---ci---
phase: 3
milestone: v1.0
status: verify
requirements:
covered: [REQ-04, REQ-05, REQ-06, REQ-07, REQ-08, REQ-11]
partial: [REQ-12]
lessons:
- 'set -e' + command substitution kills the parent script when the
child exits non-zero, even when 'rc=$?' follows. verify_phase03.sh
uses 'set -uo pipefail' (no set -e) so policy_checker's intended
exit 1 can be captured. Same pattern recommended for future
verify_phaseNN.sh scripts that test negative cases.
- 'mock_executor.sh' resolves modules/l2/ relative to cwd, not to the
script location. The pipeline (Phase 04) must 'cd' to the repo
root before invoking it. Documented in the I/O contract.
- Python json.dumps collapses 0.90 -> 0.9; confidence_signal emits
the JSON literal as a string to preserve the spec-mandated 0.90/0.40.
This is a demo-aesthetic choice; the parsed float is identical.
- l3b_agent_stub keyword priority matters: 'gas price' (commodity)
wins over 'compliance' (regulatory) because commodity is checked
first per D-008. The Act 3 example was crafted to hit this case.
review:
p0: 0
p1: 0
---/ci---
Layer 1 STRUCTURAL: PASS (10/10 files; bash -n + py_compile + yaml load clean; no TODO/FIXME).
Layer 2 BEHAVIORAL: PASS (verify_phase03.sh 18/18; all 9 PLAN.md must-haves met).
Layer 3 SECURITY: PASS (no secrets; subprocess calls use argv lists; hash chain is tamper-evident).
Layer 4 QUALITY: PASS (correctness, testing, security, performance, maintainability, adversarial all green).
Requirements covered this phase: REQ-04, REQ-05, REQ-06, REQ-07, REQ-08, REQ-11.
Partial: REQ-12 (l3b_agent_stub created; full issue-trigger wiring in Phase 04).
ACDL — Agentic Cloud Delivery Platform
A 30-minute executive demo proving that infrastructure can be delivered automatically, safely, and with a complete audit trail — without the usual weeks of manual tickets, reviews, and copy-pasted configuration.
The demo runs entirely on local stubs (no AWS/GCP/Azure, no external LLM APIs). It shows intent and safety behavior rather than provisioning real cloud resources.
Four acts
- Act 1 — The Friction: the old manual 2-week deployment process.
- Act 2 — Developer Self-Service: commit a valid
contract.yamlforl2-commodity-price-feed, watch Dev auto-run, QA + Prod approval gates, then the evidence timeline. - Act 3 — Citizen Developer: open a GitHub/Gitea Issue with natural-
language intent; the Python keyword parser generates the same
contract.yamland triggers the identical pipeline. - Act 4 — The Safety Net: commit a malicious
contract.yaml(public-ingress: true) forl2-regulatory-reporting; the pipeline halts in Dev because the confidence signal drops below 0.50, and the rejection is visible on the evidence stream.
Repositories
All under the continuous-intelligence Gitea org at
https://git.cloudinit.dev:
acdl(this repo) — platform + stubs + reusable workflowsacdl-contracts— developer surface (contract.yaml+ issue trigger)acdl-evidence— audit timeline (served via raw file URLs; Gitea has no native Pages — see.ciagent/ARCHITECTURE.mdGitea API Surface table)
Project metadata
See .ciagent/PROJECT.md for the full spec, .ciagent/ROADMAP.md for the
5-phase breakdown, .ciagent/REQUIREMENTS.md for traceable requirements,
and .ciagent/PERSONAS.md for the active persona roster.
Phase 01 verification
After running scripts/gitea_setup.sh (which creates acdl-contracts and
acdl-evidence in the org and pushes the placeholder index.html), run:
ACDL_GITEA_TOKEN=<token> scripts/verify_phase01.sh
The script confirms:
- both new repos exist via the Gitea API
- the raw
index.htmlURL onacdl-evidencereturns HTTP 200 - the
qaandprodbranches exist onacdl-contracts
Exit 0 = Phase 01 success criteria met.