d5bae868a4
core/env.py dual-read helper (D-108); 21 ACDL_*→NOVA_* env vars migrated across core/scripts/adapters/tests/workflows + .env/.env.secrets (key rename, values stay). G-106 binding: run_platform.sh:288-289 + regression_verify.py:309-312 dual-read (NOVA first, ACDL fallback). G-108 binding: Gitea NOVA_* secrets created via API + workflow secrets: refs updated (deploy.yml + modules-lifecycle.yml, .gitea + .github). acdl_tagging.py→nova_tagging.py (D-109 warn mode, nova:* enforced). .acdl/→.nova/ consumer path (resolver + deploy workflow + schema + tests + docs). Test fixtures updated; pytest + run_ci.sh PASS. ---ci--- project: acdl phase: 2 milestone: v1.15 status: execute ---/ci---
53 lines
2.4 KiB
JSON
53 lines
2.4 KiB
JSON
{
|
|
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
|
"$id": "https://nova.cloudinit.dev/schemas/policy_check_result.schema.json",
|
|
"title": "Nova PolicyCheckResult",
|
|
"description": "Normalized policy check result — the contract between policy engines and the confidence signal. Engine-specific adapters (checkov_adapter.py, future kyverno_adapter) translate native engine output to this shape. The confidence signal consumes a list of these as its policy input; it is engine-agnostic. The severity enum drives the severity->penalty mapping (critical hard-override, high -0.2, medium -0.05, low -0.01, info 0.0).",
|
|
"$comment": "Canonical PolicyCheckResult (ARCHITECTURE.md §12.6). The confidence signal (platform/confidence_signal.py) consumes a list of these as its policy input; it is engine-agnostic. Adapters translate native output to this shape; the signal never reads engine-specific evidence.",
|
|
"type": "object",
|
|
"required": ["contractId", "evaluatedAt", "engine", "ruleId", "severity", "result", "message", "resourceRef"],
|
|
"properties": {
|
|
"contractId": {
|
|
"type": "string",
|
|
"format": "uuid",
|
|
"description": "The contract this check was evaluated against."
|
|
},
|
|
"evaluatedAt": {
|
|
"type": "string",
|
|
"format": "date-time",
|
|
"description": "ISO-8601 timestamp of evaluation."
|
|
},
|
|
"engine": {
|
|
"type": "string",
|
|
"enum": ["checkov", "kyverno", "opa", "wiz"],
|
|
"description": "Policy engine that produced this result."
|
|
},
|
|
"ruleId": {
|
|
"type": "string",
|
|
"description": "Rule identifier (e.g. CKV_AWS_24, KYVERNO_NO_PRIVILEGED, NOVA_TAG_NAMING)."
|
|
},
|
|
"severity": {
|
|
"type": "string",
|
|
"enum": ["critical", "high", "medium", "low", "info"],
|
|
"description": "Severity drives the confidence signal's penalty mapping (ARCHITECTURE.md §8)."
|
|
},
|
|
"result": {
|
|
"type": "string",
|
|
"enum": ["pass", "fail", "skipped", "error"],
|
|
"description": "Check outcome."
|
|
},
|
|
"message": {
|
|
"type": "string",
|
|
"description": "Human-readable result message."
|
|
},
|
|
"evidence": {
|
|
"type": "object",
|
|
"additionalProperties": true,
|
|
"description": "Engine-specific payload (file_path, resource, code_block, etc.). Opaque to the confidence signal; present for audit/debug."
|
|
},
|
|
"resourceRef": {
|
|
"type": "string",
|
|
"description": "IR-typed resource identifier (the resource this check evaluated)."
|
|
}
|
|
}
|
|
} |