Files
acdl/tests/fixtures/kyverno_policyreport.json
T
Jon Chery 1fd37a2843 feat(P23): tagging standard + Wiz adapter + Kyverno adapter
Phase 23 (v1.7) — tagging standards and security adapters.

* schemas/tagging-standard.json (D-054): canonical required-tags schema
  (acdl:owner, acdl:contract, acdl:environment, acdl:cost-center).
* adapters/terraform/policy/custom_rules/acdl_tagging.py: Checkov custom
  rule (ACDL_TAG_NAMING) loaded via --external-checks-dir; closes D-043
  (synthetic SKIPPED record replaced by real PASS/FAIL records).
* checkov_adapter.py: removed _emit_tag_naming_skipped(), added
  ACDL_TAG_NAMING to RULE_MAP, updated docstring.
* scripts/run_platform.sh: both Checkov invocations pass
  --external-checks-dir adapters/terraform/policy/custom_rules/.
* adapters/wiz/ (D-052): Wiz adapter translating issue records to
  PolicyCheckResult (engine: "wiz"); graceful degradation emits
  WIZ_NOT_CONFIGURED SKIPPED when unconfigured; is_configured() gate.
* adapters/kyverno/ (D-053): Kyverno adapter translating PolicyReport
  results to PolicyCheckResult (engine: "kyverno"); ready but inactive
  for Terraform-only stacks; 3 sample ClusterPolicies in policies/.
* schemas/policy_check_result.schema.json: engine enum += "wiz".
* tests: fixtures + test_wiz_adapter.py (8 tests) + test_kyverno_adapter.py
  (13 tests); updated test_checkov_adapter.py to not expect the removed
  synthetic ACDL_TAG_NAMING SKIPPED record.
* scripts/run_ci.sh: lint stage compiles the new adapter modules.

202 tests pass; CI pipeline OK (lint + test + check-only).

Deviations:
- Wiz adapt() had an AttributeError on bare-list top-level input
  (data.get() on a list); fixed to dispatch on isinstance(data, list)
  before calling .get(). No spec change — bare-list handling is implied
  by the original docstring's "data if isinstance(data, list)" branch.
- Kyverno _to_pcr({}) defaults result to "skipped" (entry.get("result",
  "skip") -> "skip"), not "error"; test expectation corrected. Added an
  explicit unknown-result-string test to cover the "error" fallback.

---ci---
project: acdl
phase: 23
milestone: v1.7
status: execute
---/ci---
2026-07-22 20:00:46 +00:00

40 lines
1.0 KiB
JSON

{
"apiVersion": "wgpolicyk8s.io/v1alpha1",
"kind": "PolicyReport",
"metadata": {
"name": "acdl-policy-report",
"namespace": "default"
},
"results": [
{
"policy": "disallow-privileged-containers",
"severity": "high",
"result": "pass",
"message": "Pod spec is compliant (no privileged container).",
"resource": "default/Pod/acdl-app",
"namespace": "default",
"kind": "Pod",
"name": "acdl-app"
},
{
"policy": "require-resource-labels",
"severity": "medium",
"result": "fail",
"message": "Pod missing required label acdl:owner.",
"resource": "default/Pod/acdl-bad-app",
"namespace": "default",
"kind": "Pod",
"name": "acdl-bad-app"
},
{
"policy": "require-image-digests",
"severity": "high",
"result": "warn",
"message": "Container image uses a mutable tag; consider pinning to a digest.",
"resource": "default/Pod/acdl-app",
"namespace": "default",
"kind": "Pod",
"name": "acdl-app"
}
]
}