feat(remediation): resolve source-owned GitOps provenance - #302
Conversation
Add an immutable GitOps provenance bundle and pure fail-closed resolver for confirmed entity-local R2/R4 candidates. Bind readiness to one fresh source claim and the exact live GitHub handler adapter and schema. Reuse handler-owned canonicalization, preserve every source-owned Git precondition, close descriptor/freshness/cancellation drift windows, and keep PEP, credentials, network, mutation, and execution structurally absent. GSTACK-Checkpoint: 2026-07-22/e14-gitops-provenance#1 Signed-off-by: Gnani Rahul Nutakki <gnani.nutakki@gmail.com>
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
Review clarification: the hosted CodeRabbit bot skipped automatic review because this repository targets |
Summary
gitops.open-prcandidates against exactly one fresh workspace-matching bundleAuthority boundary
Ready means provenance-complete, not authorized. This change adds no actor, role, server intent ID, credential, PEP call, approval, persistence, network, Git operation, dispatch, mutation, or execution path. F14.6 and E14 remain open for the authenticated Hub-to-PEP composition and live canonical read adapter.
Proof
make ci(format, vet, lint, govulncheck, all race/e2e/policy/perf/build gates)make e2e-isolation(PostgreSQL 18.4 forced RLS + two 50,000-execution workspace fuzzers)make release-check(dual reproducible four-platform builds, SPDX SBOMs, formula, amd64/arm64 OCI)make e2e-kindwith pinned Kubernetes 1.36.1 in 243.913s; clean teardownSecurity and cost
The resolver is pure and offline. It adds no cloud resource, API call, egress, storage, telemetry cardinality, or recurring cost. A future live provenance adapter owns credential custody, GitHub rate limits, egress, and remote freshness.
Closes #301