031c32055135f5c84c18f929aad915371dafeef6
---ci--- project: acdl phase: 0 milestone: v1.1 status: audit verdict: CLEAN ---/ci--- v1.1 milestone audit. Verdict: CLEAN — 0 P0 (no critical issues, no feedback loop to EXECUTE), 5 P1 post-hoc hygiene items flagged for v1.2 cleanup. Reconstruction test: PASS. HEAD ci block (d6b1923, == v1.2.0 tag) reads status: complete, milestone: v1.1, requirements.covered: [REQ-16..28] — matches the prompt's expected block. Walking back through the ci blocks reproduces plan -> plan-as-execute -> shipped -> verify for every phase (06-10) with the correct phase numbers + status progression. Tags v1.1.0..v1.1.5 + v1.2.0 all present; ROADMAP.md phase statuses match the tags; REQUIREMENTS.md traceability matches (REQ-16..22 -> v1.1.2, REQ-23 -> v1.1.3, REQ-24/26 -> v1.1.4, REQ-25/27/28 -> v1.1.5). File discipline: PASS with one P1 hygiene item. All 10 required .ciagent/ files present (config.json, PROJECT, ARCHITECTURE, REQUIREMENTS, ROADMAP, PERSONAS, PLAN, RESEARCH, VERIFY, REVIEW). PLAN.md = Phase 10 (last phase, not stale). VERIFY.md = Phase 10 (last verification). REVIEW.md present (milestone review). No orphan files. PROJECT.md correctly frames v1.1 as architecture finalization + v1 spike (no "30-min stub demo" as current objective; v1.0 demo archived under demo/). P1-A: config.json status field still reads "specify" (milestone is complete); PERSONAS.md territory paths use stale platform/ prefix (renamed to acdl_platform/ in Phase 08 prep commit727c873) on lines 7, 38, 47, 56, 80, 109. Branch hygiene: PASS. git branch -a shows only main + milestone/v1.0-initial + remotes/origin/*. No leftover phase/NN-* branches (all 5 deleted post-merge). Working tree clean (gitignored artifacts excluded). Commit discipline: PASS with one P1 hygiene item. 45 of 48 commits in v1.1.0..HEAD carry a well-formed ---ci--- block with project/phase/ milestone/status from the documented set. The 3 no-ci commits (52665b8Add docs/architecture.md,7614c41Add docs/vision.md,b84a8a2Update docs/architecture.md) are pre-specify upstream-doc ingestion commits — each is an ancestor of the v1.1 specify commit (288607b); they predate the v1.1 CIAgent protocol and fall inside the audit range only because v1.1.0 is tagged at the v1.0 Phase 05 traceability commit. P1-C: document tag-placement guidance in run.md for v1.2. Field usage rules hold: release.tag only on the 5 ship commits; verdict only on the 5 verify + 1 review commit; requirements.covered on plan-as-execute + complete. Merges: exactly the 5 documented --no-ff squash-merge ship commits (each with 2 parents: prior verify + phase branch tip); no other merges. All ci blocks close with ---/ci--- (no malformed closes). P1-1 (carried-forward from REVIEW.md): two AWS access key IDs in .ciagent/VERIFY.md Phase 09 narrative — public identifiers, not secret pairs, in the audit narrative not in executable code. Non-blocking; recommended redaction for v1.2. P1-D: ROADMAP.md line 81 says "audit pending" — now stale (this audit closes it). No critical issues. The milestone is shippable as-is. The v1.2.0 tag on main HEAD is valid.
ACDL — Agentic Cloud Delivery Platform
Consumers declare intent; the platform delivers safe production deployment through an agentic stack — automatically, safely, and with a complete audit trail. A merged change progresses through lower environments end-to-end without a platform engineer joining a thread; a non-technical consumer ships a production deployment by declaring intent, without authoring a workflow, a configuration file, or a Terraform module.
- Vision (the why):
docs/vision.md - Architecture (the how):
docs/architecture.md - Decisions:
.ciagent/PROJECT.md - Target architecture:
.ciagent/ARCHITECTURE.md - Phase plan:
.ciagent/ROADMAP.md
Status
- v1.1 (active): architecture finalization + v1 spike. Finalize the
architecture to v1.0 (resolve the 11 open design decisions) and prove the
locked commitments with one end-to-end implementation spike
(
l1-s3+l2-static-asset+ Terraform adapter → realterraform planagainst AWS). - v1.0 demo (complete, archived): tag
v1.1.0. The 30-minute stub-driven executive demo is preserved underdemo/as the intent reference; it is not the platform.
Repository layout
| Path | Purpose | Populated |
|---|---|---|
acdl_platform/ |
Platform code: confidence signal, contract resolver, outbox, HITL/ledger designs (renamed from platform/ in Phase 08 to avoid shadowing the stdlib platform module) |
Phase 07+ |
schemas/ |
JSON Schemas: IR, PolicyCheckResult, contract | Phase 07 |
adapters/ |
Substrate adapters (Terraform adapter in v1; the only substrate-specific code per §12) | Phase 09 |
terraform/ |
State backend + provider config (S3 state + DynamoDB lock) | Phase 08+ |
modules-ir/ |
IR-typed L1/L2 modules (l1-s3, l2-static-asset) |
Phase 09–10 |
scripts/ |
v1.1 verify scripts (verify_phaseNN.sh) |
Phase 06+ |
demo/ |
Archived v1.0 executive demo (tag v1.1.0); runs locally via demo/scripts/run_demo.sh --no-upload |
complete |
.ciagent/ |
CIAgent metadata (plans, decisions, personas, roadmap, research) | active |
docs/ |
Upstream vision + architecture sources | active |
Running the archived demo
The v1.0 demo is an archived artifact. To re-run it locally:
bash demo/scripts/run_demo.sh --no-upload
The demo deck is at demo/ACDL_DEMO.md. The demo runs
entirely on local stubs — no AWS, no AI — and shows intent and safety
behavior rather than provisioning real cloud resources. It is the reference
of intent for the real platform; it is not the platform itself.
Description
Nova — The New Dawn of DevSecOps. Autonomous infrastructure delivery: consumers declare intent, the platform ships safely with an immutable audit trail.
agenticaudit-ledgerawscontinuous-deploymentdevsecopsgitea-actionsinfrastructure-as-codekyverno-jsonpolicy-as-codeterraform
Readme
69 MiB
Releases
128
Languages
Python
87.2%
Shell
8.6%
HCL
4.2%