85c500e45a
Nova Slides Render / render (push) Failing after 1m1s
Two-stage policy scan per item 20: 1. Checkov on static code BEFORE terraform plan (fail-fast, quick dev feedback). Added to run_platform.sh Step 3c + run_codegen.sh Step 3c (runs on the authored TF dir before plan, using --framework terraform). 2. Runtime policy scan on the plan AFTER terraform plan: Wiz when configured (WIZ_API_TOKEN + WIZ_API_URL), else Checkov against the plan as a drop-in replacement (--framework terraform_plan). Wiz and Checkov are NEVER both run on the plan. Replaces the old single Checkov-on-main.tf step in run_platform.sh Step 5 + run_postapply.sh Step 5. pipelines/contract.yml: stage list updated — 'checkov' stage replaced by 'checkov-static' (before terraform-plan) + 'runtime-policy-scan' (after terraform-plan). 9 stages → 10 stages. Header comment updated. adapters/wiz/wiz_adapter.py: add --plan mode CLI (fetch_and_adapt_plan) for scanning a terraform plan; backward-compat with the positional <wiz_issues.json> <contract-id> mode. is_configured() gates the Wiz path. Tests: test_pipeline_contract.py (9 → 10 stages, new stage names); test_contract_resolver.py (rename test, assert checkov-static + runtime-policy-scan present, old 'checkov' gone). Full suite: 685 pass + 1 pre-existing attestation failure (NOVA_ATTESTATION_SIGNING_KEY_ID unset, unrelated to v1.21, fails on main without these changes too). ---ci--- project: acdl phase: 4 milestone: v1.21 status: execute phase_role: execution ---/ci---
Nova Pipelines
Overview
Nova uses declarative pipeline contracts (YAML) as the single source of truth. GitHub workflows implement the same contract (byte-identical across forges). The shell runner (scripts/run_ci.sh) mirrors the CI pipeline locally so that every stage that runs in CI can be reproduced on a developer machine without a forge.
Existing Pipelines
| Pipeline | File | Stages | Triggers |
|---|---|---|---|
| Nova CI | ci.yml |
lint, test, check-only |
push/PR to main |
| Nova Deploy | contract.yml |
validate-contract, resolve-stack, terraform-plan, checkov, confidence, apply, publish-outputs, deploy-uptime, comment-outputs |
push/PR to main (consumer repos via workflow_call) |
| Nova Modules Lifecycle | modules-lifecycle.yml |
platform-vpc-apply, lifecycle-apply, lifecycle-modify, lifecycle-destroy, l2-lifecycle-apply, l2-lifecycle-modify, l2-lifecycle-destroy, platform-vpc-destroy |
PR to main + workflow_dispatch |
How to Write a Pipeline
- YAML structure:
name,environment,triggers(withpushandpull_requestbranch arrays),runner,python_version, and astages[]list. - Each stage is an object with
name,command,required(boolean), and optionalinstall(pip install command) +description(human-readable summary). - Validate the resulting YAML against
schemas/pipeline.schema.json(CI) orschemas/deploy-pipeline.schema.json(deploy).
How to Wire a Pipeline
- Create the workflow YAML in
.github/workflows/<name>.yml. - Both workflows must implement the same stages, commands, triggers, and runner declared in the contract.
scripts/run_ci.shmirrorsci.ymllocally so the same stages run without a forge.- Consumer repos reference the deploy pipeline via
uses: acdl/.github/workflows/deploy.yml@vX.Y.
Dependencies
scripts/run_ci.sh— local CI mirror that runs theci.ymlstages.scripts/run_platform.sh— platform pipeline runner that implements thecontract.ymlstages.- Workflow YAMLs in
.github/workflows/. - Schemas in
schemas/(pipeline.schema.json,deploy-pipeline.schema.json).
How to Test Pipelines
tests/test_pipeline_contract.py— validates each pipeline YAML against its schema, asserts workflow conformance (byte-identical workflows with the same stages/commands/triggers), and testsscripts/run_ci.shexecution against the contract.
Adding a New Pipeline
- Create
pipelines/<name>.ymlusing the structure above. - Create or extend the schema in
schemas/for the new pipeline shape. - Create the workflow YAML in
.github/workflows/<name>.yml. - Extend
scripts/run_ci.shif a local mirror of the new pipeline is needed. - Write or extend tests in
tests/test_pipeline_contract.pyto assert schema validity and workflow conformance.