Files
acdl/.gitea/workflows
Jon Chery ac18c98385 feat(P1): kyverno-json engine core + PolicyEngine protocol (REQ-291..294, 308, 309)
core/policy_engine.py: PolicyEngine Protocol (PEP 544, runtime_checkable)
+ PolicyEngineRegistry (selects from config.json.policy.engine) + NullEngine
fallback (NULL_ENGINE_INACTIVE when policy key absent).

adapters/kyverno-json/: KyvernoJsonEngine — shells to , translates
native output → list[dict] PCR records (engine: "kyverno", ruleId KJ_ prefix,
severity via nova.cloudinit.dev/severity annotation, default info).
is_configured() guards on  → KJ_ENGINE_NOT_CONFIGURED SKIPPED PCR
(distinct from NullEngine). Defensive parsing (malformed → error PCR).

config.json: new  object {engine: kyverno-json, policy_root}.

scripts/install-kyverno-json.sh: go install kj@latest (D-115).
CI (.gitea + .github): install Go + kj for policy-engine tests (best-effort;
tests skip when kj absent).

tests: 24 pass, 2 skip (kj not installed). 132 existing tests unchanged.
NullEngine satisfies PolicyEngine Protocol (G-Q8a — proves swap boundary).

---ci---
project: acdl
phase: 1
milestone: v1.25
status: execute
phase_role: execution
requirements:
  covered: [REQ-291, REQ-292, REQ-293, REQ-294, REQ-308, REQ-309]
  partial: []
---/ci---
2026-08-12 18:19:16 +00:00
..

Gitea Workflows — Limitation Documentation (v1.14, REQ-150)

Shared workflows (byte-identical Gitea + GitHub)

These 3 workflows exist in both .gitea/workflows/ and .github/workflows/ and are byte-identical (asserted by tests/test_pipeline_contract.py):

  • ci.yml — lint + test + check-only (runs on every PR)
  • deploy.yml — reusable deploy workflow (invoked by consumer repos)
  • modules-lifecycle.yml — L1 + L2 module lifecycle pipeline (plan-only default, full on workflow_dispatch override)

GitHub-only workflows (no Gitea mirror)

These 4 workflows exist only in .github/workflows/:

  • platform-test.yml — PR pipeline: lint + unit + integration + schema validation. Uses GitHub Actions features (reusable workflow composition, environment protection) not available in Gitea Actions.
  • primitives-plan.yml — PR plan-only matrix over all L1 primitives. Uses GitHub matrix strategy + terraform plan against live AWS.
  • patterns-plan.yml — PR plan-only matrix over all L2 modules. Same pattern as primitives-plan.
  • release.yml — release job on merge to main: computes next semver, creates + updates MAJOR.MINOR.PATCH / MAJOR.MINOR / MAJOR floating tags, creates a GitHub release. GitHub-only by design (Gitea releases are created via the ship workflow's API call, not a workflow).

Why no Gitea mirror

Gitea Actions (act_runner) has limited support for reusable workflow composition, environment protection, and the gh CLI used by the release job. The 3 shared workflows are the ones that need to run on both forges (CI + deploy + lifecycle). The 4 GitHub-only workflows are the production-grade platform pipelines that run on GitHub Actions; Gitea is the dev/integration forge. Mirroring them would require feature parity that Gitea Actions does not currently provide.

This is a documented limitation, not a defect. A future milestone may add Gitea mirrors if act_runner gains the required features.