Skip to content
This repository was archived by the owner on Sep 28, 2026. It is now read-only.
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions .github/workflows/repository-validation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -306,6 +306,7 @@ jobs:
"tools/bootstrap-cloud-shell",
"tools/deploy-clean-room",
"tools/verify-clean-room",
"terraform/.terraform.lock.hcl",
]
for path in required:
if not Path(path).is_file():
Expand All @@ -326,6 +327,9 @@ jobs:
"ansible/playbooks/private-runtime-config.yml",
"NoPublicAccess",
"TF_VERSION=1.15.8",
"tools/bootstrap-cloud-shell",
"tools/deploy-clean-room",
"tools/verify-clean-room",
):
if needle not in runbook:
raise SystemExit(f"runbook missing required contract text: {needle}")
Expand Down Expand Up @@ -499,6 +503,11 @@ jobs:
# Isolated fixture only: no OCI provider, no remote backend, no credentials.
run: ./tests/unit/test_terraform_cidr_validation.sh

- name: Run Terraform provider lockfile contract unit tests
# Static only: tracked lockfile, oracle/oci 8.26.x selection, multi-platform hashes.
# Does not contact OCI or run terraform plan/apply.
run: ./tests/unit/test_terraform_lockfile_contract.sh

- name: Run Terraform PV encryption contract unit tests
# Static consistency between instance launch_options and scratch attachment.
# Does not contact OCI, initialize a backend, or run terraform plan.
Expand Down
2 changes: 2 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/).

### Added

- Tracked `terraform/.terraform.lock.hcl` for `oracle/oci` `8.26.0` on `linux_amd64` and `linux_arm64`.
- Added resumable clean-room operator automation (`tools/bootstrap-cloud-shell`, `tools/deploy-clean-room`, `tools/verify-clean-room`) with state-aware reruns, explicit APPLY, FORMAT, and REBOOT gates, and an optional tmux warning.
- Added a minimal Cursor/AI-assisted governance workflow: implementation and independent review rules, plus human-facing `docs/AI_AGENT_WORKFLOW.md`
- Configured Terraform to use the native OCI Object Storage backend with an externally supplied state bucket and environment-specific object key.
Expand Down Expand Up @@ -42,6 +43,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/).

### Changed

- Made `docs/V2_CLEAN_ROOM_DEPLOYMENT.md` the canonical Greenfield V2 operator runbook for the existing clean-room tools, tracked Terraform provider lockfile, and destroy-acceptance procedure.
- Replaced a fixed repository-wide response-language rule with a task-driven contract in `AGENTS.md` and the always-applied foundation rule
- Documented the current GitHub `main-protection` required checks as present external policy, not future work
- Documented one explicitly authorized finalization task after PRE-COMMIT review, with stop-on-failure and a mandatory exact-head CI gate
Expand Down
25 changes: 14 additions & 11 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,11 +21,14 @@ GitHub Actions → static validation only

**Start here for a fresh environment:** [`docs/V2_CLEAN_ROOM_DEPLOYMENT.md`](docs/V2_CLEAN_ROOM_DEPLOYMENT.md).

That runbook is the canonical operator contract. Remaining Phase-A scopes are
the first live clean-room deployment and post-proof V1 cleanup. Cloud Shell
operator prerequisites are partially live validated (APIKey authentication and
backend bootstrap). The first V2 clean-room deployment is **not yet executed**.
It is **not** live-validated merely because CI passes.
That runbook is the canonical operator contract:

```text
tools/bootstrap-cloud-shell → tools/deploy-clean-room → tools/verify-clean-room
```

GitHub Actions static validation is not live rebuild proof. Historical V1
executable paths are retired.

The historical in-place SecretProviderClass handoff document
([`docs/RUNTIME_SPC_OWNERSHIP_CUTOVER.md`](docs/RUNTIME_SPC_OWNERSHIP_CUTOVER.md))
Expand All @@ -44,8 +47,8 @@ is a fallback procedure, not the primary V2 path.
### Version 2 path (target)

See [`docs/V2_CLEAN_ROOM_DEPLOYMENT.md`](docs/V2_CLEAN_ROOM_DEPLOYMENT.md) for the
deterministic operator sequence (Terraform outputs → Ansible inventory →
`site.yml` → Argo → private runtime → acceptance).
canonical operator sequence (`tools/bootstrap-cloud-shell` →
`tools/deploy-clean-room` → `tools/verify-clean-room`).

### Version 1 (historical record only)

Expand Down Expand Up @@ -233,7 +236,7 @@ Open <https://localhost:8080> while the port-forward is active.

## Scratch Storage Model

### V2 contract (Git; awaiting live validation)
### V2 contract

```text
Terraform → OCI scratch block volume (default 150 GB) + attachment
Expand All @@ -249,7 +252,7 @@ Argo CD → StorageClass tradingchassis-scratch + static hostPath PVs + namesp

### V1 historical note

Legacy V1 Bash storage bootstrap mounted `/mnt/scratch` while scratch PVCs used `microk8s-hostpath`. That gap is closed in the V2 Git manifests above and still requires live clean-room validation.
Legacy V1 Bash storage bootstrap mounted `/mnt/scratch` while scratch PVCs used `microk8s-hostpath`. That gap is closed in the V2 Git manifests above. Operator verification of the mount and PVC binding is part of the canonical clean-room tools, not a hardcoded host device path.

## Post-Install Verification

Expand Down Expand Up @@ -289,7 +292,7 @@ sudo rm -rf ~/.kube/

After reset, also review manually:

- `/etc/fstab` entries added for `/dev/oracleoci/oraclevds`
- `/etc/fstab` UUID entries for `/mnt/scratch` (Ansible owns persistent mounting; kernel names such as `/dev/oracleoci/oraclevds` are not a stable contract)
- whether `/mnt/scratch` should be unmounted/cleaned
- whether attached block volume data should be preserved or re-formatted

Expand Down Expand Up @@ -332,7 +335,7 @@ For vulnerability reporting and security policy, see `SECURITY.md`.
- Vault lifecycle and Vault secret **values** (referenced by Terraform / consumed via CSI; not provisioned as secret contents here)

Additional Version 1 limitations and evidence gaps are listed in [`VERSION_1_BASELINE.md`](VERSION_1_BASELINE.md).
V2 clean-room status and remaining blockers are listed in [`docs/V2_CLEAN_ROOM_DEPLOYMENT.md`](docs/V2_CLEAN_ROOM_DEPLOYMENT.md).
The V2 clean-room operator procedure is [`docs/V2_CLEAN_ROOM_DEPLOYMENT.md`](docs/V2_CLEAN_ROOM_DEPLOYMENT.md).

## AI-Assisted Development

Expand Down
Loading
Loading