core/policy_engine.py: PolicyEngine Protocol (PEP 544, runtime_checkable)
+ PolicyEngineRegistry (selects from config.json.policy.engine) + NullEngine
fallback (NULL_ENGINE_INACTIVE when policy key absent).
adapters/kyverno-json/: KyvernoJsonEngine — shells to , translates
native output → list[dict] PCR records (engine: "kyverno", ruleId KJ_ prefix,
severity via nova.cloudinit.dev/severity annotation, default info).
is_configured() guards on → KJ_ENGINE_NOT_CONFIGURED SKIPPED PCR
(distinct from NullEngine). Defensive parsing (malformed → error PCR).
config.json: new object {engine: kyverno-json, policy_root}.
scripts/install-kyverno-json.sh: go install kj@latest (D-115).
CI (.gitea + .github): install Go + kj for policy-engine tests (best-effort;
tests skip when kj absent).
tests: 24 pass, 2 skip (kj not installed). 132 existing tests unchanged.
NullEngine satisfies PolicyEngine Protocol (G-Q8a — proves swap boundary).
---ci---
project: acdl
phase: 1
milestone: v1.25
status: execute
phase_role: execution
requirements:
covered: [REQ-291, REQ-292, REQ-293, REQ-294, REQ-308, REQ-309]
partial: []
---/ci---
Gitea Workflows — Limitation Documentation (v1.14, REQ-150)
Shared workflows (byte-identical Gitea + GitHub)
These 3 workflows exist in both .gitea/workflows/ and .github/workflows/
and are byte-identical (asserted by tests/test_pipeline_contract.py):
ci.yml— lint + test + check-only (runs on every PR)deploy.yml— reusable deploy workflow (invoked by consumer repos)modules-lifecycle.yml— L1 + L2 module lifecycle pipeline (plan-only default, full on workflow_dispatch override)
GitHub-only workflows (no Gitea mirror)
These 4 workflows exist only in .github/workflows/:
platform-test.yml— PR pipeline: lint + unit + integration + schema validation. Uses GitHub Actions features (reusable workflow composition, environment protection) not available in Gitea Actions.primitives-plan.yml— PR plan-only matrix over all L1 primitives. Uses GitHub matrix strategy +terraform planagainst live AWS.patterns-plan.yml— PR plan-only matrix over all L2 modules. Same pattern as primitives-plan.release.yml— release job on merge to main: computes next semver, creates + updates MAJOR.MINOR.PATCH / MAJOR.MINOR / MAJOR floating tags, creates a GitHub release. GitHub-only by design (Gitea releases are created via the ship workflow's API call, not a workflow).
Why no Gitea mirror
Gitea Actions (act_runner) has limited support for reusable workflow
composition, environment protection, and the gh CLI used by the release
job. The 3 shared workflows are the ones that need to run on both forges
(CI + deploy + lifecycle). The 4 GitHub-only workflows are the
production-grade platform pipelines that run on GitHub Actions; Gitea is
the dev/integration forge. Mirroring them would require feature parity
that Gitea Actions does not currently provide.
This is a documented limitation, not a defect. A future milestone may add Gitea mirrors if act_runner gains the required features.