# Nova Central Deployment Pipeline Contract (v1.8 + v1.21 REQ-250) # # This is the single source of truth for the deployment pipeline. It # declares the stages that run when a consumer submits a contract: # validate-contract -> resolve-stack -> checkov-static (fail-fast) -> # terraform-plan -> runtime-policy-scan (Wiz-or-Checkov, never both) -> # confidence -> apply (dev only) -> publish-outputs -> deploy-uptime -> # comment-outputs # # REQ-250 (v1.21): the policy scan is two-stage. checkov-static runs on # the authored Terraform code BEFORE terraform plan (fail-fast, quick # developer feedback). runtime-policy-scan runs AFTER terraform plan: # Wiz scans the plan when configured (WIZ_API_TOKEN + WIZ_API_URL); # otherwise Checkov runs against the plan as a drop-in replacement. Wiz # and Checkov are NEVER both run on the plan. # # Decommission mode (mode: decommission) runs a different set of stages: # validate-change-request -> disable-deletion-protection (HITL SRE) -> # zero-counts (HITL SRE) -> confirm-decommission # # This file is the declarative pipeline spec (a contract, not an executable # workflow). The executable workflow is .github/workflows/deploy.yml # (GitHub Actions), which # implements these stages by invoking scripts/run_platform.sh. # # Validated against schemas/deploy-pipeline.schema.json. name: nova-deploy environment: dev triggers: push: [main] pull_request: [main] runner: ubuntu-latest python_version: "3.12" stages: - name: validate-contract description: Validate the consumer contract against the contract schema command: python3 -c "import jsonschema, yaml; jsonschema.validate(yaml.safe_load(open('contracts/static-assets.yaml')), json.load(open('schemas/contract.schema.json')))" required: true - name: resolve-stack description: Resolve the contract to a Target Stack instance via the contract resolver command: python3 core/contract_resolver.py contracts/static-assets.yaml /tmp/acdl-stack.json required: true - name: checkov-static description: Run Checkov on the authored Terraform code (fail-fast, before terraform plan) — REQ-250 command: bash scripts/run_codegen.sh --check-only required: true - name: terraform-plan description: Compile the stack to Terraform and run terraform plan command: bash scripts/run_platform.sh --plan-only contracts/static-assets.yaml required: true - name: runtime-policy-scan description: Run Wiz against the plan when configured, else Checkov against the plan (never both) — REQ-250 command: bash scripts/run_postapply.sh contracts/static-assets.yaml --quiet required: true - name: confidence description: Compute the confidence signal from policy + validation inputs command: python3 core/confidence_signal.py /tmp/acdl-deploy-inputs.json dev required: true - name: apply description: Apply the Terraform plan (dev environment only, autonomous per §10) command: bash scripts/run_platform.sh --plan-only required: false - name: publish-outputs description: Publish deploy outputs to SSM Parameter Store (SecureString) + GitHub PR comment command: bash scripts/run_platform.sh required: false - name: deploy-uptime description: Deploy uptime-kuma monitoring stack (separate terraform state) with endpoints from L2 outputs command: bash scripts/run_platform.sh --deploy-uptime required: false - name: comment-outputs description: Post a structured GitHub PR comment with human-readable deploy outputs command: bash scripts/post_stage_comment.sh publish-outputs pass required: false