63f3a2b66c
Rebrand ACDL/Agentic Cloud Delivery Platform → Nova across README, docs/, decks (markdown + mermaid .mmd + HTML), pyproject.toml name/description, schema $id URLs (acdl.cloudinit.dev→nova.cloudinit.dev), release.yml title/workflow-name. Nova tagline added to README header + both deck title slides + docs/vision.md (alongside existing North Star, D-106). S&P theme untouched (D-107). New docs/NOVA_MIGRATION.md consumer guide. Data values (env vars, resource names, tag keys, SSM/consumer paths) left for P2-P4. ---ci--- project: acdl phase: 1 milestone: v1.15 status: execute ---/ci---
53 lines
2.4 KiB
JSON
53 lines
2.4 KiB
JSON
{
|
|
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
|
"$id": "https://nova.cloudinit.dev/schemas/policy_check_result.schema.json",
|
|
"title": "Nova PolicyCheckResult",
|
|
"description": "Normalized policy check result — the contract between policy engines and the confidence signal. Engine-specific adapters (checkov_adapter.py, future kyverno_adapter) translate native engine output to this shape. The confidence signal consumes a list of these as its policy input; it is engine-agnostic. The severity enum drives the severity->penalty mapping (critical hard-override, high -0.2, medium -0.05, low -0.01, info 0.0).",
|
|
"$comment": "Canonical PolicyCheckResult (ARCHITECTURE.md §12.6). The confidence signal (platform/confidence_signal.py) consumes a list of these as its policy input; it is engine-agnostic. Adapters translate native output to this shape; the signal never reads engine-specific evidence.",
|
|
"type": "object",
|
|
"required": ["contractId", "evaluatedAt", "engine", "ruleId", "severity", "result", "message", "resourceRef"],
|
|
"properties": {
|
|
"contractId": {
|
|
"type": "string",
|
|
"format": "uuid",
|
|
"description": "The contract this check was evaluated against."
|
|
},
|
|
"evaluatedAt": {
|
|
"type": "string",
|
|
"format": "date-time",
|
|
"description": "ISO-8601 timestamp of evaluation."
|
|
},
|
|
"engine": {
|
|
"type": "string",
|
|
"enum": ["checkov", "kyverno", "opa", "wiz"],
|
|
"description": "Policy engine that produced this result."
|
|
},
|
|
"ruleId": {
|
|
"type": "string",
|
|
"description": "Rule identifier (e.g. CKV_AWS_24, KYVERNO_NO_PRIVILEGED, ACDL_TAG_NAMING)."
|
|
},
|
|
"severity": {
|
|
"type": "string",
|
|
"enum": ["critical", "high", "medium", "low", "info"],
|
|
"description": "Severity drives the confidence signal's penalty mapping (ARCHITECTURE.md §8)."
|
|
},
|
|
"result": {
|
|
"type": "string",
|
|
"enum": ["pass", "fail", "skipped", "error"],
|
|
"description": "Check outcome."
|
|
},
|
|
"message": {
|
|
"type": "string",
|
|
"description": "Human-readable result message."
|
|
},
|
|
"evidence": {
|
|
"type": "object",
|
|
"additionalProperties": true,
|
|
"description": "Engine-specific payload (file_path, resource, code_block, etc.). Opaque to the confidence signal; present for audit/debug."
|
|
},
|
|
"resourceRef": {
|
|
"type": "string",
|
|
"description": "IR-typed resource identifier (the resource this check evaluated)."
|
|
}
|
|
}
|
|
} |