Skip to main content

AEROSIM-TS-51

Project task

Enforce the CI-to-GitOps deployment boundary

Automated checks prove CI can publish artifacts but cannot directly mutate Kubernetes or Argo CD runtime state.

AEROSIM-TS-51Canonical ID TASK-0051
Verified flow state
Done
Owner
AeroSim Architecture and Delivery
Component
Gitea Actions — GitOps boundary policy checks
Repository
corp-v1-aerosim/corp-v1-aerosim

Delivery scope

Scan application Gitea workflows, scripts, actions, secrets, and container images and reject direct Kubernetes/Argo mutation capabilities while allowing OCI build/push and creation of a reviewable image-set artifact. Primary files: tests/ci/gitops-boundary.test.mjs, tests/ci/prohibited-deployment-capabilities.json, policies/ci-capabilities.rego.

Implementation contract

Implementation artifacts

  • tests/ci/gitops-boundary.test.mjs
  • tests/ci/prohibited-deployment-capabilities.json
  • policies/ci-capabilities.rego

Inputs

  • All .gitea/workflows files plus referenced scripts/actions
  • Prohibited capabilities kubectl, helm upgrade/install, argocd app sync/set, Kubernetes API clients, kubeconfig, cluster tokens, and service-account credentials

Outputs

  • GitOpsBoundaryReport proving publication-only CI capabilities
  • Policy violation naming the workflow step, command/action, and prohibited capability

Failure boundaries

  • Fail when a referenced local action/script cannot be resolved or when shell commands are dynamically assembled beyond analysis.
  • Fail on cluster credential secret names, Kubernetes API endpoints, direct GitOps repository pushes, mutable deployment tags, or imperative runtime commands.

Excluded scope

  • Harbor authentication and OCI push are intentionally allowed; Argo CD reconciliation from a reviewed Git commit remains a separate runtime responsibility.

Verification steps

  • node --test tests/ci/gitops-boundary.test.mjs
  • Inject kubectl, helm upgrade, argocd sync, kubeconfig secret, dynamic shell, and direct GitOps push fixtures; assert each is denied while publish-images passes.

Traceability

Requirements

Dependencies

UI/UX applicability

non_visual

This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.

Acceptance evidence

Verified delivery: application PR #120 merged reviewed head 9d9143eef9c8772f61bb7bf87380468ac715ac37 as 68a083c4ae86a87147c35fca4d0c5c37657cbee9; GitOpsBoundaryReport scanned all four workflows with immutable OCI/image-set capabilities and zero violations; 10 focused tests reject kubectl, helm upgrade, argocd sync, kubeconfig secrets, dynamic shell, direct GitOps push, mutable deployment tags, and unresolved scripts while immutable publish-images passes; full local validation, production audit, exact-head CI run 4185, integration/publication run 4186, and integration validation run 4187 passed. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.

Current evidence boundary

No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.