Skip to main content

AEROSIM-TS-164

Project task

Qualify each release candidate once and reuse exact evidence

One uncredentialed qualification run proves an immutable release candidate and emits evidence that credentialed publication verifies instead of rerunning the same validation and long-flight UAT.

AEROSIM-TS-164Canonical ID TASK-0164
Verified flow state
Unverified
Owner
AeroSim Architecture and Delivery
Component
Gitea Actions — release qualification and immutable publication boundary
Repository
corp-v1-aerosim/corp-v1-aerosim

Delivery scope

Replace duplicate integration and publication qualification with one exact-candidate workflow and a separate credentialed publication stage. Bind the evidence manifest to source revision, immutable image digests, test-suite version, environment identity, run attempt, and artifact hashes; require publication to reject stale, incomplete, mismatched, or previously consumed evidence.

Implementation contract

Implementation artifacts

  • .gitea/workflows/validation.yml
  • .gitea/workflows/publish-images.yaml
  • scripts/validate-release-qualification-evidence.mjs
  • tests/ci/release-qualification-evidence.test.mjs

Inputs

  • Existing exact-head CI and production UAT contracts from AEROSIM-FT-51.
  • Existing credential-isolated Harbor publication and GitOps boundaries from AEROSIM-FT-52.
  • Gitea runs 5546 and 5547 showing duplicate post-merge qualification for one merged revision.

Outputs

  • One immutable release-qualification evidence manifest for each exact candidate.
  • A credentialed publication job that verifies and consumes the manifest without executing duplicate qualification.
  • Fail-closed workflow-contract tests covering source, image, test, environment, attempt, artifact, and consumption mismatches.

Failure boundaries

  • Fail when publication can proceed without a complete successful qualification for the exact source and images.
  • Fail when evidence from another commit, image digest, test version, environment, or workflow attempt can be reused.
  • Fail when publication credentials become available to pull-request or untrusted candidate execution.

Excluded scope

  • No weakening, shortening, or bypass of the governed full release UAT evidence.
  • No direct deployment or GitOps runtime mutation from application CI.

Verification steps

  • Prove one complete qualification run supplies all required evidence for one immutable candidate.
  • Mutate each identity and evidence field independently and verify publication rejects the manifest.
  • Verify pull-request execution cannot access publication credentials and publication does not rerun qualification.

Traceability

Requirements

Dependencies

UI/UX applicability

Unclassified

Acceptance evidence

Required future evidence: exact-head workflow tests and one real candidate must show one successful qualification, one credentialed publication using the exact manifest, zero duplicate UAT runs, and rejection of every identity or evidence mismatch.

Current evidence boundary

No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.