Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
75 commits
Select commit Hold shift + click to select a range
1ba015d
docs: define P0 operationalization release
Protonmatter Aug 13, 2026
678bc1b
docs: add P0 operationalization plan
Protonmatter Aug 13, 2026
4a9d604
test: define authoritative mutation audit contract
Protonmatter Aug 13, 2026
3a95f39
test: define append-only audit storage
Protonmatter Aug 13, 2026
412f6ed
test: require immutable release image rendering
Protonmatter Aug 13, 2026
d7c65af
test: require request identity support
Protonmatter Aug 13, 2026
2a13004
feat: define mutation audit event model
Protonmatter Aug 13, 2026
57f3b37
fix: constrain mutation audit detail fields
Protonmatter Aug 13, 2026
bda9028
feat: add append-only mutation audit store
Protonmatter Aug 13, 2026
696bd23
feat: render digest-bound release manifests
Protonmatter Aug 13, 2026
ca68325
deploy: require release-rendered image digest
Protonmatter Aug 13, 2026
a050254
feat: configure authoritative mutation audit storage
Protonmatter Aug 13, 2026
65455d0
feat: add request identity helper
Protonmatter Aug 13, 2026
a3ac6e5
refactor: preserve established control-plane core
Protonmatter Aug 13, 2026
58b9624
feat: audit authoritative mutations and protect raw evidence
Protonmatter Aug 13, 2026
0d1eca2
test: add operator control-plane URL validation cases
Protonmatter Aug 13, 2026
e15d647
test: run operator control-plane URL validation cases
Protonmatter Aug 13, 2026
cb374e7
refactor: preserve operator weather adapter core
Protonmatter Aug 13, 2026
1979e5f
feat: validate control-plane destination before credential use
Protonmatter Aug 13, 2026
7c861c2
test: supply explicit control-plane host allowlist
Protonmatter Aug 13, 2026
0f80fa9
test: fix operator URL contract fixture
Protonmatter Aug 13, 2026
7748185
ci: add Python dependency lock generation
Protonmatter Aug 13, 2026
3ae6188
test: verify operational mutation accountability
Protonmatter Aug 13, 2026
a60a9fb
ci: pin pip for compatible lock generation
Protonmatter Aug 13, 2026
73be113
feat: generate digest-bound release metadata
Protonmatter Aug 13, 2026
b8b4f54
ci: publish digest-bound deployment evidence
Protonmatter Aug 13, 2026
78f3ef9
build: include wheel toolchain in dependency locks
Protonmatter Aug 13, 2026
2b87bd9
build: lock the Python wheel toolchain
Protonmatter Aug 13, 2026
f31c234
build: construct release images from locked wheels
Protonmatter Aug 13, 2026
2f894af
style: import release sequence from collections
Protonmatter Aug 13, 2026
b6869e3
style: format operationalization route assertions
Protonmatter Aug 13, 2026
0a28f0a
build: add one-shot lock materialization workflow
Protonmatter Aug 13, 2026
95817a8
build: materialize hash-pinned Python locks
github-actions[bot] Aug 13, 2026
2f57909
ci: install Python from hash-pinned lock
Protonmatter Aug 13, 2026
fff86da
ci: bootstrap Python from hash-pinned lock
Protonmatter Aug 13, 2026
cc7c37b
ci: lock operational weather contract dependencies
Protonmatter Aug 13, 2026
d24368a
ci: lock schema contract dependencies
Protonmatter Aug 13, 2026
b911f86
ci: use reproducible scientific dependency set
Protonmatter Aug 13, 2026
540edac
build: include build-system packages in Python locks
Protonmatter Aug 13, 2026
7f23ada
build: materialize hash-pinned Python locks
github-actions[bot] Aug 13, 2026
a152243
build: refresh one-shot lock materializer
Protonmatter Aug 13, 2026
28c12c7
build: recreate one-shot lock materializer
Protonmatter Aug 13, 2026
9c3aea4
build: allow explicit TypeScript module imports
Protonmatter Aug 13, 2026
30c139f
fix: use explicit TypeScript core module
Protonmatter Aug 13, 2026
8e348a1
feat: render immutable release deployment evidence
Protonmatter Aug 14, 2026
265e116
test: verify release image reference contract
Protonmatter Aug 14, 2026
b03d07f
test: inspect handled audit-store failures
Protonmatter Aug 14, 2026
36fdc34
build: expose release tooling module
Protonmatter Aug 14, 2026
a0a19be
docs: align license with public source visibility
Protonmatter Aug 14, 2026
238574c
chore: make repository ownership enforceable
Protonmatter Aug 14, 2026
7baa783
docs: define public proprietary repository posture
Protonmatter Aug 14, 2026
010c4d7
ci: remove one-shot lock materializer
Protonmatter Aug 14, 2026
694fcbf
docs: document operationalization and repository posture
Protonmatter Aug 14, 2026
fdb6a18
docs: document control-plane destination policy
Protonmatter Aug 14, 2026
7af0d8b
ci: lock specification validation dependencies
Protonmatter Aug 14, 2026
52e3cfb
style: replace release module with formatted source
Protonmatter Aug 14, 2026
674ef66
style: restore formatted release module
Protonmatter Aug 14, 2026
836b7d5
docs: record P0 operationalization release evidence
Protonmatter Aug 14, 2026
3cf7cf2
fix: resolve operationalization review findings
Protonmatter Aug 14, 2026
5d3f05c
fix: reconcile interrupted audit mutations
Protonmatter Aug 14, 2026
c24ac30
test: cover audit recovery boundaries
Protonmatter Aug 14, 2026
49daef2
fix: harden audit recovery and release builds
Protonmatter Aug 14, 2026
56722b0
docs: refresh PR 30 validation evidence
Protonmatter Aug 14, 2026
536c298
fix: preserve request identity and base image trust
Protonmatter Aug 14, 2026
b680c68
docs: refresh review validation evidence
Protonmatter Aug 14, 2026
b78fb10
Address crash-consistency review findings
Protonmatter Aug 14, 2026
bdc91e1
Preserve source retention request IDs
Protonmatter Aug 14, 2026
0e8714f
Cover crash-consistency recovery branches
Protonmatter Aug 14, 2026
0e30874
fix: close operational audit durability gaps
Protonmatter Aug 14, 2026
6449be4
feat: enforce spec-driven delivery pipeline
Protonmatter Aug 14, 2026
482a35a
fix: preserve npm lockfile integrity
Protonmatter Aug 14, 2026
089debb
fix: isolate release dependencies and index audit identities
Protonmatter Aug 15, 2026
e2422a2
fix: hash lock compiler and validate requirement identities
Protonmatter Aug 15, 2026
86ef973
fix: atomically bind ingestion receipts and bound audit reads
Protonmatter Aug 15, 2026
a7a7ec9
Harden reusable CI and catalog durability
Protonmatter Aug 15, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 4 additions & 7 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1,7 +1,4 @@
/specs/ @program-governance @scientific-review
/schemas/ @data-architecture
/src/weather_platform/scientific/ @probabilistic-modeling @independent-verification
/deploy/ @platform-sre @security-architecture
/apps/operator-console/ @platform-sre @product-security
/.github/workflows/ @platform-sre @product-security
/docs/NETWORK_BOUNDARY.md @security-architecture
# The repository is currently owned by a personal account, so organization
# team handles cannot enforce reviews here. Replace this fallback with real
# organization teams after repository migration.
* @Protonmatter
3 changes: 3 additions & 0 deletions .github/PULL_REQUEST_TEMPLATE/default.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,9 @@

## Requirement IDs

- Specifications:
- Requirements:

## Scientific impact

- Baseline:
Expand Down
59 changes: 59 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,59 @@
version: 2
updates:
- package-ecosystem: pip
directory: /
schedule:
interval: weekly
day: monday
time: "04:00"
timezone: America/New_York
open-pull-requests-limit: 10
groups:
python-production:
dependency-type: production
update-types: [minor, patch]
python-development:
dependency-type: development
update-types: [minor, patch]
ignore:
- dependency-name: "*"
update-types: [version-update:semver-major]

- package-ecosystem: npm
directory: /apps/operator-console
schedule:
interval: weekly
day: monday
time: "04:20"
timezone: America/New_York
open-pull-requests-limit: 10
groups:
operator-console-production:
dependency-type: production
update-types: [minor, patch]
operator-console-development:
dependency-type: development
update-types: [minor, patch]
ignore:
- dependency-name: "*"
update-types: [version-update:semver-major]

- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
day: monday
time: "04:40"
timezone: America/New_York
groups:
github-actions:
patterns: ["*"]

- package-ecosystem: docker
directory: /deploy/docker
schedule:
interval: weekly
day: monday
time: "05:00"
timezone: America/New_York

45 changes: 38 additions & 7 deletions .github/workflows/build-image.yml
Original file line number Diff line number Diff line change
@@ -1,34 +1,65 @@
name: build-image

on:
push:
branches: [main]
tags: ['v*']
workflow_dispatch:
workflow_call:

permissions:
contents: read

concurrency:
group: release-image-${{ github.ref }}
cancel-in-progress: false

jobs:
build:
runs-on: [self-hosted, linux, weather-build]
environment: release
timeout-minutes: 30
steps:
- name: Checkout
uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09
- name: Require internal registry configuration
- name: Require internal release configuration
run: |
test -n "${{ vars.INTERNAL_REGISTRY }}"
test -n "${{ vars.PYTHON_BASE_IMAGE }}"
test -n "${{ vars.PYPI_MIRROR_URL }}"
Comment thread
Protonmatter marked this conversation as resolved.
test -n "${{ vars.PYPI_MIRROR_ORIGIN }}"
test -n "${INTERNAL_RELEASE_ATTEST_COMMAND:-}"
test -f requirements/production.lock
test -f requirements/ci.lock
- name: Build wheelhouse from the internal mirror
env:
PIP_INDEX_URL: ${{ vars.PYPI_MIRROR_URL }}
PYPI_MIRROR_ORIGIN: ${{ vars.PYPI_MIRROR_ORIGIN }}
IMAGE: ${{ vars.INTERNAL_REGISTRY }}/weather/platform:${{ github.sha }}
BASE_IMAGE: ${{ vars.PYTHON_BASE_IMAGE }}
INTERNAL_REGISTRY: ${{ vars.INTERNAL_REGISTRY }}
run: ./scripts/build_image.sh
- name: Run internal artifact policy and signing
- name: Push, scan, sign, and attest internally
env:
IMAGE: ${{ vars.INTERNAL_REGISTRY }}/weather/platform:${{ github.sha }}
RELEASE_IMAGE_REF_FILE: release/image-ref.txt
run: |
test -n "${INTERNAL_RELEASE_ATTEST_COMMAND:-}"
mkdir -p release
bash -lc "$INTERNAL_RELEASE_ATTEST_COMMAND"
test -s "$RELEASE_IMAGE_REF_FILE"
- name: Render immutable release evidence
run: |
PYTHONPATH=src python -m scripts.render_release_manifest \
--source deploy/k8s/weather-acquisition.yaml \
--output release/weather-acquisition.yaml \
Comment on lines +46 to +50

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Attest the rendered release bundle

In the checked build-image.yml ordering, the internal signing and attestation command finishes before this step creates weather-acquisition.yaml and release-metadata.json, so neither file can be covered by that attestation even though the subsequent upload publishes them as immutable release evidence and SPEC-820 requires signed release evidence. Render the bundle before the attestation step or add a subsequent signature/attestation over the completed bundle so consumers can verify the source, lock, manifest, and image binding.

Useful? React with 👍 / 👎.

--image-reference-file release/image-ref.txt \
--expected-repository "${{ vars.INTERNAL_REGISTRY }}/weather/platform" \
--metadata release/release-metadata.json \
Comment thread
Protonmatter marked this conversation as resolved.
--git-sha "${GITHUB_SHA}" \
--production-lock requirements/production.lock \
--ci-lock requirements/ci.lock
! grep -q 'sha256:0000000000000000000000000000000000000000000000000000000000000000' \
release/weather-acquisition.yaml
- name: Upload release evidence
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
with:
name: weather-release-${{ github.sha }}
path: release/
if-no-files-found: error
retention-days: 90
19 changes: 14 additions & 5 deletions .github/workflows/ci-bootstrap.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,8 @@
name: ci-bootstrap

on:
workflow_call:
pull_request:
push:
branches: [main]

permissions:
contents: read
Expand All @@ -21,12 +20,22 @@ jobs:
- name: Install Python 3.12
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1
with:
python-version: '3.12'
python-version-file: '.python-version'
cache: pip
cache-dependency-path: requirements/ci.lock
- name: Create isolated environment
run: python -m venv .venv
- name: Install (with the ecCodes decode extra)
run: .venv/bin/python -m pip install -e '.[dev,eccodes]'
- name: Install hash-pinned dependencies
run: |
.venv/bin/python -m pip install \
--disable-pip-version-check \
--require-hashes \
--requirement requirements/ci.lock
.venv/bin/python -m pip install \
--disable-pip-version-check \
--no-build-isolation \
--no-deps \
--editable .
- name: Lint
run: PATH="$PWD/.venv/bin:$PATH" make lint
- name: Type check
Expand Down
22 changes: 22 additions & 0 deletions .github/workflows/continuous-delivery.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
name: continuous-delivery

on:
push:
branches: [main]
tags: ['v*']
workflow_dispatch:

permissions:
contents: read

concurrency:
group: continuous-delivery-${{ github.ref }}
cancel-in-progress: false

jobs:
continuous-integration:
uses: ./.github/workflows/continuous-integration.yml
immutable-release:
needs: continuous-integration
uses: ./.github/workflows/build-image.yml

30 changes: 30 additions & 0 deletions .github/workflows/continuous-integration.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
name: continuous-integration

on:
workflow_call:

permissions:
contents: read

jobs:
specification:
uses: ./.github/workflows/spec-validation.yml
dependency-locks:
uses: ./.github/workflows/python-lock.yml
python-quality:
uses: ./.github/workflows/ci-bootstrap.yml
python-fast:
uses: ./.github/workflows/pr-fast.yml
schema-contract:
uses: ./.github/workflows/schema-contract.yml
weather-contract:
uses: ./.github/workflows/weather-contract.yml
scientific-validation:
uses: ./.github/workflows/scientific-validation.yml
weather-integration:
uses: ./.github/workflows/weather-integration.yml
operator-console:
uses: ./.github/workflows/operator-console.yml
end-to-end:
uses: ./.github/workflows/end-to-end.yml

80 changes: 80 additions & 0 deletions .github/workflows/end-to-end.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,80 @@
name: end-to-end

on:
workflow_call:
pull_request:
paths:
- 'src/**'
- 'apps/operator-console/**'
- 'requirements/ci.lock'
- 'pyproject.toml'
- 'specs/**'
- 'scripts/validate_dependency_policy.py'
- '.github/dependabot.yml'
- '.github/workflows/end-to-end.yml'
- '.github/workflows/continuous-integration.yml'
- '.github/workflows/continuous-delivery.yml'
- '.github/workflows/build-image.yml'

permissions:
contents: read

concurrency:
group: end-to-end-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true

jobs:
verify:
runs-on: ubuntu-latest
timeout-minutes: 25
steps:
- name: Checkout
uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09
- name: Install Python
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1
with:
python-version-file: '.python-version'
cache: pip
cache-dependency-path: requirements/ci.lock
- name: Install hash-pinned Python graph
run: |
python -m venv .venv
.venv/bin/python -m pip install \
--disable-pip-version-check \
--require-hashes \
--requirement requirements/ci.lock
.venv/bin/python -m pip install \
--disable-pip-version-check \
--no-build-isolation \
--no-deps \
--editable .
- name: Validate specifications and dependency policy
run: PATH="$PWD/.venv/bin:$PATH" make validate
- name: Install Node.js
uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38
with:
node-version-file: apps/operator-console/.nvmrc
cache: npm
cache-dependency-path: apps/operator-console/package-lock.json
- name: Install locked operator-console graph
working-directory: apps/operator-console
run: npm run install:ci
- name: Build deployable operator-console worker
working-directory: apps/operator-console
run: npm run build
- name: Run process-boundary end-to-end verification
working-directory: apps/operator-console
env:
PYTHON_BIN: ${{ github.workspace }}/.venv/bin/python
run: |
mkdir -p ../../artifacts
node --test --test-reporter=junit tests/control-plane.e2e.test.mjs \
> ../../artifacts/end-to-end-junit.xml
- name: Upload end-to-end evidence
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
with:
name: end-to-end-${{ github.sha }}
path: artifacts/end-to-end-junit.xml
if-no-files-found: error
retention-days: 30
10 changes: 2 additions & 8 deletions .github/workflows/operator-console.yml
Original file line number Diff line number Diff line change
@@ -1,18 +1,12 @@
name: operator-console

on:
workflow_call:
pull_request:
paths:
- 'apps/operator-console/**'
- 'Makefile'
- '.github/workflows/operator-console.yml'
push:
branches: [main]
paths:
- 'apps/operator-console/**'
- 'Makefile'
- '.github/workflows/operator-console.yml'

permissions:
contents: read

Expand All @@ -29,7 +23,7 @@ jobs:
- name: Install Node.js
uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38
with:
node-version: '22.13.1'
node-version-file: apps/operator-console/.nvmrc
cache: npm
cache-dependency-path: apps/operator-console/package-lock.json
- name: Install locked dependencies
Expand Down
19 changes: 14 additions & 5 deletions .github/workflows/pr-fast.yml
Original file line number Diff line number Diff line change
@@ -1,9 +1,8 @@
name: pr-fast

on:
workflow_call:
pull_request:
push:
branches: [main]

permissions:
contents: read
Expand All @@ -18,12 +17,22 @@ jobs:
- name: Install Python 3.12
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1
with:
python-version: '3.12'
python-version-file: '.python-version'
cache: pip
cache-dependency-path: requirements/ci.lock
- name: Create isolated environment
run: python -m venv .venv
- name: Install
run: .venv/bin/python -m pip install -e '.[dev,eccodes]'
- name: Install hash-pinned dependencies
run: |
.venv/bin/python -m pip install \
--disable-pip-version-check \
--require-hashes \
--requirement requirements/ci.lock
.venv/bin/python -m pip install \
--disable-pip-version-check \
--no-build-isolation \
--no-deps \
--editable .
- name: Lint
run: PATH="$PWD/.venv/bin:$PATH" make lint
- name: Type check
Expand Down
Loading
Loading