Skip to content
Open
Show file tree
Hide file tree
Changes from 59 commits
Commits
Show all changes
75 commits
Select commit Hold shift + click to select a range
1ba015d
docs: define P0 operationalization release
Protonmatter Aug 13, 2026
678bc1b
docs: add P0 operationalization plan
Protonmatter Aug 13, 2026
4a9d604
test: define authoritative mutation audit contract
Protonmatter Aug 13, 2026
3a95f39
test: define append-only audit storage
Protonmatter Aug 13, 2026
412f6ed
test: require immutable release image rendering
Protonmatter Aug 13, 2026
d7c65af
test: require request identity support
Protonmatter Aug 13, 2026
2a13004
feat: define mutation audit event model
Protonmatter Aug 13, 2026
57f3b37
fix: constrain mutation audit detail fields
Protonmatter Aug 13, 2026
bda9028
feat: add append-only mutation audit store
Protonmatter Aug 13, 2026
696bd23
feat: render digest-bound release manifests
Protonmatter Aug 13, 2026
ca68325
deploy: require release-rendered image digest
Protonmatter Aug 13, 2026
a050254
feat: configure authoritative mutation audit storage
Protonmatter Aug 13, 2026
65455d0
feat: add request identity helper
Protonmatter Aug 13, 2026
a3ac6e5
refactor: preserve established control-plane core
Protonmatter Aug 13, 2026
58b9624
feat: audit authoritative mutations and protect raw evidence
Protonmatter Aug 13, 2026
0d1eca2
test: add operator control-plane URL validation cases
Protonmatter Aug 13, 2026
e15d647
test: run operator control-plane URL validation cases
Protonmatter Aug 13, 2026
cb374e7
refactor: preserve operator weather adapter core
Protonmatter Aug 13, 2026
1979e5f
feat: validate control-plane destination before credential use
Protonmatter Aug 13, 2026
7c861c2
test: supply explicit control-plane host allowlist
Protonmatter Aug 13, 2026
0f80fa9
test: fix operator URL contract fixture
Protonmatter Aug 13, 2026
7748185
ci: add Python dependency lock generation
Protonmatter Aug 13, 2026
3ae6188
test: verify operational mutation accountability
Protonmatter Aug 13, 2026
a60a9fb
ci: pin pip for compatible lock generation
Protonmatter Aug 13, 2026
73be113
feat: generate digest-bound release metadata
Protonmatter Aug 13, 2026
b8b4f54
ci: publish digest-bound deployment evidence
Protonmatter Aug 13, 2026
78f3ef9
build: include wheel toolchain in dependency locks
Protonmatter Aug 13, 2026
2b87bd9
build: lock the Python wheel toolchain
Protonmatter Aug 13, 2026
f31c234
build: construct release images from locked wheels
Protonmatter Aug 13, 2026
2f894af
style: import release sequence from collections
Protonmatter Aug 13, 2026
b6869e3
style: format operationalization route assertions
Protonmatter Aug 13, 2026
0a28f0a
build: add one-shot lock materialization workflow
Protonmatter Aug 13, 2026
95817a8
build: materialize hash-pinned Python locks
github-actions[bot] Aug 13, 2026
2f57909
ci: install Python from hash-pinned lock
Protonmatter Aug 13, 2026
fff86da
ci: bootstrap Python from hash-pinned lock
Protonmatter Aug 13, 2026
cc7c37b
ci: lock operational weather contract dependencies
Protonmatter Aug 13, 2026
d24368a
ci: lock schema contract dependencies
Protonmatter Aug 13, 2026
b911f86
ci: use reproducible scientific dependency set
Protonmatter Aug 13, 2026
540edac
build: include build-system packages in Python locks
Protonmatter Aug 13, 2026
7f23ada
build: materialize hash-pinned Python locks
github-actions[bot] Aug 13, 2026
a152243
build: refresh one-shot lock materializer
Protonmatter Aug 13, 2026
28c12c7
build: recreate one-shot lock materializer
Protonmatter Aug 13, 2026
9c3aea4
build: allow explicit TypeScript module imports
Protonmatter Aug 13, 2026
30c139f
fix: use explicit TypeScript core module
Protonmatter Aug 13, 2026
8e348a1
feat: render immutable release deployment evidence
Protonmatter Aug 14, 2026
265e116
test: verify release image reference contract
Protonmatter Aug 14, 2026
b03d07f
test: inspect handled audit-store failures
Protonmatter Aug 14, 2026
36fdc34
build: expose release tooling module
Protonmatter Aug 14, 2026
a0a19be
docs: align license with public source visibility
Protonmatter Aug 14, 2026
238574c
chore: make repository ownership enforceable
Protonmatter Aug 14, 2026
7baa783
docs: define public proprietary repository posture
Protonmatter Aug 14, 2026
010c4d7
ci: remove one-shot lock materializer
Protonmatter Aug 14, 2026
694fcbf
docs: document operationalization and repository posture
Protonmatter Aug 14, 2026
fdb6a18
docs: document control-plane destination policy
Protonmatter Aug 14, 2026
7af0d8b
ci: lock specification validation dependencies
Protonmatter Aug 14, 2026
52e3cfb
style: replace release module with formatted source
Protonmatter Aug 14, 2026
674ef66
style: restore formatted release module
Protonmatter Aug 14, 2026
836b7d5
docs: record P0 operationalization release evidence
Protonmatter Aug 14, 2026
3cf7cf2
fix: resolve operationalization review findings
Protonmatter Aug 14, 2026
5d3f05c
fix: reconcile interrupted audit mutations
Protonmatter Aug 14, 2026
c24ac30
test: cover audit recovery boundaries
Protonmatter Aug 14, 2026
49daef2
fix: harden audit recovery and release builds
Protonmatter Aug 14, 2026
56722b0
docs: refresh PR 30 validation evidence
Protonmatter Aug 14, 2026
536c298
fix: preserve request identity and base image trust
Protonmatter Aug 14, 2026
b680c68
docs: refresh review validation evidence
Protonmatter Aug 14, 2026
b78fb10
Address crash-consistency review findings
Protonmatter Aug 14, 2026
bdc91e1
Preserve source retention request IDs
Protonmatter Aug 14, 2026
0e8714f
Cover crash-consistency recovery branches
Protonmatter Aug 14, 2026
0e30874
fix: close operational audit durability gaps
Protonmatter Aug 14, 2026
6449be4
feat: enforce spec-driven delivery pipeline
Protonmatter Aug 14, 2026
482a35a
fix: preserve npm lockfile integrity
Protonmatter Aug 14, 2026
089debb
fix: isolate release dependencies and index audit identities
Protonmatter Aug 15, 2026
e2422a2
fix: hash lock compiler and validate requirement identities
Protonmatter Aug 15, 2026
86ef973
fix: atomically bind ingestion receipts and bound audit reads
Protonmatter Aug 15, 2026
a7a7ec9
Harden reusable CI and catalog durability
Protonmatter Aug 15, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 4 additions & 7 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1,7 +1,4 @@
/specs/ @program-governance @scientific-review
/schemas/ @data-architecture
/src/weather_platform/scientific/ @probabilistic-modeling @independent-verification
/deploy/ @platform-sre @security-architecture
/apps/operator-console/ @platform-sre @product-security
/.github/workflows/ @platform-sre @product-security
/docs/NETWORK_BOUNDARY.md @security-architecture
# The repository is currently owned by a personal account, so organization
# team handles cannot enforce reviews here. Replace this fallback with real
# organization teams after repository migration.
* @Protonmatter
32 changes: 29 additions & 3 deletions .github/workflows/build-image.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,19 +16,45 @@ jobs:
steps:
- name: Checkout
uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09
- name: Require internal registry configuration
- name: Require internal release configuration
run: |
test -n "${{ vars.INTERNAL_REGISTRY }}"
test -n "${{ vars.PYTHON_BASE_IMAGE }}"
test -n "${{ vars.PYPI_MIRROR_URL }}"
Comment thread
Protonmatter marked this conversation as resolved.
test -n "${INTERNAL_RELEASE_ATTEST_COMMAND:-}"
test -f requirements/production.lock
test -f requirements/ci.lock
- name: Build wheelhouse from the internal mirror
env:
PIP_INDEX_URL: ${{ vars.PYPI_MIRROR_URL }}
IMAGE: ${{ vars.INTERNAL_REGISTRY }}/weather/platform:${{ github.sha }}
BASE_IMAGE: ${{ vars.PYTHON_BASE_IMAGE }}
run: ./scripts/build_image.sh
- name: Run internal artifact policy and signing
- name: Push, scan, sign, and attest internally
env:
IMAGE: ${{ vars.INTERNAL_REGISTRY }}/weather/platform:${{ github.sha }}
RELEASE_IMAGE_REF_FILE: release/image-ref.txt
run: |
test -n "${INTERNAL_RELEASE_ATTEST_COMMAND:-}"
mkdir -p release
bash -lc "$INTERNAL_RELEASE_ATTEST_COMMAND"
test -s "$RELEASE_IMAGE_REF_FILE"
- name: Render immutable release evidence
run: |
PYTHONPATH=src python -m scripts.render_release_manifest \
--source deploy/k8s/weather-acquisition.yaml \
--output release/weather-acquisition.yaml \
Comment on lines +46 to +50

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Attest the rendered release bundle

In the checked build-image.yml ordering, the internal signing and attestation command finishes before this step creates weather-acquisition.yaml and release-metadata.json, so neither file can be covered by that attestation even though the subsequent upload publishes them as immutable release evidence and SPEC-820 requires signed release evidence. Render the bundle before the attestation step or add a subsequent signature/attestation over the completed bundle so consumers can verify the source, lock, manifest, and image binding.

Useful? React with 👍 / 👎.

--image-reference-file release/image-ref.txt \
--expected-repository "${{ vars.INTERNAL_REGISTRY }}/weather/platform" \
--metadata release/release-metadata.json \
Comment thread
Protonmatter marked this conversation as resolved.
--git-sha "${GITHUB_SHA}" \
--production-lock requirements/production.lock \
--ci-lock requirements/ci.lock
! grep -q 'sha256:0000000000000000000000000000000000000000000000000000000000000000' \
release/weather-acquisition.yaml
- name: Upload release evidence
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
with:
name: weather-release-${{ github.sha }}
path: release/
if-no-files-found: error
retention-days: 90
14 changes: 12 additions & 2 deletions .github/workflows/ci-bootstrap.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,10 +23,20 @@ jobs:
with:
python-version: '3.12'
cache: pip
cache-dependency-path: requirements/ci.lock
- name: Create isolated environment
run: python -m venv .venv
- name: Install (with the ecCodes decode extra)
run: .venv/bin/python -m pip install -e '.[dev,eccodes]'
- name: Install hash-pinned dependencies
run: |
.venv/bin/python -m pip install \
--disable-pip-version-check \
--require-hashes \
--requirement requirements/ci.lock
.venv/bin/python -m pip install \
--disable-pip-version-check \
--no-build-isolation \
--no-deps \
--editable .
- name: Lint
run: PATH="$PWD/.venv/bin:$PATH" make lint
- name: Type check
Expand Down
14 changes: 12 additions & 2 deletions .github/workflows/pr-fast.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,10 +20,20 @@ jobs:
with:
python-version: '3.12'
cache: pip
cache-dependency-path: requirements/ci.lock
- name: Create isolated environment
run: python -m venv .venv
- name: Install
run: .venv/bin/python -m pip install -e '.[dev,eccodes]'
- name: Install hash-pinned dependencies
run: |
.venv/bin/python -m pip install \
--disable-pip-version-check \
--require-hashes \
--requirement requirements/ci.lock
.venv/bin/python -m pip install \
--disable-pip-version-check \
--no-build-isolation \
--no-deps \
--editable .
- name: Lint
run: PATH="$PWD/.venv/bin:$PATH" make lint
- name: Type check
Expand Down
56 changes: 56 additions & 0 deletions .github/workflows/python-lock.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
name: python-lock

on:
pull_request:
paths:
- 'pyproject.toml'
- 'requirements/**'
- 'scripts/compile_requirements.sh'
- '.github/workflows/python-lock.yml'
push:
branches: [main]
paths:
- 'pyproject.toml'
- 'requirements/**'
- 'scripts/compile_requirements.sh'
- '.github/workflows/python-lock.yml'

permissions:
contents: read

concurrency:
group: python-lock-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
Comment thread
Protonmatter marked this conversation as resolved.

jobs:
validate:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Checkout
uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09
- name: Install Python 3.12
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1
with:
python-version: '3.12'
cache: pip
- name: Install locked compiler
run: python -m pip install --disable-pip-version-check 'pip==26.1.2' 'pip-tools==7.6.0'
Comment thread
Protonmatter marked this conversation as resolved.
Outdated
- name: Generate lock evidence
run: bash scripts/compile_requirements.sh generated-locks
- name: Verify checked lock files are current
run: |
if [[ -f requirements/production.lock || -f requirements/ci.lock ]]; then
test -f requirements/production.lock
test -f requirements/ci.lock
diff -u requirements/production.lock generated-locks/production.lock
diff -u requirements/ci.lock generated-locks/ci.lock
fi
- name: Upload generated locks
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
with:
name: python-locks-${{ github.sha }}
path: generated-locks/*.lock
if-no-files-found: error
retention-days: 14
18 changes: 16 additions & 2 deletions .github/workflows/schema-contract.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,10 @@ on:
paths:
- 'schemas/**'
- 'src/weather_platform/domain/**'
- 'src/scripts/**'
- 'deploy/k8s/weather-*.yaml'
- 'requirements/ci.lock'
- 'tests/unit/test_release_manifest.py'
- 'tests/contract/test_weather_schemas.py'
- 'tests/contract/test_weather_deployment_policy.py'
- 'scripts/validate_schemas.py'
Expand All @@ -32,17 +35,28 @@ jobs:
with:
python-version: '3.12'
cache: pip
cache-dependency-path: requirements/ci.lock
- name: Create isolated environment
run: python -m venv .venv
- name: Install
run: .venv/bin/python -m pip install -e '.[dev]'
- name: Install hash-pinned dependencies
run: |
.venv/bin/python -m pip install \
--disable-pip-version-check \
--require-hashes \
--requirement requirements/ci.lock
.venv/bin/python -m pip install \
--disable-pip-version-check \
--no-build-isolation \
--no-deps \
--editable .
- name: Validate JSON Schemas
run: .venv/bin/python scripts/validate_schemas.py
- name: Run schema and deployment contracts
run: |
mkdir -p artifacts
.venv/bin/python -m pytest -q --no-cov \
--junitxml=artifacts/schema-contract-junit.xml \
tests/unit/test_release_manifest.py \
tests/contract/test_weather_schemas.py \
tests/contract/test_weather_deployment_policy.py
- name: Upload schema evidence
Expand Down
8 changes: 6 additions & 2 deletions .github/workflows/scientific-validation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ on:
- 'src/weather_platform/ingestion/eccodes_backend.py'
- 'src/weather_platform/scientific/**'
- 'src/weather_platform/serving/vector_tiles.py'
- 'requirements/ci.lock'
- 'tests/unit/test_probability.py'
- 'tests/unit/test_verification.py'
- 'tests/unit/test_grid_assets.py'
Expand Down Expand Up @@ -42,10 +43,13 @@ jobs:
with:
python-version: '3.12'
cache: pip
cache-dependency-path: requirements/ci.lock
- name: Create isolated environment
run: python -m venv .venv
- name: Install with ecCodes
run: .venv/bin/python -m pip install -e '.[dev,eccodes]'
- name: Install reproducible dependencies
run: |
.venv/bin/python -m pip install --require-hashes -r requirements/ci.lock
.venv/bin/python -m pip install --no-build-isolation --no-deps -e .
- name: Run physical and temporal invariants
run: |
mkdir -p artifacts
Expand Down
12 changes: 7 additions & 5 deletions .github/workflows/spec-validation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,11 @@ on:
pull_request:
paths:
- 'specs/**'
- 'requirements/ci.lock'
- 'scripts/validate_specs.py'
- 'scripts/generate_traceability.py'
- 'artifacts/traceability.json'
- '.github/workflows/spec-validation.yml'
push:
branches: [main]

Expand All @@ -25,12 +27,12 @@ jobs:
with:
python-version: '3.12'
cache: pip
cache-dependency-path: requirements/ci.lock
- name: Create isolated environment
shell: bash
run: python -m venv .venv
- name: Install validation dependencies
shell: bash
run: .venv/bin/python -m pip install -e '.[dev]'
- name: Install reproducible dependencies
run: |
.venv/bin/python -m pip install --require-hashes -r requirements/ci.lock
.venv/bin/python -m pip install --no-build-isolation --no-deps -e .
- name: Validate specifications and traceability
shell: bash
run: PATH="$PWD/.venv/bin:$PATH" make validate
26 changes: 24 additions & 2 deletions .github/workflows/weather-contract.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,13 +4,18 @@ on:
pull_request:
paths:
- 'src/weather_platform/acquisition/**'
- 'src/weather_platform/api/**'
- 'src/weather_platform/domain/**'
- 'src/weather_platform/grids/**'
- 'src/weather_platform/ingestion/eccodes_backend.py'
- 'src/weather_platform/serving/**'
- 'src/weather_platform/storage/audit.py'
- 'src/scripts/**'
- 'schemas/grids/**'
- 'schemas/manifests/**'
- 'deploy/k8s/weather-*.yaml'
- 'requirements/ci.lock'
- 'tests/unit/test_audit_domain.py'
- 'tests/unit/test_source_manifests.py'
- 'tests/unit/test_grid_assets.py'
- 'tests/unit/test_grib_index.py'
Expand All @@ -20,6 +25,9 @@ on:
- 'tests/unit/test_coordinates.py'
- 'tests/unit/test_wind.py'
- 'tests/unit/test_vector_tiles.py'
- 'tests/unit/test_release_manifest.py'
- 'tests/contract/test_operationalization_routes.py'
- 'tests/contract/test_request_identity.py'
- 'tests/contract/test_weather_schemas.py'
- 'tests/contract/test_weather_deployment_policy.py'
- 'tests/functional/test_weather_acquisition_cli.py'
Expand Down Expand Up @@ -48,15 +56,26 @@ jobs:
with:
python-version: '3.12'
cache: pip
cache-dependency-path: requirements/ci.lock
- name: Create isolated environment
run: python -m venv .venv
- name: Install
run: .venv/bin/python -m pip install -e '.[dev,eccodes]'
- name: Install hash-pinned dependencies
run: |
.venv/bin/python -m pip install \
--disable-pip-version-check \
--require-hashes \
--requirement requirements/ci.lock
.venv/bin/python -m pip install \
--disable-pip-version-check \
--no-build-isolation \
--no-deps \
--editable .
- name: Run weather contract tests
run: |
mkdir -p artifacts
.venv/bin/python -m pytest -q --no-cov \
--junitxml=artifacts/weather-contract-junit.xml \
tests/unit/test_audit_domain.py \
tests/unit/test_source_manifests.py \
tests/unit/test_grid_assets.py \
tests/unit/test_grib_index.py \
Expand All @@ -66,6 +85,9 @@ jobs:
tests/unit/test_coordinates.py \
tests/unit/test_wind.py \
tests/unit/test_vector_tiles.py \
tests/unit/test_release_manifest.py \
tests/contract/test_operationalization_routes.py \
tests/contract/test_request_identity.py \
tests/contract/test_weather_schemas.py \
tests/contract/test_weather_deployment_policy.py \
tests/functional/test_weather_acquisition_cli.py \
Expand Down
11 changes: 10 additions & 1 deletion .github/workflows/weather-integration.yml
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,16 @@ jobs:
- name: Create isolated environment
run: python -m venv .venv
- name: Install with ecCodes
run: .venv/bin/python -m pip install -e '.[dev,eccodes]'
run: |
.venv/bin/python -m pip install \
--disable-pip-version-check \
--require-hashes \
--requirement requirements/ci.lock
.venv/bin/python -m pip install \
--disable-pip-version-check \
--no-build-isolation \
--no-deps \
--editable .
- name: Run fixture-driven functional and integration paths
run: |
mkdir -p artifacts
Expand Down
14 changes: 7 additions & 7 deletions LICENSE
Original file line number Diff line number Diff line change
@@ -1,13 +1,13 @@
Copyright (c) 2026 Protonmatter. All rights reserved.

This software and its associated specifications, schemas, and documentation
(the "Software") are proprietary and confidential. The Software is made
available for internal development and evaluation only.
This repository is publicly viewable, but the software, specifications,
schemas, and documentation in it (the "Software") are proprietary. No
open-source license is granted.

No license or right, express or implied, to use, copy, modify, merge, publish,
distribute, sublicense, or sell any part of the Software is granted except
under a separate written agreement with the copyright holder. Unauthorized
copying or distribution of the Software, in whole or in part, is prohibited.
Except for rights required to view or interact with this public repository
through GitHub, no license or right, express or implied, is granted to use,
copy, modify, merge, publish, distribute, sublicense, or sell any part of the
Software without a separate written agreement from the copyright holder.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
Expand Down
Loading
Loading