AEROSIM-TS-164
Qualify each release candidate once and reuse exact evidence
One uncredentialed qualification run proves an immutable release candidate and emits evidence that credentialed publication verifies instead of rerunning the same validation and long-flight UAT.
- Verified flow state
- Unverified
- Owner
- AeroSim Architecture and Delivery
- Feature
- AEROSIM-FT-54
- Component
- Gitea Actions — release qualification and immutable publication boundary
- Repository
- corp-v1-aerosim/corp-v1-aerosim
Delivery scope
Replace duplicate integration and publication qualification with one exact-candidate workflow and a separate credentialed publication stage. Bind the evidence manifest to source revision, immutable image digests, test-suite version, environment identity, run attempt, and artifact hashes; require publication to reject stale, incomplete, mismatched, or previously consumed evidence.
Implementation contract
Implementation artifacts
- .gitea/workflows/validation.yml
- .gitea/workflows/publish-images.yaml
- scripts/validate-release-qualification-evidence.mjs
- tests/ci/release-qualification-evidence.test.mjs
Inputs
- Existing exact-head CI and production UAT contracts from AEROSIM-FT-51.
- Existing credential-isolated Harbor publication and GitOps boundaries from AEROSIM-FT-52.
- Gitea runs 5546 and 5547 showing duplicate post-merge qualification for one merged revision.
Outputs
- One immutable release-qualification evidence manifest for each exact candidate.
- A credentialed publication job that verifies and consumes the manifest without executing duplicate qualification.
- Fail-closed workflow-contract tests covering source, image, test, environment, attempt, artifact, and consumption mismatches.
Failure boundaries
- Fail when publication can proceed without a complete successful qualification for the exact source and images.
- Fail when evidence from another commit, image digest, test version, environment, or workflow attempt can be reused.
- Fail when publication credentials become available to pull-request or untrusted candidate execution.
Excluded scope
- No weakening, shortening, or bypass of the governed full release UAT evidence.
- No direct deployment or GitOps runtime mutation from application CI.
Verification steps
- Prove one complete qualification run supplies all required evidence for one immutable candidate.
- Mutate each identity and evidence field independently and verify publication rejects the manifest.
- Verify pull-request execution cannot access publication credentials and publication does not rerun qualification.
Traceability
Dependencies
- AEROSIM-TS-46Canonical ID: TASK-0046
- AEROSIM-TS-52Canonical ID: TASK-0052
UI/UX applicability
Unclassified
Acceptance evidence
Required future evidence: exact-head workflow tests and one real candidate must show one successful qualification, one credentialed publication using the exact manifest, zero duplicate UAT runs, and rejection of every identity or evidence mismatch.
Current evidence boundary
No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.