-
Notifications
You must be signed in to change notification settings - Fork 0
promote: foundation batch and platform gates #20
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
93 commits
Select commit
Hold shift + click to select a range
d1a9931
chore(ops): refresh checkpoint and batch policy
BeforeLights 4eff6f5
feat(infra): add safe local service lifecycle
BeforeLights 8ba1d4e
docs(infra): record local foundation evidence
BeforeLights b0a53c1
fix(infra): reject duplicate local host ports
BeforeLights 9ce6b6b
test(infra): cover local preflight argument failures
BeforeLights 9f2d047
docs(infra): document safe local lifecycle
BeforeLights b60d942
test(infra): enforce hosted safety boundaries
BeforeLights caa090a
test(infra): verify production recovery defaults
BeforeLights 7d6d1e3
feat(infra): add daemon-free compose validation
BeforeLights 77deac3
docs(infra): record compose validation evidence
BeforeLights 5de31b0
ci: include infrastructure validation in repo checks
BeforeLights 917e313
docs(operations): update foundation verification gates
BeforeLights 69c4459
fix(telemetry): ignore accessor-backed diagnostics
BeforeLights b51195c
docs(telemetry): describe hostile field handling
BeforeLights da3d732
ci: route infrastructure changes through shared gates
BeforeLights 7fc973b
fix(ci): correct infrastructure scope assertion
BeforeLights fcabfb3
docs(operations): add foundation batch handoff
BeforeLights e424f1a
docs(orchestration): record foundation batch checkpoint
BeforeLights 76c1882
test(infra): verify local volume and bucket safety
BeforeLights 185fa1d
test(infra): reject destructive local bootstrap SQL
BeforeLights 7bd479b
test(infra): guard lifecycle against destructive Docker cleanup
BeforeLights 8e5071f
test(infra): pin GitHub OIDC deployment subject
BeforeLights 5fa01f6
test(infra): keep hosted state outside source
BeforeLights 49f82db
feat(infra): configure local disk headroom
BeforeLights 03b79e0
feat(infra): enable init supervision for local services
BeforeLights d5c0438
feat(infra): isolate local service network
BeforeLights 8f0b50d
docs(operations): reconcile local infrastructure limits
BeforeLights 5300d95
docs(plan): specify local infrastructure lifecycle
BeforeLights f941357
docs(infra): document non-applying AWS validation
BeforeLights bdaf5f5
docs(operations): define telemetry safety boundary
BeforeLights a548584
feat(infra): bound hosted web object retention
BeforeLights 340110d
feat(infra): harden hosted task containers
BeforeLights d9f1ad1
feat(infra): enable production database insights
BeforeLights bb8a55b
docs(infra): document production database insights
BeforeLights 6d3368c
ci: disable checkout credential persistence
BeforeLights 7811dbc
fix(telemetry): fail closed on hostile Python mappings
BeforeLights ced1568
fix(infra): make object lifecycle filter explicit
BeforeLights ad12965
docs(infra): clarify alpha plan-only workflow
BeforeLights 52fc370
feat(infra): expose daemon-free local preflight
BeforeLights a0e4d75
docs(infra): record daemon-free preflight evidence
BeforeLights b989fa5
test(infra): pin local telemetry signal pipelines
BeforeLights b6062dc
fix(infra): match indented collector pipeline config
BeforeLights 8cd55cc
fix(infra): correct collector safety assertions
BeforeLights 5755d79
fix(infra): require immutable production task images
BeforeLights d951d4e
docs(infra): document digest-pinned production images
BeforeLights 93a6df6
fix(infra): allow wrapped image guidance text
BeforeLights a78e135
feat(infra): parameterize worker task capacity
BeforeLights 199ce77
fix(infra): remove unused ECS task secret permissions
BeforeLights f291fd5
ci: bound every runner job with a timeout
BeforeLights 385dae7
fix(ci): bound release provenance runtime
BeforeLights d3cf73c
ci: fail when release artifacts are missing
BeforeLights 0cacf2f
feat(infra): add bounded local log diagnostics
BeforeLights e69e5cd
fix(infra): validate local compose project names
BeforeLights 560f5d7
fix(infra): honor safe project override from environment
BeforeLights 6a0efe7
ci: require every provenance artifact
BeforeLights 291d3d3
fix(ci): validate provenance output arguments
BeforeLights 38a4670
ci: validate SBOM output arguments
BeforeLights 7bef4fd
test(infra): reject invalid disk threshold environment
BeforeLights 74737c5
fix(infra): bound local container log storage
BeforeLights 511e70c
docs(infra): explain local log retention
BeforeLights 039de6b
docs(ci): record supply chain gate evidence
BeforeLights f293d1a
docs(orchestration): refresh foundation batch checkpoint
BeforeLights b1bb092
docs(operations): record foundation batch commit window
BeforeLights 20ff047
feat(infra): verify Redis persistence after restart
BeforeLights a19917e
fix(infra): distinguish restart and persistence checks
BeforeLights 46145ee
fix(telemetry): fail closed on hostile trace headers
BeforeLights 30421f5
docs(telemetry): document hostile header handling
BeforeLights 0072076
ci: require explicit read-only repository permissions
BeforeLights 6e5b930
ci: require the protected release environment
BeforeLights f0251d4
fix(infra): protect hosted web bucket deletion
BeforeLights 33a6398
docs(orchestration): finalize foundation batch checkpoint
BeforeLights d9598a2
fix(repo): satisfy formatting and lint gates
BeforeLights 214e45b
docs(operations): record foundation verification boundary
BeforeLights 0f47f81
Merge pull request #19 from DatabreezeService/feat/fnd003-local-infra…
BeforeLights 2b79e49
test(cli): verify generated artifact contents
BeforeLights f263be7
fix(local): bind published services to loopback
BeforeLights 901d76f
fix(local): bound Docker probes and cleanup sentinels
BeforeLights 0d5635b
fix(telemetry): normalize hostile reflection failures
BeforeLights 2ebadd5
fix(infra): enforce AWS policy and Fargate constraints
BeforeLights 2286770
docs(infra): mark persistence evidence environment-gated
BeforeLights 2a1df9e
test(local): exercise preflight and service topology
BeforeLights 806a81f
fix(ci): parse workflow policy as YAML
BeforeLights 24d117d
style(cli): format infrastructure assertions
BeforeLights 432fe76
docs(ci): record external release protection gate
BeforeLights 68218b2
docs(infra): list complete local command surface
BeforeLights 48a596a
style(local): format service lifecycle code
BeforeLights 7a242f5
Merge pull request #21 from DatabreezeService/fix/promotion-20-review
BeforeLights 8118456
test(telemetry): assert normalized hostile errors
BeforeLights a19238d
fix(infra): scan Terraform blocks safely
BeforeLights 01dc664
fix(ci): require commands in run steps
BeforeLights 0172494
Merge pull request #22 from DatabreezeService/fix/promotion-20-review
BeforeLights bfb1214
test(infra): cover Terraform slash comments
BeforeLights 783a471
Merge pull request #23 from DatabreezeService/fix/promotion-20-review
BeforeLights File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,78 @@ | ||
| # Foundation batch handoff | ||
|
|
||
| Observed at (UTC): 2026-08-02 | ||
| Canonical repository: `databreeze-platform` | ||
| Branch: `feat/fnd003-local-infra-batch` | ||
| Base: `origin/dev` at `92b3e9a4d581f3a6947b7a2bf58c8334f4ae0c18` | ||
| Promotion base: `origin/main` at `a2fcba34037c1ffd77816be16be75453abfb16fa` | ||
|
|
||
| ## Active delivery boundary | ||
|
|
||
| - FND-003 local infrastructure is `in-progress`. Static Compose, bootstrap, | ||
| lifecycle, port, Docker-diagnostic, disk-preflight, and daemon-free config | ||
| checks are committed. | ||
| - Live Docker health, port-collision simulation, disk-pressure threshold, and | ||
| restart-persistence evidence remain environment-gated because the Docker | ||
| daemon is unavailable on the current machine. | ||
| - The batch also hardens AWS static checks, content-safe telemetry handling, | ||
| infrastructure path-aware CI, and the updated 30–70 commit policy. These | ||
| changes are not marked as verified foundation tasks until their own gates are | ||
| recorded. | ||
|
|
||
| ## Verification already run | ||
|
|
||
| - Local infrastructure, AWS infrastructure, CI policy, change-scope, telemetry, | ||
| orchestration, and diff checks pass in their scoped commands. | ||
| - `node tools/repo-cli/src/local-services.mjs config` passes without a Docker | ||
| daemon; `check` fails closed with a clear daemon-unavailable reason. | ||
| - Android lifecycle review fixes were promoted through PRs #17 and #18; the | ||
| existing PR #14 promotion was merged to `main` after hosted checks and its | ||
| single CodeRabbit review/incremental dispositions. | ||
|
|
||
| ## Git batching rule | ||
|
|
||
| This is a normal feature batch. Keep atomic commits and do not open the feature | ||
| PR until the branch reaches at least 30 commits, targeting approximately 70 and | ||
| never reaching 100. The only small-PR exceptions are focused promotion-review | ||
| fixes required to close an already-open `dev`→`main` gate. | ||
|
|
||
| At this checkpoint the branch is 72 commits ahead of `origin/dev`. The current | ||
| boundary is still coherent: FND-003 local lifecycle hardening is accompanied by | ||
| portable AWS safety, telemetry, CI/supply-chain, and evidence updates. Continue | ||
| with scoped foundation work until the final handoff boundary; do not manufacture | ||
| empty commits or open a small feature PR merely to reset the count. | ||
|
|
||
| ## Final scoped verification before the feature PR | ||
|
|
||
| Passed from this worktree: | ||
|
|
||
| - `corepack pnpm format:check` | ||
| - `corepack pnpm lint` | ||
| - `corepack pnpm typecheck` | ||
| - `corepack pnpm contracts:check` | ||
| - `corepack pnpm orchestration:check` | ||
| - `corepack pnpm requirements:check` | ||
| - `corepack pnpm test` (67 repository CLI tests plus all workspace suites) | ||
| - `corepack pnpm repo:build` (API, Web, Desktop, shared packages, and engine) | ||
| - `uv run --locked pytest`, Ruff, format, and mypy (91 engine tests) | ||
| - `apps/android/gradlew.bat :app:testDebugUnitTest --offline --no-daemon` | ||
|
|
||
| Environment-gated and intentionally not claimed as verified: | ||
|
|
||
| - OpenTofu format/init/validate because OpenTofu is not installed locally. | ||
| - Live Docker startup, health, port-collision, disk-pressure, Redis | ||
| persistence, and restart checks because the Docker daemon is unavailable. | ||
| - Android instrumentation/emulator and signed release packaging. | ||
|
|
||
| ## Safest next command | ||
|
|
||
| ```powershell | ||
| git status --short --branch | ||
| git fetch origin dev main | ||
| node tools/repo-cli/src/check-execution-orchestration.mjs | ||
| node --test tools/repo-cli/test/**/*.test.mjs | ||
| ``` | ||
|
|
||
| After the normal batch reaches its commit boundary, push this branch, open one | ||
| PR to `dev` without CodeRabbit, merge after hosted checks, then create the | ||
| separate `dev`→`main` promotion PR and invoke CodeRabbit exactly once there. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,51 @@ | ||
| # FND-006 CI and supply-chain evidence | ||
|
|
||
| Observed at (UTC): 2026-08-02 | ||
| Branch: `feat/fnd003-local-infra-batch` | ||
| Task: `FND-006 — Close CI and supply-chain gaps` | ||
|
|
||
| ## Implemented boundaries | ||
|
|
||
| - Path-aware scope detection treats infrastructure, tooling, contracts, plans, | ||
| and workflows as shared quality-gate inputs. | ||
| - Every required workflow uses SHA-pinned actions, least-privilege top-level | ||
| permissions, discarded checkout credentials, bounded runner timeouts, and | ||
| no `pull_request_target` or long-lived AWS credentials. | ||
| - Artifact uploads fail when an expected output is missing. | ||
| - SBOM and provenance generators reject malformed output arguments; provenance | ||
| fails closed when a declared artifact is missing and records sorted SHA-256 | ||
| subjects. | ||
| - Container image, secret-pattern, license, SBOM, and provenance checks remain | ||
| non-deploying repository operations. | ||
|
|
||
| ## Verification | ||
|
|
||
| Passed: | ||
|
|
||
| - `node --test tools/repo-cli/test/ci-policy.test.mjs` | ||
| - `node --test tools/repo-cli/test/provenance.test.mjs` | ||
| - `node --test tools/repo-cli/test/sbom.test.mjs` | ||
| - `node tools/repo-cli/src/check-ci-policy.mjs` | ||
| - `node tools/repo-cli/src/check-container-policy.mjs` | ||
| - `node tools/repo-cli/src/check-secret-patterns.mjs` | ||
| - `node tools/repo-cli/src/check-license-policy.mjs` | ||
| - `node tools/repo-cli/src/generate-sbom.mjs --output <temporary-file>` | ||
| - `node tools/repo-cli/src/generate-provenance.mjs --output <temporary-file> --artifact <temporary-sbom>` | ||
| - `git diff --check` | ||
|
|
||
| Hosted CI remains authoritative for the complete dependency, SAST, container, | ||
| OpenTofu, build, and release-environment gates. The generators never write | ||
| runtime evidence inside the repository during these checks. | ||
|
|
||
| The `release` environment's required reviewers and branch restrictions are | ||
| GitHub repository settings rather than workflow YAML. Before promoting to | ||
| `main`, an administrator must verify those settings and record the check in | ||
| the release evidence; the repository policy checker deliberately verifies the | ||
| workflow's environment reference but cannot infer external protection rules. | ||
|
|
||
| ## Rollback | ||
|
|
||
| Revert the focused CI or generator commit that introduced the behavior, rerun | ||
| the scoped tests and `pnpm ci:policy`, then record the resulting gap before | ||
| merging. No cloud resource, credential, or customer data is changed by these | ||
| checks. |
56 changes: 56 additions & 0 deletions
56
docs/operations/foundation-local-infrastructure-2026-08-02.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,56 @@ | ||
| # FND-003 local infrastructure evidence | ||
|
|
||
| Observed at (UTC): 2026-08-02 | ||
| Branch: `feat/fnd003-local-infra-batch` | ||
| Task: `FND-003 — Close local infrastructure gaps` | ||
|
|
||
| ## Implemented boundaries | ||
|
|
||
| - PostgreSQL 17.5, Redis 7.4.5, MinIO, Mailpit, and the OpenTelemetry collector | ||
| remain pinned in `infrastructure/local/compose.yml`. | ||
| - PostgreSQL initialization creates every module-owned schema and contains no | ||
| credentials, roles, or secret literals. | ||
| - `tools/repo-cli/src/local-services.mjs` provides daemon-free `config` and | ||
| `preflight` commands plus `check`, `start`, `stop`, `reset`, | ||
| `restart-check`, `status`, bounded read-only `logs`, and legacy `smoke` | ||
| commands. | ||
| - Lifecycle commands preserve named volumes. `reset` uses Compose | ||
| `down --remove-orphans` without `--volumes`; data deletion is never implicit. | ||
| - Preflight reports missing Docker CLI/daemon, host port collisions, and | ||
| insufficient free disk space before starting containers. | ||
| - `restart-check` restarts the running stack and waits for every service health | ||
| check, providing the entry point for persistence evidence. | ||
| - `persistence-check` writes a five-minute Redis sentinel, restarts only Redis, | ||
| verifies the sentinel, and deletes it; it never flushes a database or volume. | ||
| - The documented lifecycle command set includes `config`, `preflight`, `check`, | ||
| `start`, `stop`, `reset`, `restart-check`, `persistence-check`, `status`, | ||
| `logs`, and the legacy `smoke` entry point. | ||
|
|
||
| ## Verification | ||
|
|
||
| Passed: | ||
|
|
||
| - `node --test tools/repo-cli/test/local-infrastructure.test.mjs` | ||
| - `node tools/repo-cli/src/local-services.mjs --help` | ||
| - `node tools/repo-cli/src/local-services-smoke.mjs --help` | ||
| - `node tools/repo-cli/src/local-services.mjs config` | ||
| - `node tools/repo-cli/src/local-services.mjs preflight --min-free-gib=0` | ||
| - `git diff --check` | ||
|
|
||
| Environment-gated: | ||
|
|
||
| - `node tools/repo-cli/src/local-services.mjs check` fails closed with | ||
| `Docker daemon is unavailable` because no Docker daemon is running here. | ||
| - The daemon-free `preflight` command completes Compose, port, and disk checks | ||
| without starting containers; the evidence run used a zero-GiB threshold so | ||
| it remains independent of the workstation's available disk headroom. | ||
| - Live `compose up`, health polling, port-collision simulation, disk-pressure | ||
| threshold validation, and restart-persistence checks (including | ||
| `persistence-check`) must run on a machine with Docker Desktop/Compose v2 | ||
| before FND-003 can become `verified`. | ||
|
|
||
| ## Rollback | ||
|
|
||
| Revert the lifecycle commit and retain the prior static Compose checks. No | ||
| containers, named volumes, host files, or credentials are modified by the | ||
| repository changes. | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,33 @@ | ||
| # Content-safe telemetry boundary | ||
|
|
||
| DataBreeze telemetry is operational metadata, not a source-data transport. | ||
| Every runtime emits the versioned `@databreeze/telemetry/v1` shape and the | ||
| Python/Kotlin mirrors are checked against its allowlist. | ||
|
|
||
| ## Allowed data | ||
|
|
||
| - correlation, trace, workspace, job, artifact, dataset, and device IDs | ||
| - bounded route/operation/outcome/reason/provider tokens | ||
| - status, duration, queue, retry, item, byte, and redaction counters | ||
| - an explicit sampling boolean | ||
|
|
||
| ## Prohibited data | ||
|
|
||
| Paths, filenames, source values, formulas, document text, previews, evidence | ||
| snippets, questions/prompts, transcripts, contact data, secrets, tokens, | ||
| provider causes, and raw exception messages never enter ordinary telemetry. | ||
| Unknown attributes are dropped. Strict assertion helpers reject unsafe records | ||
| at adapter boundaries. JavaScript sanitization reads only own data properties, | ||
| so accessor-backed diagnostics cannot execute arbitrary getters during logging. | ||
|
|
||
| ## Failure behavior | ||
|
|
||
| Malformed correlation or trace headers fail closed. Ambiguous duplicate headers | ||
| are rejected, including accessor-backed or non-string header values; hostile | ||
| header mappings fail with a generic unreadable-header reason. Invalid or | ||
| oversized values are omitted by the permissive sanitizer and rejected by strict mode. Providers and exporters remain | ||
| replaceable; a collector outage cannot become domain authority or block durable | ||
| jobs and audit writes. | ||
|
|
||
| See `packages/telemetry/README.md` and the TypeScript/Python/Android parity | ||
| tests before adding an attribute or event. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.