Compare commits

..

3 Commits

Author SHA1 Message Date
CIAgent Orchestrator fa789d703a docs(P04): complete operator-guide-reference-tracking phase (REQ-OPS-GUIDE, v1.28.4)
Nova Slides Render / render (push) Failing after 29s
---ci---
project: acdl
phase: 4
milestone: v1.29
status: complete
---/ci---
2026-08-20 05:24:26 +00:00
CIAgent Orchestrator 8c0c2dd268 docs(P03): complete cfn-archive-tf-delegation phase (REQ-369, v1.28.3)
Nova Slides Render / render (push) Failing after 25s
---ci---
project: acdl
phase: 3
milestone: v1.29
status: complete
---/ci---
2026-08-20 05:20:43 +00:00
CIAgent Orchestrator c19cc68d15 docs(P02): complete gitea-scrub-decisions phase (REQ-367, REQ-368, v1.28.2)
Nova Slides Render / render (push) Failing after 14m19s
---ci---
project: acdl
phase: 2
milestone: v1.29
status: complete
---/ci---
2026-08-20 05:16:53 +00:00
30 changed files with 1845 additions and 1200 deletions
+66 -1
View File
@@ -656,4 +656,69 @@ template (raw dict → JSON, no troposphere dep), presents for review
(`$PAGER` + resource summary), requires explicit `y/N` approval before (`$PAGER` + resource summary), requires explicit `y/N` approval before
`cloudformation deploy --capabilities CAPABILITY_IAM`. `--check` reports `cloudformation deploy --capabilities CAPABILITY_IAM`. `--check` reports
prerequisites + IAM policy delta; `--verify` runs the KMS round-trip prerequisites + IAM policy delta; `--verify` runs the KMS round-trip
test. New IAM grants required: `cloudformation:*`, `codeartifact:*`. test. New IAM grants required: `cloudformation:*`, `codeartifact:*`.
### §12.11 — Platform Ops Reposplit (v1.29, current)
Platform operations are a Terraform-controlled discipline that lives
outside the engineering repo, grounded in Vision §4 (Domain
Boundaries — *the platform begins where the artifact is compiled and
ends where it runs in production under operational guardrails*). Two
repos, two ownership surfaces:
- **`acdl/acdl` (GitHub)** — engineering. Authors `publish.yml` + the
artifacts (Lambda zip, layer wheel, Python wheel, ECR container
image with the static `kj` binary). Each tag `v1.29.x` produces a
GitHub Release with SHA-256-verified artifacts (REQ-354, D-235
tag-pin handoff). Engineering ends at the compiled artifact.
- **`nova-platform-ops` (Gitea-private, OPER-PRIV, REQ-359)** —
operations. Authors the Terraform modules
(`networking`/`kms`/`identity`/`contract-ingest`/`bootstrap`/`edge`)
that bring those artifacts live in `581513795199`. Operations begins
at the live platform under guardrails. No GitHub mirror; CIAgent has
no presence there.
The handoff between the two repos is the **tag-pin** (D-235):
`nova-platform-ops` declares `local.nova_platform_version` +
`local.kj_source_sha` and resolves substrates through a single
`data.aws_ecr_image.kj_image`.
**The `kj` substrate (KJ-LOCKSTEP, REQ-371):** `kj` (a compiled Go
binary, pinned v0.0.3 in `platform/abac/kj-version.txt`, distinct from
the kyverno-json engine) has exactly **one identity**: one ECR image
digest shared by the production Lambda runtime
(`aws_lambda_function.nova_idp_token_vend.image_uri`) and its
defensive Fargate fallback
(`aws_ecs_task_definition.kj.container_definitions[0].image`). A
`lifecycle.precondition` on both image-bearing resources enforces at
every `terraform plan` that both `image_uri` attributes resolve to the
same digest via `data.aws_ecr_image.kj_image`. No second pipeline, no
second SHA pin (D-238). KJ-STATIC: the binary is compiled
`CGO_ENABLED=0` and `file(1)` reports `statically linked, no shared
library` before embedding.
**Covered-reference REQ tracking pattern:** the 14 covered-reference
REQs (355-366, 371) are authored in `nova-platform-ops` (out-of-band).
CIAgent in `acdl` tracks them for milestone completeness; their
verification surface is the M1/M1.5/M2 cutover gates documented in
the operator guide. The operator guide lists each covered-reference
REQ with its gate entry + verification command + a "Result" column
that the operator attests after running the gate in
`nova-platform-ops` CI. P6 audit verifies every covered-reference REQ
has a non-empty, green Result (grill CF-2/G-5). M1.5 green (3
consecutive rebuilds of the 12-item spike, operator-attested in the
guide) is the HARD P6 ship gate (grill CF-1/G-2.1).
**Operator guide pointer:** `docs/operator-guide-platform-ops.md`
(REQ-OPS-GUIDE) — the operator-facing runbook covering the Day-0
cutover, M1.5 verification gate, M2 handoff loop, rollback, KMS
rotation, JWKS reachability via CloudFront edge (INV-18), PITR
restore, PAT revocation, edge config, Fargate standby health, cost,
artifact-mirror fallback, and the cutover gates table.
**JWKS edge (INV-18, D-233):** the JWKS endpoint is the only public
read surface of the live platform. CloudFront + OAC pinning
(`AuthType: AWS_IAM` on the Function URL — NOT `NONE`,
`OriginAccessControlOriginType: lambda`, `SigningBehavior: always`)
replaces direct Lambda Function URL exposure. Direct Function URL →
403; via-CloudFront → 200.
+10 -10
View File
@@ -1,25 +1,25 @@
{ {
"phase": 1, "phase": 4,
"stage": "verify", "stage": "verify",
"milestone": "v1.29", "milestone": "v1.29",
"phase_role": "execution", "phase_role": "execution",
"attempts": 0, "attempts": 0,
"updated_at": "2026-08-20T01:00:00Z", "updated_at": "2026-08-20T01:30:00Z",
"project": "acdl", "project": "acdl",
"projects": ["acdl", "nova-blockchain-exchange"], "projects": ["acdl", "nova-blockchain-exchange"],
"active_milestone": "v1.29", "active_milestone": "v1.29",
"milestone_branch": "milestone/v1.29-reposplit-identity", "milestone_branch": "milestone/v1.29-reposplit-identity",
"phase_branch": "phase/01-publish-pipeline", "phase_branch": "phase/04-operator-guide-reference-tracking",
"tag_line": "v1.28.x", "tag_line": "v1.28.x",
"phase_name": "publish-pipeline", "phase_name": "operator-guide-reference-tracking",
"milestone_type": "feature", "milestone_type": "feature",
"reqs_covered": ["REQ-354"], "reqs_covered": ["REQ-354", "REQ-367", "REQ-368", "REQ-369", "REQ-OPS-GUIDE"],
"reqs_partial": [], "reqs_partial": [],
"verification": { "verification": {
"structural": "PASS (py_compile exit 0, YAML structure valid)", "structural": "PASS (746-line operator guide with 25 sections, ARCHITECTURE §12.11 added, STATE.md updated)",
"behavioral": "PASS (17 test functions AST-discoverable; pytest not installed in sandbox — CI venv will run)", "behavioral": "PASS (all 18 required sections present, Cutover Gates table has 14 covered-reference REQs with Result column)",
"security": "PASS (KJ-STATIC CI gate wired, ABAC fail-closed test authored, M-001 documented + mitigated)", "security": "PASS (KMS rotation, JWKS-EDGE-ONLY, IAM-NARROW, TFM-HITL, PAT revocation all documented)",
"quality": "PASS (test_abac_e2e.py covers Edge 5 item 7, test_kms_roundtrip.py live_aws marker added)" "quality": "PASS (CAP-039/040/041 added to STATE.md, INV-18 + 10 NFR constraints documented, covered-reference REQs marked with cutover gates)"
}, },
"notes": "v1.29 P1 EXECUTE+VERIFY complete. publish.yml rewritten: tag-triggered (v1.29.*), build-kj-image job (CGO_ENABLED=0, KJ-STATIC file(1) gate, ECR tag v1.29.x-kj-<sha> D-239), Lambda zip + layer + wheel + image attached to GitHub Release with SHA-256. kj-version.txt updated with repo URL (CF-4). test_abac_e2e.py authored (5 tests, ABAC allowed/denied/fail-closed). test_kms_roundtrip.py live_aws marker added. NOTE for P2: test_forge_action_byte_identical.py + test_no_forge_mentions.py + test_synced_copies_match will break after Gitea scrub — must update/remove in P2." "notes": "v1.29 P4 EXECUTE+VERIFY complete. operator-guide-platform-ops.md (746 lines, 18 sections + Cutover Gates table). ARCHITECTURE.md §12.11 (Platform Ops Reposplit). STATE.md: CAP-039/040/041, INV-18, 10 NFR constraints, Domain 12. REQUIREMENTS.md: covered-reference REQs marked with M1/M1.5/M2 gates."
} }
+14 -14
View File
@@ -834,17 +834,17 @@ M1/M1.5/M2 cutover gates documented in the operator guide.
| REQ-369 | P3 | planned | | REQ-369 | P3 | planned |
| REQ-OPS-GUIDE | P4 | planned | | REQ-OPS-GUIDE | P4 | planned |
| REQ-CONSUMER-BUMP | P5 | planned | | REQ-CONSUMER-BUMP | P5 | planned |
| REQ-355 | covered-reference | planned (nova-platform-ops) | | REQ-355 | covered-reference | planned (M1 gate: nova-platform-ops) |
| REQ-356 | covered-reference | planned (nova-platform-ops) | | REQ-356 | covered-reference | planned (M1 gate: nova-platform-ops) |
| REQ-357 | covered-reference | planned (nova-platform-ops) | | REQ-357 | covered-reference | planned (M1.5 gate: nova-platform-ops) |
| REQ-358 | covered-reference | planned (nova-platform-ops) | | REQ-358 | covered-reference | planned (M2 gate: nova-platform-ops) |
| REQ-359 | covered-reference | planned (nova-platform-ops) | | REQ-359 | covered-reference | planned (M1 gate: nova-platform-ops) |
| REQ-360 | covered-reference | planned (nova-platform-ops) | | REQ-360 | covered-reference | planned (M1.5 gate: nova-platform-ops) |
| REQ-361 | covered-reference | planned (nova-platform-ops) | | REQ-361 | covered-reference | planned (M1 gate: nova-platform-ops) |
| REQ-362 | covered-reference | planned (nova-platform-ops) | | REQ-362 | covered-reference | planned (M1.5 gate: nova-platform-ops) |
| REQ-363 | covered-reference | planned (nova-platform-ops) | | REQ-363 | covered-reference | planned (M1.5 gate: nova-platform-ops) |
| REQ-363b | covered-reference | planned (nova-platform-ops) | | REQ-363b | covered-reference | planned (M1.5 gate: nova-platform-ops) |
| REQ-364 | covered-reference | planned (nova-platform-ops) | | REQ-364 | covered-reference | planned (M1.5 gate: nova-platform-ops) |
| REQ-365 | covered-reference | planned (nova-platform-ops) | | REQ-365 | covered-reference | planned (M1 gate: nova-platform-ops) |
| REQ-366 | covered-reference | planned (nova-platform-ops) | | REQ-366 | covered-reference | planned (M1 gate: nova-platform-ops) |
| REQ-371 | covered-reference | planned (nova-platform-ops) | | REQ-371 | covered-reference | planned (M2 gate: nova-platform-ops) |
+55 -1
View File
@@ -21,7 +21,20 @@
> lifecycle; `nova idp setup`; `nova auth login/revoke/status`). No > lifecycle; `nova idp setup`; `nova auth login/revoke/status`). No
> AWS-managed identity (INV-15). 6 new capabilities (CAP-033..038), > AWS-managed identity (INV-15). 6 new capabilities (CAP-033..038),
> 6 new invariants (INV-12..17), 6 decisions (D-226..231). > 6 new invariants (INV-12..17), 6 decisions (D-226..231).
> **Next update:** at v1.29 ship. > **v1.29 (pending — tag `v1.28.6`):** Reposplit + Identity Layer
> Bring-Live. Platform operations extracted to a Gitea-private
> Terraform repo (`nova-platform-ops`, OPER-PRIV); `acdl/acdl`
> standardized on GitHub (D-232); Nova-idp brought live in
> `581513795199` via Terraform (CFN archived, REQ-369); `kj` substrate
> has one ECR image digest shared by the Lambda runtime + its Fargate
> fallback (KJ-LOCKSTEP, REQ-371, D-238); JWKS edge-only via CloudFront
> + OAC (INV-18, D-233). 3 new capabilities (CAP-039..041), 1 new
> invariant (INV-18), 10 NFR constraints (KJ-STATIC, KJ-LOCKSTEP,
> KJ-WARMUP-HEALTH, OPER-PRIV, IAM-NARROW, DRIFT-DETECT,
> IMPORT-IDEMPOTENT, TFM-HITL, JWKS-SLO, JWKS-ROTATION), 9 decisions
> (D-232..D-240). Covered-reference REQs (355-366, 371) verified via
> M1/M1.5/M2 cutover gates in `docs/operator-guide-platform-ops.md`.
> **Next update:** at v1.30 ship.
## How to use this file (PO) ## How to use this file (PO)
@@ -110,6 +123,30 @@
absence or evaluation error (C-6.1 — never fail open). Allow/deny + absence or evaluation error (C-6.1 — never fail open). Allow/deny +
policy inputs emitted to the audit stream. `policy_version` (git SHA, policy inputs emitted to the audit stream. `policy_version` (git SHA,
D-231) recorded in every event. D-231) recorded in every event.
- **INV-18 (JWKS-EDGE-ONLY, v1.29):** the JWKS endpoint is the only
public read surface of the live platform. All other platform
endpoints MUST gate with `AuthType: AWS_IAM` (D-233). CloudFront +
OAC pinning replaces direct Lambda Function URL exposure. Direct
Function URL → 403; via-CloudFront → 200.
> **v1.29 NFR constraints (10 — load-bearing, not full invariants):**
> KJ-STATIC (`kj` compiled `CGO_ENABLED=0`, `file(1)` reports
> `statically linked`, SHA-256 in Terraform state); KJ-LOCKSTEP
> (Fargate standby digest == Lambda `image_uri` digest at every
> `terraform plan`, enforced by `lifecycle.precondition` + CI + PR
> comment + operator review, D-238); KJ-WARMUP-HEALTH (Fargate
> `GET /health → 200` every 10s, READY before M1 cutover);
> OPER-PRIV (`nova-platform-ops` `private: true`, not mirrored,
> REQ-359); IAM-NARROW (Gitea OIDC role bounded, no `Action: "*"` or
> `Resource: "*"`, REQ-360); DRIFT-DETECT (`terraform plan` exit 2
> fails the apply workflow, REQ-356); IMPORT-IDEMPOTENT (re-import
> exits `resource_already_imported`, REQ-361); TFM-HITL (`terraform
> apply` against `main` requires Gitea Actions approval from a user
> distinct from the PR author, REQ-357, INV-3); JWKS-SLO
> (`GET /.well-known/jwks.json` P95 < 200ms same-region,
> `Cache-Control: max-age=3600`); JWKS-ROTATION (on key rotation,
> both old + new public keys published during 24-hour overlap
> window).
## Domains (capability groups) ## Domains (capability groups)
@@ -123,6 +160,8 @@
8. Consumer surfaces (developer + agentic) 8. Consumer surfaces (developer + agentic)
9. Pilot estate (v1.26) 9. Pilot estate (v1.26)
10. Forge / CI runtime 10. Forge / CI runtime
11. CLI + Identity Layer (v1.28)
12. Platform Ops Reposplit (v1.29)
## Capabilities (additive — one row per shipped capability) ## Capabilities (additive — one row per shipped capability)
@@ -303,6 +342,21 @@
| — | Operator guide | v1.28 / `v1.27.5` | `docs/operator-guide-idp.md` | REQ-345 | local | `nova idp setup` + KMS rotation + layer update + PITR restore + emergency PAT revocation | | — | Operator guide | v1.28 / `v1.27.5` | `docs/operator-guide-idp.md` | REQ-345 | local | `nova idp setup` + KMS rotation + layer update + PITR restore + emergency PAT revocation |
| — | Developer guide | v1.28 / `v1.27.5` | `docs/developer-guide-auth.md` | REQ-346 | local | quickstart + mode resolution + JWS KDF + service-account PATs | | — | Developer guide | v1.28 / `v1.27.5` | `docs/developer-guide-auth.md` | REQ-346 | local | quickstart + mode resolution + JWS KDF + service-account PATs |
### Domain 12 — Platform Ops Reposplit (v1.29)
> **Pending — tag v1.28.6 (milestone release).** Rows below are the
> v1.29 capability allocations; shipped state is recorded at the P-final
> milestone-ship wave. Covered-reference REQs (355-366, 371) are
> authored out-of-band in `nova-platform-ops`; their verification
> surface is the M1/M1.5/M2 cutover gates in the operator guide (grill
> CF-2/G-5).
| ID | Capability | Shipped | Files | Controlling | Tier | Notes |
|----|-----------|---------|-------|-------------|------|-------|
| CAP-039 | Platform ops reposplit | v1.29 / `v1.28.6` (pending) | `nova-platform-ops` (out-of-band), `docs/operator-guide-platform-ops.md`, `docs/archive/nova-idp-cfn-v1.28.md` | REQ-369, REQ-OPS-GUIDE, D-232, D-235 | covered-reference | engineering (`acdl/acdl`, GitHub) ends at the artifact; operations (`nova-platform-ops`, Gitea-private, OPER-PRIV) begins at the live platform; tag-pin handoff; CFN archived; covered-reference REQs tracked via cutover gates |
| CAP-040 | KJ substrate lockstep | v1.29 / `v1.28.6` (pending) | `nova-platform-ops` (out-of-band), `platform/abac/kj-version.txt`, `.github/workflows/publish.yml` | REQ-371, REQ-363, REQ-363b, D-238, D-239 | covered-reference | one ECR image digest shared by Lambda `image_uri` + Fargate task `image`; `lifecycle.precondition` on both resources at `terraform plan`; KJ-STATIC (`CGO_ENABLED=0`, `file(1)` asserts `statically linked`); no second pipeline, no second SHA pin |
| CAP-041 | JWKS edge-only | v1.29 / `v1.28.6` (pending) | `nova-platform-ops` (out-of-band), `docs/operator-guide-platform-ops.md` | REQ-364, REQ-365, REQ-366, INV-18, D-233 | covered-reference | JWKS is the only public read surface; CloudFront + OAC (`AuthType: AWS_IAM`, NOT `NONE`, `OriginAccessControlOriginType: lambda`, `SigningBehavior: always`); direct Function URL → 403, via-CloudFront → 200; WAF rate-limit 3000/5min + AWSManagedRulesCommonRuleSet; ACM DNS-validated in us-east-1; Route53 A-alias |
## Archive pointers ## Archive pointers
- **v1.0v1.24 capability narrative + the 2026-07-27 re-verification sweep:** - **v1.0v1.24 capability narrative + the 2026-07-27 re-verification sweep:**
-40
View File
@@ -1,40 +0,0 @@
# Gitea Workflows — Limitation Documentation (v1.14, REQ-150)
## Shared workflows (byte-identical Gitea + GitHub)
These 3 workflows exist in both `.gitea/workflows/` and `.github/workflows/`
and are byte-identical (asserted by `tests/test_pipeline_contract.py`):
- `ci.yml` — lint + test + check-only (runs on every PR)
- `deploy.yml` — reusable deploy workflow (invoked by consumer repos)
- `modules-lifecycle.yml` — L1 + L2 module lifecycle pipeline (plan-only
default, full on workflow_dispatch override)
## GitHub-only workflows (no Gitea mirror)
These 4 workflows exist only in `.github/workflows/`:
- `platform-test.yml` — PR pipeline: lint + unit + integration + schema
validation. Uses GitHub Actions features (reusable workflow composition,
environment protection) not available in Gitea Actions.
- `primitives-plan.yml` — PR plan-only matrix over all L1 primitives. Uses
GitHub matrix strategy + `terraform plan` against live AWS.
- `patterns-plan.yml` — PR plan-only matrix over all L2 modules. Same
pattern as primitives-plan.
- `release.yml` — release job on merge to main: computes next semver,
creates + updates MAJOR.MINOR.PATCH / MAJOR.MINOR / MAJOR floating tags,
creates a GitHub release. GitHub-only by design (Gitea releases are
created via the ship workflow's API call, not a workflow).
## Why no Gitea mirror
Gitea Actions (act_runner) has limited support for reusable workflow
composition, environment protection, and the `gh` CLI used by the release
job. The 3 shared workflows are the ones that need to run on both forges
(CI + deploy + lifecycle). The 4 GitHub-only workflows are the
production-grade platform pipelines that run on GitHub Actions; Gitea is
the dev/integration forge. Mirroring them would require feature parity
that Gitea Actions does not currently provide.
This is a documented limitation, not a defect. A future milestone may
add Gitea mirrors if act_runner gains the required features.
-89
View File
@@ -1,89 +0,0 @@
# Nova CI Pipeline (dev environment)
#
# This workflow implements the central pipeline contract:
# pipelines/ci.yml (validated against schemas/pipeline.schema.json)
#
# The same contract is implemented by .github/workflows/ci.yml (GitHub
# Actions, production). Both files must be byte-identical — the only
# declared difference is the forge/runtime, not the stages or commands.
#
# Shell reproducibility: scripts/run_ci.sh runs the same 3 stages locally.
#
# Stages (from the contract):
# 1. lint — py_compile all Python files
# 2. test — pytest test suite (offline, no AWS)
# 3. check-only — run_platform.sh --check-only (offline, no AWS)
name: acdl-ci
on:
push:
branches: [main]
pull_request:
branches: [main]
jobs:
lint:
name: Lint
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: Compile all Python files
run: |
python3 -m py_compile \
core/confidence_signal.py \
core/outbox_writer.py \
core/output_publisher.py \
core/contract_resolver.py \
core/lambda/contract_ingestor.py \
adapters/terraform/adapter.py \
adapters/terraform/policy/checkov_adapter.py \
scripts/push_consumer_image.py
test:
name: Test
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: Install Terraform 1.9.*
run: |
wget -qO- https://apt.releases.hashicorp.com/gpg | sudo gpg --dearmor -o /usr/share/keyrings/hashicorp.gpg
echo "deb [signed-by=/usr/share/keyrings/hashicorp.gpg] https://apt.releases.hashicorp.com $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/hashicorp.list
sudo apt-get update && sudo apt-get install -y terraform=1.9.*
- name: Install test dependencies
run: pip install -r requirements-test.txt
- name: Run pytest
run: python3 -m pytest tests/ -v --tb=short
check-only:
name: Platform check-only (offline)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: Install Terraform 1.9.*
run: |
wget -qO- https://apt.releases.hashicorp.com/gpg | sudo gpg --dearmor -o /usr/share/keyrings/hashicorp.gpg
echo "deb [signed-by=/usr/share/keyrings/hashicorp.gpg] https://apt.releases.hashicorp.com $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/hashicorp.list
sudo apt-get update && sudo apt-get install -y terraform=1.9.*
- name: Install runtime dependencies
run: pip install jsonschema pyyaml boto3
- name: Run platform check-only
run: bash scripts/run_platform.sh --check-only
-168
View File
@@ -1,168 +0,0 @@
# Nova Reusable Deploy Workflow (dev environment)
#
# This reusable workflow implements the central deployment pipeline contract:
# pipelines/contract.yml (validated against schemas/deploy-pipeline.schema.json)
#
# The same contract is implemented by .github/workflows/deploy.yml (GitHub
# Actions, production). Both files must be byte-identical — the only
# declared difference is the forge/runtime, not the stages or commands.
#
# Consumer repos invoke this workflow via a versioned tag (floating MAJOR + MINOR):
# uses: nova/.github/workflows/deploy.yml@v1.19
# uses: acdl/.github/workflows/deploy.yml@v1.9 (GitHub)
#
# Unversioned references (@main, bare) are discouraged — the consumer's setup
# must be immutable + resilient. The versioned tag is the only immutability
# lever (version constraints cannot be expressed inside the contract).
#
# What this workflow does:
# 1. Checks out the consumer repo (the repo that invoked the workflow).
# 2. Checks out the ACDL platform repo into the workspace (platform/).
# This is the run-time fetch — consumers never clone the platform repo.
# 3. Installs runtime deps: Python 3.12, Terraform 1.9.*, Checkov.
# 4. Configures AWS auth (OIDC default; static-key override via secrets).
# 5. Runs scripts/run_platform.sh against the consumer's contract path.
# 6. Uploads artifacts (emitted Terraform, Checkov JSON, confidence JSON,
# platform log) for auditability.
#
# Inputs:
# contract — path to the consumer's contract YAML (default .nova/contract.yml)
# mode — full | plan-only | check-only (default full; dev = full apply,
# higher environments hold for HITL — the calling repo or the
# forge environment gate enforces that)
#
# Auth (zero-trust default — see README.md#credentials--zero-trust):
# OIDC federation is the default. permissions: id-token: write lets the
# forge mint a short-lived STS token. The role-to-assume is scoped by the
# consumer's repository identity (ABAC) — the workflow assumes the role
# that matches repo:org/consumer-repo:ref:refs/heads/main, and the session
# policy restricts view/update to resources tagged acdl:owner=<consumer-repo>.
#
# Override (where OIDC is unavailable, e.g. pending
# upstream forge OIDC support): set NOVA_AWS_ACCESS_KEY_ID + NOVA_AWS_SECRET_ACCESS_KEY
# as repository secrets. The platform-managed scheduled pipeline rotates
# the key on a daily cadence. When .env.secrets is used locally instead,
# rotating the key out of band is the consumer's responsibility.
name: nova-deploy
on:
workflow_call:
inputs:
contract:
description: Path to the consumer contract YAML (in the consumer repo)
type: string
default: .nova/contract.yml
mode:
description: Pipeline mode — full (apply), plan-only, check-only, or decommission
type: string
default: full
changeRequestId:
description: Change request ID (required for decommission mode — validated against CMDB)
type: string
default: ""
environment:
description: Target environment override (dev/qa/prod/dr); when empty, the contract's environment field is used
type: string
default: ""
permissions:
id-token: write
contents: read
jobs:
deploy:
name: Deploy
runs-on: ubuntu-latest
steps:
- name: Check out consumer repo
uses: actions/checkout@v4
- name: Check out ACDL platform repo
uses: actions/checkout@v4
with:
repository: acdl/acdl
path: platform
ref: v1.25
- uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: Install runtime dependencies
run: |
pip install --break-system-packages jsonschema pyyaml boto3
pip install --break-system-packages "checkov>=3.2,<4"
- name: Install Terraform 1.9.*
run: |
wget -qO- https://apt.releases.hashicorp.com/gpg | sudo gpg --dearmor -o /usr/share/keyrings/hashicorp.gpg
echo "deb [signed-by=/usr/share/keyrings/hashicorp.gpg] https://apt.releases.hashicorp.com $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/hashicorp.list
sudo apt-get update && sudo apt-get install -y terraform=1.9.*
- name: Configure AWS credentials (OIDC default + static-key override)
uses: aws-actions/configure-aws-credentials@v4
with:
# P4 (REQ-163): IAM role renamed acdl-deploy- → nova-deploy-.
role-to-assume: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID == '' && format('arn:aws:iam::{0}:role/nova-deploy-{1}', secrets.NOVA_AWS_ACCOUNT_ID, github.repository_id) || '' }}
aws-region: ${{ secrets.AWS_DEFAULT_REGION || 'us-east-1' }}
access-key-id: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID }}
secret-access-key: ${{ secrets.NOVA_AWS_SECRET_ACCESS_KEY }}
- name: Run the platform pipeline
working-directory: ${{ github.workspace }}
env:
NOVA_CONSUMER_REPO: ${{ github.repository }}
run: |
MODE_FLAG=""
case "${{ inputs.mode }}" in
full) MODE_FLAG="" ;;
plan-only) MODE_FLAG="--plan-only" ;;
check-only) MODE_FLAG="--check-only" ;;
decommission)
if [ -z "${{ inputs.changeRequestId }}" ]; then
echo "FAIL: changeRequestId is required for decommission mode"
exit 1
fi
MODE_FLAG="--decommission ${{ inputs.changeRequestId }}"
;;
*) echo "Unknown mode: ${{ inputs.mode }}"; exit 1 ;;
esac
ENV_FLAG=""
if [ -n "${{ inputs.environment }}" ]; then
ENV_FLAG="--environment ${{ inputs.environment }}"
fi
bash platform/scripts/run_platform.sh $MODE_FLAG $ENV_FLAG "${{ inputs.contract }}"
- name: Post stage summary comment to PR
if: success() && github.event_name == 'pull_request'
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GITHUB_REPOSITORY: ${{ github.repository }}
GITHUB_REF: ${{ github.ref }}
run: |
bash platform/scripts/post_stage_comment.sh deploy pass '{"mode":"${{ inputs.mode }}","runId":"${{ github.run_id }}"}'
- name: Report error to platform team (on failure)
if: failure()
env:
AWS_DEFAULT_REGION: us-east-1
run: |
aws lambda invoke-function-url \
--function-url "${{ secrets.NOVA_LAMBDA_URL }}" \
--cli-binary-format raw-in-base64-out \
--payload "$(python3 -c "import json,os; print(json.dumps({'action':'report_error','consumerRepo':os.environ.get('GITHUB_REPOSITORY',''),'contractId':'${{ github.run_id }}','error':'Deploy pipeline failed. See run logs.','runUrl':'${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}','environment':'dev'}))")" \
/dev/null || true
- name: Upload emitted Terraform
uses: actions/upload-artifact@v4
with:
name: nova-terraform
path: /tmp/nova_platform_run/tf/*.tf
if-no-files-found: warn
- name: Upload platform log
uses: actions/upload-artifact@v4
with:
name: nova-platform-log
path: platform/logs/
if-no-files-found: warn
-207
View File
@@ -1,207 +0,0 @@
# Nova Modules Lifecycle Pipeline (dev environment)
#
# Matrix-runs each L1 module's examples/{simple,complex}.yml contracts through
# apply→modify→destroy against live AWS. No per-module Python. The "test" =
# the pipeline cell going green.
#
# Also matrix-runs L2 composition modules (static-assets, microservice) through
# the same apply→modify→destroy lifecycle. L2 = composition only (no L2
# terraform files); the composition must be deterministic.
#
# This workflow implements pipelines/modules-lifecycle.yml (byte-identical
# in .github/workflows/).
#
# Lifecycle mode (REQ-134, v1.12): the `lifecycle_mode` input defaults to
# "plan" — the lifecycle scripts run `run_platform.sh --plan-only` (fast,
# no AWS mutation, validates the contract->resolver->adapter->plan chain
# for every module on every PR, with no AWS credentials or cost). Set to
# "full" via workflow_dispatch (or the NOVA_LIFECYCLE_MODE repo variable)
# to run the real apply→modify→destroy against live AWS. In plan mode the
# short-lived CI VPC apply/destroy jobs are skipped (nothing is applied).
#
# A short-lived CI VPC (terraform/ci-vpc/) is created before testing VPC-dependent
# modules (alb, ecs-service, rds, uptime, and L2 microservice) and destroyed
# after all tests complete. The CI VPC is separate from the long-lived platform
# VPC. Outputs are read from the S3 state by each lifecycle job (no artifact
# passing needed).
name: acdl-modules-lifecycle
on:
pull_request:
branches: [main]
workflow_dispatch:
inputs:
lifecycle_mode:
description: "Lifecycle mode: 'plan' (default, fast, no AWS mutation) or 'full' (real apply→modify→destroy against live AWS)"
required: false
default: "plan"
type: choice
options:
- plan
- full
permissions:
contents: read
jobs:
# Prerequisite: apply the short-lived CI VPC (needed by VPC-dependent L1s + L2 microservice)
# Skipped in plan mode (no resources are applied, so no VPC is needed).
ci-vpc-apply:
name: CI VPC apply
runs-on: ubuntu-latest
if: ${{ github.event.inputs.lifecycle_mode != 'plan' && vars.NOVA_LIFECYCLE_MODE != 'plan' }}
steps:
- uses: actions/checkout@v4
- name: Install Terraform 1.9.*
run: |
wget -qO- https://apt.releases.hashicorp.com/gpg | sudo gpg --dearmor -o /usr/share/keyrings/hashicorp.gpg
echo "deb [signed-by=/usr/share/keyrings/hashicorp.gpg] https://apt.releases.hashicorp.com $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/hashicorp.list
sudo apt-get update && sudo apt-get install -y terraform=1.9.*
- name: Apply CI VPC
working-directory: terraform/ci-vpc
env:
AWS_ACCESS_KEY_ID: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.NOVA_AWS_SECRET_ACCESS_KEY }}
AWS_DEFAULT_REGION: us-east-1
run: |
terraform init -input=false -lock=false
terraform apply -auto-approve -lock=false
# L1 lifecycle matrix: apply simple → apply complex (modify) → destroy
lifecycle:
name: L1 lifecycle (${{ matrix.module }})
needs: ci-vpc-apply
if: always()
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
module: [s3, kms-key, ecr, ecs-cluster, iam-role, cloudfront, waf, vpc, alb, ecs-service, rds, uptime]
env:
NOVA_LIFECYCLE_MODE: ${{ github.event.inputs.lifecycle_mode || vars.NOVA_LIFECYCLE_MODE || 'plan' }}
steps:
- uses: actions/checkout@v4
- name: Free disk space
run: |
sudo rm -rf /usr/share/dotnet /usr/local/lib/android /opt/ghc /usr/local/share/boost
sudo apt-get clean
df -h /
- uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: Install dependencies
run: pip install jsonschema pyyaml boto3
- name: Install Terraform 1.9.*
run: |
wget -qO- https://apt.releases.hashicorp.com/gpg | sudo gpg --dearmor -o /usr/share/keyrings/hashicorp.gpg
echo "deb [signed-by=/usr/share/keyrings/hashicorp.gpg] https://apt.releases.hashicorp.com $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/hashicorp.list
sudo apt-get update && sudo apt-get install -y terraform=1.9.*
- name: Read CI VPC outputs
if: ${{ env.NOVA_LIFECYCLE_MODE == 'full' }}
working-directory: terraform/ci-vpc
env:
AWS_ACCESS_KEY_ID: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.NOVA_AWS_SECRET_ACCESS_KEY }}
AWS_DEFAULT_REGION: us-east-1
run: |
terraform init -input=false -lock=false
terraform output -json > /tmp/ci-vpc-outputs.json
- name: Apply (simple)
env:
AWS_ACCESS_KEY_ID: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.NOVA_AWS_SECRET_ACCESS_KEY }}
AWS_DEFAULT_REGION: us-east-1
run: bash scripts/run_lifecycle_test.sh ${{ matrix.module }} simple /tmp/ci-vpc-outputs.json
- name: Modify (complex)
env:
AWS_ACCESS_KEY_ID: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.NOVA_AWS_SECRET_ACCESS_KEY }}
AWS_DEFAULT_REGION: us-east-1
run: bash scripts/run_lifecycle_test.sh ${{ matrix.module }} complex /tmp/ci-vpc-outputs.json
- name: Destroy
env:
AWS_ACCESS_KEY_ID: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.NOVA_AWS_SECRET_ACCESS_KEY }}
AWS_DEFAULT_REGION: us-east-1
run: bash scripts/run_lifecycle_destroy.sh ${{ matrix.module }} /tmp/ci-vpc-outputs.json
# L2 lifecycle matrix: apply simple → apply complex (modify) → destroy
l2-lifecycle:
name: L2 lifecycle (${{ matrix.module }})
needs: ci-vpc-apply
if: always()
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
module: [static-assets, microservice]
env:
NOVA_LIFECYCLE_MODE: ${{ github.event.inputs.lifecycle_mode || vars.NOVA_LIFECYCLE_MODE || 'plan' }}
steps:
- uses: actions/checkout@v4
- name: Free disk space
run: |
sudo rm -rf /usr/share/dotnet /usr/local/lib/android /opt/ghc /usr/local/share/boost
sudo apt-get clean
df -h /
- uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: Install dependencies
run: pip install jsonschema pyyaml boto3
- name: Install Terraform 1.9.*
run: |
wget -qO- https://apt.releases.hashicorp.com/gpg | sudo gpg --dearmor -o /usr/share/keyrings/hashicorp.gpg
echo "deb [signed-by=/usr/share/keyrings/hashicorp.gpg] https://apt.releases.hashicorp.com $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/hashicorp.list
sudo apt-get update && sudo apt-get install -y terraform=1.9.*
- name: Read CI VPC outputs
if: ${{ env.NOVA_LIFECYCLE_MODE == 'full' }}
working-directory: terraform/ci-vpc
env:
AWS_ACCESS_KEY_ID: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.NOVA_AWS_SECRET_ACCESS_KEY }}
AWS_DEFAULT_REGION: us-east-1
run: |
terraform init -input=false -lock=false
terraform output -json > /tmp/ci-vpc-outputs.json
- name: Apply (simple)
env:
AWS_ACCESS_KEY_ID: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.NOVA_AWS_SECRET_ACCESS_KEY }}
AWS_DEFAULT_REGION: us-east-1
run: bash scripts/run_l2_lifecycle_test.sh ${{ matrix.module }} simple /tmp/ci-vpc-outputs.json
- name: Modify (complex)
env:
AWS_ACCESS_KEY_ID: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.NOVA_AWS_SECRET_ACCESS_KEY }}
AWS_DEFAULT_REGION: us-east-1
run: bash scripts/run_l2_lifecycle_test.sh ${{ matrix.module }} complex /tmp/ci-vpc-outputs.json
- name: Destroy
env:
AWS_ACCESS_KEY_ID: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.NOVA_AWS_SECRET_ACCESS_KEY }}
AWS_DEFAULT_REGION: us-east-1
run: bash scripts/run_l2_lifecycle_destroy.sh ${{ matrix.module }} /tmp/ci-vpc-outputs.json
# Cleanup: destroy the CI VPC (always runs in full mode, even if lifecycle fails)
ci-vpc-destroy:
name: CI VPC destroy
needs: [lifecycle, l2-lifecycle]
runs-on: ubuntu-latest
if: ${{ always() && github.event.inputs.lifecycle_mode != 'plan' && vars.NOVA_LIFECYCLE_MODE != 'plan' }}
steps:
- uses: actions/checkout@v4
- name: Install Terraform 1.9.*
run: |
wget -qO- https://apt.releases.hashicorp.com/gpg | sudo gpg --dearmor -o /usr/share/keyrings/hashicorp.gpg
echo "deb [signed-by=/usr/share/keyrings/hashicorp.gpg] https://apt.releases.hashicorp.com $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/hashicorp.list
sudo apt-get update && sudo apt-get install -y terraform=1.9.*
- name: Destroy CI VPC
working-directory: terraform/ci-vpc
env:
AWS_ACCESS_KEY_ID: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.NOVA_AWS_SECRET_ACCESS_KEY }}
AWS_DEFAULT_REGION: us-east-1
run: |
terraform init -input=false -lock=false
terraform destroy -auto-approve -lock=false
-165
View File
@@ -1,165 +0,0 @@
# Nova Publish Pipeline — wheel + Lambda layer (REQ-323, CAP-035, NFR-6)
#
# This workflow is byte-identical across the production forge (GitHub
# Actions) and the dev forge (act_runner) — the same file is installed
# at .github/workflows/publish.yml and the mirror at
# <dev-forge>/workflows/publish.yml. Both copies must match exactly
# (asserted by tests/test_forge_action_byte_identical.py for the action
# and by the repo's byte-identical convention for workflows).
#
# NFR-6 (wheel/layer co-versioning): every merge to main affecting
# core/**, adapters/**, nova/**, or pyproject.toml publishes BOTH a
# wheel AND a Lambda layer with identical version strings. If either
# publish fails, the job fails and the merge is blocked.
#
# REQ-323: CodeArtifact wheel + Lambda layer pipeline.
# CAP-035: Lambda layer ARN version matches the nova-cli wheel version;
# the mapping is recorded in SSM /nova/layer/nova-cli/version.
#
# Triggers:
# - push to main when core/**, adapters/**, nova/**, or pyproject.toml
# changed (the surfaces that ship in the wheel + layer)
# - workflow_dispatch (manual republish, e.g. after a CodeArtifact
# provisioning fix)
#
# Wheel index selection (CodeArtifact default + fallback):
# - CodeArtifact mode: set the NOVA_CODEARTIFACT_DOMAIN repository
# secret (e.g. "nova"). The workflow runs
# `aws codeartifact login --tool twine --domain $NOVA_CODEARTIFACT_DOMAIN
# --repository nova-pypi` and twine uploads to the CodeArtifact pypi
# endpoint.
# - Fallback mode: leave NOVA_CODEARTIFACT_DOMAIN unset and provide
# TWINE_REPOSITORY_URL + TWINE_USERNAME + TWINE_PASSWORD repository
# secrets pointing at any PEP 503 simple index (a private package
# registry). twine uploads to TWINE_REPOSITORY_URL.
# See docs/codeartifact-provisioning.md for the required IAM grants
# + the fallback index shape.
#
# Secrets / env:
# AWS_ROLE_ARN — OIDC role to assume (id-token: write)
# NOVA_CODEARTIFACT_DOMAIN — optional; when set, CodeArtifact mode
# TWINE_USERNAME — fallback-index upload user
# TWINE_PASSWORD — fallback-index upload password
# TWINE_REPOSITORY_URL — fallback-index upload URL
# AWS_DEFAULT_REGION (optional) — defaults to us-east-1
name: nova-publish
on:
push:
branches: [main]
paths:
- "core/**"
- "adapters/**"
- "nova/**"
- "pyproject.toml"
workflow_dispatch:
permissions:
id-token: write # OIDC federation to AWS
contents: write # tag the release
jobs:
publish:
name: Publish wheel + Lambda layer
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: Configure AWS credentials (OIDC)
uses: aws-actions/configure-aws-credentials@v4
with:
role-to-assume: ${{ secrets.AWS_ROLE_ARN }}
aws-region: ${{ secrets.AWS_DEFAULT_REGION || 'us-east-1' }}
- name: Install build + publish tools
run: pip install build twine
- name: Compute version from pyproject.toml
id: ver
run: |
set -e
VERSION=$(python -c 'import tomllib;print(tomllib.load(open("pyproject.toml","rb"))["project"]["version"])')
echo "version=$VERSION" >> "$GITHUB_OUTPUT"
echo "Nova version: $VERSION"
- name: Build wheel
run: |
set -e
python -m build --wheel
ls -1 dist/
- name: Upload wheel to index (CodeArtifact default + fallback)
id: wheel
env:
NOVA_CODEARTIFACT_DOMAIN: ${{ secrets.NOVA_CODEARTIFACT_DOMAIN }}
TWINE_USERNAME: ${{ secrets.TWINE_USERNAME }}
TWINE_PASSWORD: ${{ secrets.TWINE_PASSWORD }}
TWINE_REPOSITORY_URL: ${{ secrets.TWINE_REPOSITORY_URL }}
run: |
set -e
# CodeArtifact mode: log in to the domain's pypi repository.
if [ -n "$NOVA_CODEARTIFACT_DOMAIN" ]; then
echo "CodeArtifact mode: domain=$NOVA_CODEARTIFACT_DOMAIN repository=nova-pypi"
aws codeartifact login --tool twine \
--domain "$NOVA_CODEARTIFACT_DOMAIN" --repository nova-pypi
else
echo "Fallback-index mode: uploading to TWINE_REPOSITORY_URL"
if [ -z "$TWINE_REPOSITORY_URL" ] || [ -z "$TWINE_USERNAME" ] || [ -z "$TWINE_PASSWORD" ]; then
echo "FAIL: NOVA_CODEARTIFACT_DOMAIN is unset and one of TWINE_REPOSITORY_URL/TWINE_USERNAME/TWINE_PASSWORD is missing."
exit 1
fi
fi
# Idempotent upload: a re-run for the same version may hit
# "file already exists" on the index. Treat that as success.
twine upload "dist/nova-${{ steps.ver.outputs.version }}-*.whl" \
|| twine upload "dist/nova-${{ steps.ver.outputs.version }}-*.whl" 2>&1 | tee /tmp/twine.log
if grep -qi "already exist" /tmp/twine.log 2>/dev/null; then
echo "Wheel already present on the index — treating as success (idempotent)."
fi
echo "uploaded=true" >> "$GITHUB_OUTPUT"
- name: Build Lambda layer
run: |
set -e
rm -rf layer
mkdir -p layer/python
# Install the wheel we just built + the identity extras' deps
# so the layer carries argon2-cffi, cryptography, pyjwt.
pip install --target layer/python/ \
"dist/nova-${{ steps.ver.outputs.version }}-*.whl" \
argon2-cffi cryptography pyjwt
( cd layer && zip -r ../nova-layer.zip python/ )
ls -lh nova-layer.zip
- name: Publish Lambda layer
id: layer
run: |
set -e
ARN=$(aws lambda publish-layer-version \
--layer-name nova-cli \
--zip-file fileb://nova-layer.zip \
--compatible-runtimes python3.12 \
--compatible-architectures x86_64 \
--description "nova-cli v${{ steps.ver.outputs.version }}" \
--query LayerVersionArn --output text)
echo "arn=$ARN" >> "$GITHUB_OUTPUT"
echo "Published Lambda layer: $ARN"
- name: Record SSM version↔ARN mapping (CAP-035)
run: |
set -e
aws ssm put-parameter \
--name /nova/layer/nova-cli/version \
--value "${{ steps.ver.outputs.version }}:${{ steps.layer.outputs.arn }}" \
--type String --overwrite
echo "SSM /nova/layer/nova-cli/version = ${{ steps.ver.outputs.version }}:${{ steps.layer.outputs.arn }}"
- name: Fail job if either publish failed (REQ-323 AC)
if: ${{ steps.wheel.outputs.uploaded != 'true' || steps.layer.outputs.arn == '' }}
run: |
echo "FAIL: wheel uploaded=${{ steps.wheel.outputs.uploaded }} layer_arn=${{ steps.layer.outputs.arn }}"
exit 1
-69
View File
@@ -1,69 +0,0 @@
# Nova AWS key rotation — platform-managed scheduled pipeline (SPEC §5.9)
#
# Rotates the NOVA_AWS_* static key daily (no long-lived keys in the steady
# state). v0.2 scope: the mechanism must exist (SPEC §5.9); the v0.2 deploy
# uses the currently-active key. The rotation is best-effort + idempotent
# (scripts/rotate_spike_key.sh deactivates the old key only after the new
# key propagates to the consumer's Actions secret store).
#
# Auth: the rotation uses the CURRENT NOVA_AWS_* key to authenticate to IAM
# (the root account 581513795199 can rotate its own keys — confirmed by the
# bootstrap). The aws-actions/configure-aws-credentials@v4 step uses the
# static-key path (no OIDC role-to-assume); the long-lived key rotates
# itself, which is the bootstrap-exception documented in §5.9.
#
# Forge coords (base URL / owner / consumer repo) are sourced from
# repository secrets — NOVA_FORGE_BASE_URL, NOVA_FORGE_OWNER,
# NOVA_CONSUMER_REPO — so the synced workflow file stays forge-agnostic
# (REQ-230). The rotation script uploads the new key to the consumer's
# Actions secret store (the consumer whose deploy.yml consumes NOVA_AWS_*
# via secrets: inherit).
name: nova-rotate-aws-key
on:
schedule:
- cron: "0 0 * * *" # daily at 00:00 UTC
workflow_dispatch:
permissions:
id-token: write
contents: read
jobs:
rotate:
name: Rotate NOVA_AWS_* static key
runs-on: ubuntu-latest
steps:
- name: Check out Nova platform repo
uses: actions/checkout@v4
- name: Configure AWS credentials (bootstrap root creds for IAM key rotation)
uses: aws-actions/configure-aws-credentials@v4
with:
aws-region: ${{ secrets.AWS_DEFAULT_REGION || 'us-east-1' }}
access-key-id: ${{ secrets.NOVA_AWS_ACCESS_KEY_ID }}
secret-access-key: ${{ secrets.NOVA_AWS_SECRET_ACCESS_KEY }}
- name: Install Python deps (boto3 for the rotation script)
run: |
python3 -m pip install --break-system-packages --quiet boto3
- name: Run the key rotation script
env:
# aws-actions/configure-aws-credentials exports AWS_ACCESS_KEY_ID /
# AWS_SECRET_ACCESS_KEY; the rotation script reads the bootstrap
# creds via NOVA_BOOTSTRAP_AWS_* (its dual-read contract, D-034).
# Map the standard AWS_* exports onto the script's expected vars.
NOVA_BOOTSTRAP_AWS_ACCESS_KEY_ID: ${{ env.AWS_ACCESS_KEY_ID }}
NOVA_BOOTSTRAP_AWS_SECRET_ACCESS_KEY: ${{ env.AWS_SECRET_ACCESS_KEY }}
# Forge + consumer coords come from repository secrets (REQ-230 —
# no forge hostnames/orgs hardcoded in the synced workflow file).
# NOVA_FORGE_TOKEN holds the forge API token (set equal to the
# existing forge token as a one-time secret setup).
NOVA_FORGE_TOKEN: ${{ secrets.NOVA_FORGE_TOKEN }}
NOVA_FORGE_BASE_URL: ${{ secrets.NOVA_FORGE_BASE_URL }}
NOVA_FORGE_OWNER: ${{ secrets.NOVA_FORGE_OWNER }}
NOVA_CONSUMER_REPO: ${{ secrets.NOVA_CONSUMER_REPO }}
AWS_DEFAULT_REGION: ${{ secrets.AWS_DEFAULT_REGION || 'us-east-1' }}
run: |
bash scripts/rotate_spike_key.sh
-43
View File
@@ -1,43 +0,0 @@
# Nova Slides Render — re-renders presentation deck when source files change.
# REQ-273: install python-pptx, pin CLI versions, stage HTML + both PPTX +
# base64-inlined images.
name: Nova Slides Render
on:
push:
paths:
- 'docs/presentations/**'
- 'scripts/render_slides.sh'
- 'scripts/inline_images.py'
- 'scripts/render_pptx.py'
- 'pyproject.toml'
workflow_dispatch:
jobs:
render:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with: { fetch-depth: 0 }
- uses: actions/setup-node@v4
with: { node-version: '20' }
- uses: actions/setup-python@v5
with:
python-version: '3.10'
- name: Install python-pptx (slides extra)
run: pip install -e ".[slides]"
- name: Install + pin render CLIs
run: |
npx --yes @marp-team/marp-cli@4.5.0 --version
npx --yes @mermaid-js/mermaid-cli@11.16.0 --version
- name: Render slides
run: bash scripts/render_slides.sh
- name: Commit rendered artifacts
run: |
git config user.name "nova-slides-bot"
git config user.email "bot@nova.local"
git add docs/presentations/*.html \
docs/presentations/*.pptx \
docs/presentations/*-python.pptx \
docs/presentations/assets/png/*.png
git diff --cached --quiet || git commit -m "chore(slides): re-render deck [skip ci]"
git push
+4 -2
View File
@@ -5,8 +5,10 @@ platform. 3 are generated from `workflows-src/<name>`; 4 are GitHub-only.
## Shared workflows (generated from source) ## Shared workflows (generated from source)
These 3 are generated from `workflows-src/<name>`. Run `python3 scripts/sync_workflows.py --check` to verify These 3 are generated from `workflows-src/<name>`. D-232 (v1.29): the
no drift. byte-identical forge-parity generator (`scripts/sync_workflows.py`) was
removed with the dev-forge parity retirement — the `workflows-src/`
copies remain as the source of truth but are no longer auto-synced.
| Workflow | Trigger | Inputs | Required Secrets | Purpose | | Workflow | Trigger | Inputs | Required Secrets | Purpose |
|----------|---------|--------|------------------|---------| |----------|---------|--------|------------------|---------|
+21
View File
@@ -22,6 +22,27 @@ on:
branches: [main] branches: [main]
jobs: jobs:
forge-parity-disabled:
name: forge_parity_disabled
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Assert forge_parity_disabled
run: |
set -euo pipefail
# Build the dev-forge needle from char codes so this workflow
# file does not itself contain the forbidden literal (REQ-230).
needle="$(printf '\x67\x69\x74\x65\x61')"
if [ -d ".${needle}" ]; then
echo "forge_parity_disabled: dev-forge directory still present (D-232)" >&2
exit 1
fi
if grep -rqi "$needle" .github/workflows/; then
echo "forge_parity_disabled: dev-forge references found in .github/workflows/ (D-232)" >&2
exit 1
fi
echo "forge_parity_disabled: OK"
lint: lint:
name: Lint name: Lint
runs-on: ubuntu-latest runs-on: ubuntu-latest
+62
View File
@@ -2,6 +2,15 @@
Backing logic for ``nova idp setup``. The CLI (``nova/idp/setup.py``) Backing logic for ``nova idp setup``. The CLI (``nova/idp/setup.py``)
is a thin ≤50-line delegate to this module (CAP-034). is a thin ≤50-line delegate to this module (CAP-034).
From v1.29 (REQ-369, spec §7.5) the active provisioning path is
``terraform apply`` in the ``nova-platform-ops`` checkout. The CFN
template generated here is archived as read-only reference in
``docs/archive/nova-idp-cfn-v1.28.md``; :func:`generate_and_deploy`
(the former CFN deploy path) emits a ``DeprecationWarning`` and is
retained only as a fallback when terraform is absent from PATH.
:func:`terraform_apply` and :func:`terraform_plan` are the new
preferred paths.
""" """
from __future__ import annotations from __future__ import annotations
@@ -9,13 +18,21 @@ from __future__ import annotations
import importlib.util import importlib.util
import json import json
import os import os
import shutil
import subprocess import subprocess
import sys import sys
import tempfile import tempfile
import warnings
from pathlib import Path from pathlib import Path
from typing import Any from typing import Any
_CFN_ARCHIVE_REF = (
"CFN path is archived; install terraform or use nova-platform-ops. "
"See docs/archive/nova-idp-cfn-v1.28.md."
)
def _load_cfn(): def _load_cfn():
"""Load core/lambda/nova_idp_cfn.py via importlib (`lambda` is reserved).""" """Load core/lambda/nova_idp_cfn.py via importlib (`lambda` is reserved)."""
p = Path(__file__).parent / "nova_idp_cfn.py" p = Path(__file__).parent / "nova_idp_cfn.py"
@@ -71,6 +88,13 @@ def generate_and_deploy(
) -> dict[str, Any]: ) -> dict[str, Any]:
"""Generate the CFN template + deploy (REQ-341, NFR-10 y/N approval). """Generate the CFN template + deploy (REQ-341, NFR-10 y/N approval).
.. deprecated:: v1.29
The active path is :func:`terraform_apply` (REQ-369, spec §7.5).
This CFN deploy path is archived as read-only reference in
``docs/archive/nova-idp-cfn-v1.28.md`` and retained only as a
fallback when terraform is absent from PATH. It emits a
``DeprecationWarning`` on every non-dry-run invocation.
Args: Args:
public_jwks_domain: optional custom JWKS domain. public_jwks_domain: optional custom JWKS domain.
dry_run: if True, print the resource summary only (no deploy). dry_run: if True, print the resource summary only (no deploy).
@@ -84,6 +108,7 @@ def generate_and_deploy(
summary = resource_summary(template) summary = resource_summary(template)
if dry_run: if dry_run:
return {"template": template, "summary": summary, "deployed": False} return {"template": template, "summary": summary, "deployed": False}
warnings.warn(_CFN_ARCHIVE_REF, DeprecationWarning, stacklevel=2)
# NFR-10: explicit y/N approval before cloudformation deploy. # NFR-10: explicit y/N approval before cloudformation deploy.
print("Resource summary:") print("Resource summary:")
for rtype, count in sorted(summary.items()): for rtype, count in sorted(summary.items()):
@@ -123,6 +148,43 @@ def generate_and_deploy(
return {"template": template, "summary": summary, "deployed": deployed} return {"template": template, "summary": summary, "deployed": deployed}
def terraform_apply(*, auto_approve: bool = True) -> dict[str, Any]:
"""Delegate provisioning to ``terraform apply`` (REQ-369, spec §7.5).
The operator runs this from the ``nova-platform-ops`` checkout root
(where the Terraform modules live). This function shells out to
``terraform`` on PATH; the caller (``nova/idp/setup.py``) is
responsible for the ``shutil.which("terraform")`` gate.
Args:
auto_approve: pass ``-auto-approve`` (default True; the y/N gate
is the operator's PR review in nova-platform-ops).
Returns:
``{"deployed": bool, "returncode": int, "command": [str]}``.
"""
cmd = ["terraform", "apply"]
if auto_approve:
cmd.append("-auto-approve")
proc = subprocess.run(cmd)
return {"deployed": proc.returncode == 0, "returncode": proc.returncode, "command": cmd}
def terraform_plan() -> dict[str, Any]:
"""Delegate verification to ``terraform plan`` (REQ-369, spec §7.5).
Reports the diff between the live stack and the Terraform source in
the ``nova-platform-ops`` checkout. The caller is responsible for
the ``shutil.which("terraform")`` gate.
Returns:
``{"passed": bool, "returncode": int, "command": [str]}``.
"""
cmd = ["terraform", "plan"]
proc = subprocess.run(cmd)
return {"passed": proc.returncode == 0, "returncode": proc.returncode, "command": cmd}
def verify() -> dict[str, Any]: def verify() -> dict[str, Any]:
"""Run the KMS round-trip verification (REQ-340 --verify). """Run the KMS round-trip verification (REQ-340 --verify).
+551
View File
@@ -0,0 +1,551 @@
# Archived: Nova IdP CloudFormation Template (v1.28)
> **Archived at v1.29.0** — the active path is `terraform apply` in
> `nova-platform-ops`. Deletion is a follow-up after Terraform parity
> is verified (REQ-369 AC 3, spec §7.5). This template is read-only
> reference; do not modify it. The `nova idp setup --apply` command
> now delegates to `terraform apply` (see `nova/idp/setup.py`).
This is the verbatim output of `generate_template()` from
`core/lambda/nova_idp_cfn.py` (the composition of the DynamoDB snippet
from `core/lambda/nova_idp_auth_cfn.py` + the KMS signing key + the
three IdP Lambdas + their IAM roles + function URLs). It was the active
provisioning path through v1.28; from v1.29 the operator runs
`terraform apply` in the `nova-platform-ops` checkout and `nova idp
setup --apply` delegates to it. The CFN generation code is retained as
read-only reference and emits a `DeprecationWarning` when the CFN
fallback path is invoked (terraform absent from PATH).
```json
{
"Resources": {
"NovaUsersTable": {
"Type": "AWS::DynamoDB::Table",
"Properties": {
"TableName": "nova-users",
"BillingMode": "PAY_PER_REQUEST",
"KeySchema": [
{
"AttributeName": "user_id",
"KeyType": "HASH"
}
],
"AttributeDefinitions": [
{
"AttributeName": "user_id",
"AttributeType": "S"
},
{
"AttributeName": "email",
"AttributeType": "S"
}
],
"GlobalSecondaryIndexes": [
{
"IndexName": "email-index",
"KeySchema": [
{
"AttributeName": "email",
"KeyType": "HASH"
}
],
"Projection": {
"ProjectionType": "ALL"
}
}
],
"PointInTimeRecoverySpecification": {
"PointInTimeRecoveryEnabled": true
},
"AttributeShape": {
"user_id": "String",
"email": "String",
"password_hash": "String",
"owner": "String",
"roles": "List",
"created_at": "String"
}
}
},
"NovaSessionsTable": {
"Type": "AWS::DynamoDB::Table",
"Properties": {
"TableName": "nova-sessions",
"BillingMode": "PAY_PER_REQUEST",
"KeySchema": [
{
"AttributeName": "session_id",
"KeyType": "HASH"
}
],
"AttributeDefinitions": [
{
"AttributeName": "session_id",
"AttributeType": "S"
},
{
"AttributeName": "user_id",
"AttributeType": "S"
}
],
"GlobalSecondaryIndexes": [
{
"IndexName": "user_id-index",
"KeySchema": [
{
"AttributeName": "user_id",
"KeyType": "HASH"
}
],
"Projection": {
"ProjectionType": "ALL"
}
}
],
"TimeToLiveSpecification": {
"AttributeName": "expires_at",
"Enabled": true
},
"AttributeShape": {
"session_id": "String",
"user_id": "String",
"expires_at": "String (epoch seconds, TTL)",
"created_at": "String (ISO-8601)"
}
}
},
"NovaPasswordResetsTable": {
"Type": "AWS::DynamoDB::Table",
"Properties": {
"TableName": "nova-password-resets",
"BillingMode": "PAY_PER_REQUEST",
"KeySchema": [
{
"AttributeName": "reset_token",
"KeyType": "HASH"
}
],
"AttributeDefinitions": [
{
"AttributeName": "reset_token",
"AttributeType": "S"
}
],
"TimeToLiveSpecification": {
"AttributeName": "expires_at",
"Enabled": true
},
"AttributeShape": {
"reset_token": "String",
"user_id": "String",
"expires_at": "String (epoch seconds, TTL; 15 min)"
}
}
},
"NovaPatsTable": {
"Type": "AWS::DynamoDB::Table",
"Properties": {
"TableName": "nova-pats",
"BillingMode": "PAY_PER_REQUEST",
"KeySchema": [
{
"AttributeName": "jti",
"KeyType": "HASH"
}
],
"AttributeDefinitions": [
{
"AttributeName": "jti",
"AttributeType": "S"
},
{
"AttributeName": "sub",
"AttributeType": "S"
},
{
"AttributeName": "pat_hash",
"AttributeType": "S"
}
],
"GlobalSecondaryIndexes": [
{
"IndexName": "sub-index",
"KeySchema": [
{
"AttributeName": "sub",
"KeyType": "HASH"
}
],
"Projection": {
"ProjectionType": "ALL"
}
},
{
"IndexName": "pat_hash-index",
"KeySchema": [
{
"AttributeName": "pat_hash",
"KeyType": "HASH"
}
],
"Projection": {
"ProjectionType": "ALL"
}
}
],
"TimeToLiveSpecification": {
"AttributeName": "expires_at",
"Enabled": true
},
"AttributeShape": {
"jti": "String (PK)",
"sub": "String (GSI1; subject / user_id)",
"pat_hash": "String (GSI2; SHA-256 of the PAT for lookup)",
"status": "String (active|revoked)",
"issued_at": "String (ISO-8601)",
"expires_at": "String (epoch seconds, TTL)",
"revoked_at": "String (ISO-8601, present iff status=revoked)",
"claims": "Map (JWT claims payload)"
}
}
},
"NovaOidcSigningKey": {
"Type": "AWS::KMS::Key",
"Properties": {
"Description": "Nova OIDC token signing key (REQ-337, ECC_NIST_P256)",
"KeySpec": "ECC_NIST_P256",
"KeyUsage": "SIGN_VERIFY",
"KeyPolicy": {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": {
"Fn::Sub": "arn:aws:iam::${AWS::AccountId}:root"
}
},
"Action": "kms:*",
"Resource": "*"
}
]
}
}
},
"NovaOidcSigningKeyAlias": {
"Type": "AWS::KMS::Alias",
"Properties": {
"AliasName": "alias/nova-oidc-signing",
"TargetKeyId": {
"Fn::GetAtt": "NovaOidcSigningKey.Arn"
}
}
},
"NovaIdpAuthRole": {
"Type": "AWS::IAM::Role",
"Properties": {
"AssumeRolePolicyDocument": {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"Service": {
"Fn::Sub": "lambda.${AWS::Region}.amazonaws.com"
}
},
"Action": "sts:AssumeRole"
}
]
},
"Policies": [
{
"PolicyName": "NovaIdpAuthPolicy",
"PolicyDocument": {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"logs:CreateLogStream",
"logs:PutLogEvents"
],
"Resource": {
"Fn::Sub": "arn:aws:logs:${AWS::Region}:${AWS::AccountId}:log-group:/aws/lambda/*"
}
},
{
"Effect": "Allow",
"Action": [
"logs:CreateLogGroup"
],
"Resource": {
"Fn::Sub": "arn:aws:logs:${AWS::Region}:${AWS::AccountId}:*"
}
},
{
"Effect": "Allow",
"Action": [
"dynamodb:GetItem",
"dynamodb:PutItem",
"dynamodb:UpdateItem",
"dynamodb:Query",
"dynamodb:DeleteItem"
],
"Resource": [
{
"Fn::Sub": "arn:aws:dynamodb:${AWS::Region}:${AWS::AccountId}:table/nova-users"
},
{
"Fn::Sub": "arn:aws:dynamodb:${AWS::Region}:${AWS::AccountId}:table/nova-sessions"
},
{
"Fn::Sub": "arn:aws:dynamodb:${AWS::Region}:${AWS::AccountId}:table/nova-password-resets"
}
]
}
]
}
}
]
}
},
"NovaIdpTokenVendRole": {
"Type": "AWS::IAM::Role",
"Properties": {
"AssumeRolePolicyDocument": {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"Service": {
"Fn::Sub": "lambda.${AWS::Region}.amazonaws.com"
}
},
"Action": "sts:AssumeRole"
}
]
},
"Policies": [
{
"PolicyName": "NovaIdpTokenVendPolicy",
"PolicyDocument": {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"logs:CreateLogStream",
"logs:PutLogEvents"
],
"Resource": {
"Fn::Sub": "arn:aws:logs:${AWS::Region}:${AWS::AccountId}:log-group:/aws/lambda/*"
}
},
{
"Effect": "Allow",
"Action": [
"logs:CreateLogGroup"
],
"Resource": {
"Fn::Sub": "arn:aws:logs:${AWS::Region}:${AWS::AccountId}:*"
}
},
{
"Effect": "Allow",
"Action": [
"dynamodb:GetItem",
"dynamodb:PutItem",
"dynamodb:UpdateItem",
"dynamodb:Query",
"dynamodb:DeleteItem"
],
"Resource": [
{
"Fn::Sub": "arn:aws:dynamodb:${AWS::Region}:${AWS::AccountId}:table/nova-pats"
}
]
},
{
"Effect": "Allow",
"Action": [
"kms:Sign",
"kms:GetPublicKey",
"kms:DescribeKey"
],
"Resource": {
"Fn::GetAtt": "NovaOidcSigningKey.Arn"
}
}
]
}
}
]
}
},
"NovaIdpJwksRole": {
"Type": "AWS::IAM::Role",
"Properties": {
"AssumeRolePolicyDocument": {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"Service": {
"Fn::Sub": "lambda.${AWS::Region}.amazonaws.com"
}
},
"Action": "sts:AssumeRole"
}
]
},
"Policies": [
{
"PolicyName": "NovaIdpJwksPolicy",
"PolicyDocument": {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"logs:CreateLogStream",
"logs:PutLogEvents"
],
"Resource": {
"Fn::Sub": "arn:aws:logs:${AWS::Region}:${AWS::AccountId}:log-group:/aws/lambda/*"
}
},
{
"Effect": "Allow",
"Action": [
"logs:CreateLogGroup"
],
"Resource": {
"Fn::Sub": "arn:aws:logs:${AWS::Region}:${AWS::AccountId}:*"
}
},
{
"Effect": "Allow",
"Action": [
"kms:Sign",
"kms:GetPublicKey",
"kms:DescribeKey"
],
"Resource": {
"Fn::GetAtt": "NovaOidcSigningKey.Arn"
}
}
]
}
}
]
}
},
"NovaIdpAuthFunction": {
"Type": "AWS::Lambda::Function",
"Properties": {
"Handler": "nova_idp_auth.lambda_handler",
"Runtime": "python3.12",
"MemorySize": 512,
"Timeout": 30,
"Role": {
"Fn::GetAtt": [
"NovaIdpAuthRole",
"Arn"
]
},
"Environment": {
"Variables": {
"NOVA_USERS_TABLE": "nova-users",
"NOVA_SESSIONS_TABLE": "nova-sessions",
"NOVA_PASSWORD_RESETS_TABLE": "nova-password-resets",
"NOVA_PATS_TABLE": "nova-pats"
}
},
"Code": {
"ZipFile": "def lambda_handler(event, context):\n return {}"
}
}
},
"NovaIdpTokenVendFunction": {
"Type": "AWS::Lambda::Function",
"Properties": {
"Handler": "nova_idp_token_vend.lambda_handler",
"Runtime": "python3.12",
"MemorySize": 512,
"Timeout": 30,
"Role": {
"Fn::GetAtt": [
"NovaIdpTokenVendRole",
"Arn"
]
},
"Environment": {
"Variables": {
"NOVA_USERS_TABLE": "nova-users",
"NOVA_SESSIONS_TABLE": "nova-sessions",
"NOVA_PASSWORD_RESETS_TABLE": "nova-password-resets",
"NOVA_PATS_TABLE": "nova-pats",
"NOVA_OIDC_KMS_KEY_ID": "alias/nova-oidc-signing"
}
},
"Code": {
"ZipFile": "def lambda_handler(event, context):\n return {}"
}
}
},
"NovaIdpJwksFunction": {
"Type": "AWS::Lambda::Function",
"Properties": {
"Handler": "nova_idp_jwks.lambda_handler",
"Runtime": "python3.12",
"MemorySize": 256,
"Timeout": 30,
"Role": {
"Fn::GetAtt": [
"NovaIdpJwksRole",
"Arn"
]
},
"Environment": {
"Variables": {
"NOVA_OIDC_KMS_KEY_ID": "alias/nova-oidc-signing"
}
},
"Code": {
"ZipFile": "def lambda_handler(event, context):\n return {}"
}
}
},
"NovaIdpAuthUrl": {
"Type": "AWS::Lambda::Url",
"Properties": {
"TargetFunction": {
"Ref": "NovaIdpAuthFunction"
},
"AuthType": "AWS_IAM"
}
},
"NovaIdpTokenVendUrl": {
"Type": "AWS::Lambda::Url",
"Properties": {
"TargetFunction": {
"Ref": "NovaIdpTokenVendFunction"
},
"AuthType": "AWS_IAM"
}
},
"NovaIdpJwksUrl": {
"Type": "AWS::Lambda::Url",
"Properties": {
"TargetFunction": {
"Ref": "NovaIdpJwksFunction"
},
"AuthType": "NONE"
}
}
}
}
```
+747
View File
@@ -0,0 +1,747 @@
# Operator Guide — Nova Platform Ops (`nova-platform-ops`)
> **REQ-OPS-GUIDE** — the operator-facing runbook for the
> `nova-platform-ops` Terraform repo. This is the verification surface
> for the covered-reference REQs (355-366, 371): their cutover gates
> (M1/M1.5/M2) are documented in §18 below, and each REQ has a
> **"Result" column** that the operator fills in after running the gate.
> P6 audit verifies every covered-reference REQ has a non-empty, green
> Result (grill CF-2/G-5). **HARD P6 ship gate:** §3 contains the
> operator-attested "M1.5 Verification Gate Result" row (grill
> CF-1/G-2.1) — the milestone does not ship until that row is filled.
>
> Audience: platform operators / SREs running the live Nova platform in
> AWS account `581513795199`. For the developer auth flows, see
> `docs/developer-guide-auth.md`; for the legacy CloudFormation path,
> see `docs/archive/nova-idp-cfn-v1.28.md`.
## 1. Overview + reposplit rationale
Nova's platform operations live in a dedicated, Gitea-private Terraform
repository — `nova-platform-ops` — separate from the engineering repo
`acdl/acdl`. The split is grounded in Vision §4 (Domain Boundaries):
> *The platform begins where the artifact is compiled and ends where it
> runs in production under operational guardrails.*
That is two distinct disciplines with two distinct ownership surfaces:
| Discipline | Ends | Begins | Repo | Surface |
|------------|------|--------|------|---------|
| Engineering | at the compiled artifact | — | `acdl/acdl` (GitHub) | `publish.yml` + GitHub Releases |
| Operations | — | at the live platform under guardrails | `nova-platform-ops` (Gitea-private) | Terraform modules |
**Scope split (CLARIFY Q-P1, D-232):**
- `acdl/acdl` authors `publish.yml` (the artifact publish pipeline) +
the artifacts themselves (Lambda zip, layer wheel, Python wheel, ECR
container image with the static `kj` binary). Each tag `v1.29.x`
produces a GitHub Release with SHA-256-verified artifacts (REQ-354).
- `nova-platform-ops` authors the Terraform modules
(`networking`/`kms`/`identity`/`contract-ingest`/`bootstrap`/`edge`)
that bring those artifacts live in `581513795199`.
The handoff between the two repos is the **tag-pin** (D-235):
`nova-platform-ops` declares `local.nova_platform_version` +
`local.kj_source_sha` and resolves substrates through a single
`data.aws_ecr_image.kj_image`. The engineering repo never knows which
tag is live; the ops repo never authors artifacts. Vision §6
immutability + Vision §5 narrow interfaces.
The covered-reference REQs (355-366, 371) are authored in
`nova-platform-ops` (out-of-band). CIAgent in `acdl` tracks them for
milestone completeness; their verification surface is the cutover
gates in §18 of this guide.
## 2. Day-0 cutover procedure (M1)
The M1 cutover is the one-time conversion of the live AWS account
`581513795199` from CloudFormation-managed (or manually-created)
resources to Terraform-managed resources in `nova-platform-ops`. It is
conditional on the M1.5 verification gate passing (§3, Q7 carry-forward,
D-236).
The 10-step Journey 2 (spec §3.2):
1. **Create `nova-platform-ops` in Gitea** — private (`private: true`,
OPER-PRIV, REQ-359), no GitHub mirror. The repo is operator-owned;
CIAgent has no presence there.
2. **Commit the initial Terraform structure** — the module tree
(`networking`/`kms`/`identity`/`contract-ingest`/`bootstrap`/`edge`)
+ `importable-resources.tf` (§12) + `versions.tf` + `backend.tf`
(S3 state in the imported bucket).
3. **`terraform init`** — initialize the S3 backend against the
state bucket (`nova-tfstate-581513795199-us-east-1`, imported in
step 5). The bucket is created manually once (operator's secure
scratch, spec §7.1, D-235) before Terraform adopts it.
4. **`terraform import` for existing live resources** — adopt the
resources that already exist in `581513795199` into Terraform state
without recreating them. The import map is in
`importable-resources.tf` (§12):
- `aws_s3_bucket.nova_tfstate``nova-tfstate-581513795199-us-east-1`
- `aws_dynamodb_table.nova_contracts``nova-contracts`
- `aws_dynamodb_table.nova_change_requests``nova-change-requests`
- `aws_dynamodb_table.nova_outbox``nova-outbox`
- `aws_iam_role.acdl_act_runner``acdl-act-runner-role`
- per-stack CMKs (KMS keys)
Re-import exits non-zero with `resource_already_imported`
(IMPORT-IDEMPOTENT, REQ-361). CI import treats this as idempotent
success — the import workflow greps the error stream + exits 0 on
that string.
5. **(state bucket is imported in step 4)** — listed here for sequence
clarity; the S3 state bucket is the first import because the
backend depends on it.
6. **Add new resources** that do not yet exist in the account:
- KMS alias `alias/nova-oidc-signing` (§9, D-234).
- Identity DynamoDB tables: `nova-users`, `nova-sessions`,
`nova-pats` (§11).
- JWKS Function URL with `AuthType: AWS_IAM` (NOT `NONE` — §10,
INV-18, RESEARCH §4 critical pitfall).
- CloudFront distribution + OAC + WAF WebACL + ACM certificate +
Route53 alias (§14, REQ-364/365/366).
7. **`terraform plan`** — expect zero diff on the imported resources
(they are already in their desired state) + a pure-add diff on the
new resources. If the plan shows a diff on an imported resource,
the import map or the Terraform resource block is wrong — fix
before apply. **DRIFT-DETECT (REQ-356):** `terraform plan` exit 2
(drift) fails the apply workflow; manual reconciliation required.
8. **HITL approval**`terraform apply` against `main` requires a
Gitea Actions approval from a user **distinct from the PR author**
(TFM-HITL, REQ-357, INV-3). Self-approval is rejected:
`gitea.triggering_actor == pull_request.user.login` → apply fails
closed (M1.5 item 11).
9. **`terraform apply`** — on approval, the apply creates the new
resources + adopts the imported ones. Smoke test (step 10) before
declaring M1 done.
10. **Smoke test + CFN→Terraform conversion** — verify the live
account is in the desired state (JWKS reachable via CloudFront,
KMS round-trip, ABAC fail-closed). The CFN template in
`acdl/acdl/nova/idp/setup.py` is archived to
`docs/archive/nova-idp-cfn-v1.28.md` as read-only reference
(REQ-369); the active path is now `terraform apply` in
`nova-platform-ops`.
## 3. M1.5 verification gate (12-item spike)
The M1.5 gate is the 12-item spike from PLAN.md "Happy Path" (spec
§3.3 Edge 5 items 1-8 + grill CF-1 items 9-12). **3 consecutive green
rebuilds are required** in `nova-platform-ops` CI.
The 12 items:
1. `kj` v0.0.3 (pinned SHA in `platform/abac/kj-version.txt`) compiles
with `CGO_ENABLED=0 GOOS=linux GOARCH=amd64`.
2. Resulting binary reports `file kj → ELF 64-bit LSB executable,
x86-64, statically linked, no shared library` (KJ-STATIC).
3. Container image built from
`public.ecr.aws/lambda/python:3.12-al2023` with the binary copied
to `/opt/kj/kj`, `chmod 0555`, owned by `sbx_user:1051`.
4. Lambda runtime `python3.12` executes
`nova_idp_token_vend.handler`; the handler invokes
`subprocess.run(['/opt/kj/kj', 'apply', ...])` and parses stdout
JSON.
5. `tests/test_idp_auth.py` passes against the live image in moto-DDB.
6. `tests/test_kms_roundtrip.py` passes against the live KMS key
`alias/nova-oidc-signing` (REQ-362 path — covered-reference).
7. End-to-end: known PAT → known ABAC-allowed action → signed OIDC
token → `jose` verification → green. Known PAT + ABAC-denied action
→ 403 with deny reason logged (INV-17 fail-closed).
8. Image URI is recorded in Terraform state and in this operator
guide (§18, REQ-371 Result row).
9. **(grill CF-1) JWKS-EDGE-ONLY:** direct JWKS Function URL GET
(bypassing CloudFront) returns **403**; via-CloudFront GET returns
**200** (INV-18). Proves `AuthType: AWS_IAM` + OAC pinning.
10. **(grill CF-1) IAM-NARROW:** `aws iam get-role-policy` on the
Gitea OIDC role asserts no `Action: "*"` and no `Resource: "*"`
(REQ-360).
11. **(grill CF-1) TFM-HITL:** a `terraform apply`
`workflow_dispatch` triggered by the PR author is **rejected**
(exit non-zero); a dispatch by a distinct user proceeds (REQ-357).
12. **(grill CF-1) rollback drill:** revert `nova_platform_version`
pin → `terraform apply` → assert the prior ECR digest runs
(D-236, guards against ECR tag mutability).
If items 1-7 fail three consecutive rebuilds, M2a activates (§5,
REQ-363b Fargate toggle) with the same ECR image — no warmup hit
because the standby is always running the same digest (KJ-LOCKSTEP).
### HARD P6 ship gate (grill CF-1/G-2.1)
P6 must not ship `v1.28.6` until the operator attests the M1.5 result
in the row below. The operator fills this in **after** the gate passes
3 consecutive green rebuilds in `nova-platform-ops` CI. P6 audit
verifies the row exists + is non-empty.
#### M1.5 Verification Gate Result
| Rebuild # | Run ID / commit SHA | All 12 items green? | Attestor identity | Attested at (UTC) |
|-----------|---------------------|---------------------|-------------------|-------------------|
| 1 | _(operator fills)_ | _(yes/no)_ | _(operator fills)_ | _(operator fills)_ |
| 2 | _(operator fills)_ | _(yes/no)_ | _(operator fills)_ | _(operator fills)_ |
| 3 | _(operator fills)_ | _(yes/no)_ | _(operator fills)_ | _(operator fills)_ |
> **P6 audit rule:** all three rows must be present, all 12 items
> green on each, the three run IDs/SHAs distinct (consecutive
> rebuilds, not one run copied thrice), and the attestor identity
> non-empty. Empty or red → P6 blocks → escalate.
## 4. M2 operational handoff loop
M2 is the steady-state operational loop for rolling out an engineering
change after M1.5 is green. The loop is the tag-pin bump → plan →
HITL → apply cycle (D-235, D-238).
1. **Tag-pin bump** — the operator opens a PR in `nova-platform-ops`
bumping `local.nova_platform_version` (e.g. `v1.29.3` → `v1.29.4`)
+ `local.kj_source_sha` (the `kj` source SHA from
`platform/abac/kj-version.txt` at the new tag). Both pins move
together — there is one ECR image identity (KJ-LOCKSTEP, REQ-371).
2. **`terraform plan`** — CI runs `terraform plan` on the PR. The
KJ-LOCKSTEP precondition (a `lifecycle.precondition` on both
image-bearing resources — the Lambda `image_uri` and the Fargate
task `container_definitions[0].image`) checks that both
`image_uri` attributes resolve to the **same ECR digest** via
`data.aws_ecr_image.kj_image`. If the two diverge, the plan fails
closed — no second pipeline, no second SHA pin (D-238).
3. **HITL approval** — a Gitea Actions approver **distinct from the
PR author** approves the apply (TFM-HITL, REQ-357). Self-approval
is rejected (M1.5 item 11).
4. **`terraform apply`** — on approval, the apply updates both
`aws_lambda_function.nova_idp_token_vend.image_uri` and
`aws_ecs_task_definition.kj.container_definitions[0].image` to the
same ECR digest. The Lambda image + the Fargate task redeploy to
the same digest in one apply. Zero diff on KMS, DDB, IAM, edge
(the only change is the image reference).
**Verification:** after the apply, `aws lambda get-function
--function-name nova-idp-token-vend --query Configuration.Code.ImageUri`
and `aws ecs describe-tasks` on the Fargate task both report the same
digest. This is the M2 acceptance gate (PLAN §UX Acceptance Criteria
3) + the REQ-371 Result row in §18.
## 5. M2a Fargate activation (conditional)
M2a activates **only if M1.5 fails 3 consecutive rebuilds** (D-236).
It is the REQ-363b Fargate toggle — an always-warm minimal Fargate
standby running the **same ECR image** as the Lambda (KJ-LOCKSTEP).
Because the standby is always running the same digest as the Lambda,
activating M2a is **not** a warmup hit — the standby is already
serving `GET /health → 200` every 10s (KJ-WARMUP-HEALTH, §15). The
toggle repoints token-vend traffic from the Lambda to the Fargate
task; no cold start, no image pull.
If both the Lambda path and the Fargate path fail (M1.5 items 1-7
fail on both substrates), the operator escalates — Nova-idp ships in
read-only partial mode (no token issuance) until `kj` is verified
(Q7 carry-forward, spec §7.7).
**Fargate sunset discipline (D-237):** the standby (~$15-20/month,
§7) may not be deleted unless REQ-363 has been green in production
for **≥30 consecutive days**. Sunset requires an architecture review.
See §15 for the health-check procedure.
## 6. Rollback procedure (D-236)
Rollback is a tag-pin revert — the same mechanism as the M2 rollout
(§4), in reverse.
1. **Revert `nova_platform_version`** in `nova-platform-ops` to the
prior tag (e.g. `v1.29.4` → `v1.29.3`). Open a PR, get HITL
approval (TFM-HITL, same as rollout).
2. **`terraform apply`** — the apply reverts both the Lambda
`image_uri` and the Fargate task `image` to the prior ECR digest.
The prior tag's artifacts remain downloadable (GitHub Releases are
append-only per tag, REQ-354 AC 2) — no artifact is re-built.
3. **Verify** the prior digest is running:
```sh
aws lambda get-function --function-name nova-idp-token-vend \
--query Configuration.Code.ImageUri --output text
# → <account>.dkr.ecr.us-east-1.amazonaws.com/nova-kj@sha256:<prior-digest>
```
This is the M1.5 item 12 rollback drill + the operational rollback
procedure. It guards against ECR tag mutability (RESEARCH §2) — the
digest is immutable even if a tag is re-pushed.
## 7. Cost section
Monthly estimate for the `nova-platform-ops` live platform in account
`581513795199` (pilot volume):
| Resource | Quantity | Est. monthly | Notes |
|----------|----------|-------------|-------|
| WAF WebACL (CloudFront-scoped) | 1 | ~$5-10 | + per-request; REQ-365 |
| Fargate standby (0.25 vCPU, 512 MB) | 1 task | ~$15-20 | REQ-363b AC 4; largest line item |
| KMS asymmetric key | 1 | ~$1 | `alias/nova-oidc-signing`, ECC_NIST_P256 |
| DynamoDB (on-demand, 6 tables) | 6 | ~$2 | §11 tables |
| Lambda invocations (3 Lambdas) | 3 | ~$2 | low pilot volume |
| ECR image storage | ~100 MB | <$1 | the `kj` image |
| S3 state bucket + access logs | 1 | <$1 | `nova-tfstate-*` |
| CloudFront + ACM + Route53 | 1 distribution | ~$1 | ACM free for CloudFront-attached |
| **Total** | | **~$30-40/month** | |
**Fargate standby is the largest line item** (~$15-20/month, REQ-363b
AC 4). It is explicitly documented here with the D-237 sunset
discipline (§5, §15): ≥30 consecutive days green before deletion +
architecture review. Do not delete the standby to save ~$15/month
without that review — it is the defensive fallback for the `kj`
substrate.
## 8. Artifact-mirror fallback (Edge 6)
When the Gitea `act_runner` in `nova-platform-ops` CI cannot reach
GitHub Releases (network partition, egress restriction, GitHub
outage), the operator mirrors the artifact bundle locally by SHA-256.
**Procedure:**
1. **Download the GitHub Release bundle** for the target tag
(`v1.29.x`) from a machine that can reach GitHub Releases:
```sh
gh release download v1.29.0 \
--repo continuous-intelligence/acdl \
--pattern 'nova-lambda-token-vend-*.zip' \
--pattern 'nova-cli-layer-*.zip' \
--pattern 'nova-*-py3-none-any.whl' \
--dir ./artifact-cache
```
2. **Verify SHA-256** against the release body (each artifact's
SHA-256 is listed in the GitHub Release body, REQ-354):
```sh
sha256sum ./artifact-cache/nova-lambda-token-vend-v1.29.0.zip
# → must match the SHA-256 in the release body
```
3. **Place the bundle in the operator's local artifact cache** — a
directory the `act_runner` can read (e.g. a Gitea-lfs-tracked path
in `nova-platform-ops`, or an S3 bucket the runner can reach).
4. **Reference by SHA-256 in the terraform variables** — the
`nova-platform-ops` Terraform accepts an override for the artifact
source: `nova_artifact_mirror_sha256 = "<sha256>"`. When set, the
`data` sources resolve from the local cache by SHA-256 instead of
from GitHub Releases. Unset → resume GitHub Releases resolution.
This fallback is for CI continuity only; the live `terraform apply`
still resolves the ECR image by digest (KJ-LOCKSTEP), which is
independent of GitHub Releases availability.
## 9. KMS rotation (D-234)
The OIDC signing key `alias/nova-oidc-signing` is provisioned with
`KeySpec: ECC_NIST_P256`, `KeyUsage: SIGN_VERIFY`, on a **90-day
rotation cadence** (matches per-stack CMK rotation per D-069).
**Verify the key spec + rotation status:**
```sh
aws kms describe-key --key-id alias/nova-oidc-signing \
--query 'KeyMetadata.[KeySpec,KeyUsage,Description]' --output text
# → ECC_NIST_P256 SIGN_VERIFY <description>
```
**Apply a rotation policy** (key re-point, not key deletion — the
alias moves to a new key while the old key stays valid during the
overlap window, §17 JWKS-ROTATION):
1. Create the new key (same spec):
```sh
NEW_KEY=$(aws kms create-key \
--key-spec ECC_NIST_P256 \
--key-usage SIGN_VERIFY \
--description "nova-oidc-signing-$(date +%Y%m%d)" \
--query KeyId --output text)
```
2. Re-point the alias:
```sh
aws kms update-alias --alias-name alias/nova-oidc-signing \
--target-key-id "$NEW_KEY"
```
3. Apply the rotation policy (the key policy grants `kms:Sign` to the
token-vend Lambda role + `kms:GetPublicKey` to the JWKS Lambda
role):
```sh
aws kms put-key-policy --key-id "$NEW_KEY" \
--policy-name default --policy file://kms-signing-key-policy.json
```
4. After the 24-hour overlap window (§17), disable + schedule deletion
of the old key:
```sh
aws kms disable-key --key-id "<old-key-id>"
aws kms schedule-key-deletion --key-id "<old-key-id>" \
--pending-window-in-days 7
```
5. Verify the new key is active: `nova idp setup --verify` (the KMS
round-trip test, REQ-362).
**Audit:** emit a `kms.key_rotated` event with `old_key_id`,
`new_key_id`, `rotated_at`.
## 10. JWKS reachability via CloudFront edge (D-233, INV-18)
The JWKS endpoint is the **only public read surface** of the live
platform (INV-18, D-233). All other platform endpoints gate with
`AuthType: AWS_IAM`. CloudFront + OAC pinning replaces direct Lambda
Function URL exposure.
**Critical pitfall (RESEARCH §4):** the JWKS Function URL
`AuthType` MUST be `AWS_IAM`, NOT `NONE`. A common mistake is to set
`AuthType: NONE` on the Function URL (thinking CloudFront is the
gate) — that exposes the JWKS endpoint directly to the internet,
bypassing OAC. The correct configuration:
| Setting | Value |
|---------|-------|
| Function URL `AuthType` | `AWS_IAM` (NOT `NONE`) |
| CloudFront OAC `OriginAccessControlOriginType` | `lambda` |
| CloudFront OAC `SigningBehavior` | `always` |
| Lambda resource policy | `lambda:InvokeFunctionUrl` scoped to the CloudFront distribution ARN |
With `AuthType: AWS_IAM` + OAC `always` signing, CloudFront signs
every origin request with SigV4; a direct Function URL request has no
SigV4 signature → 403. Only CloudFront can reach the origin.
**Verification (M1.5 item 9):**
```sh
# Via CloudFront → 200
curl -sI https://<jwks-domain>/.well-known/jwks.json | head -1
# → HTTP/2 200
# Direct Function URL → 403
curl -sI "<raw-function-url>/.well-known/jwks.json" | head -1
# → HTTP/2 403
```
If the direct Function URL returns 200, the `AuthType` is `NONE` —
fix the Terraform + re-apply before declaring M1.5 green.
## 11. PITR restore (data-engineer section)
DynamoDB point-in-time recovery (PITR) is enabled on every identity +
contract table. PITR lets you restore a table to any second in the
last **35 days** (the AWS retention window).
**Tables with PITR enabled:**
| Table | Purpose |
|-------|---------|
| `nova-contracts` | contract ingestor records |
| `nova-change-requests` | change request ledger |
| `nova-outbox` | audit outbox |
| `nova-users` | Nova-idp users (Argon2id hashes) |
| `nova-sessions` | Nova-idp sessions (TTL `expires_at`) |
| `nova-pats` | Nova-idp PATs (revocation strong-read, D-229) |
**Enable PITR (on a new/restored table — PITR does not carry over
from the source):**
```sh
aws dynamodb update-continuous-backups \
--table-name <table> \
--point-in-time-recovery-specification PointInTimeRecoveryEnabled=true
```
**Restore a table to a point in time** (PITR never overwrites the
source — restore to a NEW table, then repoint):
```sh
RESTORE_TO=$(date -u -d '1 hour ago' +%Y-%m-%dT%H:%M:%SZ)
aws dynamodb restore-table-to-point-in-time \
--source-table-name <table> \
--target-table-name <table>-restored \
--restore-date-time "$RESTORE_TO" \
--billing-mode-restore-as-is
# After the restore completes (status ACTIVE), repoint the app:
# - update the stack env var to the restored table name, or
# - rename: delete <table>, then update-table --new-table-name <table>
# Then re-enable PITR on the restored table (see above).
```
**Verify PITR is enabled on all tables:**
```sh
for t in nova-contracts nova-change-requests nova-outbox \
nova-users nova-sessions nova-pats; do
aws dynamodb describe-continuous-backups --table-name "$t" \
--query 'ContinuousBackupsDescription.PointInTimeRecoveryDescription.PointInTimeRecoveryStatus' \
--output text
done
# → ENABLED (x6)
```
Restores older than 35 days are impossible — for longer retention,
export to S3 via the on-demand export or a scheduled AWS Backup plan.
## 12. DynamoDB import addresses (REQ-361, covered-reference)
The `importable-resources.tf` map in `nova-platform-ops` lists the
existing live resources that `terraform import` adopts at M1 cutover
(§2 step 4). Re-import exits non-zero with
`resource_already_imported` (IMPORT-IDEMPOTENT); CI import treats this
as idempotent success.
| Terraform address | AWS resource | Type |
|-------------------|--------------|------|
| `aws_s3_bucket.nova_tfstate` | `nova-tfstate-581513795199-us-east-1` | S3 bucket (state backend) |
| `aws_dynamodb_table.nova_contracts` | `nova-contracts` | DynamoDB table |
| `aws_dynamodb_table.nova_change_requests` | `nova-change-requests` | DynamoDB table |
| `aws_dynamodb_table.nova_outbox` | `nova-outbox` | DynamoDB table |
| `aws_iam_role.acdl_act_runner` | `acdl-act-runner-role` | IAM role (reused, spec §7.6) |
| `aws_kms_key.<per_stack_cmk>` | per-stack CMKs | KMS key (one per stack) |
The identity tables (`nova-users`, `nova-sessions`, `nova-pats`) are
**new** resources added at M1 (§2 step 6), not imported — they do
not yet exist in the account at M1.
## 13. PAT revocation (D-229)
PAT revocation has a **60s SLO**: the token-vend Lambda does a
strongly-consistent DynamoDB read (`ConsistentRead=True`) on every
token-vend request. A revoked PAT is reflected on the next vend,
within 60s P95.
**Verify a PAT's revocation status (strong read):**
```sh
aws dynamodb get-item \
--table-name nova-pats \
--key '{"jti":{"S":"<pat-id>"}}' \
--consistent-read \
--query 'Item.status.S' --output text
# → active (still valid)
# → revoked (next token-vend returns 403)
```
**Revoke a PAT at the DDB level** (emergency — when the CLI is
unavailable; the `jti` is known but the raw PAT is not):
```sh
aws dynamodb update-item \
--table-name nova-pats \
--key '{"jti":{"S":"<pat-id>"}}' \
--update-expression "SET #s = :r" \
--expression-attribute-names '{"#s":"status"}' \
--expression-attribute-values '{":r":{"S":"revoked"}}'
```
The item is **retained** (not deleted) so the audit trail is intact —
only `status` flips from `active` to `revoked`. The next `token-vend`
call with that `jti` returns `403 pat_revoked` immediately (D-229:
the strong read is synchronous).
## 14. Edge configuration (REQ-364/365/366, covered-reference)
The edge stack fronts the JWKS Lambda with CloudFront + WAF + ACM +
Route53. This is the public read surface (§10, INV-18).
### CloudFront + OAC (REQ-364)
- Distribution origin = the JWKS Lambda Function URL.
- OAC: `OriginAccessControlOriginType: lambda`,
`SigningBehavior: always` (§10).
- Cache behavior: `Cache-Control: max-age=3600` honored (JWKS-SLO).
### WAF WebACL (REQ-365)
- Scope: `CLOUDFRONT` (the WebACL is in `us-east-1`, the only region
for CloudFront-scoped WebACLs).
- Rate-based rule: `RateBasedStatement` with `Limit: 3000`,
`AggregateKeyType: IP`, `EvaluationWindowSec: 300` (3000 requests
per 5 minutes per IP).
- Managed rules: `AWSManagedRulesCommonRuleSet` (the AWS managed rule
group for common attacks).
### ACM certificate (REQ-366)
- Certificate in `us-east-1` (CloudFront requires the cert in
us-east-1).
- DNS validation (a CNAME record per validation record is written to
Route53). The cert status MUST be `ISSUED` (not
`PENDING_VALIDATION`) before the CloudFront distribution can serve
the domain.
### Route53 (REQ-366)
- An A-alias record pointing to the CloudFront distribution's domain
name.
### `route53_record_not_resolvable` debugging
If the JWKS domain does not resolve (`route53_record_not_resolvable`
or `NXDOMAIN`):
1. **Check ACM cert status:**
```sh
aws acm describe-certificate --certificate-arn <arn> \
--query 'Certificate.Status' --output text
# → must be ISSUED, not PENDING_VALIDATION
```
If `PENDING_VALIDATION`, the DNS validation CNAME records are not
in Route53 (or not propagated). Re-apply the validation records +
wait for AWS to validate (typically minutes).
2. **Check CloudFront status:**
```sh
aws cloudfront get-distribution --id <id> \
--query 'Distribution.Status' --output text
# → must be Deployed
```
If `InProgress`, wait for the deployment to finish. CloudFront
deployments take ~5-15 minutes.
3. **Check the Route53 alias record** points to the CloudFront
distribution domain name (not the Function URL).
## 15. Fargate standby health (KJ-WARMUP-HEALTH, REQ-363b)
The Fargate standby is the always-warm minimal defensive fallback
(REQ-363b). It runs the **same ECR image** as the Lambda (KJ-LOCKSTEP,
REQ-371) — so it is always running the current digest, never a stale
one.
**Health probe:** `GET /health → 200` every **10s**
(KJ-WARMUP-HEALTH).
**Failure handling:** 3 consecutive probe failures → alert + the
token-vend path **fails closed** (no signing). The standby does not
silently degrade — if it is not healthy, token-vend does not fall
back to it; it fails closed (INV-17 ABAC discipline extended to the
substrate).
**Verify the standby is `READY` before M1 cutover:**
```sh
# The Fargate task health check (target group)
aws elbv2 describe-target-health \
--target-group-arn <tg-arn> \
--query 'TargetHealthDescriptions[0].TargetHealth.State' --output text
# → healthy
# Direct probe
curl -sI https://<fargate-endpoint>/health | head -1
# → HTTP/1.1 200
```
**Fargate sunset discipline (D-237):** the standby may not be deleted
unless REQ-363 has been green in production for **≥30 consecutive
days**. Sunset requires an architecture review. Do not delete the
standby to save ~$15/month (§7) without that review — it is the
defensive fallback for the `kj` substrate.
## 16. IAM scope (IAM-NARROW, REQ-360, covered-reference)
The Gitea OIDC role for `act_runner` (reused `acdl-act-runner-role`,
spec §7.6) is bounded per REQ-360. **No `Action: "*"` or `Resource:
"*"`** (IAM-NARROW).
The scope covers only:
| Action | Scope | Why |
|--------|-------|-----|
| `kms:*` | customer-managed keys in `581513795199` | KMS signing + rotation |
| `dynamodb:*` | tables prefixed `nova-` | identity + contract tables |
| `lambda:*` | functions prefixed `nova-` | the 3 Nova-idp Lambdas |
| `s3:*` | buckets prefixed `nova-` | state bucket + artifact cache |
| `cloudfront:*` | tagged resources | the JWKS distribution |
| `wafv2:*` | tagged resources | the WebACL |
| `acm:*` | tagged resources | the JWKS cert |
| `route53:*` | tagged resources | the JWKS alias |
| `iam:PassRole` | roles tagged `nova-ops-only` | pass roles to Lambda/ECS only |
**Verify (M1.5 item 10):**
```sh
aws iam get-role-policy --role-name acdl-act-runner-role \
--policy-name <policy-name> --query 'PolicyDocument' --output json \
| jq '.Statement[].Action, .Statement[].Resource'
# → no "*" in either list
```
If `Action: "*"` or `Resource: "*"` appears, the IAM policy is too
broad — fix the Terraform + re-apply before declaring M1.5 green.
## 17. JWKS-ROTATION
On KMS key rotation (§9), **both old + new public keys** are
published in the JWKS during a **24-hour overlap window**. The old
key is removed from the JWKS only after consumers pick up the new
one.
- During the overlap: the JWKS Lambda lists all keys the alias has
pointed at that are still enabled. Already-issued OIDC tokens
(signed with the old key) keep verifying until they expire (OIDC
TTL default 15 min; PAT TTL ≤ 24h dev / ≤ 1h service-account).
- **Do not disable the old key until at least the max PAT TTL (24h)
has elapsed.**
- After the overlap, the old key is removed from the JWKS + disabled +
scheduled for deletion (§9 step 4).
This is JWKS-ROTATION (NFR) — the rotation is non-disruptive because
consumers cache the JWKS for up to `max-age=3600` (1h, JWKS-SLO) and
re-fetch within that window, picking up both keys during the overlap.
## 18. Cutover Gates (grill CF-2/G-5)
Each covered-reference REQ has a cutover gate (M1/M1.5/M2) with a
verification command + a **"Result" column**. The operator fills the
Result column after running the gate in `nova-platform-ops` CI.
**P6 audit verifies every covered-reference REQ has a non-empty,
green Result.** Empty or red → P6 blocks (grill CF-2/G-5).
| REQ | Gate | Verification command | Result |
|-----|------|----------------------|--------|
| REQ-355 | M1 | `terraform plan` resolves `data.aws_ecr_image.kj_image` from `local.nova_platform_version` + `local.kj_source_sha`; both image_uri attributes present | _(operator fills: green/red + run ID/SHA + attestor)_ |
| REQ-356 | M1 | `terraform plan` exit 0 (no drift) on a clean checkout of `main`; exit 2 → `drift_detected` fails the apply workflow | _(operator fills)_ |
| REQ-357 | M1.5 | `terraform apply` `workflow_dispatch` triggered by PR author → rejected; distinct user → proceeds (M1.5 item 11) | _(operator fills)_ |
| REQ-358 | M2 | bump `nova_platform_version` → `terraform apply` → `aws lambda get-function ... ImageUri` `CodeSha256` matches the artifact SHA-256 from the GitHub Release body | _(operator fills)_ |
| REQ-359 | M1 | `git -C nova-platform-ops remote -v` shows only the Gitea private remote (no GitHub mirror); Gitea repo `private: true` | _(operator fills)_ |
| REQ-360 | M1.5 | `aws iam get-role-policy` on the OIDC role asserts no `Action: "*"` + no `Resource: "*"` (M1.5 item 10, §16) | _(operator fills)_ |
| REQ-361 | M1 | `terraform import` on each address in `importable-resources.tf` (§12) succeeds; re-import exits `resource_already_imported` → CI treats as idempotent success (IMPORT-IDEMPOTENT) | _(operator fills)_ |
| REQ-362 | M1.5 | `nova idp setup --verify` (KMS round-trip) against `alias/nova-oidc-signing` (`ECC_NIST_P256`, `SIGN_VERIFY`) → `{"passed":true}` (M1.5 item 6) | _(operator fills)_ |
| REQ-363 | M1.5 | `nova_idp_token_vend.handler` invokes `subprocess.run(['/opt/kj/kj','apply',...])` on the live image; `file(1)` reports `statically linked` (M1.5 items 2-4, KJ-STATIC) | _(operator fills)_ |
| REQ-363b | M1.5 | Fargate standby `GET /health → 200` every 10s (KJ-WARMUP-HEALTH); same ECR digest as the Lambda (KJ-LOCKSTEP); activates only if M1.5 items 1-7 fail 3× (§5) | _(operator fills)_ |
| REQ-364 | M1.5 | direct JWKS Function URL → 403; via-CloudFront → 200 (M1.5 item 9, §10, INV-18) | _(operator fills)_ |
| REQ-365 | M1 | `aws wafv2 get-web-acl` shows `RateBasedStatement` Limit 3000, AggregateKeyType IP, EvaluationWindowSec 300 + `AWSManagedRulesCommonRuleSet`; Scope CLOUDFRONT in us-east-1 (§14) | _(operator fills)_ |
| REQ-366 | M1 | `aws acm describe-certificate` Status `ISSUED`; Route53 A-alias resolves to the CloudFront distribution domain (§14) | _(operator fills)_ |
| REQ-371 | M2 | after `terraform apply`, both `aws_lambda_function.nova_idp_token_vend.image_uri` and `aws_ecs_task_definition.kj.container_definitions[0].image` report the same ECR digest (KJ-LOCKSTEP precondition green at plan) | _(operator fills)_ |
> **P6 audit rule (grill CF-2/G-5):** every row's Result column must
> be non-empty + green. An empty or red Result blocks the milestone
> ship. The operator attestation is the acdl-side evidence surface;
> the live verification runs in `nova-platform-ops` CI.
---
## Appendix — quick reference
| Procedure | Cadence / trigger | Section |
|-----------|-------------------|---------|
| Day-0 cutover (M1) | one-time | §2 |
| M1.5 verification gate | one-time (3 consecutive green rebuilds) | §3 |
| M2 operational handoff | per engineering change (tag-pin bump) | §4 |
| M2a Fargate activation | conditional (M1.5 fails 3×) | §5 |
| Rollback | on regression | §6 |
| Artifact-mirror fallback | on GitHub Releases unreachable | §8 |
| KMS rotation | every 90 days | §9 |
| JWKS-ROTATION overlap | on each KMS rotation (24h window) | §17 |
| PITR restore | on data loss / corruption (35-day window) | §11 |
| Emergency PAT revocation | on compromise (DDB-level, immediate) | §13 |
| Fargate standby health check | continuous (every 10s) | §15 |
| Fargate sunset | ≥30 consecutive days green + architecture review | §5, §15 |
| `route53_record_not_resolvable` debug | on JWKS domain not resolving | §14 |
| Cutover gate attestation | at M1/M1.5/M2 (operator fills Result column) | §18 |
+8 -3
View File
@@ -1,9 +1,10 @@
"""nova idp setup --check/--apply/--verify (REQ-340, REQ-341, C-2.1, ≤50 lines).""" """nova idp setup --check/--apply/--verify (REQ-340, REQ-341, REQ-369, ≤50 lines)."""
from __future__ import annotations from __future__ import annotations
import importlib.util import importlib.util
import json import json
import shutil
import sys import sys
from pathlib import Path from pathlib import Path
@@ -19,8 +20,8 @@ def _load_setup():
def add_parser(subparsers): def add_parser(subparsers):
p = subparsers.add_parser("setup", help="check/apply/verify the Nova IdP stack") p = subparsers.add_parser("setup", help="check/apply/verify the Nova IdP stack")
p.add_argument("--check", action="store_true", help="check prerequisites") p.add_argument("--check", action="store_true", help="check prerequisites")
p.add_argument("--apply", action="store_true", help="generate + deploy (NFR-10 y/N)") p.add_argument("--apply", action="store_true", help="terraform apply (REQ-369; CFN fallback)")
p.add_argument("--verify", action="store_true", help="run the KMS round-trip test") p.add_argument("--verify", action="store_true", help="terraform plan (REQ-369; KMS fallback)")
p.add_argument("--dry-run", action="store_true", help="resource summary only") p.add_argument("--dry-run", action="store_true", help="resource summary only")
p.add_argument("--public-jwks-domain", default=None, help="custom JWKS domain") p.add_argument("--public-jwks-domain", default=None, help="custom JWKS domain")
p.set_defaults(_run=run) p.set_defaults(_run=run)
@@ -31,8 +32,12 @@ def run(args) -> int:
if args.check: if args.check:
print(json.dumps(mod.check_prerequisites(), indent=2)); return 0 print(json.dumps(mod.check_prerequisites(), indent=2)); return 0
if args.verify: if args.verify:
if shutil.which("terraform"):
r = mod.terraform_plan(); print(json.dumps(r, indent=2)); return 0 if r["passed"] else 1
r = mod.verify(); print(json.dumps(r, indent=2)); return 0 if r["passed"] else 1 r = mod.verify(); print(json.dumps(r, indent=2)); return 0 if r["passed"] else 1
if args.apply or args.dry_run: if args.apply or args.dry_run:
if not args.dry_run and shutil.which("terraform"):
r = mod.terraform_apply(); print(json.dumps(r, indent=2)); return 0 if r["deployed"] else 1
r = mod.generate_and_deploy(args.public_jwks_domain, dry_run=args.dry_run) r = mod.generate_and_deploy(args.public_jwks_domain, dry_run=args.dry_run)
print(json.dumps(r["summary"], indent=2)) print(json.dumps(r["summary"], indent=2))
return 0 if (r["deployed"] or args.dry_run) else 1 return 0 if (r["deployed"] or args.dry_run) else 1
+1 -1
View File
@@ -1,6 +1,6 @@
[project] [project]
name = "nova" name = "nova"
version = "1.14.0" version = "1.29.0"
description = "Nova — consumers declare intent; the platform delivers safe production deployment." description = "Nova — consumers declare intent; the platform delivers safe production deployment."
requires-python = ">=3.12" requires-python = ">=3.12"
dependencies = [ dependencies = [
-96
View File
@@ -1,96 +0,0 @@
#!/usr/bin/env python3
"""scripts/attach_release_asset.py — upload one or more files as Gitea release
attachments.
REQ-228 (v1.18): PPTX (and any deck artifact) is attached to the phase's
Gitea release. Uses the Gitea API:
POST /api/v1/repos/{owner}/{repo}/releases/{id}/assets
multipart form: name=<filename>, attachment=<file bytes>
REQ-270 (v1.23): supports dual PPTX attachment — the MARP PPTX (primary,
attached first) and the python-pptx PPTX (comparison artifact). Multiple
file paths are accepted; the first is the primary attachment.
Usage:
python3 scripts/attach_release_asset.py <file-path> <release-id>
python3 scripts/attach_release_asset.py <file-path> <file-path-2>... <release-id>
python3 scripts/attach_release_asset.py docs/presentations/nova-autonomous-cloud-delivery.pptx 522
python3 scripts/attach_release_asset.py \
docs/presentations/nova-autonomous-cloud-delivery.pptx \
docs/presentations/nova-autonomous-cloud-delivery-python.pptx 522
The last positional argument is always the release id; every preceding
argument is an asset path (backward compatible with the single-asset call).
Token resolution: reads NOVA_GITEA_TOKEN (or ACDL_GITEA_TOKEN) from .env.secrets
/ .env, matching the ship_phase.sh pattern. Never uses shell env tokens.
"""
import os
import sys
import json
import urllib.request
import urllib.error
from pathlib import Path
GITEA_BASE = "https://git.cloudinit.dev"
OWNER = "continuous-intelligence"
REPO = "acdl"
def resolve_token() -> str:
for fn in (".env.secrets", ".env"):
try:
for line in Path(fn).read_text().splitlines():
if line.startswith("NOVA_GITEA_TOKEN=") or line.startswith("ACDL_GITEA_TOKEN="):
return line.split("=", 1)[1].strip()
except (FileNotFoundError, PermissionError):
continue
raise RuntimeError("No Gitea token found in .env.secrets or .env (NOVA_GITEA_TOKEN/ACDL_GITEA_TOKEN)")
def attach_asset(file_path: str, release_id: str) -> dict:
token = resolve_token()
p = Path(file_path)
if not p.is_file():
raise FileNotFoundError(f"Asset file not found: {file_path}")
url = f"{GITEA_BASE}/api/v1/repos/{OWNER}/{REPO}/releases/{release_id}/assets"
filename = p.name
boundary = "----NovaBoundary7MAgYbk"
body = (
f"--{boundary}\r\n"
f'Content-Disposition: form-data; name="name"\r\n\r\n'
f"{filename}\r\n"
f"--{boundary}\r\n"
f'Content-Disposition: form-data; name="attachment"; filename="{filename}"\r\n'
f"Content-Type: application/octet-stream\r\n\r\n"
).encode() + p.read_bytes() + f"\r\n--{boundary}--\r\n".encode()
req = urllib.request.Request(
url,
data=body,
headers={
"Authorization": f"token {token}",
"Content-Type": f"multipart/form-data; boundary={boundary}",
},
method="POST",
)
try:
resp = urllib.request.urlopen(req, timeout=60)
return json.loads(resp.read())
except urllib.error.HTTPError as e:
err = e.read().decode()[:300]
raise RuntimeError(f"HTTP {e.code} attaching {filename} to release {release_id}: {err}") from e
if __name__ == "__main__":
if len(sys.argv) < 3:
print("Usage: attach_release_asset.py <file-path> [<file-path-2>...] <release-id>")
sys.exit(1)
asset_paths = sys.argv[1:-1]
release_id = sys.argv[-1]
for idx, path in enumerate(asset_paths):
result = attach_asset(path, release_id)
primary = " (primary)" if idx == 0 and len(asset_paths) > 1 else ""
print(f"Attached{primary}: {result.get('name')} → release {release_id} (asset id {result.get('id')})")
+10 -111
View File
@@ -6,25 +6,19 @@
# 1. List nova-spike-runner's access keys. # 1. List nova-spike-runner's access keys.
# 2. Create a new key. # 2. Create a new key.
# 3. Write the new key to gitignored .env.secrets (chmod 600). # 3. Write the new key to gitignored .env.secrets (chmod 600).
# 4. Upload the new key to the consumer's Actions secret store + verify # 4. Deactivate + delete the old key(s).
# (GET) that it propagated (SPEC §5.9 idempotency).
# 5. Deactivate + delete the old key(s) ONLY after the upload is verified.
# If the upload/verify fails, the old key stays Active + the run exits
# non-zero (the consumer's deploy keeps a working credential).
# #
# Env vars (forge coords): NOVA_FORGE_TOKEN / NOVA_FORGE_BASE_URL / # Idempotent: re-running always ends with exactly 1 active key for the user.
# NOVA_FORGE_OWNER / NOVA_CONSUMER_REPO (the scheduled workflow passes these
# forge-agnostic names, REQ-230). NOVA_GITEA_* are a backward-compat
# fallback for ad-hoc local runs.
#
# Idempotent: re-running always ends with exactly 1 active key for the user
# (once the new key has propagated to the secret store).
# Does NOT rotate the bootstrap root key (D-034 closure = manual user step). # Does NOT rotate the bootstrap root key (D-034 closure = manual user step).
# #
# Spike scope (D-039): the spike user key is per-run-rotated; real OIDC is # Spike scope (D-039): the spike user key is per-run-rotated; real OIDC is
# v1.2 (blocked on go-gitea/gitea#36988). # v1.2.
# Nova rebrand (P4, REQ-163): IAM user renamed acdl-spike-runner → # Nova rebrand (P4, REQ-163): IAM user renamed acdl-spike-runner →
# nova-spike-runner. # nova-spike-runner.
# D-232 (v1.29): the forge Actions secret-store upload was dev-forge-only
# and has been removed with the forge-parity retirement. The rotated key
# is written to .env.secrets only; the consumer's deploy reads it from
# there.
set -euo pipefail set -euo pipefail
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
cd "$ROOT" cd "$ROOT"
@@ -72,10 +66,6 @@ new_id = new["AccessKeyId"]
new_secret = new["SecretAccessKey"] new_secret = new["SecretAccessKey"]
print(f"iam: created new key {new_id} for {user}", file=sys.stderr) print(f"iam: created new key {new_id} for {user}", file=sys.stderr)
# Deactivation of the old keys is deferred to AFTER the new key propagates
# to the Gitea Actions secret store (SPEC §5.9 idempotency — see below).
# Writing .env.secrets first keeps the local operator's working key current.
# Write the new key to gitignored .env.secrets (chmod 600). # Write the new key to gitignored .env.secrets (chmod 600).
# Nova rebrand (P2): keys are NOVA_*; the ACDL_* legacy keys are the # Nova rebrand (P2): keys are NOVA_*; the ACDL_* legacy keys are the
# dual-read fallback source until P5 (kept as comments in .env.secrets). # dual-read fallback source until P5 (kept as comments in .env.secrets).
@@ -86,106 +76,15 @@ with open(env_file, "w") as fh:
os.chmod(env_file, 0o600) os.chmod(env_file, 0o600)
print(f"rotated key written to {env_file} (chmod 600)", file=sys.stderr) print(f"rotated key written to {env_file} (chmod 600)", file=sys.stderr)
# Upload the new key to the consumer's Actions secret store BEFORE # Deactivate + delete the old keys. The new key is already in .env.secrets
# deactivating the old key (SPEC §5.9 — idempotency: the old key is # so deactivating is safe (D-039 local-rotation contract).
# deactivated only after the new one propagates). If the upload or the
# post-upload verification fails, the old key is left Active so the
# consumer's deploy still has a working credential; the run exits non-zero
# so the scheduled workflow surfaces the failure (rather than silently
# stranding the consumer with a key that never reached the secret store).
#
# Forge + consumer coords come from env vars. The scheduled workflow passes
# forge-agnostic NOVA_FORGE_* names (REQ-230 — no forge hostnames in the
# synced workflow file); NOVA_GITEA_* are accepted as a backward-compat
# fallback for ad-hoc local runs. Defaults keep the legacy platform-repo
# target when nothing is set.
# Dual-read token: NOVA_FORGE_TOKEN preferred, NOVA_GITEA_TOKEN fallback (G-106).
gitea_token = os.environ.get("NOVA_FORGE_TOKEN") or os.environ.get("NOVA_GITEA_TOKEN")
gitea_base = (
os.environ.get("NOVA_FORGE_BASE_URL")
or os.environ.get("NOVA_GITEA_BASE_URL")
or "https://git.cloudinit.dev"
).rstrip("/")
gitea_owner = (
os.environ.get("NOVA_FORGE_OWNER")
or os.environ.get("NOVA_GITEA_OWNER")
or "continuous-intelligence"
)
gitea_repo = (
os.environ.get("NOVA_CONSUMER_REPO")
or os.environ.get("NOVA_GITEA_REPO")
or "acdl"
)
secrets_api = f"{gitea_base}/api/v1/repos/{gitea_owner}/{gitea_repo}/actions/secrets"
if gitea_token:
import urllib.request
import urllib.error
import time
def _put_secret(name, value):
req = urllib.request.Request(
f"{secrets_api}/{name}",
data=json.dumps({"value": value}).encode(),
method="PUT",
headers={"Authorization": f"token {gitea_token}",
"Content-Type": "application/json"},
)
urllib.request.urlopen(req).read()
print(f"gitea: secret {name} uploaded to {gitea_owner}/{gitea_repo}", file=sys.stderr)
def _verify_secret(name):
# Gitea does not return secret *values*; a 200 confirms the secret
# exists with the expected name. Retry briefly so eventual
# consistency on the secrets API settles (observed sub-second lag).
for attempt in range(5):
req = urllib.request.Request(
f"{secrets_api}/{name}",
method="GET",
headers={"Authorization": f"token {gitea_token}"},
)
try:
with urllib.request.urlopen(req) as resp:
if resp.status == 200:
print(f"gitea: secret {name} verified present", file=sys.stderr)
return True
except urllib.error.HTTPError as e:
if e.code == 404:
time.sleep(0.5)
continue
raise
return False
try:
_put_secret("NOVA_AWS_ACCESS_KEY_ID", new_id)
_put_secret("NOVA_AWS_SECRET_ACCESS_KEY", new_secret)
ok = _verify_secret("NOVA_AWS_ACCESS_KEY_ID") and \
_verify_secret("NOVA_AWS_SECRET_ACCESS_KEY")
if not ok:
raise RuntimeError("gitea secret verification failed (404 after PUT)")
except Exception as e:
# Upload/verify failed: leave the old key Active so the consumer's
# deploy still works. Surface non-zero so the schedule is noisy.
print(f"gitea: secret upload/verify FAILED ({e}); old key left Active", file=sys.stderr)
sys.exit(2)
else:
print("gitea: NOVA_FORGE_TOKEN/NOVA_GITEA_TOKEN not set; secret upload skipped (v1.2 hardening)", file=sys.stderr)
# No forge target → the new key is already in .env.secrets, so the
# operator's local env works. The old key is deactivated below so the
# user ends with exactly 1 active key (D-039 local-rotation contract).
# Deactivate + delete the old keys. When a forge token was set, this runs
# ONLY after the new key propagated to the consumer's secret store (the
# sys.exit(2) above prevents reaching here on upload/verify failure). When
# no token was set, the new key is already in .env.secrets so deactivating
# is safe (D-039 local-rotation contract).
for k in active: for k in active:
old_id = k["AccessKeyId"] old_id = k["AccessKeyId"]
if old_id == new_id: if old_id == new_id:
continue continue
iam.update_access_key(UserName=user, AccessKeyId=old_id, Status="Inactive") iam.update_access_key(UserName=user, AccessKeyId=old_id, Status="Inactive")
iam.delete_access_key(UserName=user, AccessKeyId=old_id) iam.delete_access_key(UserName=user, AccessKeyId=old_id)
print(f"iam: deactivated+deleted old key {old_id} (after propagation)", file=sys.stderr) print(f"iam: deactivated+deleted old key {old_id}", file=sys.stderr)
print(f"OK: {user} now has exactly 1 active key: {new_id}") print(f"OK: {user} now has exactly 1 active key: {new_id}")
PY PY
-46
View File
@@ -1,46 +0,0 @@
#!/usr/bin/env bash
# scripts/ship_phase.sh — internal CIAgent per-phase ship helper (v1.16)
# Usage: bash scripts/ship_phase.sh <phase_num> <req_id> <phase_slug> <release_body>
set -euo pipefail
PHASE="$1"; REQ="$2"; SLUG="$3"; BODY="$4"
MS="milestone/v1.16-nova-simplification"
BR="phase/$(printf '%02d' "$PHASE")-${SLUG}"
cd "$(git rev-parse --show-toplevel)"
git checkout "$MS" 2>/dev/null
git merge --squash "$BR" 2>&1 | tail -2
MSG="verify(P${PHASE}): ${SLUG} — 4-layer verify PASS + ship
${BODY}
---ci---
project: acdl
phase: ${PHASE}
milestone: v1.16
status: complete
phase_role: execution
requirements:
covered: [${REQ}]
partial: []
---/ci---"
git commit -q -m "$MSG"
PREV=$(git tag -l "v1.15.*" --sort=-version:refname | head -1)
PATCH=$(($(echo "$PREV" | sed 's/v1.15.//')))
NEWPATCH=$((PATCH + 1))
TAG="v1.15.${NEWPATCH}"
git tag -a "$TAG" -m "${TAG}: v1.16 P${PHASE}${SLUG}"
git push origin "$MS" --tags 2>&1 | grep -E "new tag|new branch" | head -2
python3 - "$TAG" "$PREV" <<'PYEOF'
import json, subprocess, sys, urllib.request, urllib.error
tag, prev = sys.argv[1], sys.argv[2]
tok = [l.split("=",1)[1].strip() for l in open(".env.secrets") if l.startswith("NOVA_GITEA_TOKEN=")][0]
body = subprocess.check_output(["git","log",f"{prev}..{tag}","--oneline"]).decode()
payload = {"tag_name":tag,"name":f"Nova {tag} — v1.16 P{tag.split('.')[-1]}","body":body}
req = urllib.request.Request("https://git.cloudinit.dev/api/v1/repos/continuous-intelligence/acdl/releases", data=json.dumps(payload).encode(), headers={"Authorization":f"token {tok}","Content-Type":"application/json"}, method="POST")
try:
r = urllib.request.urlopen(req, timeout=30); d = json.loads(r.read()); print(f"release_id: {d.get('id')} tag: {tag}")
except urllib.error.HTTPError as e:
if e.code == 409: print(f"release exists for {tag}")
else: print(f"HTTP {e.code}: {e.read().decode()[:120]}")
except Exception as e: print(f"ERROR: {e}")
PYEOF
echo "SHIPPED ${TAG}"
-4
View File
@@ -102,7 +102,6 @@ DOMAINS=(
EXCLUDE_SCRIPTS=( EXCLUDE_SCRIPTS=(
sync_to_gl.sh sync_to_gl.sh
sync_to_nova.sh sync_to_nova.sh
ship_phase.sh
update_atelier_vendor.sh update_atelier_vendor.sh
post_stage_comment.sh post_stage_comment.sh
rotate_spike_key.sh rotate_spike_key.sh
@@ -114,8 +113,6 @@ EXCLUDE_SCRIPTS=(
untag_acdl_keys.py untag_acdl_keys.py
seed_uptime_monitors.py seed_uptime_monitors.py
push_consumer_image.py push_consumer_image.py
sync_workflows.py
attach_release_asset.py
check_north_star_diff.sh check_north_star_diff.sh
render_slides.sh render_slides.sh
) )
@@ -198,7 +195,6 @@ echo ""
# Hidden dirs/files in SRC that are NOT consumer-facing. .github is kept. # Hidden dirs/files in SRC that are NOT consumer-facing. .github is kept.
EXCLUDES=( EXCLUDES=(
--exclude=/.ciagent --exclude=/.ciagent
--exclude=/.gitea
--exclude=/.env --exclude=/.env
--exclude=/.env.secrets --exclude=/.env.secrets
--exclude=/.coverage --exclude=/.coverage
-83
View File
@@ -1,83 +0,0 @@
#!/usr/bin/env python3
"""Sync byte-identical workflows from workflows-src/ to .gitea/ + .github/ (P8, REQ-172).
Three workflow pairs are byte-identical Gitea + GitHub mirrors:
ci.yml, deploy.yml, modules-lifecycle.yml, rotate-aws-key.yml.
This generator reads the single source from ``workflows-src/<name>`` and
writes byte-identical copies to both ``.gitea/workflows/<name>`` and
``.github/workflows/<name>``. Use ``--check`` to verify the committed
files match the generated output (CI gate); use ``--write`` to regenerate
the committed files from the sources.
The 4 GitHub-only workflows (platform-test.yml, primitives-plan.yml,
patterns-plan.yml, release.yml) have no Gitea mirror (act_runner feature
gaps) and are NOT touched by this generator.
"""
from __future__ import annotations
import argparse
import filecmp
import sys
from pathlib import Path
ROOT = Path(__file__).resolve().parent.parent
SRC_DIR = ROOT / "workflows-src"
GITEA_DIR = ROOT / ".gitea" / "workflows"
GITHUB_DIR = ROOT / ".github" / "workflows"
PAIRS = ["ci.yml", "deploy.yml", "modules-lifecycle.yml", "rotate-aws-key.yml"]
def _read_source(name: str) -> str:
src = SRC_DIR / name
if not src.is_file():
raise FileNotFoundError(f"source {src} missing")
return src.read_text()
def check() -> int:
"""Verify committed files match the sources. Exit 0 if clean, 1 if drift."""
drift = []
for name in PAIRS:
content = _read_source(name)
for dest_dir in (GITEA_DIR, GITHUB_DIR):
dest = dest_dir / name
if not dest.is_file():
drift.append(f"{dest} MISSING (expected from workflows-src/{name})")
continue
if dest.read_text() != content:
drift.append(f"{dest} DRIFTED from workflows-src/{name}")
if drift:
for d in drift:
print(f"DRIFT: {d}", file=sys.stderr)
print("\nRun: python3 scripts/sync_workflows.py --write", file=sys.stderr)
return 1
print(f"OK: {len(PAIRS)} workflow pairs match workflows-src/ sources")
return 0
def write() -> int:
"""Regenerate .gitea/ + .github/ from workflows-src/ sources."""
for name in PAIRS:
content = _read_source(name)
for dest_dir in (GITEA_DIR, GITHUB_DIR):
dest_dir.mkdir(parents=True, exist_ok=True)
(dest_dir / name).write_text(content)
print(f"wrote: .gitea/workflows/{name} + .github/workflows/{name}")
return 0
def main(argv: list[str] | None = None) -> int:
parser = argparse.ArgumentParser(description="Sync byte-identical workflow pairs.")
group = parser.add_mutually_exclusive_group(required=True)
group.add_argument("--check", action="store_true", help="verify committed files match sources (CI gate)")
group.add_argument("--write", action="store_true", help="regenerate committed files from sources")
args = parser.parse_args(argv)
if args.check:
return check()
return write()
if __name__ == "__main__":
sys.exit(main())
+30 -30
View File
@@ -1,11 +1,12 @@
"""NFR-11 / REQ-326 AC: byte-identical Nova CLI composite action. """NFR-11 / REQ-326 AC: byte-identical Nova CLI composite action.
This test verifies the structural invariants of the `nova cli-action` D-232 (v1.29): the byte-identical cross-forge parity is deliberately
composite action at `.github/actions/nova-cli/action.yml`. The action is disabled — the dev-forge mirror was removed and forge parity is no longer
discovered by both the production forge (GitHub Actions) and the dev maintained (forge_parity_disabled). The composite action at
forge (act_runner) via the same `.github/actions/nova-cli/` path, so a `.github/actions/nova-cli/action.yml` is now GitHub-only; the structural
single source file under test guarantees both platforms consume the invariants below remain valid as the unit-testable subset of the action's
same bytes — which is the byte-identical requirement (NFR-11). correctness. The `test_forge_parity_disabled` assertion documents the
abandoned parity (REQ-367 AC 3, D-232).
What this unit test can verify (structural invariants): What this unit test can verify (structural invariants):
(a) action.yml is valid YAML (a) action.yml is valid YAML
@@ -18,25 +19,8 @@ What this unit test can verify (structural invariants):
(g) an install step exists that installs `nova` (CodeArtifact default (g) an install step exists that installs `nova` (CodeArtifact default
or fallback-index path) or fallback-index path)
(h) a run step executes `nova ${{ inputs.command }}` (h) a run step executes `nova ${{ inputs.command }}`
(i) forge_parity_disabled — the dev-forge mirror dir is absent and no
What this unit test CANNOT verify (and intentionally does not): dev-forge references remain in .github/workflows/ (D-232)
The full byte-identical cross-platform verification (NFR-11,
REQ-326 AC2) requires running the action with identical inputs on a
production-forge ubuntu-latest runner AND a dev-forge act_runner, then
asserting identical stdout + exit code. That is a CI matrix job
(matrix over the two forges), not a unit test — it cannot be
reproduced in-process because it depends on two external runner
environments. The structural invariants below are the unit-testable
subset: if the single action.yml source is structurally correct and
both forges consume the same file path, the byte-identical guarantee
reduces to "the file does not branch on the forge identity" — which
the assertions below enforce (no forge-specific conditionals, single
install path selected by env, single run step).
The CI matrix job that completes the NFR-11 verification is defined
out-of-band (a workflow that invokes this action on both forges with
a fixed `command: --version` and asserts the outputs match). It is
not part of this pytest suite.
""" """
import sys import sys
from pathlib import Path from pathlib import Path
@@ -202,10 +186,9 @@ def test_action_run_step_forwards_mode_and_contract_env():
def test_action_source_contains_no_forge_specific_strings(): def test_action_source_contains_no_forge_specific_strings():
"""NFR-11: the single action.yml must not embed forge-specific """NFR-11: the single action.yml must not embed forge-specific
hostnames, org names, or the dev-forge / consumer-mirror names. Both hostnames, org names, or the dev-forge / consumer-mirror names. This
forges consume the same file, so the file must not branch on the is the unit-testable half of the byte-identical guarantee (still
forge identity. This is the unit-testable half of the byte-identical enforced post-D-232 so the action stays forge-agnostic)."""
guarantee."""
text = ACTION.read_text() text = ACTION.read_text()
for needle in _FORBIDDEN: for needle in _FORBIDDEN:
assert needle.lower() not in text.lower(), \ assert needle.lower() not in text.lower(), \
@@ -215,7 +198,7 @@ def test_action_source_contains_no_forge_specific_strings():
def test_action_has_single_install_path_selected_by_env(): def test_action_has_single_install_path_selected_by_env():
"""NFR-11: the install step must select CodeArtifact vs fallback by """NFR-11: the install step must select CodeArtifact vs fallback by
env var at runtime — NOT by a forge-specific conditional. This keeps env var at runtime — NOT by a forge-specific conditional. This keeps
the file byte-identical across forges (no platform branching).""" the file forge-agnostic (no platform branching)."""
a = _load_action() a = _load_action()
steps = a["runs"]["steps"] steps = a["runs"]["steps"]
install = next( install = next(
@@ -233,6 +216,23 @@ def test_action_has_single_install_path_selected_by_env():
assert needle.lower() not in run.lower() assert needle.lower() not in run.lower()
# --- D-232: forge_parity_disabled ------------------------------------------
def test_forge_parity_disabled():
"""D-232 (v1.29): the dev-forge mirror is removed and forge parity is
deliberately disabled (forge_parity_disabled, REQ-367 AC 3). The
dev-forge directory must be absent and no dev-forge references may
remain in .github/workflows/."""
forge_dir = ROOT / f".{_FORGE}"
assert not forge_dir.is_dir(), \
f"{forge_dir} still present — forge parity should be disabled (D-232)"
workflows = ROOT / ".github" / "workflows"
for wf in workflows.glob("*"):
text = wf.read_text(errors="replace")
assert _FORGE.lower() not in text.lower(), \
f"{wf} contains a dev-forge reference — parity should be disabled (D-232)"
# --- documentation: the CI matrix job is out-of-band ------------------------ # --- documentation: the CI matrix job is out-of-band ------------------------
def test_action_header_documents_byte_identical_matrix_job(): def test_action_header_documents_byte_identical_matrix_job():
+217
View File
@@ -0,0 +1,217 @@
"""nova idp setup terraform-delegation tests (REQ-369, spec §7.5).
P3 Wave 2: verifies the ``nova idp setup --apply`` / ``--verify`` paths
delegate to ``terraform apply -auto-approve`` / ``terraform plan`` when
``terraform`` is on PATH, and fall back to the archived CFN path
(emitting a ``DeprecationWarning``) when terraform is absent.
Mirrors the importlib loading + ``mock.patch``/``monkeypatch`` style of
``tests/test_idp_setup.py`` (``lambda`` is a Python reserved word).
"""
from __future__ import annotations
import importlib.util
import sys
import warnings
from pathlib import Path
from unittest import mock
import pytest
sys.path.insert(0, str(Path(__file__).resolve().parent.parent))
def _load(mod_name, rel_path):
spec = importlib.util.spec_from_file_location(mod_name, rel_path)
mod = importlib.util.module_from_spec(spec)
spec.loader.exec_module(mod)
return mod
_SETUP_PATH = Path(__file__).resolve().parent.parent / "core" / "lambda" / "nova_idp_setup.py"
setup = _load("nova_idp_setup_tf_test", _SETUP_PATH)
# ---------------------------------------------------------------------------
# core/lambda/nova_idp_setup.py — terraform_apply / terraform_plan
# ---------------------------------------------------------------------------
class TestTerraformApply:
def test_apply_invokes_terraform_apply_auto_approve(self, monkeypatch):
"""terraform_apply shells out to ``terraform apply -auto-approve``."""
called = {}
def _fake_run(cmd, **kw):
called["cmd"] = list(cmd)
return mock.MagicMock(returncode=0)
monkeypatch.setattr(setup.subprocess, "run", _fake_run)
r = setup.terraform_apply()
assert called["cmd"] == ["terraform", "apply", "-auto-approve"]
assert r["deployed"] is True
assert r["returncode"] == 0
assert r["command"] == ["terraform", "apply", "-auto-approve"]
def test_apply_auto_approve_false_omits_flag(self, monkeypatch):
called = {}
def _fake_run(cmd, **kw):
called["cmd"] = list(cmd)
return mock.MagicMock(returncode=0)
monkeypatch.setattr(setup.subprocess, "run", _fake_run)
setup.terraform_apply(auto_approve=False)
assert called["cmd"] == ["terraform", "apply"]
def test_apply_nonzero_returncode_means_not_deployed(self, monkeypatch):
monkeypatch.setattr(
setup.subprocess, "run", lambda cmd, **kw: mock.MagicMock(returncode=1)
)
r = setup.terraform_apply()
assert r["deployed"] is False
assert r["returncode"] == 1
class TestTerraformPlan:
def test_plan_invokes_terraform_plan(self, monkeypatch):
called = {}
def _fake_run(cmd, **kw):
called["cmd"] = list(cmd)
return mock.MagicMock(returncode=0)
monkeypatch.setattr(setup.subprocess, "run", _fake_run)
r = setup.terraform_plan()
assert called["cmd"] == ["terraform", "plan"]
assert r["passed"] is True
assert r["command"] == ["terraform", "plan"]
def test_plan_nonzero_returncode_means_not_passed(self, monkeypatch):
monkeypatch.setattr(
setup.subprocess, "run", lambda cmd, **kw: mock.MagicMock(returncode=2)
)
r = setup.terraform_plan()
assert r["passed"] is False
assert r["returncode"] == 2
# ---------------------------------------------------------------------------
# generate_and_deploy emits DeprecationWarning (CFN fallback path)
# ---------------------------------------------------------------------------
class TestCfnFallbackDeprecation:
def test_generate_and_deploy_warns_on_cfn_path(self):
"""The archived CFN deploy path raises DeprecationWarning (REQ-369)."""
with warnings.catch_warnings(record=True) as caught:
warnings.simplefilter("always")
with mock.patch("subprocess.check_call", return_value=0):
r = setup.generate_and_deploy(approve_fn=lambda: True)
assert r["deployed"] is True
dep = [w for w in caught if issubclass(w.category, DeprecationWarning)]
assert len(dep) == 1, f"expected one DeprecationWarning, got {dep}"
assert "CFN path is archived" in str(dep[0].message)
assert "docs/archive/nova-idp-cfn-v1.28.md" in str(dep[0].message)
def test_generate_and_deploy_dry_run_does_not_warn(self):
"""--dry-run is read-only inspection; it must not warn."""
with warnings.catch_warnings(record=True) as caught:
warnings.simplefilter("always")
r = setup.generate_and_deploy(dry_run=True)
assert r["deployed"] is False
dep = [w for w in caught if issubclass(w.category, DeprecationWarning)]
assert dep == [], f"dry-run must not emit DeprecationWarning, got {dep}"
# ---------------------------------------------------------------------------
# nova/idp/setup.py CLI wrapper — terraform delegation vs CFN fallback
# ---------------------------------------------------------------------------
def _cli_args(**kw):
"""Build a MagicMock mimicking the argparse Namespace for `nova idp setup`."""
a = mock.MagicMock()
a.check = kw.get("check", False)
a.apply = kw.get("apply", False)
a.verify = kw.get("verify", False)
a.dry_run = kw.get("dry_run", False)
a.public_jwks_domain = kw.get("public_jwks_domain", None)
return a
class TestCliApplyDelegation:
def test_apply_delegates_to_terraform_when_on_path(self, monkeypatch, capsys):
"""terraform on PATH → --apply runs `terraform apply -auto-approve`."""
monkeypatch.setattr("shutil.which", lambda name: "/usr/bin/terraform" if name == "terraform" else None)
called = {}
def _fake_run(cmd, **kw):
called["cmd"] = list(cmd)
return mock.MagicMock(returncode=0)
from nova.idp import setup as cli_setup
monkeypatch.setattr(cli_setup.shutil, "which", lambda name: "/usr/bin/terraform" if name == "terraform" else None)
# Patch subprocess.run inside the loaded core module (used by terraform_apply).
monkeypatch.setattr(setup.subprocess, "run", _fake_run)
rc = cli_setup.run(_cli_args(apply=True))
assert rc == 0
assert called["cmd"] == ["terraform", "apply", "-auto-approve"]
out = capsys.readouterr().out
assert "deployed" in out
def test_apply_falls_back_to_cfn_when_terraform_absent(self, monkeypatch, capsys):
"""terraform absent → --apply falls back to the CFN path + warns."""
monkeypatch.setattr("shutil.which", lambda name: None)
from nova.idp import setup as cli_setup
monkeypatch.setattr(cli_setup.shutil, "which", lambda name: None)
# Stub the CFN deploy so it succeeds without touching aws CLI; answer
# the NFR-10 y/N prompt (the CLI path has no approve_fn hook).
monkeypatch.setattr("subprocess.check_call", return_value=0)
monkeypatch.setattr("builtins.input", lambda *a, **kw: "y")
with warnings.catch_warnings(record=True) as caught:
warnings.simplefilter("always")
rc = cli_setup.run(_cli_args(apply=True))
assert rc == 0
dep = [w for w in caught if issubclass(w.category, DeprecationWarning)]
assert len(dep) == 1, f"expected DeprecationWarning on CFN fallback, got {dep}"
assert "docs/archive/nova-idp-cfn-v1.28.md" in str(dep[0].message)
out = capsys.readouterr().out
assert "AWS::Lambda::Function" in out # CFN resource summary printed
class TestCliVerifyDelegation:
def test_verify_delegates_to_terraform_plan_when_on_path(self, monkeypatch, capsys):
"""terraform on PATH → --verify runs `terraform plan`."""
from nova.idp import setup as cli_setup
monkeypatch.setattr(cli_setup.shutil, "which", lambda name: "/usr/bin/terraform" if name == "terraform" else None)
called = {}
def _fake_run(cmd, **kw):
called["cmd"] = list(cmd)
return mock.MagicMock(returncode=0)
monkeypatch.setattr(setup.subprocess, "run", _fake_run)
rc = cli_setup.run(_cli_args(verify=True))
assert rc == 0
assert called["cmd"] == ["terraform", "plan"]
out = capsys.readouterr().out
assert "passed" in out
def test_verify_falls_back_to_kms_roundtrip_when_terraform_absent(self, monkeypatch, capsys):
"""terraform absent → --verify falls back to the existing KMS round-trip."""
from nova.idp import setup as cli_setup
monkeypatch.setattr(cli_setup.shutil, "which", lambda name: None)
# The CLI loads core/lambda/nova_idp_setup.py into its own module
# instance; stub _load_setup so verify() is deterministic and does
# not require pyjwt/cryptography (the real round-trip is covered by
# tests/test_idp_setup.py).
fake_mod = mock.MagicMock()
fake_mod.verify.return_value = {"passed": True, "detail": "KMS round-trip OK"}
monkeypatch.setattr(cli_setup, "_load_setup", lambda: fake_mod)
rc = cli_setup.run(_cli_args(verify=True))
assert rc == 0
fake_mod.verify.assert_called_once()
out = capsys.readouterr().out
assert "passed" in out # KMS round-trip result printed
+2 -3
View File
@@ -32,14 +32,13 @@ _EXCLUDE = {".ciagent", ".gitea", ".git", "terraform", "demo",
# Internal-only scripts (by basename) excluded from sync. # Internal-only scripts (by basename) excluded from sync.
_EXCLUDE_SCRIPTS = { _EXCLUDE_SCRIPTS = {
"sync_to_gl.sh", "sync_to_nova.sh", "ship_phase.sh", "sync_to_gl.sh", "sync_to_nova.sh",
"update_atelier_vendor.sh", "post_stage_comment.sh", "update_atelier_vendor.sh", "post_stage_comment.sh",
"rotate_spike_key.sh", "run_l2_lifecycle_destroy.sh", "rotate_spike_key.sh", "run_l2_lifecycle_destroy.sh",
"run_lifecycle_destroy.sh", "run_lifecycle_test.sh", "run_lifecycle_destroy.sh", "run_lifecycle_test.sh",
"migrate_dynamodb_data.py", "migrate_ssm_paths.py", "migrate_dynamodb_data.py", "migrate_ssm_paths.py",
"untag_acdl_keys.py", "seed_uptime_monitors.py", "untag_acdl_keys.py", "seed_uptime_monitors.py",
"push_consumer_image.py", "sync_workflows.py", "push_consumer_image.py", "check_north_star_diff.sh",
"attach_release_asset.py", "check_north_star_diff.sh",
"render_slides.sh", "render_slides.sh",
} }
+12 -9
View File
@@ -97,15 +97,18 @@ class TestWorkflowConformance:
def test_github_workflow_exists(self): def test_github_workflow_exists(self):
assert (ROOT / ".github/workflows/ci.yml").is_file() assert (ROOT / ".github/workflows/ci.yml").is_file()
def test_sync_workflows_check_passes(self): def test_forge_parity_disabled(self):
"""P8 (REQ-172): sync_workflows.py --check exits 0 (committed """D-232 (v1.29): the byte-identical forge-parity generator
files match the workflows-src/ sources).""" (scripts/sync_workflows.py) is removed and the dev-forge mirror
import subprocess is gone. Forge parity is deliberately disabled (forge_parity_disabled,
rc = subprocess.call( REQ-367 AC 3). This test asserts that state holds."""
[sys.executable, "scripts/sync_workflows.py", "--check"], # Build the dev-forge dir name from chr() so this file does not
stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL, # contain the forbidden literal (REQ-230 self-matching guard).
) _forge = chr(103) + chr(105) + chr(116) + chr(101) + chr(97)
assert rc == 0, "sync_workflows.py --check failed — run scripts/sync_workflows.py --write" assert not (ROOT / "scripts" / "sync_workflows.py").is_file(), \
"scripts/sync_workflows.py should be removed (D-232 forge_parity_disabled)"
assert not (ROOT / f".{_forge}").is_dir(), \
"dev-forge mirror should be removed (D-232 forge_parity_disabled)"
class TestRunCiScript: class TestRunCiScript:
def test_run_ci_script_exists_and_executable(self): def test_run_ci_script_exists_and_executable(self):
+13 -4
View File
@@ -5,7 +5,12 @@ daily. v0.2 scope: the mechanism must *exist* (exists-not-ran); the v0.2
deploy uses the currently-active key. These tests assert the workflow file deploy uses the currently-active key. These tests assert the workflow file
exists, is valid YAML, declares the schedule + dispatch triggers, invokes exists, is valid YAML, declares the schedule + dispatch triggers, invokes
scripts/rotate_spike_key.sh, uses the static-key auth path (not OIDC), and scripts/rotate_spike_key.sh, uses the static-key auth path (not OIDC), and
that the synced mirror copies are byte-identical to the source. that the GitHub copy matches the workflows-src/ source.
D-232 (v1.29): the dev-forge mirror is removed and forge parity is
deliberately disabled (forge_parity_disabled). The
test_synced_copies_match assertion now verifies the mirror is absent
rather than byte-identical.
This test file is itself synced to the consumer mirror, so it must be This test file is itself synced to the consumer mirror, so it must be
forge-agnostic (REQ-230): the dev-forge directory name + the forge-mention forge-agnostic (REQ-230): the dev-forge directory name + the forge-mention
@@ -87,11 +92,15 @@ def test_workflow_uses_static_key_auth():
def test_synced_copies_match(): def test_synced_copies_match():
assert GITHUB.is_file(), f"{GITHUB} missing (run scripts/sync_workflows.py --write)" """D-232 (v1.29): the dev-forge mirror is removed and forge parity is
assert FORGE_MIRROR.is_file(), "mirror copy missing (run scripts/sync_workflows.py --write)" deliberately disabled (forge_parity_disabled, REQ-367 AC 3). The
GitHub copy must still match the workflows-src/ source; the dev-forge
mirror must be absent."""
assert GITHUB.is_file(), f"{GITHUB} missing"
assert not FORGE_MIRROR.is_file(), \
f"{FORGE_MIRROR} should be removed (D-232 forge_parity_disabled)"
src_text = SRC.read_text() src_text = SRC.read_text()
assert GITHUB.read_text() == src_text, f"{GITHUB} drifted from workflows-src/" assert GITHUB.read_text() == src_text, f"{GITHUB} drifted from workflows-src/"
assert FORGE_MIRROR.read_text() == src_text, "mirror drifted from workflows-src/"
def test_workflow_is_forge_agnostic(): def test_workflow_is_forge_agnostic():
+1 -1
View File
@@ -108,7 +108,7 @@ class TestSyncToNovaScript:
script = (ROOT / "scripts" / "sync_to_nova.sh").read_text() script = (ROOT / "scripts" / "sync_to_nova.sh").read_text()
# Isolate the EXCLUDE_SCRIPTS=( ... ) block. # Isolate the EXCLUDE_SCRIPTS=( ... ) block.
block = script.split("EXCLUDE_SCRIPTS=(")[1].split(")")[0] block = script.split("EXCLUDE_SCRIPTS=(")[1].split(")")[0]
for internal in ("sync_to_gl.sh", "sync_to_nova.sh", "ship_phase.sh", for internal in ("sync_to_gl.sh", "sync_to_nova.sh",
"update_atelier_vendor.sh", "rotate_spike_key.sh", "update_atelier_vendor.sh", "rotate_spike_key.sh",
"post_stage_comment.sh", "untag_acdl_keys.py"): "post_stage_comment.sh", "untag_acdl_keys.py"):
assert internal in block, f"{internal} missing from EXCLUDE_SCRIPTS" assert internal in block, f"{internal} missing from EXCLUDE_SCRIPTS"
+21
View File
@@ -22,6 +22,27 @@ on:
branches: [main] branches: [main]
jobs: jobs:
forge-parity-disabled:
name: forge_parity_disabled
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Assert forge_parity_disabled
run: |
set -euo pipefail
# Build the dev-forge needle from char codes so this workflow
# file does not itself contain the forbidden literal (REQ-230).
needle="$(printf '\x67\x69\x74\x65\x61')"
if [ -d ".${needle}" ]; then
echo "forge_parity_disabled: dev-forge directory still present (D-232)" >&2
exit 1
fi
if grep -rqi "$needle" .github/workflows/; then
echo "forge_parity_disabled: dev-forge references found in .github/workflows/ (D-232)" >&2
exit 1
fi
echo "forge_parity_disabled: OK"
lint: lint:
name: Lint name: Lint
runs-on: ubuntu-latest runs-on: ubuntu-latest