 8 deferred placeholder views) (P3, REQ-190) |
| Metrics schemas | `schemas/metrics_*.schema.json` | Schemas for all event types + fact/dim tables (P1P2, REQ-187/189) |
| Metrics catalog | `docs/METRICS.md` + `docs/metrics/<kpi>.md` | Canonical catalog + per-KPI definition-of-success docs (P4, REQ-195, D-127) |
| Unified narrative deck | `docs/presentations/nova-no-humans-platform.md` | Merged deck: Problem→Vision→How→Proof→Roadmap; x3 arc at deck+slide level (P5, REQ-196/197, D-130) |
| Strategic direction | `.ciagent/NORTH_STAR.md` | PO-authored durable vision/objectives/anti-goals/targets; read by CIAgent in every future `/ci-run` (P0, REQ-185/186) |
### Modified components
| Component | Change | Phase |
|-----------|--------|-------|
| `core/outbox_writer.py` | Extended to emit to SQLite append-only hash-chain table (Decision Ledger); `ai.decision.made` + `attestation.recorded` events added (P1, D-121) | P1 |
| `scripts/run_platform.sh` | Per-run manifest writer invoked; `$WORK/*.json` persisted to `metrics/runs/`; Infracost post-processor invoked after plan (P1) | P1 |
| `core/hitl_gates.py` | Emits `attestation.recorded` event to Decision Ledger on qa/prod/dr gate (P1, D-132) | P1 |
| `core/confidence_signal.py` | Emits `nova.confidence.computed` + `nova.ai.decision.made` events (P1, D-122) | P1 |
| `adapters/terraform/policy/checkov_adapter.py` | Emits `nova.policy.evaluated` event (P1) | P1 |
| `core/regression_verify.py` | Emits `nova.capability.verified` event; CAP-023 (metrics collector) + CAP-024 (deck structure) added (P1, P6) | P1, P6 |
| `pyproject.toml` | `addopts` gains `--junitxml=metrics/test-results.xml` + `--json-report` (P1, D-120) | P1 |
| `docs/presentations/` | Two old decks retired (deleted); unified deck added (P5, D-130) | P5 |
### Telemetry/observability layer architecture (D-120)
```
┌─────────────────────────────────────────────────────────────────────┐
│ Nova platform components (existing) │
│ run_platform.sh · confidence_signal · checkov_adapter · │
│ hitl_gates · regression_verify · outbox_writer · contract_ingestor │
└──────────────────────┬──────────────────────────────────────────────┘
│ CloudEvents 1.0 envelope (new emitters, P1)
┌─────────────────────────────────────────────────────────────────────┐
│ metrics/events.jsonl (append-only CloudEvents log) │
│ metrics/runs/<run_id>.json (per-run manifests) │
│ metrics/decision_ledger.db (SQLite hash-chain, D-121) │
│ metrics/test-results.xml (junit, P1) │
└──────────────────────┬──────────────────────────────────────────────┘
│ collector reads (P2)
┌─────────────────────────────────────────────────────────────────────┐
│ metrics/nova_metrics.db (SQLite cold store, D-126) │
│ fact_run · fact_capability · fact_policy_check · fact_confidence │
│ fact_test · fact_decision · fact_cost_estimate │
│ dim_capability · dim_milestone │
│ + 8 empty placeholder views (deferred metrics) │
└──────────────────────┬──────────────────────────────────────────────┘
│ powerbi_export (P3)
┌─────────────────────────────────────────────────────────────────────┐
│ metrics/powerbi/ (CSV/JSON views, folder connector, D-129) │
│ → PowerBI dashboards (external) │
└─────────────────────────────────────────────────────────────────────┘
```
**Hot path: deferred (D-126).** No live ops dashboard; SQLite is
cold-only (batch/historical). The hot path activates when live AWS is
re-provisioned (D-096 lift).
### NORTH_STAR integration point (REQ-186)
`.ciagent/NORTH_STAR.md` is read by CIAgent in context-loading for all
future milestones. The integration mechanism (to be finalized in P4):
a reference from `PROJECT.md` + `ARCHITECTURE.md` (this section) + a
config entry in `config.json` (`strategic_direction_file:
".ciagent/NORTH_STAR.md"`) that the run workflow reads at SPECIFY. This
ensures the strategic direction survives across milestones without
being overwritten by status updates.
### §12.7 — Policy Engine Registry (v1.25, REQ-291)
The policy-engine abstraction is first-class: a swappable `PolicyEngine`
protocol so the engine may change without touching the confidence
signal, the pipeline, or the `PolicyCheckResult` schema. This is the
**swap boundary** that keeps the platform's compliance posture
replaceable (Strategic Objective #2 — provable trust via a replaceable
substrate, not a vendor lock-in).
```
contract.yml ─┐ ┌─→ list[PolicyCheckResult] ─┐
stack IR ─────┼─→ PolicyEngine.evaluate ├─→ list[PolicyCheckResult] ─┼─→ confidence_signal
plan JSON ────┤ (protocol) └─→ list[PolicyCheckResult] ─┘ (engine-agnostic,
PCR list ─────┘ unchanged)
┌─ KyvernoJsonEngine (shells to `kj scan`; engine: "kyverno")
└─ OpaEngine (future — same protocol; engine: "opa")
checkov/wiz ──→ raw findings ──→ (merged PCR list is the meta-policy payload)
```
**The protocol (`core/policy_engine.py`):**
```python
class PolicyEngine(Protocol):
@property
def name(self) -> str: ...
def is_configured(self) -> bool: ...
def evaluate(self, payload, policy_dir: Path, contract_id: str) -> list[dict]: ...
```
**The registry** reads `config.json.policy.engine` (default
`"kyverno-json"`) and returns the active engine. A `NullEngine` is the
fallback when the `policy` key is absent (emits `SKIPPED` PCRs —
backward compatibility for tests that don't set the key). The
confidence signal is **untouched** — it already consumes
`list[PolicyCheckResult]` engine-agnostically (§12.6). v1.25 only
changes *who produces* the PCR list, not *what* the list is.
**Engine enum reuse (D-116):** kyverno-json PCR records carry
`engine: "kyverno"` (no new enum value). The `engine` field records the
policy-engine *family*, not the specific binary. The K8s Kyverno adapter
and the kyverno-json engine are distinguished by `ruleId` prefix
(`KYVERNO_` vs `KJ_`) and `evidence` payload shape (`namespace`/`kind`
vs `assertion`/`jmespath`).
**Defense-in-depth (D-119):** the declarative meta-policy
`block-on-any-critical` (asserts no PCR has `severity: critical` +
`result: fail`) is the *source of truth* for "critical = block". The
`confidence_signal.py` `PENALTY["critical"]: None` hard-override stays
as the *imperative* safety net — the meta-policy runs *before* the
confidence signal (produces PCRs that flow in), the hard-override runs
*inside* it (the last gate). Removing the hard-override would make the
"critical = block" guarantee depend on a single policy file — a
regression in provable trust.
**Graceful degradation (D-120):** `KyvernoJsonEngine.is_configured()`
returns false when `which kj` is absent → `evaluate()` returns a single
`SKIPPED` PCR (`ruleId: "KJ_ENGINE_NOT_CONFIGURED"`). The platform
functions without the binary (the "platform functions without AI /
deterministic scripts" tenet holds — kyverno-json is deterministic, not
AI; the `is_configured()` guard ensures the platform runs even when the
binary is not installed).
@@ -0,0 +1,46 @@
# P4 — Live Pilot Run Evidence (v1.26, v0.2 re-run)
> The live `terraform apply` against AWS `581513795199` succeeded. The
> Decision Ledger + outcome backfill are complete. SPEC §5.8 evidence
> stream verified.
## Apply result (account 581513795199, dev, autonomous)
- **ALB DNS**: `app-254671247.us-east-1.elb.amazonaws.com`
- **ECS service**: `arn:aws:ecs:us-east-1:581513795199:service/nova-cluster/nova-microservice`
- **DynamoDB table**: `nova-blkex-ledger-dev` (PK `block_index`, PAY_PER_REQUEST)
- **S3 bucket**: `nova-blkex-blocks-dev-581513795199-us-east-1` (versioning + SSE)
- **ECS cluster**: `arn:aws:ecs:us-east-1:581513795199:cluster/nova-cluster`
- **ECR repo**: `581513795199.dkr.ecr.us-east-1.amazonaws.com/app-repo`
- **IAM role**: `arn:aws:iam::581513795199:role/nova-app-role`
- **KMS key**: `arn:aws:kms:us-east-1:581513795199:key/e9a7ba15-d5cb-4f4d-ab20-bfac5cb62bcf`
- **Platform VPC** (prerequisite): `vpc-0d7c8867e6cc080f1` + 6 subnets + ECS SG `sg-0c95704b16859e86f`
## Confidence signal
- score: **0.800**, band: **pass** (dev autonomous, ≥0.50, no HITL)
- human_override: false
- escalation_reason: absent (clean apply — REQ-318)
## Decision Ledger (SQLite hash-chain, /root/metrics/decision_ledger.db)
- `nova.ai.decision.made` — decision_id `blkex-pilot-apply-v0.2`, chosen_action `pass`, human_override false
- `nova.outcome.backfilled` — outcome `pending → succeeded`, backfilled_at `2026-08-19T03:05:04Z`
- chain valid: true (0 breaks)
## Outcome backfill (REQ-317)
- fact_decision.outcome: `pending``succeeded` (NOT stuck pending)
- backfilled_at: `2026-08-19T03:05:04Z`
## Module-completeness gaps fixed (uncovered by the live apply)
- ecs-service L1: added `execution_role_arn` + `task_role_arn` (Fargate requires execution role for ECR pull)
- microservice L2 composition: wired `roles.outputs.role_arn``service.inputs.{execution,task}_role_arn`
- microservice L2 composition: wired `platform_vpc.outputs.ecs_security_group_id``alb.inputs.security_group` (ALB requires a SG)
## Run id
- NOVA_RUN_ID: `blkex-pilot-apply-v0.2`
---ci---
project: acdl
phase: 4
milestone: v1.26
status: execute
wave: W1
---
File diff suppressed because it is too large Load Diff
+78
View File
@@ -0,0 +1,78 @@
# `.ciagent/archive/` — Completed-Milestone History
This directory holds byte-identical snapshots of `.ciagent/` files that
were compressed out of the active agent context. Compression is **lossless
via relocation**: every original byte is reachable here, and the git
history at the commit prior to compression preserves the authoritative
state for offline agent loading.
## Why archive
The active milestone is v1.26 (Live Pilot Estate Activation). The
`.ciagent/` root held ~11,164 lines dominated by completed-milestone
narratives (v1.0v1.24). Per the run.md context-loading model, agents
read `.ciagent/` every `/ci-run`; the historical narrative was not
load-bearing for v1.26 execution and was relocated to keep the working
context lean.
## Contents
### Snapshots of slimmed files (full content before compression)
| File | Original (lines) | Replaces | Status at time of snapshot |
|---|---|---|---|
| `PROJECT-v1.0-v1.24.md` | 1784 | `.ciagent/PROJECT.md` | v1.0v1.24 milestone-by-milestone narrative + active milestone v1.26 sections |
| `REQUIREMENTS-v1.0-v1.24.md` | 2490 | `.ciagent/REQUIREMENTS.md` | All requirements v1.0 (REQ-01) through v1.26 (REQ-322) |
| `ROADMAP-v1.0-v1.24.md` | 2341 | `.ciagent/ROADMAP.md` | All phase breakdowns v1.0 through v1.26 |
| `ARCHITECTURE-v1.0-v1.24.md` | 945 | `.ciagent/ARCHITECTURE.md` | Full architecture reference + historical "how we got here" narrative |
The slimmed in-place files retain: active milestone v1.26 context, the
v1.25 milestone (since v1.26 tags ride the v1.25.x line), the durable
vision/tenets/RACI/capability-status sections, and the current-state
architecture reference.
### Completed-phase artifacts (relocated verbatim)
| File | Original (lines) | Phase(s) documented |
|---|---|---|
| `REVIEW.md` | 111 | Multi-persona code review records from completed phases |
| `AUDIT.md` | 553 | Project health audit records (reconstruction tests, branch hygiene) |
| `VERIFY.md` | 86 | Per-phase verification records |
| `PRE_MORTEM.md` | 228 | Pre-mortem analyses for completed milestones |
### Live operational files NOT archived
These files remain at their canonical `.ciagent/` paths because they are
read/write targets of live code paths and must not be relocated:
- `REGRESSION_REPORT.json` — written by `core/regression_verify.py:705`,
read by `core/metrics/collector.py:27` + `core/metrics/trust_snapshot.py:21`
+ `metrics/` views.
- `REGRESSION_REPORT.md` — written by `core/regression_verify.py:704`,
referenced by `scripts/run_regression.sh`.
- `CHECKPOINT.json` — the authoritative resume point for `/ci-run`.
- `config.json` — operational configuration (no historical content).
## How to load archived content
Agents that need completed-milestone history can read these files
directly (they live inside `.ciagent/`, so the path convention holds):
```
.ciagent/archive/PROJECT-v1.0-v1.24.md
.ciagent/archive/REQUIREMENTS-v1.0-v1.24.md
.ciagent/archive/ROADMAP-v1.0-v1.24.md
.ciagent/archive/ARCHITECTURE-v1.0-v1.24.md
.ciagent/archive/{REVIEW,AUDIT,VERIFY,PRE_MORTEM}.md
```
For the authoritative pre-compression state of any `.ciagent/` file,
use git history at the commit immediately preceding the compression
commit (search the log for `chore(P02): compress .ciagent/ files`).
## `completed-milestones/`
Reserved for future per-milestone summary files if a milestone's
narrative is too large for the slimmed in-place ROADMAP/PROJECT. Currently
empty; v1.0v1.24 narrative is fully preserved in the four snapshot
files above.
File diff suppressed because it is too large Load Diff
+219
View File
@@ -0,0 +1,219 @@
# P05 Final Review + Audit — v1.26 Live Pilot Estate Activation
> **Phase:** 5 (final review + audit + ship) — review + audit only; the
> milestone ship (merge to main / tag v1.25.5 / branch deletion) is the
> orchestrator's next step, deliberately out of scope here.
> **Branch:** `phase/05-final-review-ship`
> **Milestone:** `milestone/v1.26-pilot-activation`
> **Tags so far:** v1.25.0 (P0) → v1.25.1 (P1) → v1.25.2 (P2) →
> v1.25.3 (P3) → v1.25.4 (P4). P5 ships v1.25.5 (= the v1.26 release).
> **Date:** 2026-08-19
---
## 1. Review (ciagent-review equivalent)
Multi-persona review across P1..P4 (lead-developer coordination;
correctness / testing / security / maintainability axes). The spot-checks
below confirm the P3/P4 commits deliver what their messages claim.
### Correctness spot-checks (all PASS)
- **kyverno-json substrate fix (59d837f):** the engine `_translate` parses
the real `kj` v0.0.3 bare-list output (not the v1.25-assumed
`{"results":[...]}` dict); `_materialize_yaml_policy_dir` mirrors `.json`
policies to `.yaml` twins (kj v0.0.3 ignores `.json`); the `validate`
wrapper was removed from all 16 policies + the check syntax fixed
(`expression: expected_value`). All 36 kj-dependent tests pass against
real `kj` (0 skips). The install script fixed
(`go install .../kyverno-json@latest` + symlink, not the broken
`cmd/kj@latest`).
- **outcome backfill (51b886f, REQ-317):** `core/metrics/outcome_backfill.py`
updates `fact_decision.outcome` pending → succeeded/failed; idempotent +
terminal (no overwrite of a non-pending outcome); wired into the
collector. The P4 run evidence (6ced8ed) confirms
`nova.outcome.backfilled (pending->succeeded)`.
- **Gitea adapter (P3 W0):** the consumer `deploy.yml` has no cross-repo
`uses:` — inline `actions/checkout@v4` of `acdl/acdl @ ref: v1.25` into
`platform/` then `bash platform/scripts/run_platform.sh`. SPEC §10 Q1
resolved by evidence.
- **env-JSON state_backend (3300ed2, REQ-319):** the adapter reads
`env.state_backend.bucket` when present (fallback to the computed
`nova-tfstate-{account_id}-{region}` for backwards compat). `dev.json`
bound to `581513795199` + `nova-tfstate-581513795199-us-east-1`;
qa/prod/dr stay placeholder (account `000000000000` — the pilot-readiness
policy blocks apply, D-208).
- **pilot policies (e22661a, REQ-315/320):** `no-placeholder-account.json`
passes on dev (581513795199), fails on placeholder;
`all-matches-committed.json` asserts `all_committed == true`. Both run
against real `kj` (not skipped).
### Testing
- 844 tests collected; **844 pass** (839 fast + 5 slow individually
re-run: 2 `test_run_local_e2e_*` + 3 `test_verify_regression_mode::*`).
0 failures, 0 skips that shouldn't skip.
- New feature coverage confirmed: REQ-317 backfill test
(`test_outcome_backfill.py`), REQ-318 escalation_reason test
(`test_confidence_escalation_reason.py`), REQ-315/320 policy tests
(`test_settlement_finality_policy.py`, `test_pilot_readiness_policy.py`
— both real-kj), REQ-316 CAP-025 test (`test_regression_pilot.py`), Gitea
adapter tests (`test_deploy_workflow_invocation.py` +
`test_deploy_gitea_invocation.py` — assert no cross-repo `uses:`,
`ref: v1.25`, `secrets: inherit`), rotation workflow test
(`test_rotate_key_workflow.py`), CAP-025 test
(`test_deploy_workflow_env_input.py`).
- The v1.25 `pytest.skip("kj not installed")` skips are gone — `_require_kj`
no longer skips (kj v0.0.3 installed). All kj-dependent tests exercise
the real engine.
### Security
- **No `NOVA_AWS_*` secrets in committed files.** `.env.secrets` is
gitignored and NOT tracked (`git ls-files` confirms). All `NOVA_AWS_*`
references in committed workflow files are `${{ secrets.* }}` placeholder
references — the correct pattern. The W6 fix (b237b3e) removed raw
`NOVA_AWS_*` from the shell env in `run_platform.sh`'s local fallback.
- **No forge mentions in synced files.** `test_no_forge_mentions` PASS
(the REQ-230 guard). The W6/W7 fix (03edd82) renamed `NOVA_GITEA_TOKEN`
`NOVA_FORGE_TOKEN` (forge-agnostic) after the guard tripped.
### Maintainability
- **No stale `TYPE_MAP` refs in active docs.** The P4 W2 fix (a0799f1)
fixed the stale `TYPE_MAP`/`INPUT_MAP` references in `adapters/README.md`
(IDEATE I8). Remaining `TYPE_MAP` mentions are in `.ciagent/archive/`
(historical, correct) + `.ciagent/{CLARIFY,IDEATE,RESEARCH}.md`
(decision records, correct context).
- **No new TODOs/FIXMEs in P3/P4.** `grep` over `core/` for
`TODO|FIXME|XXX|HACK` returns 0 matches.
- The P3 W0.5 fix (3735330) resolved pre-existing P2 drift (dynamodb
`simple.yaml``simple.yml`, sync_workflows re-sync, CAP-024 deck path
`nova-autonomous-cloud-delivery-marp.md`).
### Review verdict
**0 P0 issues remain** after the one P0 fix applied this phase (see §3).
**P1+ issues for post-hoc review (none blocking ship):**
| # | Severity | Issue | Disposition |
|---|----------|-------|-------------|
| R-1 | P2 (cosmetic) | `CHECKPOINT.json` `phase_branch` field is stale (`phase/03-pilot-metrics-and-policies`) — should be `phase/04-pilot-run-and-docs` or cleared. | Post-hoc. The orchestrator's ship step overwrites CHECKPOINT entirely (`stage: complete, phase: 5, phase_role: final`), so this field is transient. Not fixed here to avoid touching CHECKPOINT outside the ship step. |
| R-2 | P3 (historical) | The v1.26 consumer-repo merge commit (78da051) + the P0 merge (d391cdf) use `---/ci---` close markers; the v1.26 platform-repo commits (P3/P4) use `---ci---` only. Minor format inconsistency from the multi-project boundary. | Post-hoc. Cosmetic; both markers are recognized by the audit tooling. |
| R-3 | P3 (future-hardening) | Single `NOVA_AWS_*` root-equivalent key (D-207). Documented in PLAN.md §Future Hardening — a future milestone should split into `NOVA_BOOTSTRAP_AWS_*` + least-privilege `NOVA_AWS_*` runner key. | Post-hoc. Out of v1.26 scope by design (D-207, G-Q9). |
---
## 2. Audit (ciagent-audit equivalent)
### 2.1 Reconstruction test — **PASS**
The git log `---ci---` blocks are consistent with the `.ciagent/` file
states. The last 20 commits on `milestone/v1.26-pilot-activation` show the
expected phase progression:
- P0 (`d391cdf`, status: complete) → P1 ship (`2ee541f`) →
P2 reconcile (`d022ddc`) → P2 complete (`6a3d47e`) →
P3 W0.5 → W2 → W3 → W4 → W5 → W6 → W6/W7 → verify (`5d1a985`) →
docs (`732998b`) → merge+complete (`268f695`, `6b60c0c`) →
P4 W1 (`cec34ab`, `6ced8ed`) → W2 (`a0799f1`) → verify (`074ee05`) →
merge+complete (`6eb7af2`, `f266dcf`).
Each phase follows the `execute → verify → complete` lifecycle. The
CHECKPOINT `current_phase` (phase 4, status complete, tag v1.25.4) matches
the latest commit (`f266dcf docs(ship): P4 complete → v1.25.4`). The
`previous_phase` (phase 3, tag v1.25.3, complete) is consistent.
All 4 merge commits on the milestone branch (d391cdf, 78da051, 268f695,
6eb7af2) carry `---ci---` blocks with project/phase/milestone/status.
### 2.2 `.ciagent/` file discipline — **CLEAN** (after the one P0 fix)
- **CHECKPOINT.json:** `current_phase` (4/complete/v1.25.4) + `previous_phase`
(3/complete/v1.25.3) consistent with the git log. `waves` map + `pre_run`
map + `notes` accurately describe the P4 live apply + outcome backfill.
One stale field: `phase_branch` (R-1, post-hoc).
- **REQUIREMENTS.md:** v1.26 traceability table now shows all 13 REQs
(310..322) complete. **One P0 fix applied:** REQ-316 row corrected from
"P4 live-verify pending" → "v1.25.4 — live-verify complete" (P4 is
complete; v1.25.4 tagged; the live apply against 581513795199 succeeded
per commit 6ced8ed + verify 074ee05). The v1.25 table (REQ-291..309) is
all-complete + consistent with ROADMAP.
- **ROADMAP.md:** v1.26 phases P0..P4 marked complete; P5 marked "planned"
(correct — this phase is in progress, ship is next). v1.25 marked
complete. The phase descriptions match the commits.
- **PLAN.md:** the active phase plan covers P0..P5 with wave ordering,
persona assignment, + the REQ-322→P2 W0 revision. Consistent with what
shipped.
- **ARCHITECTURE.md:** §12.8 (Pilot Estate) + §12.9 (rotation) present
(P4 W2 docs).
- **PROJECT.md:** v1.26 active milestone noted; multi-project mode
(`nova-blockchain-exchange`) reflected.
### 2.3 Branch hygiene — **CLEAN**
`git branch -a` (local):
- `main`
- `milestone/v1.26-pilot-activation`
- `phase/05-final-review-ship` (current)
P1..P4 phase branches are deleted (only milestone + P5 remain, as
required). Remote: `origin/main` + `origin/milestone/v1.26-pilot-activation`
mirror the local state.
Tags: `v1.25` (floating) + `v1.25.0` + `v1.25.1` + `v1.25.2` + `v1.25.3` +
`v1.25.4` all exist. `v1.25.5` is not yet present (correct — it's the
orchestrator's ship step).
### 2.4 Commit discipline — **CLEAN**
Every v1.26-scope commit on the milestone branch carries a `---ci---`
block with `project` + `phase` + `milestone` + `status` (and most carry
`wave`). The 4 merge commits (d391cdf, 78da051, 268f695, 6eb7af2) all
carry `---ci---` blocks. (Historical commits from v1.0-v1.18 predate the
block convention — out of scope for this audit.)
The consumer-repo merge (78da051) correctly carries
`project: nova-blockchain-exchange` (multi-project boundary respected);
the platform commits carry `project: acdl`.
### Audit verdict
| Check | Result | Detail |
|-------|--------|--------|
| Reconstruction test | **PASS** | git-log `---ci---` blocks ↔ `.ciagent/` consistent; phase 4/complete/v1.25.4 matches HEAD. |
| File discipline | **CLEAN** | All 6 `.ciagent/` files consistent after the REQ-316 P0 fix. One stale `phase_branch` field (R-1, post-hoc). |
| Branch hygiene | **CLEAN** | Only main + milestone + P5; P1-P4 deleted; v1.25.0..v1.25.4 tagged. |
| Commit discipline | **CLEAN** | All v1.26 commits carry `---ci---` blocks; merge commits included. |
---
## 3. P0 fixes applied this phase
| # | File | Fix |
|---|------|-----|
| P0-1 | `.ciagent/REQUIREMENTS.md` | REQ-316 traceability row: "P4 live-verify pending" → "v1.25.4 — live-verify complete". P4 is complete (v1.25.4 tagged, live apply against 581513795199 succeeded per commits 6ced8ed + 074ee05); the "pending" text was stale documentation drift that misstated the milestone state. |
No code-level P0 issues found — the P3/P4 feat/fix commits deliver what
they claim; the test suite is green; no secrets leaked; no forge mentions;
no stale active-doc references.
---
## 4. Overall verdict — **PROCEED to milestone ship**
- **Review:** 0 P0 issues remain (1 P0 fix applied: REQ-316 doc drift).
3 P1+ items flagged for post-hoc (R-1 stale CHECKPOINT field, R-2 close-
marker inconsistency, R-3 future key-split — none block ship).
- **Audit:** reconstruction PASS; file discipline CLEAN; branch hygiene
CLEAN; commit discipline CLEAN.
- **Tests:** 844 passed, 0 failed, 0 unexpected skips (5 slow tests
individually confirmed green: 2 local-e2e + 3 regression-mode).
**Decision: PROCEED.** The orchestrator's next step (Wave 3 milestone
ship: merge `phase/05-final-review-ship` → `milestone/v1.26-pilot-
activation` → `main`; tag `v1.25.5`; Gitea release; delete milestone
branches; final CHECKPOINT clear) is unblocked. Per the full-autonomy
"never halt" directive, even if a P0 had been critical, the ship step
would still proceed with the issue documented — but here the single P0
was a cosmetic doc-drift, now fixed.
File diff suppressed because it is too large Load Diff
+39
View File
@@ -0,0 +1,39 @@
# VERIFY — v1.26 P3 (pilot-metrics-and-policies) PASS
> Four-layer verification. All gates green.
## Structural
- pilot-readiness/no-placeholder-account.json + settlement-finality/all-matches-committed.json exist (REQ-315/320)
- core/metrics/outcome_backfill.py + tests exist (REQ-317)
- escalation_reason emitted on block band (REQ-318) — test_confidence_escalation_reason.py
- adapters/terraform/adapter.py reads env.state_backend.bucket (REQ-319) — test_adapter_state_backend.py
- core/environments/dev.json bound to 581513795199 (D-203); qa/prod/dr placeholder (D-208)
- CAP-025 in CAPABILITY_REGISTRY (REQ-316) — test_regression_pilot.py
- workflows-src/rotate-aws-key.yml + synced copies (SPEC §5.9)
- consumer deploy.yml: no cross-repo uses: (SPEC §10 Q1 — inline adapter, option c)
- kj installed (v0.0.3); kyverno-json policy tests run (not skipped)
## Behavioral
- platform: 844 passed (full suite, including @pytest.mark.slow live-AWS CAPs)
- consumer: 90 passed, 6 skipped (pre-existing unrelated skips)
- kj substrate: 69 targeted policy/engine tests pass against real kj (zero skips)
- pilot policies: pass on valid fixtures, fail on invalid (verified via kj scan violations)
## Security
- no raw NOVA_AWS_* export in scripts/run_platform.sh shell env (SPEC §5.2 — blocked_env_vars guard)
- forge-agnostic synced files (REQ-230 — test_no_forge_mentions pass)
- no secrets tracked in git (test_no_secrets_tracked pass)
- NOVA_AWS_* redacted on emit (existing outbox_writer + confidence_signal redaction)
## Quality
- 7 pre-existing P2 failures (uncovered by W0.5 full-suite run with kj installed) all fixed:
dynamodb examples (.yml), sync_workflows drift, CAP-024 deck path (-marp.md), 3 disk-space environmental
- zero regressions vs baseline
- territory enforcement (warn mode) respected across waves
---ci---
project: acdl
phase: 3
milestone: v1.26
status: verify
---
+31
View File
@@ -0,0 +1,31 @@
# VERIFY — v1.26 P4 (pilot-run-and-docs) PASS
## Structural
- Live apply: AWS resources exist (ALB, ECS, DynamoDB, S3, KMS, ECR, IAM) — account 581513795199
- ecs-service L1: execution_role_arn + task_role_arn wired (module-completeness gap fixed)
- microservice L2 composition: roles→service wires + ALB SG wire
- Decision Ledger: ai.decision.made + nova.outcome.backfilled (hash chain valid)
- fact_decision.outcome: pending→succeeded (REQ-317 outcome backfill verified)
- Docs: adapters/README, docs/METRICS, ARCHITECTURE §12.8, consumer onboarding README
## Behavioral
- platform: 844 passed (full suite)
- consumer: 90 passed, 6 skipped (deploy invocation tests pass on the inline adapter)
- live terraform apply: exit 0 (Apply complete! Resources created)
## Security
- NOVA_AWS_* not in shell env (run_platform.sh unset after sourcing .env.secrets)
- Decision Ledger events redact secrets (no NOVA_AWS_* values in payloads)
- forge-agnostic synced files (test_no_forge_mentions pass)
## Quality
- No regressions (844 baseline holds)
- The live apply uncovered + fixed 2 module-completeness gaps (ecs-service role, ALB SG)
- The Post-Pilot metrics now have non-zero denominators (n=1 real run)
---ci---
project: acdl
phase: 4
milestone: v1.26
status: verify
---
+10 -4
View File
@@ -4,11 +4,16 @@
"slug": "acdl", "slug": "acdl",
"name": "Nova — The New Dawn of DevSecOps", "name": "Nova — The New Dawn of DevSecOps",
"default": true "default": true
},
{
"slug": "nova-blockchain-exchange",
"name": "Nova Pilot Consumer — Blockchain Stock Exchange",
"default": false
} }
], ],
"active_project": "acdl", "active_project": "acdl",
"active_projects": ["acdl"], "active_projects": ["acdl", "nova-blockchain-exchange"],
"active_milestone": "v1.25", "active_milestone": "v1.27",
"autonomy": { "autonomy": {
"level": "full", "level": "full",
"escalation_hooks": ["deploy", "delete_data", "merge_to_main"], "escalation_hooks": ["deploy", "delete_data", "merge_to_main"],
@@ -59,7 +64,7 @@
}, },
"git": { "git": {
"branching_strategy": "flat", "branching_strategy": "flat",
"_branching_strategy_note": "ACDL uses flat workflow (committed directly to main per established convention since v1.0). The 'phase' strategy is advisory; CIAgent uses milestone/phase branches for v1.14 but the project convention is flat.", "_branching_strategy_note": "Nova uses flat workflow (committed directly to main per established convention since v1.0; renamed ACDL→Nova in v1.15). The 'phase' strategy is advisory; CIAgent uses milestone/phase branches for v1.14 but the project convention is flat.",
"auto_commit": true, "auto_commit": true,
"auto_push": true "auto_push": true
}, },
@@ -67,7 +72,8 @@
"sources": [".env", ".env.secrets", ".env.*"], "sources": [".env", ".env.secrets", ".env.*"],
"disallow": ["shell_env", "netrc", "keychain", "rc_files", "global_config"], "disallow": ["shell_env", "netrc", "keychain", "rc_files", "global_config"],
"scopes": { "scopes": {
"gitea": "ACDL_GITEA_TOKEN", "forge": "NOVA_FORGE_TOKEN",
"gitea": "NOVA_FORGE_TOKEN",
"github": "GITHUB_TOKEN", "github": "GITHUB_TOKEN",
"gitlab": "GITLAB_TOKEN", "gitlab": "GITLAB_TOKEN",
"openai": "OPENAI_API_KEY", "openai": "OPENAI_API_KEY",
@@ -0,0 +1,92 @@
# Nova Pilot Consumer — Blockchain Stock Exchange
> **Milestone:** v1.26 — Live Pilot Estate Activation
> **Git:** https://git.cloudinit.dev/continuous-intelligence/nova-blockchain-exchange
> **Local clone:** /root/nova-blockchain-exchange
> **Role:** The first real consumer estate. A stock exchange built on a
> homegrown blockchain, offering equities trading (pilot scope). The
> consumer repo owns the app code + `contract.yaml`; the Nova platform
> (`acdl` repo) provides the deploy workflow, policy engine, and
> attestation gates.
---
## Vision / Core Value
A self-contained securities-trading exchange where every order, match,
and settlement is recorded as an immutable transaction on a homegrown
Proof-of-Authority (PoA) blockchain. The pilot demonstrates that Nova's
autonomous infrastructure can take a real consumer estate from contract
to production — apply, attest, record — without an operator in the loop
of normal operations.
## North Star Alignment
- **Strategic Objective #1** (production-grade zero-touch operations):
this estate is the first real consumer; the pilot activates the
autonomy claim beyond internal demos.
- **Strategic Objective #2** (provable trust): every apply decision +
attestation lands in the Decision Ledger; the settlement-finality
kyverno-json policy (IDEATE) makes trust a policy artifact.
- **Strategic Objective #3** (compounding ROI): unblocks the three
Post-Pilot targets (Touchless Resolution ≥99%, Human Escalation
<0.1%, AI Decision Accuracy ≥99.5%) — the denominators activate when
this estate runs.
## Domain Boundaries
- **This repo owns:** the blockchain (consensus, blocks, transactions),
the order-matching engine, the settlement service, the `contract.yaml`
that declares the infrastructure, and the consumer-side deploy workflow
invocation (`uses: acdl/.github/workflows/deploy.yml@v1.25`).
- **The platform (`acdl`) repo owns:** the deploy workflow, the policy
engine (kyverno-json), the contract resolver, the adapter, the
confidence signal, the HITL gates, and the Decision Ledger.
## Scope: v1.26 Pilot
- **Equities only** (bonds, derivatives, options deferred to future
milestones — different settlement models).
- **Minimal PoA ledger** — append-only blocks, single validator (pilot),
T+1 settlement finality = block commit. No multi-validator BFT.
- **Homegrown chain** — authored as part of this repo, not deployed on
Ethereum/Solana/Hyperledger.
## Anti-Goals (v1.26)
1. Not a general-purpose blockchain platform — purpose-built for
securities settlement in the pilot.
2. Not multi-validator consensus — single validator for the pilot.
3. Not bonds/derivatives/options — equities only this milestone.
4. Not a replacement for the Nova platform — this is a *consumer* of
Nova, not a fork.
## Key Decisions (v1.26 — established in SPECIFY, refined in CLARIFY)
| ID | Decision | Rationale | Affects |
|---|---|---|---|
| D-200 | Pilot scope = equities only | Bonds/derivatives/options have very different settlement models; equities (T+1) is the simplest to demonstrate the Nova platform's policy gates over a real estate. | Phase count; requirement scope. |
| D-201 | Homegrown PoA ledger (single validator) | Minimal viable chain for a pilot; settlement finality = block commit. Multi-validator BFT is a future milestone. | Blockchain core design. |
| D-202 | Consumer repo = `nova-blockchain-exchange` (Gitea) | New repo under `continuous-intelligence` org; tracked as 2nd CIAgent project. | Multi-project config. |
| D-203 | AWS account = 581513795199 (existing) | Reuse the bootstrapped account; state bucket + outbox table created in pre-run Workstream A3. | Env JSON binding. |
| D-204 | D-083 (S3 Object Lock/JWS) stays deferred | The SQLite hash-chain + DynamoDB outbox is the pilot's audit record. Tamper-evidence is a future milestone. | Audit ledger scope. |
| D-205 | Cold-only metrics sufficient (D-126) | No hot ops dashboard in the pilot; cold SQLite store + PowerBI export. | Metrics pipeline. |
## Constraints
- The consumer repo's deploy MUST go through `deploy.yml@v1.25` (the
reusable workflow) — no direct `terraform apply` bypassing the
platform's policy + attestation gates.
- The `contract.yaml` MUST validate against
`schemas/contract.schema.json`.
- The homegrown blockchain MUST be deterministic (same inputs → same
block) — it is automation, not AI (NORTH_STAR Objective #2 tenet).
## Context
- The Nova platform (`acdl` repo) completed v1.25 (kyverno-json Unified
Policy Engine). The swappable `PolicyEngine` adapter is in place.
- The AWS bootstrap (S3 state bucket + DynamoDB outbox) was re-run in
the pre-run (Workstream A3) — the platform components exist.
- The consumer repo was created on Gitea (Workstream A4) and cloned to
`/root/nova-blockchain-exchange`.
+180
View File
@@ -0,0 +1,180 @@
# nova-blockchain-exchange — Consumer Onboarding Guide
> **Milestone:** v1.26 — the first real Nova consumer estate. This
> guide is for the consumer side: how to invoke the deploy, what
> secrets to set, what the contract looks like, and how to verify the
> result. The platform side is documented in
> `.ciagent/ARCHITECTURE.md` §12.8; the live-pilot evidence is in
> `.ciagent/P4-PILOT-RUN-EVIDENCE.md`.
This is a **consumer** of the Nova platform, not a fork. The consumer
repo owns the app code (the blockchain, the order-matching engine, the
settlement service) and the `contract.yaml` that declares the
infrastructure. The Nova platform (`acdl` repo) owns the deploy
workflow, the policy engine, the contract resolver, the Terraform
adapter, the confidence signal, the HITL gates, and the Decision
Ledger. The consumer never clones the platform repo and never runs
`terraform apply` directly.
---
## 1. Invoke the deploy
The consumer's `.github/workflows/deploy.yml` (and its byte-identical
`.gitea/workflows/deploy.yml` mirror) is a `workflow_dispatch` workflow.
It does **not** use cross-repo `uses:` (SPEC §10 Q1 — the Gitea forge
rejects it). Instead it is an **inline adapter**: it checks out the
consumer repo, then checks out `acdl/acdl` @ `ref: v1.25` into
`platform/`, then runs `bash platform/scripts/run_platform.sh`.
To run a deploy:
1. In the consumer repo's Actions UI, pick the **Deploy** workflow.
2. Click **Run workflow**.
3. Inputs:
- `mode` = `full` (the default — applies the Terraform). Other
values: `plan-only` (no apply), `check-only` (policy + confidence
only), `decommission` (requires a `changeRequestId`).
- `environment` = `dev` (the pilot scope — equities only, dev only,
D-020/D-200). Leave empty to use the contract's `environment`
field.
4. The workflow runs the platform pipeline end-to-end: contract
resolve → adapter compile → terraform plan → policy (kyverno-json)
→ confidence signal → (dev: autonomous apply) → Decision Ledger
events.
For the pilot, the documented invocation is `mode=full,
environment=dev`. The first live run was `blkex-pilot-apply-v0.2`
(2026-08-19).
---
## 2. Secrets to set
Set these in the forge's Actions secret store (the consumer repo's
"Secrets and variables → Actions" page). The platform-managed
scheduled workflow `rotate-aws-key.yml` rotates the `NOVA_AWS_*` key
daily (SPEC §5.9 — the v0.2 deploy uses the currently-active key).
| Secret | Purpose |
| --- | --- |
| `NOVA_AWS_ACCESS_KEY_ID` | The static AWS access key for the deploy IAM principal. Used by `aws-actions/configure-aws-credentials` when OIDC is unavailable (the Gitea path — no OIDC token is minted). |
| `NOVA_AWS_SECRET_ACCESS_KEY` | The matching secret key. Rotated by `workflows-src/rotate-aws-key.yml`. |
| `AWS_DEFAULT_REGION` | The target region (`us-east-1` for the pilot). |
The platform's `.github/workflows/deploy.yml` (GitHub Actions reference
impl) supports an OIDC path instead of the static key — set
`NOVA_AWS_ACCOUNT_ID` and leave the `NOVA_AWS_*` key secrets empty.
The Gitea inline adapter uses the static-key path.
---
## 3. The contract shape
The consumer declares its infrastructure in `contract.yaml` at the
repo root, validated against the platform's
`schemas/contract.schema.json`. The pilot contract has the shape:
```yaml
id: blkex
name: blockchain-exchange
environment: dev
infrastructure:
microservice: # the L2 composition (ECS Fargate + ALB + roles)
...
dynamodb: # the L1 DynamoDB table (the ledger)
...
s3: # the L1 S3 bucket (block storage)
...
```
Three `infrastructure.*` blocks: `microservice` (the L2 composition
that wires the ECS service, the ALB, and the IAM roles together), and
the two L1 primitives (`dynamodb` for the ledger, `s3` for block
storage). Per-environment variants live in
`contracts/blockchain-exchange.{dev,qa,prod}.yml` (the per-env
promotion model, REQ-105). The pilot runs the `dev` variant.
The contract is the **only** consumer-facing artifact that describes
infrastructure. It is IR-typed (engine-agnostic); the platform
resolves it to a target stack, the Terraform adapter compiles the
stack to HCL, and `terraform apply` runs in the central pipeline —
never on the consumer's workstation.
---
## 4. What the platform does
When `run_platform.sh` runs against `contract.yaml`:
1. **Resolve** the contract to a target stack (a list of L1 instances +
inputs + relationships), reading `modules/registry.json` for each
L1's `terraform_dir`.
2. **Compile** the stack to Terraform HCL via the stateless adapter
(`adapters/terraform/adapter.py`) — emits `module "<rid>" { source }
` blocks + wired `ref:` refs. No `TYPE_MAP` — each L1 owns its
shape.
3. **Plan**`terraform plan` against the live AWS account. Infracost
runs on the plan JSON and emits `nova.cost.estimated`.
4. **Policy** — the kyverno-json engine evaluates the meta-policies
(`block-on-any-critical` + the pilot policies) and emits
`PolicyCheckResult` records.
5. **Confidence** — the confidence signal consumes the six inputs (the
PCRs included) and emits `nova.confidence.computed` with
`{ score, band, perInput, reasonCodes }`. Dev threshold = 0.50.
6. **Apply** (dev, autonomous — no HITL gate) — `terraform apply`
against account `581513795199`. On success, `nova.ai.decision.made`
+ `nova.run.completed` land in the Decision Ledger.
7. **Backfill** — the outcome (`pending → succeeded`) is backfilled
(REQ-317), producing `nova.outcome.backfilled`. The SQLite
hash-chain is extended, not torn up.
The consumer does not see steps 17 directly; the consumer sees the
workflow's green check + the uploaded artifacts (`nova-terraform`,
`nova-platform-log`).
---
## 5. How to verify post-deploy
Two independent verifications — read the AWS API and read the Decision
Ledger. Neither trusts the other.
**AWS API (the infrastructure landed):**
- `aws elbv2 describe-load-balancers` — the ALB
(`app-254671247.us-east-1.elb.amazonaws.com` for the pilot).
- `aws ecs describe-services --cluster nova-cluster --services
nova-microservice` — the ECS service is `ACTIVE`.
- `aws dynamodb describe-table --table-name nova-blkex-ledger-dev`
the ledger table exists (PK `block_index`, PAY_PER_REQUEST).
- `aws s3api head-bucket --bucket
nova-blkex-blocks-dev-581513795199-us-east-1` — the block bucket
exists (versioning + SSE).
**Decision Ledger (the trust record):**
- The SQLite hash-chain at `metrics/decision_ledger.db` has the
`nova.ai.decision.made` row for `blkex-pilot-apply-v0.2` (chosen
action `pass`, `human_override` false) + the
`nova.outcome.backfilled` row (outcome `pending → succeeded`).
- The chain is valid (`prev_event_hash` links, 0 breaks). The
Trust Snapshot (`metrics/TRUST_SNAPSHOT.md`) records the verdict.
If the AWS API shows the resources AND the Decision Ledger shows the
decision + outcome with a valid chain, the deploy is verified. See
`.ciagent/P4-PILOT-RUN-EVIDENCE.md` for the full pilot-evidence
checklist (every ARN, the confidence JSON, the backfill timestamp).
---
## References
- `.ciagent/ARCHITECTURE.md` §12.8 — the pilot-estate architecture
(this guide is the consumer-facing companion to that section).
- `.ciagent/P4-PILOT-RUN-EVIDENCE.md` — the live-pilot evidence
(run `blkex-pilot-apply-v0.2`).
- `.ciagent/nova-blockchain-exchange/PROJECT.md` — the consumer
project charter (vision, scope, decisions D-200..D-205).
- `.ciagent/nova-blockchain-exchange/REQUIREMENTS.md` — the consumer
requirements (REQ-313 contract, REQ-314 deploy invocation).
- `adapters/README.md` §Consumers — the Gitea adapter note
(SPEC §10 Q1 — inline checkout-then-call, no cross-repo `uses:`).
@@ -0,0 +1,221 @@
# Requirements — nova-blockchain-exchange (v1.26 pilot)
> **Project:** nova-blockchain-exchange — blockchain stock exchange (pilot)
> **Milestone:** v1.26 — Live Pilot Estate Activation
> **Scope:** equities only; minimal PoA ledger; T+1 settlement finality.
---
## v1.26 — Live Pilot Estate Activation
### REQ-310 — Homegrown PoA blockchain core
The consumer repo implements a minimal Proof-of-Authority blockchain:
append-only blocks, single validator (pilot), SHA-256 block hash chain,
deterministic block production (same ordered transactions → same block).
The chain records every order, match, and settlement as transactions.
Settlement finality = block commit (a transaction is final when its
block is committed to the chain).
**Must-haves:**
- `chain/block.py` — Block dataclass (index, timestamp, prev_hash,
transactions, nonce, hash). `compute_hash()` deterministic.
- `chain/ledger.py` — Ledger class: `append_block()`, `verify_chain()`,
`get_block(index)`, `get_latest_block()`. Genesis block on init.
- `chain/validator.py` — PoA validator: single validator (config-driven,
pilot), `propose_block(transactions)` → Block, `commit_block(block)`.
- `tests/test_block.py`, `tests/test_ledger.py`, `tests/test_validator.py`
— chain integrity, hash determinism, genesis, append/verify.
### REQ-311 — Order-matching engine
A limit-order-book matching engine: buy/sell orders with price + size,
matched at the best price (price-time priority). Produces match
transactions recorded on the chain.
**Must-haves:**
- `engine/order_book.py` — OrderBook: `add_order(order)`,
`match_orders()` → list of Match (buyer, seller, price, size).
- `engine/order.py` — Order dataclass (id, side, symbol, price, size,
timestamp).
- `tests/test_order_book.py` — match priority, partial fills, no-match.
### REQ-312 — Settlement service
T+1 settlement: matches commit to the chain; a settlement is final when
its block is committed. The service reads matches from the order engine,
produces settlement transactions, and submits them to the ledger.
**Must-haves:**
- `settlement/service.py` — SettlementService: `settle(match)`
SettlementTransaction, `submit(ledger)`. Idempotent (re-settling a
match is a no-op once final).
- `tests/test_settlement.py` — happy path, idempotency, finality check.
### REQ-313 — Consumer `contract.yaml` ✓ complete (P2, v1.25.2)
The consumer repo declares its infrastructure via a `contract.yaml` at
the repo root, validated against `schemas/contract.schema.json`. The
contract references the Nova platform's deploy workflow
(`uses: acdl/.github/workflows/deploy.yml@v1.25`) and declares the
blockchain exchange stack (the AWS resources the app needs: ECS for
the matching engine, DynamoDB for the ledger, S3 for block storage).
The DynamoDB L1 primitive (REQ-322) must land before this contract can
declare `dynamodb` — ECS + S3 already exist.
**Must-haves:**
- `contract.yaml` — id, name (`blockchain-exchange`), environment
(dev/qa/prod variants), infrastructure block.
- `contracts/blockchain-exchange.dev.yml`, `.qa.yml`, `.prod.yml`
per-environment variants (per-env promotion model, REQ-105).
- `tests/test_contract_validates.py` — schema validation against the
platform's `schemas/contract.schema.json`.
### REQ-314 — Consumer deploy workflow invocation ✓ complete (P2, v1.25.2)
The consumer repo's GitHub/Gitea Actions invoke the Nova platform's
reusable `deploy.yml@v1.25` workflow with `mode: full` for the pilot.
The workflow checks out the consumer repo + the platform repo, runs
`scripts/run_platform.sh`, and records the apply decision + attestation
in the Nova Decision Ledger.
**Must-haves:**
- `.github/workflows/deploy.yml``uses: acdl/.github/workflows/deploy.yml@v1.25`
with `with: { contract: contract.yaml, mode: full, environment: dev }`.
- `.gitea/workflows/deploy.yml` — byte-identical mirror (the platform's
deploy workflow is forge-agnostic).
- `tests/test_deploy_workflow_invocation.py` — asserts the `uses:` ref
+ inputs are correct.
### REQ-315 — Settlement-finality kyverno-json policy (IDEATE I6)
A kyverno-json policy asserting that every promotion (qa→prod) requires
settlement finality: all matches in the promotion window have committed
blocks. This is the securities-specific extension of v1.25's policy
engine — it applies Nova's compliance posture to the blockchain domain.
**Must-haves:**
- `policies/settlement-finality.json` — kyverno-json policy over the
settlement-service status JSON (asserts `all_committed: true`).
- `tests/test_settlement_finality_policy.py` — passing + failing
fixtures; skip when `kj` absent.
### REQ-316 — Pilot-estate regression capability (CAP-025)
A new capability in the regression gate: "pilot estate apply→attest→record
round-trip." The regression gate asserts that the consumer estate can
run end-to-end (contract resolve → adapter compile → terraform plan →
policy scan → confidence signal → attestation → outbox record) against
the live AWS account `581513795199`.
**Must-haves:**
- `core/regression_verify.py` gains CAP-025 (live-pilot-apply).
- `tests/test_regression_pilot.py` — the round-trip assertion.
### REQ-317 — Outcome-backfill emitter (IDEATE I1)
Wire `apply.completed` / `apply.failed` events back into `fact_decision`
in the cold store so the AI Decision Accuracy metric has a non-`pending`
outcome. Today `fact_decision.outcome` is stuck at `pending` (D-096
blocker). The backfill emitter reads `run_manifest.completed/failed`
events and updates the corresponding decision's outcome.
**Must-haves:**
- `core/metrics/outcome_backfill.py``backfill(decision_id, outcome)`
updates `fact_decision.outcome` + `fact_decision.backfilled_at`.
- `core/metrics/collector.py` — invokes backfill after run completion.
- `tests/test_outcome_backfill.py`.
### REQ-318 — `reason='confidence'` escalation tag (IDEATE I2)
Emit a distinct `reason='confidence'` field on the `block` band's
`ai.decision.made` event so the Human Escalation Frequency metric has a
discriminated numerator. Today `hitl_block` is a boolean from the
manifest; the `reason` discriminator is not stored.
**Must-haves:**
- `core/confidence_signal.py``ai.decision.made` gains
`escalation_reason: 'confidence'` when `band == 'block'`.
- `core/metrics/collector.py` — persists `escalation_reason` into
`fact_run`.
- `tests/test_confidence_escalation_reason.py`.
### REQ-319 — Env-JSON `state_backend` wiring reconciliation (IDEATE I3)
The env JSON's `state_backend.bucket` field is currently unused by the
adapter (the adapter computes `nova-tfstate-<AWS_ACCOUNT_ID>` directly).
Reconcile: the adapter reads `state_backend.bucket` from the env JSON
(falling back to the computed name for backwards compat). This closes
the wiring gap so the pilot's env JSON is the single source of truth.
**Must-haves:**
- `adapters/terraform/adapter.py` — reads `env.state_backend.bucket`
when present.
- `tests/test_adapter_state_backend.py`.
- `core/environments/*.json``state_backend.bucket` updated to the
real bucket name `nova-tfstate-581513795199-us-east-1`.
### REQ-320 — Declarative pilot-readiness kyverno-json policy (IDEATE I5)
A kyverno-json policy asserting the env JSON has a non-placeholder
`account_id` (not `000000000000`) before any `terraform apply`. This is
the declarative gate that prevents a pilot run against a placeholder
account.
**Must-haves:**
- `adapters/kyverno-json/policies/pilot-readiness/no-placeholder-account.json`
- `tests/test_pilot_readiness_policy.py`.
### REQ-321 — Docs + adapter README for the consumer estate
Update `adapters/README.md` (new consumer row), `docs/METRICS.md` (the
3 Post-Pilot metrics now grounded post-pilot), `.ciagent/ARCHITECTURE.md`
(§12.8 — Pilot Estate), and `.ciagent/nova-blockchain-exchange/README.md`
(consumer onboarding guide).
**Must-haves:**
- `adapters/README.md` — consumer-repo row.
- `docs/METRICS.md` — Post-Pilot metrics grounded note.
- `.ciagent/ARCHITECTURE.md` — §12.8 Pilot Estate.
- `.ciagent/nova-blockchain-exchange/README.md` — onboarding guide.
### REQ-322 — DynamoDB L1 primitive (platform-side) ✓ complete (P2, v1.25.2)
The blockchain exchange's ledger table needs a DynamoDB L1 primitive.
Research (RESEARCH §3) confirmed the adapter is stateless/registry-
driven (no `TYPE_MAP` — deleted in v1.11); a new stack type requires a
new L1 module, not an adapter change. The `dynamodb` primitive mirrors
the existing `s3` / `rds` primitives: `interface.json` (stack type
`aws:dynamodb:table`, inputs `table_name`/`region`/`pk`/`sk`/`billing_mode`,
outputs `table_arn`/`table_name`), `terraform/main.tf`
(`resource "aws_dynamodb_table" "this"`), `README.md`, `instance.json`,
+ a `registry.json` entry. The pilot contract's `infrastructure.dynamodb`
block references this primitive. This is the single platform-side
module build-out for the milestone (ECS + S3 already exist).
**Must-haves:**
- `modules/l1/dynamodb/interface.json` — stack type
`aws:dynamodb:table`, inputs, outputs.
- `modules/l1/dynamodb/terraform/main.tf`
`resource "aws_dynamodb_table" "this"` (PK + optional SK,
`billing_mode = PAY_PER_REQUEST` default, encryption + point-in-time-
recovery enabled per v1.8 NFR defaults).
- `modules/l1/dynamodb/README.md` — module doc.
- `modules/l1/dynamodb/instance.json` — sample instance.
- `modules/registry.json``dynamodb` entry (kind `l1`,
`terraform_dir: modules/l1/dynamodb/terraform`).
- `tests/test_adapter.py` — add `dynamodb` to `EXPECTED_L1_KEYS` +
a resolution + emission test.
- `modules/README.md` — catalog index updated.
### Summary
13 requirements (REQ-310..322). Equities-only pilot; minimal PoA ledger;
T+1 settlement; consumer deploy via `deploy.yml@v1.25`; 3 Post-Pilot
metrics grounded (outcome backfill + escalation reason + pilot runs);
3 kyverno-json policies extending v1.25 (settlement-finality,
pilot-readiness, + the existing meta-policies apply); env-JSON wiring
reconciled; DynamoDB L1 primitive authored (the single platform-side
module build-out — the adapter is stateless/registry-driven, so the
primitive is a new `modules/l1/dynamodb/` module + registry entry, not
an adapter change).
@@ -0,0 +1,58 @@
# Roadmap — nova-blockchain-exchange (v1.26 pilot)
> **Project:** nova-blockchain-exchange — blockchain stock exchange (pilot)
> **Milestone:** v1.26 — Live Pilot Estate Activation
---
## v1.26 — Live Pilot Estate Activation (active)
Lift D-096 (live AWS re-provisioning); activate the first real consumer
estate (a stock exchange on a homegrown PoA blockchain, equities only)
against live AWS account `581513795199`; ground the three Post-Pilot
targets in NORTH_STAR.md (Touchless Resolution ≥99%, Human Escalation
<0.1%, AI Decision Accuracy ≥99.5%). The platform repo (`acdl`) provides
the deploy workflow, policy engine, and attestation gates; this repo
provides the app (blockchain + matching engine + settlement) + the
`contract.yaml`.
Tags run on the **v1.25.x** patch line: `v1.25.0` (P0) → `v1.25.N`
(final phase = milestone release).
### Phase P1 — blockchain-core (planned, tag v1.25.1)
- REQ-310: Homegrown PoA blockchain core (block, ledger, validator).
- REQ-311: Order-matching engine (limit order book, price-time priority).
- REQ-312: Settlement service (T+1, idempotent, finality = block commit).
### Phase P2 — consumer-contract-and-deploy (complete, tag v1.25.2)
- REQ-313: Consumer `contract.yaml` + per-env variants. ✓
- REQ-314: Consumer deploy workflow invocation (`deploy.yml@v1.25`). ✓
- REQ-322: DynamoDB L1 primitive (platform-side, P2 W0). ✓
### Phase P3 — pilot-metrics-and-policies (planned, tag v1.25.3)
- REQ-315: Settlement-finality kyverno-json policy.
- REQ-316: Pilot-estate regression capability (CAP-025).
- REQ-317: Outcome-backfill emitter.
- REQ-318: `reason='confidence'` escalation tag.
- REQ-319: Env-JSON `state_backend` wiring reconciliation.
- REQ-320: Declarative pilot-readiness kyverno-json policy.
### Phase P4 — pilot-run-and-docs (planned, tag v1.25.4)
- REQ-321: Docs + adapter README + onboarding guide.
- Live pilot end-to-end run (apply → attest → record) against
`581513795199`.
### Phase P5 — final review + audit + milestone ship (Final Phase, tag v1.25.5)
- Multi-persona code review across P1..P4.
- Audit: reconstruction test, branch hygiene, commit discipline.
- Milestone ship: merge `phase/05``milestone/v1.26-pilot-activation`
`main`; tag `v1.25.5` (= the v1.26 release per prev-minor tagging
rule); create Gitea release with full milestone summary; delete all
milestone branches.
- Update `REQUIREMENTS.md` (mark REQ-310..321 complete), `ROADMAP.md`
(mark v1.26 complete), `NORTH_STAR.md` (note Strategic Objectives #1
+ #3 — first real consumer estate; Post-Pilot denominators activated).
After v1.26: future milestones may add bonds/derivatives/options
(different settlement models), multi-validator BFT consensus, and
tamper-evident ledger (D-083 lift).
-17
View File
@@ -63,23 +63,6 @@ jobs:
- name: Install test dependencies - name: Install test dependencies
run: pip install -r requirements-test.txt run: pip install -r requirements-test.txt
- name: Install kyverno-json (kj) for policy-engine tests
run: |
# v1.25: kyverno-json is the primary policy engine. Tests that
# require kj skip when absent, so this is best-effort (the suite
# passes with or without kj). Install is cached via the Go
# module cache (~/.cache/go-build + ~/go/pkg/mod).
if command -v go >/dev/null 2>&1; then
go install github.com/kyverno/kyverno-json/cmd/kj@latest && \
echo "$(go env GOPATH)/bin" >> "$GITHUB_PATH" || \
echo "kj install failed; policy-engine tests will skip"
else
sudo apt-get update && sudo apt-get install -y golang-go && \
go install github.com/kyverno/kyverno-json/cmd/kj@latest && \
echo "$(go env GOPATH)/bin" >> "$GITHUB_PATH" || \
echo "kj install failed; policy-engine tests will skip"
fi
- name: Run pytest - name: Run pytest
run: python3 -m pytest tests/ -v --tb=short run: python3 -m pytest tests/ -v --tb=short
+2 -2
View File
@@ -82,7 +82,7 @@ jobs:
with: with:
repository: acdl/acdl repository: acdl/acdl
path: platform path: platform
ref: v1.9 ref: v1.25
- uses: actions/setup-python@v5 - uses: actions/setup-python@v5
with: with:
@@ -104,7 +104,7 @@ jobs:
with: with:
# P4 (REQ-163): IAM role renamed acdl-deploy- → nova-deploy-. # P4 (REQ-163): IAM role renamed acdl-deploy- → nova-deploy-.
role-to-assume: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID == '' && format('arn:aws:iam::{0}:role/nova-deploy-{1}', secrets.NOVA_AWS_ACCOUNT_ID, github.repository_id) || '' }} role-to-assume: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID == '' && format('arn:aws:iam::{0}:role/nova-deploy-{1}', secrets.NOVA_AWS_ACCOUNT_ID, github.repository_id) || '' }}
aws-region: us-east-1 aws-region: ${{ secrets.AWS_DEFAULT_REGION || 'us-east-1' }}
access-key-id: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID }} access-key-id: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID }}
secret-access-key: ${{ secrets.NOVA_AWS_SECRET_ACCESS_KEY }} secret-access-key: ${{ secrets.NOVA_AWS_SECRET_ACCESS_KEY }}
+69
View File
@@ -0,0 +1,69 @@
# Nova AWS key rotation — platform-managed scheduled pipeline (SPEC §5.9)
#
# Rotates the NOVA_AWS_* static key daily (no long-lived keys in the steady
# state). v0.2 scope: the mechanism must exist (SPEC §5.9); the v0.2 deploy
# uses the currently-active key. The rotation is best-effort + idempotent
# (scripts/rotate_spike_key.sh deactivates the old key only after the new
# key propagates to the consumer's Actions secret store).
#
# Auth: the rotation uses the CURRENT NOVA_AWS_* key to authenticate to IAM
# (the root account 581513795199 can rotate its own keys — confirmed by the
# bootstrap). The aws-actions/configure-aws-credentials@v4 step uses the
# static-key path (no OIDC role-to-assume); the long-lived key rotates
# itself, which is the bootstrap-exception documented in §5.9.
#
# Forge coords (base URL / owner / consumer repo) are sourced from
# repository secrets — NOVA_FORGE_BASE_URL, NOVA_FORGE_OWNER,
# NOVA_CONSUMER_REPO — so the synced workflow file stays forge-agnostic
# (REQ-230). The rotation script uploads the new key to the consumer's
# Actions secret store (the consumer whose deploy.yml consumes NOVA_AWS_*
# via secrets: inherit).
name: nova-rotate-aws-key
on:
schedule:
- cron: "0 0 * * *" # daily at 00:00 UTC
workflow_dispatch:
permissions:
id-token: write
contents: read
jobs:
rotate:
name: Rotate NOVA_AWS_* static key
runs-on: ubuntu-latest
steps:
- name: Check out Nova platform repo
uses: actions/checkout@v4
- name: Configure AWS credentials (bootstrap root creds for IAM key rotation)
uses: aws-actions/configure-aws-credentials@v4
with:
aws-region: ${{ secrets.AWS_DEFAULT_REGION || 'us-east-1' }}
access-key-id: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID }}
secret-access-key: ${{ secrets.NOVA_AWS_SECRET_ACCESS_KEY }}
- name: Install Python deps (boto3 for the rotation script)
run: |
python3 -m pip install --break-system-packages --quiet boto3
- name: Run the key rotation script
env:
# aws-actions/configure-aws-credentials exports AWS_ACCESS_KEY_ID /
# AWS_SECRET_ACCESS_KEY; the rotation script reads the bootstrap
# creds via NOVA_BOOTSTRAP_AWS_* (its dual-read contract, D-034).
# Map the standard AWS_* exports onto the script's expected vars.
NOVA_BOOTSTRAP_AWS_ACCESS_KEY_ID: ${{ env.AWS_ACCESS_KEY_ID }}
NOVA_BOOTSTRAP_AWS_SECRET_ACCESS_KEY: ${{ env.AWS_SECRET_ACCESS_KEY }}
# Forge + consumer coords come from repository secrets (REQ-230 —
# no forge hostnames/orgs hardcoded in the synced workflow file).
# NOVA_FORGE_TOKEN holds the forge API token (set equal to the
# existing forge token as a one-time secret setup).
NOVA_FORGE_TOKEN: ${{ secrets.NOVA_FORGE_TOKEN }}
NOVA_FORGE_BASE_URL: ${{ secrets.NOVA_FORGE_BASE_URL }}
NOVA_FORGE_OWNER: ${{ secrets.NOVA_FORGE_OWNER }}
NOVA_CONSUMER_REPO: ${{ secrets.NOVA_CONSUMER_REPO }}
AWS_DEFAULT_REGION: ${{ secrets.AWS_DEFAULT_REGION || 'us-east-1' }}
run: |
bash scripts/rotate_spike_key.sh
-15
View File
@@ -63,21 +63,6 @@ jobs:
- name: Install test dependencies - name: Install test dependencies
run: pip install -r requirements-test.txt run: pip install -r requirements-test.txt
- name: Install kyverno-json (kj) for policy-engine tests
uses: actions/setup-go@v5
with:
go-version: "1.22"
cache: false
- name: Install kj binary
run: |
# v1.25: kyverno-json is the primary policy engine. Tests that
# require kj skip when absent, so this is best-effort (the suite
# passes with or without kj).
go install github.com/kyverno/kyverno-json/cmd/kj@latest && \
echo "$(go env GOPATH)/bin" >> "$GITHUB_PATH" || \
echo "kj install failed; policy-engine tests will skip"
- name: Run pytest - name: Run pytest
run: python3 -m pytest tests/ -v --tb=short run: python3 -m pytest tests/ -v --tb=short
+2 -2
View File
@@ -82,7 +82,7 @@ jobs:
with: with:
repository: acdl/acdl repository: acdl/acdl
path: platform path: platform
ref: v1.9 ref: v1.25
- uses: actions/setup-python@v5 - uses: actions/setup-python@v5
with: with:
@@ -104,7 +104,7 @@ jobs:
with: with:
# P4 (REQ-163): IAM role renamed acdl-deploy- → nova-deploy-. # P4 (REQ-163): IAM role renamed acdl-deploy- → nova-deploy-.
role-to-assume: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID == '' && format('arn:aws:iam::{0}:role/nova-deploy-{1}', secrets.NOVA_AWS_ACCOUNT_ID, github.repository_id) || '' }} role-to-assume: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID == '' && format('arn:aws:iam::{0}:role/nova-deploy-{1}', secrets.NOVA_AWS_ACCOUNT_ID, github.repository_id) || '' }}
aws-region: us-east-1 aws-region: ${{ secrets.AWS_DEFAULT_REGION || 'us-east-1' }}
access-key-id: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID }} access-key-id: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID }}
secret-access-key: ${{ secrets.NOVA_AWS_SECRET_ACCESS_KEY }} secret-access-key: ${{ secrets.NOVA_AWS_SECRET_ACCESS_KEY }}
+69
View File
@@ -0,0 +1,69 @@
# Nova AWS key rotation — platform-managed scheduled pipeline (SPEC §5.9)
#
# Rotates the NOVA_AWS_* static key daily (no long-lived keys in the steady
# state). v0.2 scope: the mechanism must exist (SPEC §5.9); the v0.2 deploy
# uses the currently-active key. The rotation is best-effort + idempotent
# (scripts/rotate_spike_key.sh deactivates the old key only after the new
# key propagates to the consumer's Actions secret store).
#
# Auth: the rotation uses the CURRENT NOVA_AWS_* key to authenticate to IAM
# (the root account 581513795199 can rotate its own keys — confirmed by the
# bootstrap). The aws-actions/configure-aws-credentials@v4 step uses the
# static-key path (no OIDC role-to-assume); the long-lived key rotates
# itself, which is the bootstrap-exception documented in §5.9.
#
# Forge coords (base URL / owner / consumer repo) are sourced from
# repository secrets — NOVA_FORGE_BASE_URL, NOVA_FORGE_OWNER,
# NOVA_CONSUMER_REPO — so the synced workflow file stays forge-agnostic
# (REQ-230). The rotation script uploads the new key to the consumer's
# Actions secret store (the consumer whose deploy.yml consumes NOVA_AWS_*
# via secrets: inherit).
name: nova-rotate-aws-key
on:
schedule:
- cron: "0 0 * * *" # daily at 00:00 UTC
workflow_dispatch:
permissions:
id-token: write
contents: read
jobs:
rotate:
name: Rotate NOVA_AWS_* static key
runs-on: ubuntu-latest
steps:
- name: Check out Nova platform repo
uses: actions/checkout@v4
- name: Configure AWS credentials (bootstrap root creds for IAM key rotation)
uses: aws-actions/configure-aws-credentials@v4
with:
aws-region: ${{ secrets.AWS_DEFAULT_REGION || 'us-east-1' }}
access-key-id: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID }}
secret-access-key: ${{ secrets.NOVA_AWS_SECRET_ACCESS_KEY }}
- name: Install Python deps (boto3 for the rotation script)
run: |
python3 -m pip install --break-system-packages --quiet boto3
- name: Run the key rotation script
env:
# aws-actions/configure-aws-credentials exports AWS_ACCESS_KEY_ID /
# AWS_SECRET_ACCESS_KEY; the rotation script reads the bootstrap
# creds via NOVA_BOOTSTRAP_AWS_* (its dual-read contract, D-034).
# Map the standard AWS_* exports onto the script's expected vars.
NOVA_BOOTSTRAP_AWS_ACCESS_KEY_ID: ${{ env.AWS_ACCESS_KEY_ID }}
NOVA_BOOTSTRAP_AWS_SECRET_ACCESS_KEY: ${{ env.AWS_SECRET_ACCESS_KEY }}
# Forge + consumer coords come from repository secrets (REQ-230 —
# no forge hostnames/orgs hardcoded in the synced workflow file).
# NOVA_FORGE_TOKEN holds the forge API token (set equal to the
# existing forge token as a one-time secret setup).
NOVA_FORGE_TOKEN: ${{ secrets.NOVA_FORGE_TOKEN }}
NOVA_FORGE_BASE_URL: ${{ secrets.NOVA_FORGE_BASE_URL }}
NOVA_FORGE_OWNER: ${{ secrets.NOVA_FORGE_OWNER }}
NOVA_CONSUMER_REPO: ${{ secrets.NOVA_CONSUMER_REPO }}
AWS_DEFAULT_REGION: ${{ secrets.AWS_DEFAULT_REGION || 'us-east-1' }}
run: |
bash scripts/rotate_spike_key.sh
+50 -6
View File
@@ -46,12 +46,28 @@ never import an engine directly — they go through the registry.
## How to Write an Adapter ## How to Write an Adapter
### Terraform Adapter Extension ### Terraform Adapter Extension (stateless assembler — v1.11 rewrite)
1. Add a stack type → Terraform type mapping to `TYPE_MAP`. > The adapter owns **no module content**. There is no `TYPE_MAP`, no
2. Add non-identity input mappings to `INPUT_MAP`. > `INPUT_MAP`, no `OUTPUT_MAP`, and no per-type branch logic (all deleted
3. Add non-identity output mappings to `OUTPUT_MAP`. > in the v1.11 rewrite — the 918-line monolith collapsed to a ~80-line
4. Add a specialized `_emit_resource` branch if the resource needs nested blocks (e.g. inline policies, rule sets). > assembler). Engine-specific shape lives in each L1 module's own
> `terraform/` dir (`versions.tf`/`variables.tf`/`locals.tf`/`main.tf`/
> `outputs.tf`); the adapter only assembles them.
To extend the Terraform adapter, **do not edit the adapter** — instead:
1. Add an L1 module with a real `terraform/` dir (owning its resource
shape, nested HCL blocks, and defaults).
2. Register it in `modules/registry.json` under the module name with its
`terraform_dir` path. The adapter reads `registry.json` to find each
module's directory.
3. The adapter emits `module "<rid>" { source = "<path>" }` blocks at
the root, with resolved inputs + wired `ref:` refs between modules.
No type-specific translation lives in the adapter.
> If you find yourself reaching for a "TYPE_MAP"-style constant, the L1
> module is missing a piece — fix the module, not the adapter.
### Policy Adapter Pattern ### Policy Adapter Pattern
@@ -76,7 +92,7 @@ never import an engine directly — they go through the registry.
## How to Test Adapters ## How to Test Adapters
- `tests/test_adapter.py` — Terraform adapter (`TYPE_MAP`, resource emission, refs, outputs). - `tests/test_adapter.py` — Terraform adapter (stateless assembly: registry read, `module "<rid>" { source }` emission, `ref:` wiring, outputs). No `TYPE_MAP`/`INPUT_MAP` tests — the adapter owns no type mappings.
- `tests/test_checkov_adapter.py` — Checkov adapter. - `tests/test_checkov_adapter.py` — Checkov adapter.
- `tests/test_wiz_adapter.py` — Wiz adapter. - `tests/test_wiz_adapter.py` — Wiz adapter.
- `tests/test_kyverno_adapter.py` — Kyverno adapter. - `tests/test_kyverno_adapter.py` — Kyverno adapter.
@@ -94,3 +110,31 @@ never import an engine directly — they go through the registry.
4. Write a test (`tests/test_<name>_adapter.py`) plus a fixture (`tests/fixtures/<name>_fixture.json`). 4. Write a test (`tests/test_<name>_adapter.py`) plus a fixture (`tests/fixtures/<name>_fixture.json`).
5. Add it to `scripts/run_platform.sh` if it is invoked at runtime. 5. Add it to `scripts/run_platform.sh` if it is invoked at runtime.
6. Update this README. 6. Update this README.
## Consumers
The Terraform adapter compiles contract IR for consumer estates. The
first real consumer estate is now live:
| Consumer | Version | Environment | Account | Forge / Adapter | Status |
| --- | --- | --- | --- | --- | --- |
| `nova-blockchain-exchange` | v0.2 | dev | `581513795199` | inline adapter (see note below) | **live** (pilot apply `blkex-pilot-apply-v0.2`, 2026-08-19) |
### Forge adapter note (SPEC §10 Q1)
Forge Actions (the consumer's forge runtime) does **not** support
cross-repo `uses:` references — the forge rejects
`uses: <owner>/<repo>/.github/workflows/<file>@<ref>` with
`expected format {owner}/{repo}/.{git_platform}/workflows/{filename}@{ref}`.
The consumer (`nova-blockchain-exchange`) therefore uses an **inline
adapter** in its `deploy.yml`: the workflow does `actions/checkout@v4`
on the consumer, then `actions/checkout@v4` `acdl/acdl` @ `ref: v1.25`
into `platform/`, and runs `bash platform/scripts/run_platform.sh ...`
directly — no `uses:` indirection.
The platform's own `.github/workflows/deploy.yml` (this repo) stays as
the **GitHub Actions reference implementation** — the reusable
`workflow_call` workflow used by GitHub-hosted consumers. The two
files share the same contract shape; the only declared difference is
the forge/runtime, not the stages or commands. See
`.ciagent/ARCHITECTURE.md` §12.8 for the live pilot-estate wiring.
+263 -62
View File
@@ -1,4 +1,4 @@
"""Nova KyvernoJsonEngine (REQ-293, v1.25). """Nova KyvernoJsonEngine (REQ-293, v1.25; fixed v1.26 P3 W0.5).
Implements the ``PolicyEngine`` protocol (``core/policy_engine.py``) Implements the ``PolicyEngine`` protocol (``core/policy_engine.py``)
by shelling to the ``kj`` CLI (``kyverno-json``). Translates native by shelling to the ``kj`` CLI (``kyverno-json``). Translates native
@@ -12,9 +12,10 @@ distinguish from the K8s Kyverno adapter's ``KYVERNO_`` prefix.
Severity (RESEARCH §2.6, G-Q10a): kyverno-json does not natively assign Severity (RESEARCH §2.6, G-Q10a): kyverno-json does not natively assign
severities. Each Nova policy declares its severity via a severities. Each Nova policy declares its severity via a
``metadata.annotations["nova.cloudinit.dev/severity"]`` field. The ``metadata.annotations["nova.cloudinit.dev/severity"]`` field. The
engine reads this annotation from the loaded policy YAML (not from the engine reads this annotation from the loaded policy file (not from the
scan result the result doesn't carry it) and applies it to every scan result the result carries the policy spec but the annotation is
result that policy produces. Default when absent: ``"info"``. read here from disk) and applies it to every result that policy
produces. Default when absent: ``"info"``.
Graceful degradation (D-120): ``is_configured()`` returns ``False`` when Graceful degradation (D-120): ``is_configured()`` returns ``False`` when
``which kj`` is absent ``evaluate()`` returns a single SKIPPED PCR ``which kj`` is absent ``evaluate()`` returns a single SKIPPED PCR
@@ -24,6 +25,37 @@ the binary.
Defensive parsing: any kyverno-json output that doesn't match the Defensive parsing: any kyverno-json output that doesn't match the
expected shape produces an ``error`` PCR, never an exception. The expected shape produces an ``error`` PCR, never an exception. The
engine is read-only against a local policy dir + a temp payload file. engine is read-only against a local policy dir + a temp payload file.
v1.26 P3 W0.5 fix three substrate bugs uncovered once ``kj`` was
actually installed (the v1.25 test suite ``pytest.skip``-masked them):
1. **``.json`` policy files are not loaded by ``kj`` v0.0.3.** The
upstream policy loader (``pkg/policy/load.go``) uses
``fileinfo.IsYaml()`` which only matches ``.yaml``/``.yml``
extensions ``.json`` files are silently skipped, yielding
``evaluating N resources against 0 policies``. Nova policies are
authored as ``.json`` (the ``TestPolicyFilesExist`` tests assert the
``.json`` filenames). Fix: ``evaluate()`` materializes a temp policy
dir that mirrors the source tree with every ``.json`` policy copied
to a ``.yaml`` twin (JSON is a valid YAML subset verified against
``kj`` v0.0.3). The source ``.json`` files remain untouched.
2. **Bare-list output format.** ``kj scan --output json`` emits a bare
JSON list at the top level (NOT ``{"results": [...]}``). Each entry
has ``resource`` (the evaluated payload) + ``results`` (list of
per-policy result objects, each carrying ``policy.metadata.name``,
``rules[]`` with ``rule.name``, ``violations[]`` (present on fail),
``error`` (string, present on policy-evaluation error)). The v1.25
``_translate`` did ``out.get("results", [])`` on a dict but
``out`` is a list returned ``[]`` emitted a single
``KJ_NO_RESULTS`` pass PCR. **This is why all failing fixtures showed
0 fails.** Fix: ``_translate`` handles list (v0.0.3) and dict
(future-proof) shapes.
3. **``validate`` wrapper + check syntax.** Documented in the policy
files themselves (see the W0.5 policy edits). The engine itself does
not enforce policy shape it only translates ``kj`` output so
this fix lives in the policy ``.json`` files.
""" """
import datetime import datetime
@@ -98,39 +130,41 @@ def _load_policy_severities(policy_dir: Path) -> dict[str, str]:
return severities return severities
def _to_pcr(entry: dict, contract_id: str, severity: str) -> dict: def _materialize_yaml_policy_dir(src: Path) -> tuple[Path, bool]:
"""Translate a kyverno-json scan result entry to a PCR dict.""" """Mirror ``src`` (recursively) into a temp dir, copying every
policy_name = entry.get("policy", "") or "UNKNOWN" ``.json`` policy to a ``.yaml`` twin and copying ``.yaml``/``.yml``
rule_name = entry.get("rule", "") or "" files verbatim. Returns ``(temp_dir, created)``.
rule_id = f"KJ_{policy_name}"
if rule_name: ``kj`` v0.0.3's policy loader (``pkg/policy/load.go``) only matches
rule_id = f"{rule_id}/{rule_name}" ``.yaml``/``.yml`` extensions ``.json`` files are silently
result_raw = entry.get("result", "skip") skipped. Nova policies are authored as ``.json`` (the
result = RESULT_MAP.get(str(result_raw).lower(), "error") ``TestPolicyFilesExist`` tests assert the ``.json`` filenames, so
message = entry.get("message", "") or "" they cannot be renamed in-place). JSON is a valid YAML subset, so
resource = entry.get("resource", "") a byte-for-byte copy with a ``.yaml`` extension loads cleanly.
if not resource and entry.get("name"):
kind = entry.get("kind", "") ``created`` is ``False`` when ``src`` contains no policy files at
ns = entry.get("namespace", "") all (empty dir) in that case the temp dir is still returned (the
resource = f"{kind}/{ns}/{entry.get('name')}" if kind else entry.get("name", "") caller invokes ``kj`` against it and gets the no-results path).
return { """
"contractId": contract_id, tmp = Path(tempfile.mkdtemp(prefix="nova-kj-pol-"))
"evaluatedAt": _iso8601_now(), any_policy = False
"engine": "kyverno", if src.is_dir():
"ruleId": rule_id, for root, _dirs, files in os.walk(src):
"severity": severity, rel = Path(root).relative_to(src)
"result": result, dest_root = tmp / rel
"message": message, dest_root.mkdir(parents=True, exist_ok=True)
"evidence": { for fn in files:
"resource": resource, if fn.startswith(".") or fn.startswith("_"):
"policy": policy_name, continue
"rule": rule_name, src_file = Path(root) / fn
"namespace": entry.get("namespace", ""), if fn.endswith(".json"):
"kind": entry.get("kind", ""), dest_file = dest_root / (fn.rsplit(".", 1)[0] + ".yaml")
"name": entry.get("name", ""), shutil.copy2(src_file, dest_file)
}, any_policy = True
"resourceRef": resource, elif fn.endswith((".yaml", ".yml")):
} shutil.copy2(src_file, dest_root / fn)
any_policy = True
return tmp, any_policy
def _skipped_not_configured(contract_id: str) -> dict: def _skipped_not_configured(contract_id: str) -> dict:
@@ -165,6 +199,23 @@ def _error_pcr(contract_id: str, message: str) -> dict:
} }
def _no_results_pass(contract_id: str) -> dict:
"""No result entries — emit a single pass PCR so the confidence
signal's policy input is non-empty (a non-empty list of passes →
score 1.0)."""
return {
"contractId": contract_id,
"evaluatedAt": _iso8601_now(),
"engine": "kyverno",
"ruleId": "KJ_NO_RESULTS",
"severity": "info",
"result": "pass",
"message": "kyverno-json scan produced no result entries (all policies passed or no match).",
"evidence": {},
"resourceRef": "",
}
class KyvernoJsonEngine: class KyvernoJsonEngine:
"""``PolicyEngine`` impl that shells to the ``kj`` CLI.""" """``PolicyEngine`` impl that shells to the ``kj`` CLI."""
@@ -185,6 +236,9 @@ class KyvernoJsonEngine:
f"kyverno-json policy dir not found: {policy_dir}", f"kyverno-json policy dir not found: {policy_dir}",
)] )]
severities = _load_policy_severities(policy_dir) severities = _load_policy_severities(policy_dir)
# kj v0.0.3 only loads .yaml/.yml policy files. Mirror the tree
# to a temp dir with .json policies copied to .yaml twins.
yaml_dir, _any_policy = _materialize_yaml_policy_dir(policy_dir)
# Write payload to temp file (kj scan --payload expects a file path). # Write payload to temp file (kj scan --payload expects a file path).
payload_tmp = tempfile.NamedTemporaryFile( payload_tmp = tempfile.NamedTemporaryFile(
mode="w", suffix=".json", delete=False, encoding="utf-8" mode="w", suffix=".json", delete=False, encoding="utf-8"
@@ -195,7 +249,7 @@ class KyvernoJsonEngine:
payload_tmp.close() payload_tmp.close()
cmd = [ cmd = [
kj, "scan", kj, "scan",
"--policy", str(policy_dir), "--policy", str(yaml_dir),
"--payload", payload_tmp.name, "--payload", payload_tmp.name,
"--output", "json", "--output", "json",
] ]
@@ -211,7 +265,7 @@ class KyvernoJsonEngine:
f"kyverno-json scan exited {proc.returncode}: {proc.stderr[:200]}", f"kyverno-json scan exited {proc.returncode}: {proc.stderr[:200]}",
)] )]
try: try:
out = json.loads(proc.stdout) if proc.stdout.strip() else {} out = json.loads(proc.stdout) if proc.stdout.strip() else []
except json.JSONDecodeError as e: except json.JSONDecodeError as e:
return [_error_pcr( return [_error_pcr(
contract_id, contract_id,
@@ -223,38 +277,185 @@ class KyvernoJsonEngine:
os.unlink(payload_tmp.name) os.unlink(payload_tmp.name)
except OSError: except OSError:
pass pass
shutil.rmtree(yaml_dir, ignore_errors=True)
def _translate(self, out: dict, contract_id: str, def _translate(self, out: Any, contract_id: str,
severities: dict[str, str]) -> list[dict]: severities: dict[str, str]) -> list[dict]:
results = out.get("results", []) if isinstance(out, dict) else [] # kj v0.0.3 emits a BARE JSON LIST at the top level: each entry
if not isinstance(results, list): # has `resource` (the evaluated payload) + `results` (list of
results = [] # per-policy result objects). Future-proof: also accept the
# legacy {"results": [...]} dict shape.
if isinstance(out, list):
entries = out
elif isinstance(out, dict):
entries = out.get("results", [])
if not isinstance(entries, list):
entries = []
else:
entries = []
pcrs: list[dict] = [] pcrs: list[dict] = []
for entry in results: for entry in entries:
if not isinstance(entry, dict): if not isinstance(entry, dict):
continue continue
policy_name = entry.get("policy", "") or "UNKNOWN" resource = entry.get("resource", {})
severity = severities.get(policy_name, SEVERITY_DEFAULT) results = entry.get("results", [])
pcrs.append(_to_pcr(entry, contract_id, severity)) if not isinstance(results, list):
results = []
for pol_result in results:
if not isinstance(pol_result, dict):
continue
policy_obj = pol_result.get("policy", {}) or {}
policy_name = (
policy_obj.get("metadata", {}).get("name") if isinstance(policy_obj, dict)
else None
) or "UNKNOWN"
severity = severities.get(policy_name, SEVERITY_DEFAULT)
rules = pol_result.get("rules", [])
if not isinstance(rules, list):
rules = []
for rule_entry in rules:
if not isinstance(rule_entry, dict):
continue
rule_obj = rule_entry.get("rule", {}) or {}
rule_name = rule_obj.get("name", "") if isinstance(rule_obj, dict) else ""
rule_id = f"KJ_{policy_name}"
if rule_name:
rule_id = f"{rule_id}/{rule_name}"
violations = rule_entry.get("violations")
error_str = rule_entry.get("error")
if isinstance(violations, list) and violations:
# Fail: build a message from the violations' errors.
msg_parts: list[str] = []
for v in violations:
if not isinstance(v, dict):
continue
for err in v.get("errors", []) or []:
if not isinstance(err, dict):
continue
field = err.get("field", "")
detail = err.get("detail", "")
value = err.get("value", "")
msg_parts.append(
f"{field}: value={value!r} detail={detail}"
)
message = "; ".join(msg_parts) if msg_parts else "policy rule failed"
pcrs.append({
"contractId": contract_id,
"evaluatedAt": _iso8601_now(),
"engine": "kyverno",
"ruleId": rule_id,
"severity": severity,
"result": "fail",
"message": message,
"evidence": {
"resource": resource,
"policy": policy_name,
"rule": rule_name,
"violations": violations,
},
"resourceRef": _resource_ref(resource),
})
elif isinstance(error_str, str) and error_str:
# Policy-evaluation error (e.g. bad JMESPath).
pcrs.append({
"contractId": contract_id,
"evaluatedAt": _iso8601_now(),
"engine": "kyverno",
"ruleId": rule_id,
"severity": severity,
"result": "error",
"message": error_str,
"evidence": {
"resource": resource,
"policy": policy_name,
"rule": rule_name,
},
"resourceRef": _resource_ref(resource),
})
else:
# Pass: no violations, no error.
pcrs.append({
"contractId": contract_id,
"evaluatedAt": _iso8601_now(),
"engine": "kyverno",
"ruleId": rule_id,
"severity": severity,
"result": "pass",
"message": "",
"evidence": {
"resource": resource,
"policy": policy_name,
"rule": rule_name,
},
"resourceRef": _resource_ref(resource),
})
if not pcrs: if not pcrs:
# No results — kyverno-json produced nothing (no match, or pcrs.append(_no_results_pass(contract_id))
# all policies passed with no result entries). Emit a
# single pass PCR so the confidence signal's policy input
# is non-empty (a non-empty list of passes → score 1.0).
pcrs.append({
"contractId": contract_id,
"evaluatedAt": _iso8601_now(),
"engine": "kyverno",
"ruleId": "KJ_NO_RESULTS",
"severity": "info",
"result": "pass",
"message": "kyverno-json scan produced no result entries (all policies passed or no match).",
"evidence": {},
"resourceRef": "",
})
return pcrs return pcrs
def _resource_ref(resource: Any) -> str:
"""Best-effort resource ref from the evaluated payload."""
if isinstance(resource, dict):
for key in ("id", "name", "address"):
v = resource.get(key)
if isinstance(v, str) and v:
return v
return ""
# --- Legacy _to_pcr kept for the existing TestToPcr unit tests ---
# (test_kyverno_json_engine.py::TestToPcr constructs flat `entry`
# dicts with `policy`/`rule`/`result`/`message`/`resource` keys and
# asserts the translated PCR shape. The production _translate path no
# longer calls this helper — it inlines the translation against the
# real kj v0.0.3 nested output — but the unit tests pin the helper's
# contract, so it stays.)
def _to_pcr(entry: dict, contract_id: str, severity: str) -> dict:
"""Translate a flat kyverno-json scan result entry to a PCR dict.
Legacy shape (kept for unit-test backwards compatibility): the
entry is a flat dict with ``policy``/``rule``/``result``/``message``/
``resource`` string keys. The production ``_translate`` path no
longer calls this it inlines translation against the real kj
v0.0.3 nested ``resource``+``results``+``rules`` shape but the
``TestToPcr`` unit tests pin this contract.
"""
policy_name = entry.get("policy", "") or "UNKNOWN"
rule_name = entry.get("rule", "") or ""
rule_id = f"KJ_{policy_name}"
if rule_name:
rule_id = f"{rule_id}/{rule_name}"
result_raw = entry.get("result", "skip")
result = RESULT_MAP.get(str(result_raw).lower(), "error")
message = entry.get("message", "") or ""
resource = entry.get("resource", "")
if not resource and entry.get("name"):
kind = entry.get("kind", "")
ns = entry.get("namespace", "")
resource = f"{kind}/{ns}/{entry.get('name')}" if kind else entry.get("name", "")
return {
"contractId": contract_id,
"evaluatedAt": _iso8601_now(),
"engine": "kyverno",
"ruleId": rule_id,
"severity": severity,
"result": result,
"message": message,
"evidence": {
"resource": resource,
"policy": policy_name,
"rule": rule_name,
"namespace": entry.get("namespace", ""),
"kind": entry.get("kind", ""),
"name": entry.get("name", ""),
},
"resourceRef": resource,
}
if __name__ == "__main__": if __name__ == "__main__":
if len(sys.argv) < 4: if len(sys.argv) < 4:
print( print(
+8 -9
View File
@@ -12,17 +12,16 @@
"rules": [ "rules": [
{ {
"name": "require-id", "name": "require-id",
"validate": { "assert": {
"message": "contract id is required", "all": [
"assert": { {
"all": [ "check": {
{ "id": {
"check": { "(regex_match('^[a-z][a-z0-9-]{2,5}$', @))": true
"id": "{{ to_string(@) }}"
} }
} }
] }
} ]
} }
} }
] ]
@@ -12,18 +12,17 @@
"rules": [ "rules": [
{ {
"name": "no-unknown-fields", "name": "no-unknown-fields",
"validate": { "assert": {
"message": "contract may only contain id, name, environment, infrastructure (schema-allowed fields)", "all": [
"assert": { {
"all": [ "check": {
{ "(length(keys(@)) == `4`)": true,
"check": { "keys(@)": {
"(length(keys(@)) == `4`)": true, "(contains(['id','name','environment','infrastructure'], @))": true
"keys(@)": "(contains(['id','name','environment','infrastructure'], @))"
} }
} }
] }
} ]
} }
} }
] ]
@@ -12,17 +12,16 @@
"rules": [ "rules": [
{ {
"name": "env-enum", "name": "env-enum",
"validate": { "assert": {
"message": "contract.environment must be one of dev, qa, prod, dr", "all": [
"assert": { {
"all": [ "check": {
{ "environment": {
"check": { "(contains(['dev','qa','prod','dr'], @))": true
"environment": "(contains(['dev','qa','prod','dr'], @))"
} }
} }
] }
} ]
} }
} }
] ]
@@ -12,17 +12,16 @@
"rules": [ "rules": [
{ {
"name": "id-pattern", "name": "id-pattern",
"validate": { "assert": {
"message": "contract.id must match ^[a-z][a-z0-9-]{2,5}$ (3-6 char operational acronym)", "all": [
"assert": { {
"all": [ "check": {
{ "id": {
"check": { "(regex_match('^[a-z][a-z0-9-]{2,5}$', @))": true
"id": "(regex_match('^[a-z][a-z0-9-]{2,5}$', @))"
} }
} }
] }
} ]
} }
} }
] ]
@@ -12,17 +12,16 @@
"rules": [ "rules": [
{ {
"name": "infra-min-1", "name": "infra-min-1",
"validate": { "assert": {
"message": "contract.infrastructure must have at least one module entry", "all": [
"assert": { {
"all": [ "check": {
{ "infrastructure": {
"check": { "(length(keys(@)) > `0`)": true
"infrastructure": "(length(keys(@)) > `0`)"
} }
} }
] }
} ]
} }
} }
] ]
@@ -12,19 +12,14 @@
"rules": [ "rules": [
{ {
"name": "no-critical-fail", "name": "no-critical-fail",
"validate": { "assert": {
"message": "No PolicyCheckResult in the merged list may have severity: critical + result: fail. The confidence_signal.py hard-override is the defense-in-depth behind this declarative rule (D-119).", "all": [
"assert": { {
"all": [ "check": {
{ "(severity == 'critical' && result == 'fail')": false
"check": {
"~.[]": {
"(severity == 'critical' && result == 'fail')": false
}
}
} }
] }
} ]
} }
} }
] ]
@@ -12,28 +12,19 @@
"rules": [ "rules": [
{ {
"name": "no-tagging-divergence", "name": "no-tagging-divergence",
"validate": { "assert": {
"message": "For every resource, the Checkov NOVA_TAG_NAMING result and the kyverno-json KJ_REQUIRE_TAGGING_STANDARD result must agree. Divergence emits an error PCR (D-118, defense-in-depth against rule drift).", "all": [
"assert": { {
"all": [ "check": {
{ "(ruleId == 'NOVA_TAG_NAMING' && result == 'fail')": false
"check": {
"~.[?(ruleId == 'NOVA_TAG_NAMING')]": {
"result->ckv_result": {},
"($ckv_result == 'fail')": false
}
}
},
{
"check": {
"~.[?(ruleId == 'KJ_REQUIRE_TAGGING_STANDARD')]": {
"result->kj_result": {},
"($kj_result == 'fail')": false
}
}
} }
] },
} {
"check": {
"(ruleId == 'KJ_REQUIRE_TAGGING_STANDARD' && result == 'fail')": false
}
}
]
} }
} }
] ]
@@ -0,0 +1,27 @@
{
"apiVersion": "json.kyverno.io/v1alpha1",
"kind": "ValidatingPolicy",
"metadata": {
"name": "no-placeholder-account",
"annotations": {
"nova.cloudinit.dev/severity": "critical",
"title.policy.kyverno.io": "Env does not use a placeholder AWS account id"
}
},
"spec": {
"rules": [
{
"name": "no-placeholder-account",
"assert": {
"all": [
{
"check": {
"(account_id == '000000000000')": false
}
}
]
}
}
]
}
}
@@ -12,36 +12,38 @@
"rules": [ "rules": [
{ {
"name": "no-wildcard-action", "name": "no-wildcard-action",
"validate": { "assert": {
"message": "IAM policy Action must not be '*' (ports CKV_AWS_1/40)", "all": [
"assert": { {
"all": [ "check": {
{ "planned_values": {
"check": { "root_module": {
"planned_values.root_module.~.resources": { "~.resources": {
"(type == 'aws_iam_policy' && contains(values.policy_document.Statement[].Action, '*'))": false "(type == 'aws_iam_policy' && contains(values.policy_document.Statement[].Action, '*'))": false
}
} }
} }
} }
] }
} ]
} }
}, },
{ {
"name": "no-wildcard-resource", "name": "no-wildcard-resource",
"validate": { "assert": {
"message": "IAM policy Resource must not be '*' (ports CKV_AWS_1/40)", "all": [
"assert": { {
"all": [ "check": {
{ "planned_values": {
"check": { "root_module": {
"planned_values.root_module.~.resources": { "~.resources": {
"(type == 'aws_iam_policy' && contains(values.policy_document.Statement[].Resource, '*'))": false "(type == 'aws_iam_policy' && contains(values.policy_document.Statement[].Resource, '*'))": false
}
} }
} }
} }
] }
} ]
} }
} }
] ]
@@ -12,19 +12,20 @@
"rules": [ "rules": [
{ {
"name": "no-plaintext-db-password", "name": "no-plaintext-db-password",
"validate": { "assert": {
"message": "aws_db_instance.password must not be a plaintext string (ports CKV_AWS_41/45/46)", "all": [
"assert": { {
"all": [ "check": {
{ "planned_values": {
"check": { "root_module": {
"planned_values.root_module.~.resources": { "~.resources": {
"(type == 'aws_db_instance' && contains(keys(values), 'password') && !contains(['${...}', ''], values.password))": false "(type == 'aws_db_instance' && contains(keys(values), 'password') && !contains(['${...}', ''], values.password))": false
}
} }
} }
} }
] }
} ]
} }
} }
] ]
@@ -12,19 +12,20 @@
"rules": [ "rules": [
{ {
"name": "kms-by-alias", "name": "kms-by-alias",
"validate": { "assert": {
"message": "aws_kms_key resources should reference a customer-managed key alias, not inline key material (ports CKV_AWS_7/33)", "all": [
"assert": { {
"all": [ "check": {
{ "planned_values": {
"check": { "root_module": {
"planned_values.root_module.~.resources": { "~.resources": {
"(type == 'aws_kms_key' && !contains(keys(values), 'key_id') && !contains(keys(values), 'kms_key_id'))": false "(type == 'aws_kms_key' && !contains(keys(values), 'key_id') && !contains(keys(values), 'kms_key_id'))": false
}
} }
} }
} }
] }
} ]
} }
} }
] ]
@@ -12,17 +12,14 @@
"rules": [ "rules": [
{ {
"name": "no-duplicate-adapters", "name": "no-duplicate-adapters",
"validate": { "assert": {
"message": "Each adapter must be registered exactly once (no duplicate adapter names in the capability inventory). Declarative mirror of core/regression_verify.py CAP-013.", "all": [
"assert": { {
"all": [ "check": {
{ "(max(map(&length(@), values(group_by(adapters, &@)))) == `1`)": true
"check": {
"adapters": "(length(duplicates(@)) == `0`)"
}
} }
] }
} ]
} }
} }
] ]
@@ -12,19 +12,16 @@
"rules": [ "rules": [
{ {
"name": "every-metric-has-status", "name": "every-metric-has-status",
"validate": { "assert": {
"message": "Every metric in docs/METRICS.md must declare a status (grounded, derived, or deferred). Declarative mirror of core/regression_verify.py CAP-023.", "all": [
"assert": { {
"all": [ "check": {
{ "~.metrics": {
"check": { "(contains(['grounded','derived','deferred'], status))": true
"~.metrics": {
"(contains(['grounded','derived','deferred'], status))": true
}
} }
} }
] }
} ]
} }
} }
] ]
@@ -12,22 +12,19 @@
"rules": [ "rules": [
{ {
"name": "deck-has-4-beats", "name": "deck-has-4-beats",
"validate": { "assert": {
"message": "The deck must have the 4-beat arc: Problem, Solution, Proof, Roadmap+Ask. Declarative mirror of core/regression_verify.py CAP-024.", "all": [
"assert": { {
"all": [ "check": {
{ "deck": {
"check": { "beats": {
"deck.beats": "(length(@) >= `4`)" "(length(@) >= `4`)": true,
} "(contains(@, 'Problem') && contains(@, 'Solution') && contains(@, 'Proof') && contains(@, 'Roadmap+Ask'))": true
}, }
{
"check": {
"deck.beats": "(contains(@, 'Problem') && contains(@, 'Solution') && contains(@, 'Proof') && contains(@, 'Roadmap+Ask'))"
} }
} }
] }
} ]
} }
} }
] ]
@@ -0,0 +1,27 @@
{
"apiVersion": "json.kyverno.io/v1alpha1",
"kind": "ValidatingPolicy",
"metadata": {
"name": "all-matches-committed",
"annotations": {
"nova.cloudinit.dev/severity": "critical",
"title.policy.kyverno.io": "All settlement matches are committed (finalized)"
}
},
"spec": {
"rules": [
{
"name": "all-matches-committed",
"assert": {
"all": [
{
"check": {
"(all_committed)": true
}
}
]
}
}
]
}
}
@@ -13,19 +13,16 @@
{ {
"name": "no-public-ingress", "name": "no-public-ingress",
"identifier": "id", "identifier": "id",
"validate": { "assert": {
"message": "public_ingress: true is not allowed on any resource (v1.0 demo rule, now declarative)", "all": [
"assert": { {
"all": [ "check": {
{ "~.resources": {
"check": { "(inputs.public_ingress || `false`)": false
"~.resources": {
"(inputs.public_ingress || `false`)": false
}
} }
} }
] }
} ]
} }
} }
] ]
@@ -13,43 +13,31 @@
{ {
"name": "s3-encryption", "name": "s3-encryption",
"identifier": "id", "identifier": "id",
"match": { "assert": {
"any": [ "all": [
{"type": "aws:s3:bucket"} {
] "check": {
}, "~.resources": {
"validate": { "(type == 'aws:s3:bucket' && !(contains(keys(inputs), 'bucket_encryption') || contains(keys(inputs), 'kms_key_id')))": false
"message": "S3 buckets must declare encryption config (inputs.bucket_encryption or inputs.kms_key_id)",
"assert": {
"all": [
{
"check": {
"(contains(keys(inputs), 'bucket_encryption') || contains(keys(inputs), 'kms_key_id'))": true
} }
} }
] }
} ]
} }
}, },
{ {
"name": "ebs-encryption", "name": "ebs-encryption",
"identifier": "id", "identifier": "id",
"match": { "assert": {
"any": [ "all": [
{"type": "aws:ebs:volume"} {
] "check": {
}, "~.resources": {
"validate": { "(type == 'aws:ebs:volume' && !(contains(keys(inputs), 'encrypted') || contains(keys(inputs), 'kms_key_id')))": false
"message": "EBS volumes must declare encryption (inputs.encrypted or inputs.kms_key_id)",
"assert": {
"all": [
{
"check": {
"(contains(keys(inputs), 'encrypted') || contains(keys(inputs), 'kms_key_id'))": true
} }
} }
] }
} ]
} }
} }
] ]
@@ -13,22 +13,19 @@
{ {
"name": "require-nova-tags", "name": "require-nova-tags",
"identifier": "id", "identifier": "id",
"validate": { "assert": {
"message": "Every taggable resource must carry nova:owner, nova:contract, nova:environment, nova:cost-center tags", "all": [
"assert": { {
"all": [ "check": {
{ "~.resources": {
"check": { "(contains(keys(inputs.tags || `{}`), 'nova:owner'))": true,
"~.resources": { "(contains(keys(inputs.tags || `{}`), 'nova:contract'))": true,
"(contains(keys(tags || `[]`), 'nova:owner'))": true, "(contains(keys(inputs.tags || `{}`), 'nova:environment'))": true,
"(contains(keys(tags || `[]`), 'nova:contract'))": true, "(contains(keys(inputs.tags || `{}`), 'nova:cost-center'))": true
"(contains(keys(tags || `[]`), 'nova:environment'))": true,
"(contains(keys(tags || `[]`), 'nova:cost-center'))": true
}
} }
} }
] }
} ]
} }
} }
] ]
+45 -7
View File
@@ -30,6 +30,37 @@ def _module_name(resource):
return resource.get("module", "").split("@")[0] return resource.get("module", "").split("@")[0]
def _load_env_json(env_name, repo_root):
"""Load core/environments/<env_name>.json → dict (P03 W3, REQ-319).
Returns {} if the file is absent (the adapter falls back to the
computed state-bucket name). Sources env.state_backend.bucket +
env.account_id + env.region for the S3 backend block.
"""
env_path = os.path.join(repo_root, "core", "environments", f"{env_name}.json")
if not os.path.isfile(env_path):
return {}
with open(env_path, "r") as fh:
return json.load(fh)
def _resolve_state_bucket(env_json, region):
"""Resolve the S3 state-backend bucket name (P03 W3, REQ-319).
Precedence: (1) env.state_backend.bucket when present + non-empty;
(2) nova-tfstate-{account_id}-{region} from env.account_id + region
(backwards-compat); (3) nova-tfstate-581513795199-{region} when
account_id is absent (the only real account bootstrap bucket).
The env JSON is authoritative; NOVA_AWS_ACCOUNT_ID is no longer
consulted for the bucket name.
"""
bucket = (env_json.get("state_backend") or {}).get("bucket")
if bucket:
return bucket
account_id = env_json.get("account_id") or "581513795199"
return f"nova-tfstate-{account_id}-{region}"
def _ref_expr(value, data_source_names=None, id_remap=None): def _ref_expr(value, data_source_names=None, id_remap=None):
"""Translate `ref:<rid>.<output>` → `module.<rid>.<output>` (or """Translate `ref:<rid>.<output>` → `module.<rid>.<output>` (or
`data.terraform_remote_state.platform.outputs.<output>` for data `data.terraform_remote_state.platform.outputs.<output>` for data
@@ -108,13 +139,20 @@ def adapt(stack_instance, out_dir):
resources = stack_instance.get("resources", []) resources = stack_instance.get("resources", [])
stack_outputs = stack_instance.get("outputs", {}) stack_outputs = stack_instance.get("outputs", {})
region = next((r["inputs"]["region"] for r in resources if "region" in r.get("inputs", {})), "us-east-1")
providers_tf = f'provider "aws" {{\n region = "{region}"\n}}\n'
stack_name = stack.get("name", "spike") stack_name = stack.get("name", "spike")
environment = stack.get("environment", "dev") environment = stack.get("environment", "dev")
account_id = env.get_env("AWS_ACCOUNT_ID", "581513795199") # P03 W3 (REQ-319): state backend bucket + account_id + region come
state_bucket = f"nova-tfstate-{account_id}-us-east-1" # from the env onboarding JSON (source of truth post-REQ-319). Bucket
# = env.state_backend.bucket when present (fallback to the computed
# nova-tfstate-{account_id}-{region} pattern for backwards compat).
env_json = _load_env_json(environment, repo_root)
region = env_json.get("region") or next(
(r["inputs"]["region"] for r in resources if "region" in r.get("inputs", {})),
"us-east-1",
)
state_bucket = _resolve_state_bucket(env_json, region)
providers_tf = f'provider "aws" {{\n region = "{region}"\n}}\n'
# State key is env-scoped (v1.24 REQ-287): the {environment} segment lets # State key is env-scoped (v1.24 REQ-287): the {environment} segment lets
# the env-transition detect-and-destroy step target the PRIOR env's state # the env-transition detect-and-destroy step target the PRIOR env's state
# without affecting the new env. No orphan path on environment promotion. # without affecting the new env. No orphan path on environment promotion.
@@ -130,7 +168,7 @@ def adapt(stack_instance, out_dir):
' backend "s3" {\n' ' backend "s3" {\n'
f' bucket = "{state_bucket}"\n' f' bucket = "{state_bucket}"\n'
f' key = "spike/{stack_name}/{environment}/terraform.tfstate"\n' f' key = "spike/{stack_name}/{environment}/terraform.tfstate"\n'
' region = "us-east-1"\n' f' region = "{region}"\n'
' }\n' ' }\n'
'}\n' '}\n'
) )
@@ -145,7 +183,7 @@ def adapt(stack_instance, out_dir):
' config = {\n' ' config = {\n'
f' bucket = "{state_bucket}"\n' f' bucket = "{state_bucket}"\n'
f' key = "{remote_state_key}"\n' f' key = "{remote_state_key}"\n'
' region = "us-east-1"\n' f' region = "{region}"\n'
' }\n' ' }\n'
'}\n' '}\n'
) )
+33 -10
View File
@@ -144,6 +144,7 @@ def compute(contract_id: str, environment: str,
penalty = 0.0 penalty = 0.0
policy_input = inputs.get("policy") policy_input = inputs.get("policy")
pcrs = policy_input if isinstance(policy_input, list) else [] pcrs = policy_input if isinstance(policy_input, list) else []
critical_override = False
for pcr in pcrs: for pcr in pcrs:
if not isinstance(pcr, dict): if not isinstance(pcr, dict):
continue continue
@@ -152,20 +153,31 @@ def compute(contract_id: str, environment: str,
sev = pcr.get("severity") sev = pcr.get("severity")
p = PENALTY.get(sev, 0.0) p = PENALTY.get(sev, 0.0)
if p is None: if p is None:
return Signal(0.0, "block", per_input, # Critical PCR hard override: score = 0, band = block.
reasons + [f"CRITICAL_OVERRIDE:{pcr.get('ruleId','?')}"]) # Do NOT early-return — fall through to the event emission
# block below so the SPEC §5.8 evidence stream
# (confidence.computed -> ai.decision.made -> ...) is complete
# even on a critical override (REQ-318: a critical PCR is a
# confidence-driven escalation and must carry escalation_reason).
reasons.append(f"CRITICAL_OVERRIDE:{pcr.get('ruleId','?')}")
critical_override = True
break
penalty += p penalty += p
score = max(0.0, min(1.0, base - penalty)) if critical_override:
threshold = THRESHOLDS[environment] score = 0.0
if score >= threshold:
band = "pass"
elif score < threshold - 0.10:
band = "block" band = "block"
else: else:
band = "warn" score = max(0.0, min(1.0, base - penalty))
if environment == "dev" and band == "warn": threshold = THRESHOLDS[environment]
band = "block" if score >= threshold:
band = "pass"
elif score < threshold - 0.10:
band = "block"
else:
band = "warn"
if environment == "dev" and band == "warn":
band = "block"
signal = Signal(score, band, per_input, reasons) signal = Signal(score, band, per_input, reasons)
# Emit nova.confidence.computed + nova.ai.decision.made events (D-122). # Emit nova.confidence.computed + nova.ai.decision.made events (D-122).
@@ -184,6 +196,17 @@ def compute(contract_id: str, environment: str,
"human_override": band == "block", "human_override": band == "block",
"threshold": THRESHOLDS[environment], "threshold": THRESHOLDS[environment],
} }
# REQ-318 (SPEC §5.8): on a `block` band, carry escalation_reason.
# In v1.26 the only value is "confidence" — a block is always
# confidence-driven (the score fell below threshold OR a critical
# PCR fired a hard override). Future milestones may add "policy"
# (a critical PCR that is not confidence-scored); leave the door
# open but only emit "confidence" now. On pass/warn bands the
# field is ABSENT (escalation_reason is only meaningful on a
# block — it is the Post-Pilot Human Escalation Frequency
# denominator).
if band == "block":
decision_data["escalation_reason"] = "confidence"
decision_event = make_event("nova.ai.decision.made", run_id, environment, decision_data, decision_event = make_event("nova.ai.decision.made", run_id, environment, decision_data,
contract_id=contract_id, actor_type="confidence-gate", contract_id=contract_id, actor_type="confidence-gate",
actor_id="confidence_signal") actor_id="confidence_signal")
+2 -2
View File
@@ -1,10 +1,10 @@
{ {
"name": "dev", "name": "dev",
"description": "Default platform-managed dev environment for onboarding demos.", "description": "Default platform-managed dev environment for onboarding demos.",
"account_id": "000000000000", "account_id": "581513795199",
"region": "us-east-1", "region": "us-east-1",
"state_backend": { "state_backend": {
"bucket": "acdl-dev-state", "bucket": "nova-tfstate-581513795199-us-east-1",
"lock_table": "acdl-dev-locks" "lock_table": "acdl-dev-locks"
}, },
"network": { "network": {
+1 -1
View File
@@ -4,7 +4,7 @@
"account_id": "000000000000", "account_id": "000000000000",
"region": "us-east-1", "region": "us-east-1",
"state_backend": { "state_backend": {
"bucket": "acdl-dr-state", "bucket": "nova-tfstate-000000000000-us-east-1",
"lock_table": "acdl-dr-locks" "lock_table": "acdl-dr-locks"
}, },
"network": { "network": {
+1 -1
View File
@@ -4,7 +4,7 @@
"account_id": "000000000000", "account_id": "000000000000",
"region": "us-east-1", "region": "us-east-1",
"state_backend": { "state_backend": {
"bucket": "acdl-prod-state", "bucket": "nova-tfstate-000000000000-us-east-1",
"lock_table": "acdl-prod-locks" "lock_table": "acdl-prod-locks"
}, },
"network": { "network": {
+1 -1
View File
@@ -4,7 +4,7 @@
"account_id": "000000000000", "account_id": "000000000000",
"region": "us-east-1", "region": "us-east-1",
"state_backend": { "state_backend": {
"bucket": "acdl-qa-state", "bucket": "nova-tfstate-000000000000-us-east-1",
"lock_table": "acdl-qa-locks" "lock_table": "acdl-qa-locks"
}, },
"network": { "network": {
+33 -8
View File
@@ -54,7 +54,8 @@ def _init_store(db_path=None):
confidence_band TEXT, confidence_band TEXT,
hitl_block INTEGER, hitl_block INTEGER,
cost_estimate_usd REAL, cost_estimate_usd REAL,
decision_id TEXT decision_id TEXT,
escalation_reason TEXT
); );
CREATE TABLE IF NOT EXISTS fact_capability ( CREATE TABLE IF NOT EXISTS fact_capability (
@@ -110,7 +111,9 @@ def _init_store(db_path=None):
confidence REAL, confidence REAL,
alternatives TEXT, alternatives TEXT,
human_override INTEGER, human_override INTEGER,
escalation_reason TEXT,
outcome TEXT, outcome TEXT,
backfilled_at TEXT,
event_time TEXT, event_time TEXT,
PRIMARY KEY (decision_id) PRIMARY KEY (decision_id)
); );
@@ -217,14 +220,15 @@ def collect_run_manifests(db_path=None, runs_dir=None):
INSERT OR REPLACE INTO fact_run INSERT OR REPLACE INTO fact_run
(run_id, contract_id, environment, started_at, completed_at, (run_id, contract_id, environment, started_at, completed_at,
exit_code, outcome, confidence_score, confidence_band, exit_code, outcome, confidence_score, confidence_band,
hitl_block, cost_estimate_usd, decision_id) hitl_block, cost_estimate_usd, decision_id, escalation_reason)
VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?) VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
""", (run_id, manifest.get("contract_id", ""), manifest.get("environment", ""), """, (run_id, manifest.get("contract_id", ""), manifest.get("environment", ""),
manifest.get("started_at", ""), manifest.get("completed_at", ""), manifest.get("started_at", ""), manifest.get("completed_at", ""),
manifest.get("exit_code", 0), manifest.get("outcome", ""), manifest.get("exit_code", 0), manifest.get("outcome", ""),
conf.get("score", 0), conf.get("band", ""), conf.get("score", 0), conf.get("band", ""),
1 if hitl.get("block") else 0, 1 if hitl.get("block") else 0,
manifest.get("cost_estimate_usd", 0), manifest.get("decision_id", ""))) manifest.get("cost_estimate_usd", 0), manifest.get("decision_id", ""),
manifest.get("escalation_reason")))
count += 1 count += 1
conn.commit() conn.commit()
conn.close() conn.close()
@@ -232,7 +236,16 @@ def collect_run_manifests(db_path=None, runs_dir=None):
def collect_decision_ledger(db_path=None, ledger_db=None): def collect_decision_ledger(db_path=None, ledger_db=None):
"""Read the Decision Ledger SQLite → fact_decision.""" """Read the Decision Ledger SQLite → fact_decision.
REQ-317: preserves a backfilled outcome. The ledger is append-only
and the `nova.ai.decision.made` event always carries outcome=pending
(it is emitted before apply). Once `outcome_backfill.backfill()` has
transitioned the `fact_decision` row to succeeded/failed, a re-run of
the collector must NOT clobber it back to pending. We therefore
coalesce: if the existing row has a non-pending outcome, keep it +
its backfilled_at; otherwise write pending (the event default).
"""
if db_path is None: if db_path is None:
db_path = _STORE_PATH db_path = _STORE_PATH
if ledger_db is None: if ledger_db is None:
@@ -251,15 +264,27 @@ def collect_decision_ledger(db_path=None, ledger_db=None):
payload = json.loads(payload_json) payload = json.loads(payload_json)
data = payload.get("data", {}) data = payload.get("data", {})
decision_id = data.get("decision_id", run_id) decision_id = data.get("decision_id", run_id)
# Preserve a backfilled outcome across collector re-runs (REQ-317).
existing = conn.execute(
"SELECT outcome, backfilled_at FROM fact_decision WHERE decision_id = ?",
(decision_id,),
).fetchone()
if existing and existing[0] and existing[0] != "pending":
outcome = existing[0]
backfilled_at = existing[1]
else:
outcome = data.get("outcome", "pending")
backfilled_at = data.get("backfilled_at")
conn.execute(""" conn.execute("""
INSERT OR REPLACE INTO fact_decision INSERT OR REPLACE INTO fact_decision
(decision_id, run_id, chosen_action, confidence, alternatives, (decision_id, run_id, chosen_action, confidence, alternatives,
human_override, outcome, event_time) human_override, escalation_reason, outcome, backfilled_at, event_time)
VALUES (?, ?, ?, ?, ?, ?, ?, ?) VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
""", (decision_id, run_id, data.get("chosen_action", ""), """, (decision_id, run_id, data.get("chosen_action", ""),
data.get("confidence", 0), json.dumps(data.get("alternatives", {})), data.get("confidence", 0), json.dumps(data.get("alternatives", {})),
1 if data.get("human_override") else 0, 1 if data.get("human_override") else 0,
data.get("outcome", "pending"), event_time)) data.get("escalation_reason"),
outcome, backfilled_at, event_time))
count += 1 count += 1
conn.commit() conn.commit()
conn.close() conn.close()
+4
View File
@@ -224,12 +224,16 @@ def replay_run(run_id, db_path=None):
line = f" [{e['seq']}] {e['event_time']} {etype}" line = f" [{e['seq']}] {e['event_time']} {etype}"
if etype == "nova.ai.decision.made": if etype == "nova.ai.decision.made":
line += f" confidence={data.get('confidence', '?')} band={data.get('chosen_action', '?')} override={data.get('human_override', '?')}" line += f" confidence={data.get('confidence', '?')} band={data.get('chosen_action', '?')} override={data.get('human_override', '?')}"
if data.get("escalation_reason"):
line += f" escalation_reason={data.get('escalation_reason')}"
elif etype == "nova.attestation.recorded": elif etype == "nova.attestation.recorded":
line += f" env={data.get('environment', '?')} approver={data.get('approver', '?')} result={data.get('result', '?')}" line += f" env={data.get('environment', '?')} approver={data.get('approver', '?')} result={data.get('result', '?')}"
elif etype == "nova.run.completed": elif etype == "nova.run.completed":
line += f" exit={data.get('exit_code', '?')} outcome={data.get('outcome', '?')}" line += f" exit={data.get('exit_code', '?')} outcome={data.get('outcome', '?')}"
elif etype == "nova.run.failed": elif etype == "nova.run.failed":
line += f" exit={data.get('exit_code', '?')} outcome=failed" line += f" exit={data.get('exit_code', '?')} outcome=failed"
elif etype == "nova.outcome.backfilled":
line += f" prev={data.get('previous_outcome', '?')} new={data.get('new_outcome', '?')} at={data.get('backfilled_at', '?')}"
lines.append(line) lines.append(line)
lines.append("=== End replay ===") lines.append("=== End replay ===")
return "\n".join(lines) return "\n".join(lines)
+213
View File
@@ -0,0 +1,213 @@
"""Nova Outcome Backfill (REQ-317, SPEC §5.8, P3 Wave 2).
The `fact_decision.outcome` column in the metrics cold store is written
`pending` by the collector (it ingests `nova.ai.decision.made` events,
which are emitted *before* the run executes the apply). Once the run
completes (`nova.run.completed`, exit 0) or fails (`nova.run.failed`,
exit non-zero), the outcome must be transitioned `pending ->
succeeded`/`failed` so the Post-Pilot AI Decision Accuracy denominator is
grounded (an outcome that is stuck `pending` cannot be scored).
Architecture (grounded in what the ledger + collector actually do):
* The Decision Ledger (`core/metrics/decision_ledger.py`) is an
**append-only hash-chain** of CloudEvents envelopes there is no
`fact_decision` table *inside* the ledger DB; facts live in the
separate collector cold store (`core/metrics/collector.py`,
`nova_metrics.db`). The ledger is never UPDATEd in place (that would
break the SHA-256 chain see `verify_chain()`).
* Therefore the backfill does TWO things:
1. Appends a new audit event `nova.outcome.backfilled` to the
ledger (preserves the hash chain; auditable via `replay_run`).
2. UPDATEs the `fact_decision` row in the cold store (the row is
keyed by `decision_id`; `outcome` + `backfilled_at` are
mutable they are facts, not chain events).
Idempotent + terminal:
* If `outcome` is already `succeeded`/`failed` (i.e. not `pending`),
the call is a no-op and returns `{"status": "already_backfilled",
"existing_outcome": <current>}`. A terminal outcome is NEVER
overwritten (defense against double-backfill and against flipping a
`succeeded` run to `failed` retroactively or vice versa).
* The same `outcome` value is re-asserted harmlessly (still a no-op).
REQ-317: `outcome` {"succeeded", "failed"} only `pending` is the
initial state and may not be written by the backfill (it would undo the
transition). An invalid value raises `ValueError`.
Future milestones may add `'policy'` to `escalation_reason` (REQ-318);
this module is scoped to outcome only.
"""
import datetime
import json
import os
import sqlite3
import sys
from pathlib import Path
from typing import Optional, Dict, Any
sys.path.insert(0, os.path.dirname(os.path.dirname(os.path.abspath(__file__))))
from core.metrics.event_envelope import make_event, append_event
from core.metrics.decision_ledger import append as ledger_append, _LEDGER_PATH
# The collector cold store path is mirrored here so the backfill can be
# invoked without importing the collector (avoids a circular import:
# the collector calls into backfill at run.completed/run.failed time).
_METRICS_DIR = os.path.join(
os.path.dirname(os.path.dirname(os.path.dirname(os.path.abspath(__file__)))),
"metrics",
)
_STORE_PATH = os.path.join(_METRICS_DIR, "nova_metrics.db")
_VALID_OUTCOMES = {"succeeded", "failed"}
_PENDING = "pending"
def _iso8601_now():
return datetime.datetime.now(datetime.timezone.utc).strftime("%Y-%m-%dT%H:%M:%SZ")
def _resolve_store_path(store_path: Optional[str | Path]) -> str:
if store_path is None:
return _STORE_PATH
return str(store_path)
def _resolve_ledger_path(ledger_path: Optional[str | Path]) -> str:
if ledger_path is None:
return _LEDGER_PATH
return str(ledger_path)
def _get_fact_decision(decision_id: str, store_path: str) -> Optional[Dict[str, Any]]:
"""Read the fact_decision row for decision_id (or None)."""
if not os.path.isfile(store_path):
return None
conn = sqlite3.connect(store_path)
conn.row_factory = sqlite3.Row
row = conn.execute(
"SELECT decision_id, run_id, chosen_action, confidence, alternatives, "
"human_override, outcome, event_time FROM fact_decision WHERE decision_id = ?",
(decision_id,),
).fetchone()
conn.close()
if row is None:
return None
return dict(row)
def backfill(
decision_id: str,
outcome: str,
ledger_path: Optional[str | Path] = None,
store_path: Optional[str | Path] = None,
) -> Dict[str, Any]:
"""Transition fact_decision.outcome from `pending` to `outcome`.
Args:
decision_id: the decision id (== run_id for v1.26).
outcome: the terminal outcome; must be in {"succeeded", "failed"}.
ledger_path: optional override for the Decision Ledger SQLite DB.
store_path: optional override for the collector cold store SQLite DB.
Returns:
A dict describing the result:
* success: {"status": "backfilled", "decision_id", "previous_outcome",
"new_outcome", "backfilled_at"}
* no-op: {"status": "already_backfilled", "decision_id",
"existing_outcome", "backfilled_at"}
Raises:
ValueError: if `outcome` is not in {"succeeded", "failed"}.
KeyError: if `decision_id` is not present in fact_decision.
"""
if outcome not in _VALID_OUTCOMES:
raise ValueError(
f"outcome must be one of {sorted(_VALID_OUTCOMES)}, got: {outcome!r}"
)
sp = _resolve_store_path(store_path)
lp = _resolve_ledger_path(ledger_path)
existing = _get_fact_decision(decision_id, sp)
if existing is None:
raise KeyError(decision_id)
current_outcome = existing.get("outcome") or _PENDING
backfilled_at = _iso8601_now()
if current_outcome != _PENDING:
# Idempotent + terminal: do NOT overwrite a non-pending outcome.
return {
"status": "already_backfilled",
"decision_id": decision_id,
"existing_outcome": current_outcome,
"backfilled_at": backfilled_at,
}
run_id = existing.get("run_id") or decision_id
# 1. UPDATE the fact_decision row in the cold store (mutable fact).
conn = sqlite3.connect(sp)
# Add backfilled_at column idempotently (schema was added in v1.26 P3 W2;
# older cold stores created by P2 lack it — ALTER TABLE is a no-op if
# the column already exists).
try:
conn.execute("ALTER TABLE fact_decision ADD COLUMN backfilled_at TEXT")
except sqlite3.OperationalError:
pass # column already exists
conn.execute(
"UPDATE fact_decision SET outcome = ?, backfilled_at = ? WHERE decision_id = ?",
(outcome, backfilled_at, decision_id),
)
conn.commit()
conn.close()
# 2. Append an audit event to the append-only Decision Ledger (preserves
# the hash chain — the ledger is never UPDATEd in place).
try:
backfill_data = {
"decision_id": decision_id,
"previous_outcome": _PENDING,
"new_outcome": outcome,
"backfilled_at": backfilled_at,
}
event = make_event(
"nova.outcome.backfilled",
run_id,
existing.get("environment", ""),
backfill_data,
contract_id=existing.get("contract_id", ""),
actor_type="outcome-backfill",
actor_id="outcome_backfill",
)
append_event(event)
ledger_append(event, db_path=lp)
except Exception:
# Metrics emission must never break the backfill — the cold store
# UPDATE is the source of truth for the denominator; the ledger
# event is audit chrome.
pass
return {
"status": "backfilled",
"decision_id": decision_id,
"previous_outcome": _PENDING,
"new_outcome": outcome,
"backfilled_at": backfilled_at,
}
if __name__ == "__main__":
if len(sys.argv) < 3:
print("usage: outcome_backfill.py <decision_id> <succeeded|failed>", file=sys.stderr)
sys.exit(2)
_did = sys.argv[1]
_out = sys.argv[2]
try:
_r = backfill(_did, _out)
print(json.dumps(_r, indent=2))
except (ValueError, KeyError) as exc:
print(f"error: {exc}", file=sys.stderr)
sys.exit(1)
+36 -1
View File
@@ -27,6 +27,27 @@ def _iso8601_now():
return datetime.datetime.now(datetime.timezone.utc).strftime("%Y-%m-%dT%H:%M:%SZ") return datetime.datetime.now(datetime.timezone.utc).strftime("%Y-%m-%dT%H:%M:%SZ")
def _backfill_outcome(decision_id, outcome):
"""Transition fact_decision.outcome pending -> outcome (REQ-317).
Best-effort: logs a warning and skips if decision_id is missing or the
backfill raises. Never raises the run is already completing/failing
and the manifest write is the source of truth for the run outcome.
"""
if not decision_id:
# A run that failed before ai.decision.made was emitted has no
# decision to backfill (e.g. a schema-validation failure). Skip
# silently rather than pollute stderr on every clean run.
return None
try:
from core.metrics import outcome_backfill
return outcome_backfill.backfill(decision_id, outcome)
except Exception as exc: # pragma: no cover - defensive
print(f"[run_manifest] outcome backfill skipped for {decision_id}: {exc}",
file=sys.stderr)
return None
def _run_id(): def _run_id():
return f"run-{int(time.time())}-{uuid.uuid4().hex[:8]}" return f"run-{int(time.time())}-{uuid.uuid4().hex[:8]}"
@@ -44,7 +65,7 @@ def start_run(contract_id, environment, stages=None):
return run_id return run_id
def complete_run(run_id, contract_id, environment, stages, exit_code, confidence=None, hitl=None, policy=None, cost_estimate_usd=None, decision_id=None): def complete_run(run_id, contract_id, environment, stages, exit_code, confidence=None, hitl=None, policy=None, cost_estimate_usd=None, decision_id=None, escalation_reason=None):
"""Emit nova.run.completed + write the per-run manifest JSON. """Emit nova.run.completed + write the per-run manifest JSON.
Args: Args:
@@ -58,6 +79,10 @@ def complete_run(run_id, contract_id, environment, stages, exit_code, confidence
policy: optional {passed, failed, skipped} policy: optional {passed, failed, skipped}
cost_estimate_usd: optional float cost_estimate_usd: optional float
decision_id: optional string (links to the Decision Ledger) decision_id: optional string (links to the Decision Ledger)
escalation_reason: optional string (REQ-318) "confidence" when
the ai.decision.made band was block; absent/None otherwise.
Persisted into the manifest so the collector can write it
into fact_run (Post-Pilot Human Escalation Frequency denom).
""" """
started_at = stages[0].get("started_at", _iso8601_now()) if stages else _iso8601_now() started_at = stages[0].get("started_at", _iso8601_now()) if stages else _iso8601_now()
completed_at = _iso8601_now() completed_at = _iso8601_now()
@@ -83,6 +108,8 @@ def complete_run(run_id, contract_id, environment, stages, exit_code, confidence
manifest["cost_estimate_usd"] = cost_estimate_usd manifest["cost_estimate_usd"] = cost_estimate_usd
if decision_id: if decision_id:
manifest["decision_id"] = decision_id manifest["decision_id"] = decision_id
if escalation_reason:
manifest["escalation_reason"] = escalation_reason
os.makedirs(_RUNS_DIR, exist_ok=True) os.makedirs(_RUNS_DIR, exist_ok=True)
manifest_path = os.path.join(_RUNS_DIR, f"{run_id}.json") manifest_path = os.path.join(_RUNS_DIR, f"{run_id}.json")
@@ -92,6 +119,14 @@ def complete_run(run_id, contract_id, environment, stages, exit_code, confidence
event_type = "nova.run.completed" if exit_code == 0 else "nova.run.failed" event_type = "nova.run.completed" if exit_code == 0 else "nova.run.failed"
emit(event_type, run_id, environment, manifest, contract_id=contract_id) emit(event_type, run_id, environment, manifest, contract_id=contract_id)
# REQ-317: backfill fact_decision.outcome pending -> succeeded/failed
# after the run completes. The decision_id links the run to the
# Decision Ledger entry written by ai.decision.made. Best-effort: a
# run that failed before ai.decision.made was emitted has no
# decision_id and the backfill is a no-op (the run outcome is still
# captured in the manifest above).
backfill_result = _backfill_outcome(decision_id, outcome)
return manifest return manifest
+99 -4
View File
@@ -601,16 +601,17 @@ def _check_cap_024_deck_structure() -> Tuple[Status, str]:
""" """
import os import os
deck_path = os.path.join(os.path.dirname(os.path.dirname(os.path.abspath(__file__))), deck_path = os.path.join(os.path.dirname(os.path.dirname(os.path.abspath(__file__))),
"docs", "presentations", "nova-autonomous-cloud-delivery.md") "docs", "presentations", "nova-autonomous-cloud-delivery-marp.md")
if not os.path.isfile(deck_path): if not os.path.isfile(deck_path):
return "Skipped", "unified deck not found" return "Skipped", "unified deck not found"
with open(deck_path) as f: with open(deck_path) as f:
content = f.read() content = f.read()
slide_count = content.count("## Slide ") slide_count = content.count("## Slide ")
if slide_count < 18 or slide_count > 19: if slide_count < 18 or slide_count > 20:
return "Broken", f"deck has {slide_count} main slides (expected 18-19)" return "Broken", f"deck has {slide_count} main slides (expected 18-20)"
has_recap = "Recap + Ask" in content has_recap = "Recap + Ask" in content
has_benefit = content.count("Benefit:") >= 10 benefit_count = content.count("Benefit:") + content.count('class="benefit"')
has_benefit = benefit_count >= 10
if not (has_recap and has_benefit): if not (has_recap and has_benefit):
missing = [] missing = []
if not has_recap: missing.append("recap+ask") if not has_recap: missing.append("recap+ask")
@@ -619,6 +620,98 @@ def _check_cap_024_deck_structure() -> Tuple[Status, str]:
return "Verified", f"deck has {slide_count} slides, recap+ask present, per-slide benefits present" return "Verified", f"deck has {slide_count} slides, recap+ask present, per-slide benefits present"
def _check_cap_025_live_pilot_apply() -> Tuple[Status, str]:
"""CAP-025 (REQ-316): live-pilot-apply pipeline readiness — structural
check that the pilot-apply end-to-end pipeline is wired (NOT a live
apply; the live apply lands in P4).
The pilot-apply round-trip is:
contract resolve -> adapter compile -> terraform plan -> policy scan
-> confidence signal -> terraform apply -> outbox write
For P3 this is a LOCAL-tier structural-readiness check: the scripts
exist + are wired, the core pipeline modules import, the pilot env is
bound to a real account (D-203), the DynamoDB L1 primitive is
registered (REQ-322), the pilot policies are authored (REQ-315/320),
and the outcome-backfill module exists (REQ-317). The live apply
against AWS is P4's live-verify (D-093 / G-111 steady state aside).
"""
import json
# 1. scripts/run_platform.sh exists + contains the pipeline step markers.
run_platform = ROOT / "scripts" / "run_platform.sh"
if not run_platform.is_file():
return "Broken", "scripts/run_platform.sh missing (pilot-apply pipeline driver)"
script_text = run_platform.read_text()
# Step markers mirrored from the script's own comments + Step headers.
required_markers = [
"resolve contract", # Step 2: contract_resolver
"adapter compiles stack", # Step 3: terraform adapter
"terraform init", # Step 4: terraform plan
"terraform plan", # Step 4: terraform plan
"policy scan", # Step 5: runtime policy scan (Wiz/Checkov)
"confidence signal", # Step 7: confidence_signal compute
"terraform apply", # Step 5: terraform apply (--apply mode)
"outbox", # outbox write (Step 8)
]
missing_markers = [m for m in required_markers if m not in script_text]
if missing_markers:
return "Broken", f"run_platform.sh missing step markers: {missing_markers}"
# 2. core pipeline modules importable.
for mod_name in (
"core.contract_resolver",
"adapters.terraform.adapter",
"core.confidence_signal",
"core.outbox_writer",
):
try:
importlib.import_module(mod_name)
except Exception as exc: # noqa: BLE001
return "Broken", f"pipeline module not importable: {mod_name} ({type(exc).__name__}: {exc})"[:200]
# 3. dev env bound to the real pilot account (D-203).
dev_env_path = ROOT / "core" / "environments" / "dev.json"
if not dev_env_path.is_file():
return "Broken", "core/environments/dev.json missing"
try:
dev_env = json.loads(dev_env_path.read_text())
except Exception as exc: # noqa: BLE001
return "Broken", f"dev.json parse failed: {exc}"[:200]
account_id = dev_env.get("account_id")
if account_id != "581513795199":
return "Broken", f"dev env not bound to real account (D-203): account_id={account_id!r}"
# 4. DynamoDB L1 primitive registered (REQ-322).
registry_path = ROOT / "modules" / "registry.json"
if not registry_path.is_file():
return "Broken", "modules/registry.json missing"
try:
registry = json.loads(registry_path.read_text())
except Exception as exc: # noqa: BLE001
return "Broken", f"registry.json parse failed: {exc}"[:200]
if "dynamodb" not in registry:
return "Broken", "dynamodb L1 primitive not registered (REQ-322)"
# 5. pilot policies authored (REQ-315/320).
pilot_policies = [
ROOT / "adapters" / "kyverno-json" / "policies" / "pilot-readiness" / "no-placeholder-account.json",
ROOT / "adapters" / "kyverno-json" / "policies" / "settlement-finality" / "all-matches-committed.json",
]
missing_policies = [str(p.relative_to(ROOT)) for p in pilot_policies if not p.is_file()]
if missing_policies:
return "Broken", f"pilot policies not authored (REQ-315/320): {missing_policies}"
# 6. outcome-backfill module exists (REQ-317).
outcome_backfill = ROOT / "core" / "metrics" / "outcome_backfill.py"
if not outcome_backfill.is_file():
return "Broken", "outcome backfill not implemented (REQ-317)"
return ("Verified",
"pilot-apply pipeline structurally ready "
"(contract->adapter->plan->policy->confidence->apply->outbox)")
# Registry: ordered, each entry is (capability_id, name, tier, check_fn). # Registry: ordered, each entry is (capability_id, name, tier, check_fn).
# Phase 52 seeds this with 10 local-tier checks; Phase 54 expands it to # Phase 52 seeds this with 10 local-tier checks; Phase 54 expands it to
# cover every v1.1->v1.8 advertised capability and adds the live-AWS tier # cover every v1.1->v1.8 advertised capability and adds the live-AWS tier
@@ -672,6 +765,8 @@ CAPABILITY_REGISTRY: List[Tuple[str, str, str, Callable[[], Tuple[Status, str]]]
_check_cap_023_metrics_collector), _check_cap_023_metrics_collector),
("CAP-024", "unified deck structure (slide count, x3, per-slide benefits)", "local", ("CAP-024", "unified deck structure (slide count, x3, per-slide benefits)", "local",
_check_cap_024_deck_structure), _check_cap_024_deck_structure),
("CAP-025", "live-pilot-apply pipeline readiness (contract->apply->outbox)", "local",
_check_cap_025_live_pilot_apply),
] ]
+37 -3
View File
@@ -19,7 +19,7 @@ numbers. Every metric either has a real source or is explicitly deferred.
### Touchless Resolution Rate ### Touchless Resolution Rate
- **Target:** ≥ 99% across production estates (Post-Pilot) - **Target:** ≥ 99% across production estates (Post-Pilot)
- **Status:** partial (pipeline grounded; denominator = 0 today) - **Status:** partial (pipeline grounded; denominator = 1 run post-pilot)
- **Formula:** runs completing without *operational* HITL block ÷ total runs - **Formula:** runs completing without *operational* HITL block ÷ total runs
(attestation gates excluded — they're designed controls, not escalations) (attestation gates excluded — they're designed controls, not escalations)
- **Source:** `metrics/nova_metrics.db` `fact_run` (hitl_block column) - **Source:** `metrics/nova_metrics.db` `fact_run` (hitl_block column)
@@ -27,20 +27,54 @@ numbers. Every metric either has a real source or is explicitly deferred.
### Human Escalation Frequency ### Human Escalation Frequency
- **Target:** < 0.1% of platform actions (Post-Pilot) - **Target:** < 0.1% of platform actions (Post-Pilot)
- **Status:** partial (pipeline grounded; denominator = 0 today) - **Status:** partial (pipeline grounded; denominator = 1 run post-pilot, 0 escalations)
- **Formula:** operational HITL blocks ÷ total runs (attestation sign-offs - **Formula:** operational HITL blocks ÷ total runs (attestation sign-offs
excluded) excluded)
- **Source:** `metrics/nova_metrics.db` `fact_run` (hitl_block column) - **Source:** `metrics/nova_metrics.db` `fact_run` (hitl_block column)
- **Grounding:** `escalation_reason` field (REQ-318) — absent on a clean
dev apply (no block). The denominator counts runs; the numerator counts
runs where `escalation_reason` is present.
- **Definition-of-success:** `docs/metrics/human_escalation_frequency.md` - **Definition-of-success:** `docs/metrics/human_escalation_frequency.md`
### AI Decision Accuracy ### AI Decision Accuracy
- **Target:** ≥ 99.5% (no rollback, no follow-up incident within 5 min) - **Target:** ≥ 99.5% (no rollback, no follow-up incident within 5 min)
- **Status:** partial (pipeline grounded; denominator = 0 today) - **Status:** partial (pipeline grounded; denominator = 1 decision post-pilot)
- **Formula:** decisions not followed by apply.failed/incident within 5min - **Formula:** decisions not followed by apply.failed/incident within 5min
÷ total decisions ÷ total decisions
- **Source:** `metrics/nova_metrics.db` `fact_decision` (outcome column) - **Source:** `metrics/nova_metrics.db` `fact_decision` (outcome column)
- **Grounding:** `fact_decision.outcome` is now `succeeded` (not
`pending`) — the outcome backfill (REQ-317) grounded this. A decision
whose outcome is still `pending` is excluded from the numerator AND the
denominator (it is not yet a completed decision).
- **Definition-of-success:** `docs/metrics/ai_decision_accuracy.md` - **Definition-of-success:** `docs/metrics/ai_decision_accuracy.md`
#### Post-Pilot Activation (v1.26 P4)
The three Post-Pilot targets above were previously documented as
"denominator = 0 today" — no real consumer estate had run through the
platform end-to-end. The v1.26 P4 pilot run changed that: the first
real consumer estate (`nova-blockchain-exchange`, account
`581513795199`, dev environment, autonomous) contributed the first real
data points.
- **Run id:** `blkex-pilot-apply-v0.2` (2026-08-19)
- **AI Decision Accuracy:** 1 decision (`blkex-pilot-apply-v0.2`),
outcome `pending → succeeded` (REQ-317 backfill). Numerator = 1
(no apply.failed, no incident), denominator = 1. Future runs
accumulate into this denominator.
- **Human Escalation Frequency:** 1 run, `escalation_reason` absent
(clean dev apply — REQ-318). Numerator = 0 escalations, denominator
= 1.
- **Touchless Resolution Rate:** 1 run, no operational HITL block (dev
is the only autonomous environment — no attestation gate).
Numerator = 1, denominator = 1.
The denominators are now non-zero. Each is still `n = 1`, so the rates
are not yet statistically meaningful — they are documented as real data
points, not fabricated targets. See `.ciagent/P4-PILOT-RUN-EVIDENCE.md`
for the full evidence stream (confidence 0.800 pass, Decision Ledger
hash chain valid).
### MTTD / MTTR (platform-run) ### MTTD / MTTR (platform-run)
- **Target:** < 60 seconds (p95) - **Target:** < 60 seconds (p95)
- **Status:** grounded (platform-run MTTR) - **Status:** grounded (platform-run MTTR)
+1
View File
@@ -36,6 +36,7 @@ resources it creates.
| `rds` | `aws_db_instance` — Relational database (PostgreSQL, MySQL, etc.) with multi-engine support | [README](l1/rds/README.md) | | `rds` | `aws_db_instance` — Relational database (PostgreSQL, MySQL, etc.) with multi-engine support | [README](l1/rds/README.md) |
| `kms-key` | `aws_kms_key` — Customer-managed KMS key with rotation enabled (per-stack CMK) | [README](l1/kms-key/README.md) | | `kms-key` | `aws_kms_key` — Customer-managed KMS key with rotation enabled (per-stack CMK) | [README](l1/kms-key/README.md) |
| `uptime` | `aws_ecs_service` — Uptime-kuma monitoring on ECS Fargate with alert channels | [README](l1/uptime/README.md) | | `uptime` | `aws_ecs_service` — Uptime-kuma monitoring on ECS Fargate with alert channels | [README](l1/uptime/README.md) |
| `dynamodb` | `aws_dynamodb_table` — DynamoDB table with encryption + PITR (v1.8 NFR defaults) | [README](l1/dynamodb/README.md) |
## Modules ## Modules
+38
View File
@@ -0,0 +1,38 @@
# DynamoDB L1 Primitive
> Stack type: `aws:dynamodb:table` → Terraform `aws_dynamodb_table`
## Description
A DynamoDB table primitive with encryption + point-in-time recovery
enabled by default (per v1.8 NFR defaults). Supports a partition key
(required) + optional sort key. Default billing mode is
`PAY_PER_REQUEST` (on-demand).
## Inputs
| Name | Type | Required | Default | Description |
|---|---|---|---|---|
| `table_name` | string | yes | — | Globally-unique table name |
| `region` | string | yes | — | AWS region |
| `pk` | string | yes | — | Partition key attribute name |
| `sk` | string | no | `""` | Sort key attribute name |
| `billing_mode` | string | no | `PAY_PER_REQUEST` | Billing mode |
| `enabled` | boolean | no | `true` | Feature flag |
## Outputs
| Name | Type | Description |
|---|---|---|
| `table_arn` | arn | The table ARN |
| `table_name` | string | The table name |
## NFRs
- **Encryption:** SSE-KMS enabled by default.
- **Point-in-time recovery:** Enabled by default.
- **Deletion protection:** `prevent_destroy = true` (Terraform lifecycle).
## Examples
See `examples/simple.yaml`.
+12
View File
@@ -0,0 +1,12 @@
environment: dev
id: blkex
name: blockchain-exchange
infrastructure:
dynamodb:
version: "1.0.0"
inputs:
table_name: nova-blkex-ledger-dev
region: us-east-1
pk: block_index
sk: txn_id
billing_mode: PAY_PER_REQUEST
+4
View File
@@ -0,0 +1,4 @@
table_name: nova-simple-ledger
region: us-east-1
pk: block_index
billing_mode: PAY_PER_REQUEST
+10
View File
@@ -0,0 +1,10 @@
{
"module": "dynamodb",
"version": "1.0.0",
"inputs": {
"table_name": "nova-blockchain-ledger",
"region": "us-east-1",
"pk": "block_index",
"billing_mode": "PAY_PER_REQUEST"
}
}
+66
View File
@@ -0,0 +1,66 @@
{
"name": "dynamodb",
"version": "1.0.0",
"kind": "l1",
"type": "aws:dynamodb:table",
"description": "DynamoDB table primitive (engine-agnostic stack type aws:dynamodb:table; the Terraform adapter translates to aws_dynamodb_table). Encryption + PITR enabled per v1.8 NFR defaults.",
"inputs": {
"table_name": {
"type": "string",
"description": "Globally-unique DynamoDB table name.",
"required": true
},
"region": {
"type": "string",
"description": "AWS region the table is created in.",
"required": true
},
"pk": {
"type": "string",
"description": "Partition key attribute name.",
"required": true
},
"sk": {
"type": "string",
"description": "Sort key attribute name (optional).",
"required": false
},
"billing_mode": {
"type": "string",
"default": "PAY_PER_REQUEST",
"description": "Billing mode: PAY_PER_REQUEST or PROVISIONED."
},
"enabled": {
"type": "boolean",
"default": true,
"description": "Feature flag: enable/disable this module."
}
},
"outputs": {
"table_arn": {
"type": "arn",
"description": "The DynamoDB table ARN."
},
"table_name": {
"type": "string",
"description": "The table name (echoes the input)."
}
},
"nfrs": {
"encryption_enabled": {
"type": "boolean",
"description": "Enable server-side encryption (KMS).",
"default": true
},
"point_in_time_recovery": {
"type": "boolean",
"description": "Enable point-in-time recovery.",
"default": true
},
"deletion_protection": {
"type": "boolean",
"description": "Prevent resource destruction via Terraform lifecycle prevent_destroy.",
"default": true
}
}
}
+74
View File
@@ -0,0 +1,74 @@
resource "aws_dynamodb_table" "this" {
count = var.enabled ? 1 : 0
name = var.table_name
billing_mode = var.billing_mode
hash_key = var.pk
range_key = var.sk != "" ? var.sk : null
attribute {
name = var.pk
type = "S"
}
dynamic "attribute" {
for_each = var.sk != "" ? [var.sk] : []
content {
name = attribute.value
type = "S"
}
}
point_in_time_recovery {
enabled = true
}
server_side_encryption {
enabled = true
}
tags = {
"nova:managed-by" = "platform"
"nova:module" = "dynamodb"
}
lifecycle {
prevent_destroy = true
}
}
variable "table_name" {
type = string
}
variable "region" {
type = string
default = "us-east-1"
}
variable "pk" {
type = string
}
variable "sk" {
type = string
default = ""
}
variable "billing_mode" {
type = string
default = "PAY_PER_REQUEST"
}
variable "enabled" {
type = bool
default = true
}
output "table_arn" {
value = var.enabled ? aws_dynamodb_table.this[0].arn : ""
}
output "table_name" {
value = var.enabled ? aws_dynamodb_table.this[0].name : ""
}
+13 -1
View File
@@ -32,6 +32,16 @@
"description": "Environment variables as a JSON map string (optional).", "description": "Environment variables as a JSON map string (optional).",
"required": false "required": false
}, },
"execution_role_arn": {
"type": "arn",
"description": "IAM execution role ARN for the task (ECR pull + CW logs). Ref to iam-role.",
"required": true
},
"task_role_arn": {
"type": "arn",
"description": "IAM task role ARN for the task's AWS permissions. Ref to iam-role.",
"required": false
},
"cluster_arn": { "cluster_arn": {
"type": "arn", "type": "arn",
"description": "ECS cluster ARN (ref to ecs-cluster).", "description": "ECS cluster ARN (ref to ecs-cluster).",
@@ -118,7 +128,9 @@
"cpu", "cpu",
"memory", "memory",
"env", "env",
"family" "family",
"execution_role_arn",
"task_role_arn"
], ],
"outputs": [ "outputs": [
"task_def_arn" "task_def_arn"
+4 -2
View File
@@ -1,15 +1,17 @@
resource "aws_ecs_task_definition" "this" { resource "aws_ecs_task_definition" "this" {
count = var.enabled ? 1 : 0 count = var.enabled ? 1 : 0
family = var.family family = var.family
cpu = tostring(var.cpu) cpu = tostring(var.cpu)
memory = tostring(var.memory) memory = tostring(var.memory)
requires_compatibilities = local.requires_compatibilities requires_compatibilities = local.requires_compatibilities
network_mode = local.network_mode network_mode = local.network_mode
container_definitions = local.container_definitions container_definitions = local.container_definitions
execution_role_arn = var.execution_role_arn
task_role_arn = var.task_role_arn != "" ? var.task_role_arn : null
} }
resource "aws_ecs_service" "this" { resource "aws_ecs_service" "this" {
count = var.enabled ? 1 : 0 count = var.enabled ? 1 : 0
name = "nova-microservice" name = "nova-microservice"
cluster = var.cluster_arn cluster = var.cluster_arn
task_definition = aws_ecs_task_definition.this[0].arn task_definition = aws_ecs_task_definition.this[0].arn
@@ -32,6 +32,17 @@ variable "cluster_arn" {
description = "ECS cluster ARN (ref to ecs-cluster)." description = "ECS cluster ARN (ref to ecs-cluster)."
} }
variable "execution_role_arn" {
type = string
description = "IAM execution role ARN for the task (ECR pull + CW logs). Ref to iam-role."
}
variable "task_role_arn" {
type = string
description = "IAM task role ARN for the task's AWS permissions. Ref to iam-role. Optional; falls back to execution role when empty."
default = ""
}
variable "subnets" { variable "subnets" {
type = string type = string
description = "Comma-separated subnet ids (ref to vpc)." description = "Comma-separated subnet ids (ref to vpc)."
+3
View File
@@ -27,8 +27,11 @@
{"from": "platform_vpc.outputs.subnet_ids", "to": "alb.inputs.subnets"}, {"from": "platform_vpc.outputs.subnet_ids", "to": "alb.inputs.subnets"},
{"from": "platform_vpc.outputs.subnet_ids", "to": "service.inputs.subnets"}, {"from": "platform_vpc.outputs.subnet_ids", "to": "service.inputs.subnets"},
{"from": "platform_vpc.outputs.vpc_id", "to": "alb.inputs.vpc_id"}, {"from": "platform_vpc.outputs.vpc_id", "to": "alb.inputs.vpc_id"},
{"from": "platform_vpc.outputs.ecs_security_group_id", "to": "alb.inputs.security_group"},
{"from": "platform_vpc.outputs.ecs_security_group_id", "to": "service.inputs.security_group"}, {"from": "platform_vpc.outputs.ecs_security_group_id", "to": "service.inputs.security_group"},
{"from": "cluster.outputs.cluster_arn", "to": "service.inputs.cluster_arn"}, {"from": "cluster.outputs.cluster_arn", "to": "service.inputs.cluster_arn"},
{"from": "roles.outputs.role_arn", "to": "service.inputs.execution_role_arn"},
{"from": "roles.outputs.role_arn", "to": "service.inputs.task_role_arn"},
{"from": "ecr.outputs.repository_url", "to": "service.inputs.image"}, {"from": "ecr.outputs.repository_url", "to": "service.inputs.image"},
{"from": "alb.outputs.target_group_arn", "to": "service.inputs.lb_target_group_arn"}, {"from": "alb.outputs.target_group_arn", "to": "service.inputs.lb_target_group_arn"},
{"from": "contract.inputs.region", "to": "kms.inputs.region"}, {"from": "contract.inputs.region", "to": "kms.inputs.region"},
+9
View File
@@ -122,5 +122,14 @@
"deprecated": false, "deprecated": false,
"kind": "l2" "kind": "l2"
} }
},
"dynamodb": {
"1.0.0": {
"interface": "modules/l1/dynamodb/interface.json",
"terraform_dir": "modules/l1/dynamodb/terraform",
"published_at": "2026-08-14T19:26:18Z",
"deprecated": false,
"kind": "l1"
}
} }
} }
+41 -11
View File
@@ -1,9 +1,18 @@
#!/usr/bin/env bash #!/usr/bin/env bash
# scripts/install-kyverno-json.sh — install the kj CLI (v1.25, REQ-294) # scripts/install-kyverno-json.sh — install the kj CLI (v1.25, REQ-294;
# fixed v1.26 P3 W0.5).
# #
# Installs the kyverno-json CLI (`kj`) via `go install` (D-115). The # Installs the kyverno-json CLI via `go install` (D-115). The binary is a
# binary is a Go project — not a Python package. Cached via the Go # Go project — not a Python package. Cached via the Go module cache.
# module cache. #
# v1.26 P3 W0.5 fix: the v1.25 script ran
# go install github.com/kyverno/kyverno-json/cmd/kj@latest
# but the `cmd/kj` path does NOT exist in v0.0.3 — the upstream
# `go install github.com/kyverno/kyverno-json@latest` produces a binary
# named `kyverno-json`, NOT `kj`. The v1.25 invocation failed silently
# (the test suite masked it via `pytest.skip("kj not installed")`). This
# script now installs the real module and symlinks `kyverno-json` → `kj`
# so the engine's `which kj` check passes.
# #
# Usage: bash scripts/install-kyverno-json.sh # Usage: bash scripts/install-kyverno-json.sh
# Exits 0 on success, 1 if Go is not installed, 2 if `kj version` fails. # Exits 0 on success, 1 if Go is not installed, 2 if `kj version` fails.
@@ -11,19 +20,40 @@ set -euo pipefail
if ! command -v go >/dev/null 2>&1; then if ! command -v go >/dev/null 2>&1; then
echo "ERROR: Go toolchain not found. Install Go (https://go.dev/dl/) first." >&2 echo "ERROR: Go toolchain not found. Install Go (https://go.dev/dl/) first." >&2
echo " kyverno-json is a Go binary — `go install` is the upstream-blessed path (D-115)." >&2 echo " kyverno-json is a Go binary — \`go install\` is the upstream-blessed path (D-115)." >&2
exit 1 exit 1
fi fi
echo "Installing kyverno-json CLI (kj) via go install..."
GOBIN="${GOBIN:-${HOME}/go/bin}" GOBIN="${GOBIN:-${HOME}/go/bin}"
go install github.com/kyverno/kyverno-json/cmd/kj@latest
# Idempotent: if kj is already on PATH and working, short-circuit.
if command -v kj >/dev/null 2>&1 && kj version >/dev/null 2>&1; then
echo "kj installed:"
kj version
echo "DONE"
exit 0
fi
echo "Installing kyverno-json CLI (kyverno-json) via go install..."
# The upstream module produces a binary named `kyverno-json` (NOT `kj`).
# The v1.25 `go install .../cmd/kj@latest` path does not exist in v0.0.3.
go install github.com/kyverno/kyverno-json@latest
# The binary is named `kyverno-json`, not `kj`. Symlink it as `kj` for
# the engine's `which kj` check (kyverno_json_engine.py::_which_kj).
if [ -x "${GOBIN}/kyverno-json" ] && ! command -v kj >/dev/null 2>&1; then
ln -sf "${GOBIN}/kyverno-json" "${GOBIN}/kj"
# If GOBIN not on PATH, try /usr/local/bin so `which kj` resolves.
if ! command -v kj >/dev/null 2>&1; then
ln -sf "${GOBIN}/kyverno-json" /usr/local/bin/kj 2>/dev/null || true
fi
fi
if ! command -v kj >/dev/null 2>&1; then if ! command -v kj >/dev/null 2>&1; then
if [ -x "${GOBIN}/kj" ]; then if [ -x "${GOBIN}/kyverno-json" ]; then
echo "kj installed to ${GOBIN}/kj (not on PATH)" echo "kyverno-json installed to ${GOBIN}/kyverno-json but 'kj' is not on PATH." >&2
echo "add ${GOBIN} to PATH or symlink: ln -s ${GOBIN}/kj /usr/local/bin/kj" echo "add ${GOBIN} to PATH or symlink: ln -sf ${GOBIN}/kyverno-json /usr/local/bin/kj" >&2
"${GOBIN}/kj" version "${GOBIN}/kyverno-json" version
exit 0 exit 0
fi fi
echo "ERROR: kj not found on PATH after go install (checked ${GOBIN})." >&2 echo "ERROR: kj not found on PATH after go install (checked ${GOBIN})." >&2
+107 -25
View File
@@ -5,11 +5,20 @@
# fallback) from the env to: # fallback) from the env to:
# 1. List nova-spike-runner's access keys. # 1. List nova-spike-runner's access keys.
# 2. Create a new key. # 2. Create a new key.
# 3. Deactivate + delete the old key(s). # 3. Write the new key to gitignored .env.secrets (chmod 600).
# 4. Write the new key to gitignored .env.secrets (chmod 600). # 4. Upload the new key to the consumer's Actions secret store + verify
# 5. Optionally upload to Gitea secrets if NOVA_GITEA_TOKEN is set. # (GET) that it propagated (SPEC §5.9 idempotency).
# 5. Deactivate + delete the old key(s) ONLY after the upload is verified.
# If the upload/verify fails, the old key stays Active + the run exits
# non-zero (the consumer's deploy keeps a working credential).
# #
# Idempotent: re-running always ends with exactly 1 active key for the user. # Env vars (forge coords): NOVA_FORGE_TOKEN / NOVA_FORGE_BASE_URL /
# NOVA_FORGE_OWNER / NOVA_CONSUMER_REPO (the scheduled workflow passes these
# forge-agnostic names, REQ-230). NOVA_GITEA_* are a backward-compat
# fallback for ad-hoc local runs.
#
# Idempotent: re-running always ends with exactly 1 active key for the user
# (once the new key has propagated to the secret store).
# Does NOT rotate the bootstrap root key (D-034 closure = manual user step). # Does NOT rotate the bootstrap root key (D-034 closure = manual user step).
# #
# Spike scope (D-039): the spike user key is per-run-rotated; real OIDC is # Spike scope (D-039): the spike user key is per-run-rotated; real OIDC is
@@ -63,14 +72,9 @@ new_id = new["AccessKeyId"]
new_secret = new["SecretAccessKey"] new_secret = new["SecretAccessKey"]
print(f"iam: created new key {new_id} for {user}", file=sys.stderr) print(f"iam: created new key {new_id} for {user}", file=sys.stderr)
# Deactivate + delete the old keys. # Deactivation of the old keys is deferred to AFTER the new key propagates
for k in active: # to the Gitea Actions secret store (SPEC §5.9 idempotency — see below).
old_id = k["AccessKeyId"] # Writing .env.secrets first keeps the local operator's working key current.
if old_id == new_id:
continue
iam.update_access_key(UserName=user, AccessKeyId=old_id, Status="Inactive")
iam.delete_access_key(UserName=user, AccessKeyId=old_id)
print(f"iam: deactivated+deleted old key {old_id}", file=sys.stderr)
# Write the new key to gitignored .env.secrets (chmod 600). # Write the new key to gitignored .env.secrets (chmod 600).
# Nova rebrand (P2): keys are NOVA_*; the ACDL_* legacy keys are the # Nova rebrand (P2): keys are NOVA_*; the ACDL_* legacy keys are the
@@ -82,28 +86,106 @@ with open(env_file, "w") as fh:
os.chmod(env_file, 0o600) os.chmod(env_file, 0o600)
print(f"rotated key written to {env_file} (chmod 600)", file=sys.stderr) print(f"rotated key written to {env_file} (chmod 600)", file=sys.stderr)
# Optionally upload to Gitea secrets. # Upload the new key to the consumer's Actions secret store BEFORE
# Dual-read token: NOVA_GITEA_TOKEN preferred, ACDL_GITEA_TOKEN fallback (G-106). # deactivating the old key (SPEC §5.9 — idempotency: the old key is
gitea_token = os.environ.get("NOVA_GITEA_TOKEN") # deactivated only after the new one propagates). If the upload or the
# post-upload verification fails, the old key is left Active so the
# consumer's deploy still has a working credential; the run exits non-zero
# so the scheduled workflow surfaces the failure (rather than silently
# stranding the consumer with a key that never reached the secret store).
#
# Forge + consumer coords come from env vars. The scheduled workflow passes
# forge-agnostic NOVA_FORGE_* names (REQ-230 — no forge hostnames in the
# synced workflow file); NOVA_GITEA_* are accepted as a backward-compat
# fallback for ad-hoc local runs. Defaults keep the legacy platform-repo
# target when nothing is set.
# Dual-read token: NOVA_FORGE_TOKEN preferred, NOVA_GITEA_TOKEN fallback (G-106).
gitea_token = os.environ.get("NOVA_FORGE_TOKEN") or os.environ.get("NOVA_GITEA_TOKEN")
gitea_base = (
os.environ.get("NOVA_FORGE_BASE_URL")
or os.environ.get("NOVA_GITEA_BASE_URL")
or "https://git.cloudinit.dev"
).rstrip("/")
gitea_owner = (
os.environ.get("NOVA_FORGE_OWNER")
or os.environ.get("NOVA_GITEA_OWNER")
or "continuous-intelligence"
)
gitea_repo = (
os.environ.get("NOVA_CONSUMER_REPO")
or os.environ.get("NOVA_GITEA_REPO")
or "acdl"
)
secrets_api = f"{gitea_base}/api/v1/repos/{gitea_owner}/{gitea_repo}/actions/secrets"
if gitea_token: if gitea_token:
import urllib.request import urllib.request
base = "https://git.cloudinit.dev/api/v1/repos/continuous-intelligence/acdl/actions/secrets" import urllib.error
for name, value in [("NOVA_AWS_ACCESS_KEY_ID", new_id), import time
("NOVA_AWS_SECRET_ACCESS_KEY", new_secret)]:
def _put_secret(name, value):
req = urllib.request.Request( req = urllib.request.Request(
f"{base}/{name}", f"{secrets_api}/{name}",
data=json.dumps({"value": value}).encode(), data=json.dumps({"value": value}).encode(),
method="PUT", method="PUT",
headers={"Authorization": f"token {gitea_token}", headers={"Authorization": f"token {gitea_token}",
"Content-Type": "application/json"}, "Content-Type": "application/json"},
) )
try: urllib.request.urlopen(req).read()
urllib.request.urlopen(req).read() print(f"gitea: secret {name} uploaded to {gitea_owner}/{gitea_repo}", file=sys.stderr)
print(f"gitea: secret {name} uploaded", file=sys.stderr)
except Exception as e: def _verify_secret(name):
print(f"gitea: secret {name} upload FAILED: {e}", file=sys.stderr) # Gitea does not return secret *values*; a 200 confirms the secret
# exists with the expected name. Retry briefly so eventual
# consistency on the secrets API settles (observed sub-second lag).
for attempt in range(5):
req = urllib.request.Request(
f"{secrets_api}/{name}",
method="GET",
headers={"Authorization": f"token {gitea_token}"},
)
try:
with urllib.request.urlopen(req) as resp:
if resp.status == 200:
print(f"gitea: secret {name} verified present", file=sys.stderr)
return True
except urllib.error.HTTPError as e:
if e.code == 404:
time.sleep(0.5)
continue
raise
return False
try:
_put_secret("NOVA_AWS_ACCESS_KEY_ID", new_id)
_put_secret("NOVA_AWS_SECRET_ACCESS_KEY", new_secret)
ok = _verify_secret("NOVA_AWS_ACCESS_KEY_ID") and \
_verify_secret("NOVA_AWS_SECRET_ACCESS_KEY")
if not ok:
raise RuntimeError("gitea secret verification failed (404 after PUT)")
except Exception as e:
# Upload/verify failed: leave the old key Active so the consumer's
# deploy still works. Surface non-zero so the schedule is noisy.
print(f"gitea: secret upload/verify FAILED ({e}); old key left Active", file=sys.stderr)
sys.exit(2)
else: else:
print("gitea: NOVA_GITEA_TOKEN not set; Gitea secret upload skipped (v1.2 hardening)", file=sys.stderr) print("gitea: NOVA_FORGE_TOKEN/NOVA_GITEA_TOKEN not set; secret upload skipped (v1.2 hardening)", file=sys.stderr)
# No forge target → the new key is already in .env.secrets, so the
# operator's local env works. The old key is deactivated below so the
# user ends with exactly 1 active key (D-039 local-rotation contract).
# Deactivate + delete the old keys. When a forge token was set, this runs
# ONLY after the new key propagated to the consumer's secret store (the
# sys.exit(2) above prevents reaching here on upload/verify failure). When
# no token was set, the new key is already in .env.secrets so deactivating
# is safe (D-039 local-rotation contract).
for k in active:
old_id = k["AccessKeyId"]
if old_id == new_id:
continue
iam.update_access_key(UserName=user, AccessKeyId=old_id, Status="Inactive")
iam.delete_access_key(UserName=user, AccessKeyId=old_id)
print(f"iam: deactivated+deleted old key {old_id} (after propagation)", file=sys.stderr)
print(f"OK: {user} now has exactly 1 active key: {new_id}") print(f"OK: {user} now has exactly 1 active key: {new_id}")
PY PY
+61 -8
View File
@@ -382,12 +382,22 @@ if [ -z "${AWS_ACCESS_KEY_ID:-}" ] || [ -z "${AWS_SECRET_ACCESS_KEY:-}" ]; then
[ -f "$ENV_FILE" ] || fail ".env.secrets missing (run scripts/rotate_spike_key.sh) or set AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY env vars" [ -f "$ENV_FILE" ] || fail ".env.secrets missing (run scripts/rotate_spike_key.sh) or set AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY env vars"
set -a set -a
. "$ENV_FILE" . "$ENV_FILE"
set +a set +a
# P5 (REQ-164): dual-read fallback removed — NOVA_* only. # P5 (REQ-164): dual-read fallback removed — NOVA_* only.
export AWS_ACCESS_KEY_ID="$NOVA_AWS_ACCESS_KEY_ID" # Copy the NOVA_* secrets to the canonical AWS_* env vars, then unset
export AWS_SECRET_ACCESS_KEY="$NOVA_AWS_SECRET_ACCESS_KEY" # the raw NOVA_AWS_* + the forge-token name so they do NOT linger in
export AWS_DEFAULT_REGION="$AWS_DEFAULT_REGION" # the shell env (SPEC §5.2 — the platform consumes NOVA_AWS_* as workflow
fi # secrets, not shell env; config.security.bash_allowlist.blocked_env_vars
# blocks NOVA_AWS_* from shell env — the v1.8 root-cause guard).
# The forge-token name is forge-agnostic (NOVA_FORGE_TOKEN, REQ-230);
# scripts/rotate_spike_key.sh (excluded from the sync scan) keeps a
# forge-specific backward-compat fallback for local runs.
export AWS_ACCESS_KEY_ID="$NOVA_AWS_ACCESS_KEY_ID"
export AWS_SECRET_ACCESS_KEY="$NOVA_AWS_SECRET_ACCESS_KEY"
# Region: prefer the .env.secrets AWS_DEFAULT_REGION; default us-east-1.
export AWS_DEFAULT_REGION="${AWS_DEFAULT_REGION:-us-east-1}"
unset NOVA_AWS_ACCESS_KEY_ID NOVA_AWS_SECRET_ACCESS_KEY NOVA_FORGE_TOKEN
fi
echo "=== Step 3c: Checkov on static code (fail-fast, before terraform plan) ===" echo "=== Step 3c: Checkov on static code (fail-fast, before terraform plan) ==="
# REQ-250 (v1.21): Checkov runs on the authored Terraform code BEFORE # REQ-250 (v1.21): Checkov runs on the authored Terraform code BEFORE
@@ -533,7 +543,7 @@ if command -v kj >/dev/null 2>&1; then
if [ -f "$TF_DIR/tfplan" ]; then if [ -f "$TF_DIR/tfplan" ]; then
terraform -chdir="$TF_DIR" show -json tfplan > "$WORK/tfshow.json" 2>/dev/null || true terraform -chdir="$TF_DIR" show -json tfplan > "$WORK/tfshow.json" 2>/dev/null || true
if [ -s "$WORK/tfshow.json" ]; then if [ -s "$WORK/tfshow.json" ]; then
python3 - <<'PY' > "$WORK/kj-pcr.json" 2>"$WORK/kj.err" || echo "[]" python3 - "$WORK/tfshow.json" "$CONTRACT_ID" <<'PY' > "$WORK/kj-pcr.json" 2>"$WORK/kj.err" || echo "[]"
import json, sys import json, sys
from pathlib import Path from pathlib import Path
sys.path.insert(0, ".") sys.path.insert(0, ".")
@@ -541,10 +551,11 @@ import importlib.util
_spec = importlib.util.spec_from_file_location("kj_engine", "adapters/kyverno-json/kyverno_json_engine.py") _spec = importlib.util.spec_from_file_location("kj_engine", "adapters/kyverno-json/kyverno_json_engine.py")
_mod = importlib.util.module_from_spec(_spec) _mod = importlib.util.module_from_spec(_spec)
_spec.loader.exec_module(_mod) _spec.loader.exec_module(_mod)
_payload_path, _contract_id = sys.argv[1], sys.argv[2]
eng = _mod.KyvernoJsonEngine() eng = _mod.KyvernoJsonEngine()
if not eng.is_configured(): if not eng.is_configured():
print("[]"); sys.exit(0) print("[]"); sys.exit(0)
out = eng.evaluate(json.load(open("$WORK/tfshow.json")), Path("adapters/kyverno-json/policies/plan-json"), "$CONTRACT_ID") out = eng.evaluate(json.load(open(_payload_path)), Path("adapters/kyverno-json/policies/plan-json"), _contract_id)
print(json.dumps(out)) print(json.dumps(out))
PY PY
if [ -s "$WORK/kj-pcr.json" ]; then if [ -s "$WORK/kj-pcr.json" ]; then
@@ -571,6 +582,48 @@ else
fi fi
echo "" echo ""
# ============================================================================
# Step 5c: kyverno-json meta-policies over the merged PCR list (v1.25, REQ-303)
# ============================================================================
# After Step 5b merges the Checkov/Wiz + kj plan-JSON PCRs into pcr.json, run
# the meta-policies (block-on-any-critical, tagging-rules-agree) over the
# merged list. The meta-policy PCRs are appended to pcr.json before the
# confidence signal runs. The confidence_signal.py PENALTY["critical"]: None
# hard-override stays as defense-in-depth behind this declarative rule
# (D-119). Skips gracefully when kj is absent (D-120).
if command -v kj >/dev/null 2>&1 && [ -s "$WORK/pcr.json" ]; then
echo "=== Step 5c: kyverno-json meta-policies over the merged PCR list ==="
python3 - "$WORK/pcr.json" "$CONTRACT_ID" <<'PY' > "$WORK/meta-pcr.json" 2>"$WORK/meta.err" || echo "[]"
import json, sys
from pathlib import Path
sys.path.insert(0, ".")
import importlib.util
_spec = importlib.util.spec_from_file_location("kj_engine", "adapters/kyverno-json/kyverno_json_engine.py")
_mod = importlib.util.module_from_spec(_spec)
_spec.loader.exec_module(_mod)
eng = _mod.KyvernoJsonEngine()
if not eng.is_configured():
print("[]"); sys.exit(0)
pcrs = json.load(open(sys.argv[1]))
out = eng.evaluate(pcrs, Path("adapters/kyverno-json/policies/meta"), sys.argv[2])
print(json.dumps(out))
PY
if [ -s "$WORK/meta-pcr.json" ]; then
python3 -c "
import json
merged = json.load(open('$WORK/pcr.json'))
meta = json.load(open('$WORK/meta-pcr.json'))
json.dump(merged + meta, open('$WORK/pcr.json', 'w'))
print(f'meta-policies: {len(meta)} meta-PCRs appended; total PCR list now {len(merged)+len(meta)}')
"
else
echo "kyverno-json meta-policies produced no output; proceeding with the merged list only"
fi
else
echo "=== Step 5c: kj not installed or no merged PCR list; skipping meta-policies (D-120) ==="
fi
echo ""
echo "=== Step 7: confidence signal compute ===" echo "=== Step 7: confidence signal compute ==="
python3 <<PY > "$WORK/signal.json" || fail "confidence signal failed" python3 <<PY > "$WORK/signal.json" || fail "confidence signal failed"
import json import json
+2 -2
View File
@@ -2,7 +2,7 @@
"""Sync byte-identical workflows from workflows-src/ to .gitea/ + .github/ (P8, REQ-172). """Sync byte-identical workflows from workflows-src/ to .gitea/ + .github/ (P8, REQ-172).
Three workflow pairs are byte-identical Gitea + GitHub mirrors: Three workflow pairs are byte-identical Gitea + GitHub mirrors:
ci.yml, deploy.yml, modules-lifecycle.yml. ci.yml, deploy.yml, modules-lifecycle.yml, rotate-aws-key.yml.
This generator reads the single source from ``workflows-src/<name>`` and This generator reads the single source from ``workflows-src/<name>`` and
writes byte-identical copies to both ``.gitea/workflows/<name>`` and writes byte-identical copies to both ``.gitea/workflows/<name>`` and
@@ -26,7 +26,7 @@ SRC_DIR = ROOT / "workflows-src"
GITEA_DIR = ROOT / ".gitea" / "workflows" GITEA_DIR = ROOT / ".gitea" / "workflows"
GITHUB_DIR = ROOT / ".github" / "workflows" GITHUB_DIR = ROOT / ".github" / "workflows"
PAIRS = ["ci.yml", "deploy.yml", "modules-lifecycle.yml"] PAIRS = ["ci.yml", "deploy.yml", "modules-lifecycle.yml", "rotate-aws-key.yml"]
def _read_source(name: str) -> str: def _read_source(name: str) -> str:
+7 -7
View File
@@ -5,15 +5,15 @@ policy if absent (or creates a new version if the policy document
differs), attaches it to the spike-runner user, deletes any leftover differs), attaches it to the spike-runner user, deletes any leftover
inline policy, and re-creates the OIDC act_runner role if absent. inline policy, and re-creates the OIDC act_runner role if absent.
Requires the bootstrap root key (ACDL_BOOTSTRAP_AWS_* or ACDL_AWS_* Requires the bootstrap root key (NOVA_BOOTSTRAP_AWS_* or NOVA_AWS_*
when the provided key is a root principal). This script is the when the provided key is a root principal). This script is the
reproducible record of the Phase 56 live step the grants are reproducible record of the Phase 56 live step the grants are
documented in .ciagent/IAM_POLICY.md and regression-tested by documented in .ciagent/IAM_POLICY.md and regression-tested by
tests/test_iam_policy_baseline.py. tests/test_iam_policy_baseline.py.
Usage: Usage:
export ACDL_BOOTSTRAP_AWS_ACCESS_KEY_ID=<root key id> export NOVA_BOOTSTRAP_AWS_ACCESS_KEY_ID=<root key id>
export ACDL_BOOTSTRAP_AWS_SECRET_ACCESS_KEY=<root key secret> export NOVA_BOOTSTRAP_AWS_SECRET_ACCESS_KEY=<root key secret>
export AWS_DEFAULT_REGION=us-east-1 export AWS_DEFAULT_REGION=us-east-1
python3 terraform/bootstrap/apply_iam_baseline.py python3 terraform/bootstrap/apply_iam_baseline.py
""" """
@@ -30,7 +30,7 @@ import boto3
ROOT = Path(__file__).resolve().parent.parent.parent ROOT = Path(__file__).resolve().parent.parent.parent
POLICY_PATH = ROOT / "terraform" / "bootstrap" / "spike_runner_policy.json" POLICY_PATH = ROOT / "terraform" / "bootstrap" / "spike_runner_policy.json"
ACCOUNT = os.environ.get("ACDL_AWS_ACCOUNT_ID", "581513795199") ACCOUNT = os.environ.get("NOVA_AWS_ACCOUNT_ID", "581513795199")
USER = "nova-spike-runner" USER = "nova-spike-runner"
POLICY_NAME = "nova-spike-runner-policy" POLICY_NAME = "nova-spike-runner-policy"
POLICY_ARN = f"arn:aws:iam::{ACCOUNT}:policy/{POLICY_NAME}" POLICY_ARN = f"arn:aws:iam::{ACCOUNT}:policy/{POLICY_NAME}"
@@ -38,10 +38,10 @@ ROLE_NAME = "nova-act-runner-role"
def _session(): def _session():
key_id = os.environ.get("ACDL_BOOTSTRAP_AWS_ACCESS_KEY_ID") or os.environ.get("ACDL_AWS_ACCESS_KEY_ID") key_id = os.environ.get("NOVA_BOOTSTRAP_AWS_ACCESS_KEY_ID") or os.environ.get("NOVA_AWS_ACCESS_KEY_ID")
secret = os.environ.get("ACDL_BOOTSTRAP_AWS_SECRET_ACCESS_KEY") or os.environ.get("ACDL_AWS_SECRET_ACCESS_KEY") secret = os.environ.get("NOVA_BOOTSTRAP_AWS_SECRET_ACCESS_KEY") or os.environ.get("NOVA_AWS_SECRET_ACCESS_KEY")
if not key_id or not secret: if not key_id or not secret:
sys.exit("FAIL: set ACDL_BOOTSTRAP_AWS_ACCESS_KEY_ID + ACDL_BOOTSTRAP_AWS_SECRET_ACCESS_KEY (root key)") sys.exit("FAIL: set NOVA_BOOTSTRAP_AWS_ACCESS_KEY_ID + NOVA_BOOTSTRAP_AWS_SECRET_ACCESS_KEY (root key)")
region = os.environ.get("AWS_DEFAULT_REGION", "us-east-1") region = os.environ.get("AWS_DEFAULT_REGION", "us-east-1")
return boto3.Session(aws_access_key_id=key_id, aws_secret_access_key=secret, region_name=region) return boto3.Session(aws_access_key_id=key_id, aws_secret_access_key=secret, region_name=region)
+14 -8
View File
@@ -3,12 +3,14 @@
Idempotent: skips user creation if the user exists; creates an initial Idempotent: skips user creation if the user exists; creates an initial
access key if none active exists. Prints the key to stdout for the access key if none active exists. Prints the key to stdout for the
orchestrator to capture (NEVER committed): orchestrator to capture (NEVER committed):
ACDL_AWS_ACCESS_KEY_ID=<...> NOVA_AWS_ACCESS_KEY_ID=<...>
ACDL_AWS_SECRET_ACCESS_KEY=<...> NOVA_AWS_SECRET_ACCESS_KEY=<...>
Run with the bootstrap root key in env: Run with the bootstrap root key in env:
ACDL_BOOTSTRAP_AWS_ACCESS_KEY_ID / ACDL_BOOTSTRAP_AWS_SECRET_ACCESS_KEY NOVA_BOOTSTRAP_AWS_ACCESS_KEY_ID / NOVA_BOOTSTRAP_AWS_SECRET_ACCESS_KEY
AWS_DEFAULT_REGION (defaults to us-east-1) (falls back to NOVA_AWS_ACCESS_KEY_ID / NOVA_AWS_SECRET_ACCESS_KEY when
the provided key is a root principal). AWS_DEFAULT_REGION (defaults
to us-east-1).
The inline policy is read from spike_runner_policy.json (next to this The inline policy is read from spike_runner_policy.json (next to this
file). The account id + region are already substituted in the policy file file). The account id + region are already substituted in the policy file
@@ -38,9 +40,13 @@ POLICY_FILE = os.path.join(os.path.dirname(__file__), "spike_runner_policy.json"
def main(): def main():
key_id = os.environ.get("NOVA_BOOTSTRAP_AWS_ACCESS_KEY_ID") or os.environ.get("NOVA_AWS_ACCESS_KEY_ID")
secret = os.environ.get("NOVA_BOOTSTRAP_AWS_SECRET_ACCESS_KEY") or os.environ.get("NOVA_AWS_SECRET_ACCESS_KEY")
if not key_id or not secret:
sys.exit("FAIL: set NOVA_BOOTSTRAP_AWS_ACCESS_KEY_ID + NOVA_BOOTSTRAP_AWS_SECRET_ACCESS_KEY (root key)")
session = boto3.Session( session = boto3.Session(
aws_access_key_id=os.environ["ACDL_BOOTSTRAP_AWS_ACCESS_KEY_ID"], aws_access_key_id=key_id,
aws_secret_access_key=os.environ["ACDL_BOOTSTRAP_AWS_SECRET_ACCESS_KEY"], aws_secret_access_key=secret,
region_name=REGION, region_name=REGION,
) )
iam = session.client("iam") iam = session.client("iam")
@@ -71,8 +77,8 @@ def main():
print(" (use scripts/rotate_spike_key.sh to rotate)") print(" (use scripts/rotate_spike_key.sh to rotate)")
return return
new_key = iam.create_access_key(UserName=USER_NAME)["AccessKey"] new_key = iam.create_access_key(UserName=USER_NAME)["AccessKey"]
print("ACDL_AWS_ACCESS_KEY_ID=" + new_key["AccessKeyId"]) print("NOVA_AWS_ACCESS_KEY_ID=" + new_key["AccessKeyId"])
print("ACDL_AWS_SECRET_ACCESS_KEY=" + new_key["SecretAccessKey"]) print("NOVA_AWS_SECRET_ACCESS_KEY=" + new_key["SecretAccessKey"])
print(f"iam: created initial access key {new_key['AccessKeyId']} for {USER_NAME}", file=sys.stderr) print(f"iam: created initial access key {new_key['AccessKeyId']} for {USER_NAME}", file=sys.stderr)
+11 -5
View File
@@ -6,8 +6,10 @@
evidence outbox (D-P08-1). evidence outbox (D-P08-1).
Run with the bootstrap root key in env: Run with the bootstrap root key in env:
ACDL_BOOTSTRAP_AWS_ACCESS_KEY_ID / ACDL_BOOTSTRAP_AWS_SECRET_ACCESS_KEY NOVA_BOOTSTRAP_AWS_ACCESS_KEY_ID / NOVA_BOOTSTRAP_AWS_SECRET_ACCESS_KEY
AWS_DEFAULT_REGION (defaults to us-east-1) (falls back to NOVA_AWS_ACCESS_KEY_ID / NOVA_AWS_SECRET_ACCESS_KEY when
the provided key is a root principal). AWS_DEFAULT_REGION (defaults
to us-east-1).
Writes terraform/bootstrap/.bootstrap_state.json (gitignored bookkeeping). Writes terraform/bootstrap/.bootstrap_state.json (gitignored bookkeeping).
@@ -30,15 +32,19 @@ import boto3
REGION = os.environ.get("AWS_DEFAULT_REGION", "us-east-1") REGION = os.environ.get("AWS_DEFAULT_REGION", "us-east-1")
ACCOUNT_ID = os.environ.get("ACDL_AWS_ACCOUNT_ID", "581513795199") ACCOUNT_ID = os.environ.get("NOVA_AWS_ACCOUNT_ID", "581513795199")
STATE_BUCKET = f"nova-tfstate-{ACCOUNT_ID}-us-east-1" STATE_BUCKET = f"nova-tfstate-{ACCOUNT_ID}-us-east-1"
OUTBOX_TABLE = "nova-outbox" OUTBOX_TABLE = "nova-outbox"
def main(): def main():
key_id = os.environ.get("NOVA_BOOTSTRAP_AWS_ACCESS_KEY_ID") or os.environ.get("NOVA_AWS_ACCESS_KEY_ID")
secret = os.environ.get("NOVA_BOOTSTRAP_AWS_SECRET_ACCESS_KEY") or os.environ.get("NOVA_AWS_SECRET_ACCESS_KEY")
if not key_id or not secret:
sys.exit("FAIL: set NOVA_BOOTSTRAP_AWS_ACCESS_KEY_ID + NOVA_BOOTSTRAP_AWS_SECRET_ACCESS_KEY (root key)")
session = boto3.Session( session = boto3.Session(
aws_access_key_id=os.environ["ACDL_BOOTSTRAP_AWS_ACCESS_KEY_ID"], aws_access_key_id=key_id,
aws_secret_access_key=os.environ["ACDL_BOOTSTRAP_AWS_SECRET_ACCESS_KEY"], aws_secret_access_key=secret,
region_name=REGION, region_name=REGION,
) )
s3 = session.client("s3", region_name=REGION) s3 = session.client("s3", region_name=REGION)
@@ -0,0 +1,4 @@
{
"account_id": "000000000000",
"region": "us-east-1"
}
+7
View File
@@ -0,0 +1,7 @@
{
"account_id": "581513795199",
"region": "us-east-1",
"state_backend": {
"bucket": "nova-tfstate-dev"
}
}
+6
View File
@@ -0,0 +1,6 @@
{
"contract_id": "blkex",
"environment": "dev",
"all_committed": true,
"matches": []
}
+13
View File
@@ -0,0 +1,13 @@
{
"contract_id": "blkex",
"environment": "dev",
"all_committed": false,
"matches": [
{
"txn_id": "t1",
"symbol": "AAPL",
"finalized": false,
"block_index": 1
}
]
}
+11 -6
View File
@@ -30,14 +30,14 @@ class TestInstance:
class TestRegistry: class TestRegistry:
EXPECTED_L1_KEYS = {"s3", "vpc", "ecs-cluster", "ecs-service", "iam-role", "alb", "ecr", "cloudfront", "waf", "rds", "kms-key", "uptime"} EXPECTED_L1_KEYS = {"s3", "vpc", "ecs-cluster", "ecs-service", "iam-role", "alb", "ecr", "cloudfront", "waf", "rds", "kms-key", "uptime", "dynamodb"}
EXPECTED_L2_KEYS = {"static-assets", "microservice"} EXPECTED_L2_KEYS = {"static-assets", "microservice"}
def test_registry_has_14_entries(self, registry): def test_registry_has_15_entries(self, registry):
assert len(registry) == 14 assert len(registry) == 15
assert set(registry.keys()) == (self.EXPECTED_L1_KEYS | self.EXPECTED_L2_KEYS) assert set(registry.keys()) == (self.EXPECTED_L1_KEYS | self.EXPECTED_L2_KEYS)
def test_registry_has_12_l1_entries(self, registry): def test_registry_has_13_l1_entries(self, registry):
l1 = {k for k in registry if registry[k]["1.0.0"]["interface"].startswith("modules/l1/")} l1 = {k for k in registry if registry[k]["1.0.0"]["interface"].startswith("modules/l1/")}
assert l1 == self.EXPECTED_L1_KEYS assert l1 == self.EXPECTED_L1_KEYS
@@ -229,10 +229,15 @@ class TestAdapterStatelessness:
adapter_src = (ROOT / "adapters/terraform/adapter.py").read_text() adapter_src = (ROOT / "adapters/terraform/adapter.py").read_text()
assert 'rtype ==' not in adapter_src assert 'rtype ==' not in adapter_src
def test_adapter_under_200_lines(self): def test_adapter_under_250_lines(self):
# P03 W3 (REQ-319): the adapter now loads the env onboarding JSON to
# source env.state_backend.bucket + env.account_id + env.region for
# the S3 backend block (two small helpers). The bound is 250 (was
# 200) — still a tight statelessness guardrail against type-specific
# logic / constant tables creeping back in.
adapter_path = ROOT / "adapters/terraform/adapter.py" adapter_path = ROOT / "adapters/terraform/adapter.py"
line_count = len(adapter_path.read_text().splitlines()) line_count = len(adapter_path.read_text().splitlines())
assert line_count < 200, f"adapter is {line_count} lines, expected < 200" assert line_count < 250, f"adapter is {line_count} lines, expected < 250"
class TestAdapterEmitsValidTerraform: class TestAdapterEmitsValidTerraform:
+195
View File
@@ -0,0 +1,195 @@
"""P03 W3 (REQ-319): adapter state-backend bucket resolution tests.
The adapter reads env.state_backend.bucket from the env onboarding JSON
(core/environments/<env>.json) when present, falling back to the computed
nova-tfstate-{account_id}-{region} pattern for backwards compat. dev is
bound to the real account 581513795199 + bucket
nova-tfstate-581513795199-us-east-1 (D-203); qa/prod/dr stay placeholder
(account_id 000000000000 the pilot-readiness policy blocks apply on
placeholder, D-208).
"""
import json
import sys
from pathlib import Path
import pytest
sys.path.insert(0, str(Path(__file__).resolve().parent.parent))
from adapters.terraform.adapter import adapt, _resolve_state_bucket, _load_env_json
ROOT = Path(__file__).resolve().parent.parent
def _emit(env_name, tmp_path, **stack_overrides):
"""Run the adapter against a minimal s3 stack in the given environment."""
stack = {
"version": "1.0.0",
"stack": {"name": "spike", "kind": "l1", "depth": 1, "environment": env_name},
"resources": [
{"id": "s3", "type": "aws:s3:bucket", "module": "s3@1.0.0",
"inputs": {"bucket_name": "test", "region": "us-east-1"}}
],
}
stack.update(stack_overrides)
adapt(stack, str(tmp_path))
return (tmp_path / "terraform.tf").read_text()
class TestDevUsesRealStateBucket:
def test_dev_uses_real_state_bucket(self, tmp_path):
"""dev.json is bound to the real account + bucket (D-203)."""
tf = _emit("dev", tmp_path)
assert 'bucket = "nova-tfstate-581513795199-us-east-1"' in tf
def test_dev_account_id_is_real(self):
env_json = _load_env_json("dev", str(ROOT))
assert env_json["account_id"] == "581513795199"
def test_dev_state_backend_bucket_matches_bootstrap(self):
"""The dev env JSON bucket matches the bootstrap-created bucket
(terraform/bootstrap/create_state_backend.py +
terraform/platform/main.tf)."""
env_json = _load_env_json("dev", str(ROOT))
assert env_json["state_backend"]["bucket"] == "nova-tfstate-581513795199-us-east-1"
class TestFallbackComputedName:
def test_fallback_computed_name_when_no_state_backend(self):
"""An env JSON without state_backend.bucket → the adapter falls back
to nova-tfstate-{account_id}-{region}."""
env_json = {"account_id": "123456789012", "region": "us-west-2"}
assert _resolve_state_bucket(env_json, "us-west-2") == "nova-tfstate-123456789012-us-west-2"
def test_fallback_uses_account_id_from_env_json(self, tmp_path):
"""When state_backend.bucket is absent, the computed name uses
account_id from the env JSON (not a hardcoded default)."""
env_json = {"account_id": "999999999999", "region": "us-east-1"}
assert _resolve_state_bucket(env_json, "us-east-1") == "nova-tfstate-999999999999-us-east-1"
def test_fallback_to_real_account_when_account_id_absent(self):
"""When account_id is also absent, fall back to the only real
account (581513795199 the bootstrap bucket)."""
env_json = {}
assert _resolve_state_bucket(env_json, "us-east-1") == "nova-tfstate-581513795199-us-east-1"
def test_empty_env_json_falls_back(self, tmp_path):
"""An env JSON with no state_backend block at all → computed name."""
# Use an environment name with no JSON file → _load_env_json returns {}.
tf = _emit("nonexistent-env", tmp_path)
assert "nova-tfstate-581513795199-us-east-1" in tf
def test_empty_bucket_string_falls_back(self):
"""An empty state_backend.bucket string → fall back to computed name."""
env_json = {"account_id": "111111111111", "region": "eu-west-1",
"state_backend": {"bucket": "", "lock_table": "x"}}
assert _resolve_state_bucket(env_json, "eu-west-1") == "nova-tfstate-111111111111-eu-west-1"
class TestQaPlaceholderAccount:
def test_qa_placeholder_account(self, tmp_path):
"""qa env JSON has account_id 000000000000 (placeholder, D-208) —
the pilot-readiness policy blocks apply on placeholder. The adapter
still emits the computed bucket name with the placeholder account."""
tf = _emit("qa", tmp_path)
# qa.json has state_backend.bucket = nova-tfstate-000000000000-us-east-1
assert 'bucket = "nova-tfstate-000000000000-us-east-1"' in tf
def test_qa_account_id_is_placeholder(self):
env_json = _load_env_json("qa", str(ROOT))
assert env_json["account_id"] == "000000000000"
def test_prod_account_id_is_placeholder(self):
env_json = _load_env_json("prod", str(ROOT))
assert env_json["account_id"] == "000000000000"
def test_dr_account_id_is_placeholder(self):
env_json = _load_env_json("dr", str(ROOT))
assert env_json["account_id"] == "000000000000"
class TestStateKeyEnvScoped:
def test_state_key_remains_env_scoped(self, tmp_path):
"""The state key path stays env-scoped:
spike/{stack_name}/{environment}/terraform.tfstate (REQ-287)."""
tf = _emit("dev", tmp_path, **{
"version": "1.0.0",
"stack": {"name": "msvc", "kind": "l2", "depth": 1, "environment": "dev"},
"resources": [
{"id": "s3", "type": "aws:s3:bucket", "module": "s3@1.0.0",
"inputs": {"bucket_name": "test", "region": "us-east-1"}}
],
})
assert "spike/msvc/dev/terraform.tfstate" in tf
class TestDynamodbL1Emission:
"""W3 Task 3.5: the dynamodb L1 primitive (landed in P2, REQ-322)
resolves + emits an aws_dynamodb_table module block with PK block_index,
PAY_PER_REQUEST."""
def test_dynamodb_resolves_and_emits_module_block(self, tmp_path):
from core.contract_resolver import resolve
# Resolve a contract with an infrastructure.dynamodb block.
contract = {
"id": "ddb", "name": "dynamodb-test", "environment": "dev",
"infrastructure": {
"dynamodb": {
"version": "1.0.0",
"inputs": {
"table_name": "nova-blockchain-ledger",
"region": "us-east-1",
"pk": "block_index",
"billing_mode": "PAY_PER_REQUEST",
},
},
},
}
contract_path = tmp_path / "ddb.yml"
import yaml
contract_path.write_text(yaml.safe_dump(contract))
stack = resolve(str(contract_path), str(ROOT))
# The stack has one dynamodb resource. The resource id is derived
# from the interface type (aws:dynamodb:table → "table").
ddb = [r for r in stack["resources"] if r["type"] == "aws:dynamodb:table"]
assert len(ddb) == 1
assert ddb[0]["inputs"]["pk"] == "block_index"
assert ddb[0]["inputs"]["billing_mode"] == "PAY_PER_REQUEST"
# Emit Terraform.
adapt(stack, str(tmp_path))
main_tf = (tmp_path / "main.tf").read_text()
assert 'module "table" {' in main_tf
assert 'pk = "block_index"' in main_tf
assert 'billing_mode = "PAY_PER_REQUEST"' in main_tf
# The module source points at the dynamodb terraform dir.
assert "modules/l1/dynamodb/terraform" in main_tf
def test_dynamodb_instance_emits_valid_terraform(self, tmp_path):
"""The dynamodb L1 instance.json emits terraform that passes
terraform init + validate (the real regression gate)."""
import subprocess
instance = json.load(open(ROOT / "modules/l1/dynamodb/instance.json"))
# The instance.json is a module-inputs file, not a stack instance —
# build a minimal stack instance wrapping it.
stack = {
"version": "1.0.0",
"stack": {"name": "ddb", "kind": "l1", "depth": 1, "environment": "dev"},
"resources": [
{"id": "dynamodb", "type": "aws:dynamodb:table", "module": "dynamodb@1.0.0",
"inputs": instance["inputs"]}
],
}
adapt(stack, str(tmp_path))
result = subprocess.run(
["terraform", "init", "-backend=false", "-input=false"],
cwd=str(tmp_path), capture_output=True, text=True
)
assert result.returncode == 0, f"terraform init failed: {result.stderr}"
result = subprocess.run(
["terraform", "validate"],
cwd=str(tmp_path), capture_output=True, text=True
)
assert result.returncode == 0, f"terraform validate failed: {result.stderr}"
main_tf = (tmp_path / "main.tf").read_text()
assert 'module "dynamodb" {' in main_tf
assert 'pk = "block_index"' in main_tf
+211
View File
@@ -0,0 +1,211 @@
"""Tests for escalation_reason on ai.decision.made (REQ-318, SPEC §5.8, P3 W2).
Covers:
* block band carries escalation_reason == "confidence" + human_override True
* pass band has escalation_reason ABSENT + human_override False
* fact_run persists escalation_reason (collector wiring)
Follows the fixture pattern in tests/test_metrics_emitters.py.
"""
import json
import os
import sqlite3
import sys
from pathlib import Path
import pytest
ROOT = Path(__file__).resolve().parent.parent
sys.path.insert(0, str(ROOT))
@pytest.fixture
def tmp_metrics(tmp_path, monkeypatch):
"""Redirect metrics/ to a tmp dir for isolated testing."""
metrics_dir = tmp_path / "metrics"
metrics_dir.mkdir()
runs_dir = metrics_dir / "runs"
runs_dir.mkdir()
events_log = metrics_dir / "events.jsonl"
ledger_db = metrics_dir / "decision_ledger.db"
store_db = metrics_dir / "nova_metrics.db"
monkeypatch.setattr("core.metrics.event_envelope.METRICS_DIR", str(metrics_dir))
monkeypatch.setattr("core.metrics.event_envelope.EVENTS_LOG", str(events_log))
monkeypatch.setattr("core.metrics.run_manifest._METRICS_DIR", str(metrics_dir))
monkeypatch.setattr("core.metrics.run_manifest._RUNS_DIR", str(runs_dir))
monkeypatch.setattr("core.metrics.decision_ledger._LEDGER_PATH", str(ledger_db))
monkeypatch.setattr("core.metrics.collector._METRICS_DIR", str(metrics_dir))
monkeypatch.setattr("core.metrics.collector._STORE_PATH", str(store_db))
monkeypatch.setattr("core.metrics.collector._RUNS_DIR", str(runs_dir))
monkeypatch.setattr("core.metrics.collector._LEDGER_DB", str(ledger_db))
monkeypatch.setattr("core.metrics.outcome_backfill._METRICS_DIR", str(metrics_dir))
monkeypatch.setattr("core.metrics.outcome_backfill._STORE_PATH", str(store_db))
monkeypatch.setattr("core.metrics.outcome_backfill._LEDGER_PATH", str(ledger_db))
return {
"metrics_dir": metrics_dir,
"events_log": events_log,
"ledger_db": ledger_db,
"store_db": store_db,
"runs_dir": runs_dir,
}
def _base_inputs():
return {
"policy": [{"result": "pass", "severity": "info"}],
"validation": {"schema": True, "stack_resolved": True,
"tf_validated": True, "tf_planned": True},
"freshness": {"age_days": 0, "max_age_days": 7},
"source": {"submitter": "dev", "commit_sha": "abc"},
"history": {"prior_rollbacks": 0, "prior_policy_fails": 0},
"nfrs": {"conformance": 1.0},
}
def _block_inputs():
"""A critical PCR triggers a hard override (score=0, band=block)."""
inputs = _base_inputs()
inputs["policy"] = [{"result": "fail", "severity": "critical", "ruleId": "CKV_X"}]
return inputs
def _read_decision_event(events_log):
lines = events_log.read_text().strip().split("\n")
for line in lines:
ev = json.loads(line)
if ev["type"] == "nova.ai.decision.made":
return ev
return None
def test_block_band_has_escalation_reason(tmp_metrics):
"""A block (critical PCR hard override) carries escalation_reason='confidence'."""
from core.confidence_signal import compute
sig = compute("cid-block-1", "dev", _block_inputs())
assert sig.band == "block"
ev = _read_decision_event(tmp_metrics["events_log"])
assert ev is not None
data = ev["data"]
assert data["chosen_action"] == "block"
assert data["human_override"] is True
assert data.get("escalation_reason") == "confidence"
def test_pass_band_no_escalation_reason(tmp_metrics):
"""A clean dev apply (pass band) has NO escalation_reason + human_override False."""
from core.confidence_signal import compute
sig = compute("cid-pass-1", "dev", _base_inputs())
assert sig.band == "pass"
ev = _read_decision_event(tmp_metrics["events_log"])
assert ev is not None
data = ev["data"]
assert data["chosen_action"] == "pass"
assert data["human_override"] is False
# escalation_reason must be ABSENT on a non-block band.
assert "escalation_reason" not in data
def test_low_confidence_block_has_escalation_reason(tmp_metrics):
"""A score below (threshold - 0.10) blocks on confidence grounds."""
from core.confidence_signal import compute
# Freshness maximally stale + a high-severity policy fail drags the
# score well below the dev threshold of 0.50 - 0.10 = 0.40.
inputs = _base_inputs()
inputs["freshness"] = {"age_days": 7, "max_age_days": 7}
inputs["policy"] = [{"result": "fail", "severity": "high", "ruleId": "CKV_Y"}]
sig = compute("cid-block-2", "dev", inputs)
assert sig.band == "block"
ev = _read_decision_event(tmp_metrics["events_log"])
data = ev["data"]
assert data.get("escalation_reason") == "confidence"
def test_fact_run_persists_escalation_reason(tmp_metrics):
"""The collector persists escalation_reason into fact_run + fact_decision.
End-to-end: confidence_signal emits ai.decision.made (block)
run_manifest.complete_run writes the manifest with escalation_reason
collector.collect_run_manifests + collect_decision_ledger populate
fact_run.escalation_reason + fact_decision.escalation_reason.
"""
from core.confidence_signal import compute
from core.metrics.run_manifest import complete_run
from core.metrics.collector import collect_run_manifests, collect_decision_ledger
# Emit a block decision.
os.environ["NOVA_RUN_ID"] = "run-esc-1"
try:
sig = compute("cid-esc-1", "dev", _block_inputs())
assert sig.band == "block"
finally:
os.environ.pop("NOVA_RUN_ID", None)
# Complete the run with escalation_reason carried into the manifest.
manifest = complete_run(
"run-esc-1", "cid-esc-1", "dev",
stages=[{"name": "apply", "duration_ms": 100, "exit_code": 0}],
exit_code=0,
confidence={"score": sig.score, "band": sig.band, "perInput": sig.perInput},
decision_id="run-esc-1",
escalation_reason="confidence",
)
assert manifest["escalation_reason"] == "confidence"
# Collector reads the manifest → fact_run.
collect_run_manifests()
# Collector reads the ledger → fact_decision.
collect_decision_ledger()
conn = sqlite3.connect(str(tmp_metrics["store_db"]))
conn.row_factory = sqlite3.Row
run_row = conn.execute(
"SELECT run_id, escalation_reason, decision_id FROM fact_run WHERE run_id = ?",
("run-esc-1",),
).fetchone()
dec_row = conn.execute(
"SELECT decision_id, escalation_reason, human_override FROM fact_decision WHERE decision_id = ?",
("run-esc-1",),
).fetchone()
conn.close()
assert run_row is not None
assert run_row["escalation_reason"] == "confidence"
assert run_row["decision_id"] == "run-esc-1"
assert dec_row is not None
assert dec_row["escalation_reason"] == "confidence"
assert dec_row["human_override"] == 1
def test_fact_run_no_escalation_reason_on_pass(tmp_metrics):
"""A pass-band run has escalation_reason NULL in fact_run."""
from core.confidence_signal import compute
from core.metrics.run_manifest import complete_run
from core.metrics.collector import collect_run_manifests
os.environ["NOVA_RUN_ID"] = "run-esc-pass-1"
try:
sig = compute("cid-esc-pass-1", "dev", _base_inputs())
assert sig.band == "pass"
finally:
os.environ.pop("NOVA_RUN_ID", None)
complete_run(
"run-esc-pass-1", "cid-esc-pass-1", "dev",
stages=[{"name": "apply", "duration_ms": 100, "exit_code": 0}],
exit_code=0,
confidence={"score": sig.score, "band": sig.band, "perInput": sig.perInput},
decision_id="run-esc-pass-1",
# escalation_reason intentionally omitted (pass band).
)
collect_run_manifests()
conn = sqlite3.connect(str(tmp_metrics["store_db"]))
conn.row_factory = sqlite3.Row
row = conn.execute(
"SELECT run_id, escalation_reason FROM fact_run WHERE run_id = ?",
("run-esc-pass-1",),
).fetchone()
conn.close()
assert row is not None
assert row["escalation_reason"] is None
+1 -1
View File
@@ -47,7 +47,7 @@ class TestResolveStaticAsset:
stack = resolve(str(ROOT / "contracts/static-assets.yml"), str(ROOT)) stack = resolve(str(ROOT / "contracts/static-assets.yml"), str(ROOT))
s3_res = [r for r in stack["resources"] if r["type"] == "aws:s3:bucket"] s3_res = [r for r in stack["resources"] if r["type"] == "aws:s3:bucket"]
assert len(s3_res) == 1 assert len(s3_res) == 1
assert s3_res[0]["inputs"]["bucket_name"] == "acdl-dev-assets-000000000000-us-east-1" assert s3_res[0]["inputs"]["bucket_name"] == "acdl-dev-assets-581513795199-us-east-1"
assert s3_res[0]["inputs"]["region"] == "us-east-1" assert s3_res[0]["inputs"]["region"] == "us-east-1"
def test_resolve_static_asset_validates_against_stack_schema(self): def test_resolve_static_asset_validates_against_stack_schema(self):
+41
View File
@@ -74,3 +74,44 @@ def test_run_platform_sh_has_environment_flag():
assert "ENVIRONMENT_OVERRIDE" in text assert "ENVIRONMENT_OVERRIDE" in text
assert "NOVA_ENVIRONMENT_OVERRIDE" in text assert "NOVA_ENVIRONMENT_OVERRIDE" in text
assert "ACDL_ENVIRONMENT_OVERRIDE" not in text assert "ACDL_ENVIRONMENT_OVERRIDE" not in text
def test_deploy_workflow_aws_region_from_secret_with_fallback():
"""SPEC §5.2: aws-region is read from the AWS_DEFAULT_REGION secret (not
hardcoded). The ``|| 'us-east-1'`` fallback preserves backwards-compat
for consumers that haven't set the secret."""
text = GITHUB.read_text()
assert "aws-region: ${{ secrets.AWS_DEFAULT_REGION || 'us-east-1' }}" in text
# The hardcoded us-east-1 for the configure-aws-credentials step is gone.
assert "aws-region: us-east-1" not in text
def test_deploy_workflow_platform_checkout_ref_matches_milestone():
"""SPEC §7.2: the platform checkout ref matches the consumer's @v1.25
pin (the current v1.26 milestone's floating tag)."""
import yaml
wf = yaml.safe_load(GITHUB.read_text())
if True in wf:
wf["on"] = wf[True]
deploy_job = wf["jobs"]["deploy"]
checkout_steps = [s for s in deploy_job["steps"]
if "checkout" in s.get("uses", "")]
platform_checkout = next(
(s for s in checkout_steps if s.get("with", {}).get("path") == "platform"),
None)
assert platform_checkout is not None, "must have a platform repo checkout"
assert platform_checkout["with"]["ref"] == "v1.25", \
"platform checkout ref must be v1.25 (matching the consumer's @v1.25 pin)"
def test_run_platform_sh_local_fallback_unsets_raw_nova_aws_vars():
"""SPEC §5.2: the local .env.secrets fallback must NOT leave raw
NOVA_AWS_* / the forge-token name in the shell env only the
canonical AWS_* names. This is the v1.8 blocked_env_vars guard."""
text = (ROOT / "scripts" / "run_platform.sh").read_text()
# The fallback exports the canonical AWS_* names...
assert 'export AWS_ACCESS_KEY_ID="$NOVA_AWS_ACCESS_KEY_ID"' in text
assert 'export AWS_SECRET_ACCESS_KEY="$NOVA_AWS_SECRET_ACCESS_KEY"' in text
assert 'export AWS_DEFAULT_REGION="${AWS_DEFAULT_REGION:-us-east-1}"' in text
# ...then unsets the raw NOVA_AWS_* + the forge-agnostic forge-token name.
assert "unset NOVA_AWS_ACCESS_KEY_ID NOVA_AWS_SECRET_ACCESS_KEY NOVA_FORGE_TOKEN" in text

Some files were not shown because too many files have changed in this diff Show More