Skip to main content

AEROSIM-TS-50

Project task

Select immutable AeroSim artifacts through GitOps

The Gondor GitOps repository declaratively selects reviewed Nebula and Singularity image revisions and linted chart configuration for the AeroSim environment.

AEROSIM-TS-50Canonical ID TASK-0050
Verified flow state
Done
Owner
AeroSim Architecture and Delivery
Component
Gondor GitOps — AeroSim Argo CD application configuration
Repository
corp-v1-aerosim/gondor-v1-aerosim

Delivery scope

In gondor-v1-aerosim, declare the Argo CD Application source and AeroSim environment values selecting reviewed Nebula and Singularity Harbor digests, chart version, ingress/config values, and existing secret names; enforce immutable selection with policy tests. Primary files: apps/aerosim/application.yaml, apps/aerosim/values-release.yaml, policies/aerosim-artifacts.rego, tests/gitops/aerosim-artifact-selection.test.mjs.

Implementation contract

Implementation artifacts

  • apps/aerosim/application.yaml
  • apps/aerosim/values-release.yaml
  • policies/aerosim-artifacts.rego
  • tests/gitops/aerosim-artifact-selection.test.mjs

Inputs

  • Reviewed image-set.json containing sourceRevision and two Harbor digests
  • AeroSim chart version and environment-specific non-secret values

Outputs

  • Argo CD Application aerosim targeting the governed namespace and Git revision
  • values-release.yaml selecting the two sha256 image digests and traceable sourceRevision

Failure boundaries

  • Reject mutable tags, non-Harbor repositories, malformed/missing digest, sourceRevision mismatch, plaintext Secret data, and Argo source revisions that are branches.
  • Reject an image-set where Nebula and Singularity were produced from different source revisions.

Excluded scope

  • The GitOps record does not build images, push Harbor artifacts, execute kubectl, or hold raw credentials.

Verification steps

  • node --test tests/gitops/aerosim-artifact-selection.test.mjs
  • conftest test apps/aerosim --policy policies; mutate each digest/repository/revision/secret rule and assert denial.

Traceability

Requirements

Dependencies

UI/UX applicability

non_visual

This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.

Acceptance evidence

Verified delivery: GitOps PR #7 selects application revision 5490c8fb8becd2a6cafef89f9f661baddb51b0f2, chart version 1.0.0, and independently read-back immutable Nebula and Singularity Harbor digests. Main-session exact-head review passed for the application and GitOps changes. Application PR #118 passed every required exact-head job, merged, and its integration revision passed validation, image build, immutable publication, and registry readback in runs 4119 and 4120. GitOps run 4122 passed the exact candidate and run 4123 passed the merged integration revision. Local Helm 4.2.4 lint/render and Conftest validation passed against the exact selected chart revision; policy mutation tests reject mutable tags, untrusted repositories, malformed or mismatched revisions and digests, plaintext Secret data, and in-cluster TLS behind Osgiliath. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.

Current evidence boundary

No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.