AEROSIM-TS-51
Enforce the CI-to-GitOps deployment boundary
Automated checks prove CI can publish artifacts but cannot directly mutate Kubernetes or Argo CD runtime state.
- Verified flow state
- Done
- Owner
- AeroSim Architecture and Delivery
- Feature
- AEROSIM-FT-52
- Component
- Gitea Actions — GitOps boundary policy checks
- Repository
- corp-v1-aerosim/corp-v1-aerosim
Delivery scope
Scan application Gitea workflows, scripts, actions, secrets, and container images and reject direct Kubernetes/Argo mutation capabilities while allowing OCI build/push and creation of a reviewable image-set artifact. Primary files: tests/ci/gitops-boundary.test.mjs, tests/ci/prohibited-deployment-capabilities.json, policies/ci-capabilities.rego.
Implementation contract
Implementation artifacts
- tests/ci/gitops-boundary.test.mjs
- tests/ci/prohibited-deployment-capabilities.json
- policies/ci-capabilities.rego
Inputs
- All .gitea/workflows files plus referenced scripts/actions
- Prohibited capabilities kubectl, helm upgrade/install, argocd app sync/set, Kubernetes API clients, kubeconfig, cluster tokens, and service-account credentials
Outputs
- GitOpsBoundaryReport proving publication-only CI capabilities
- Policy violation naming the workflow step, command/action, and prohibited capability
Failure boundaries
- Fail when a referenced local action/script cannot be resolved or when shell commands are dynamically assembled beyond analysis.
- Fail on cluster credential secret names, Kubernetes API endpoints, direct GitOps repository pushes, mutable deployment tags, or imperative runtime commands.
Excluded scope
- Harbor authentication and OCI push are intentionally allowed; Argo CD reconciliation from a reviewed Git commit remains a separate runtime responsibility.
Verification steps
- node --test tests/ci/gitops-boundary.test.mjs
- Inject kubectl, helm upgrade, argocd sync, kubeconfig secret, dynamic shell, and direct GitOps push fixtures; assert each is denied while publish-images passes.
Traceability
Dependencies
- AEROSIM-TS-50Canonical ID: TASK-0050
UI/UX applicability
non_visual
This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.
Acceptance evidence
Verified delivery: application PR #120 merged reviewed head 9d9143eef9c8772f61bb7bf87380468ac715ac37 as 68a083c4ae86a87147c35fca4d0c5c37657cbee9; GitOpsBoundaryReport scanned all four workflows with immutable OCI/image-set capabilities and zero violations; 10 focused tests reject kubectl, helm upgrade, argocd sync, kubeconfig secrets, dynamic shell, direct GitOps push, mutable deployment tags, and unresolved scripts while immutable publish-images passes; full local validation, production audit, exact-head CI run 4185, integration/publication run 4186, and integration validation run 4187 passed. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.
Current evidence boundary
No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.