Skip to content

test: validate signed tenant artifact handoff#98

Merged
devantler merged 3 commits into
mainfrom
codex/security-signed-artifact-handoff-97
Jul 21, 2026
Merged

test: validate signed tenant artifact handoff#98
devantler merged 3 commits into
mainfrom
codex/security-signed-artifact-handoff-97

Conversation

@devantler

Copy link
Copy Markdown
Contributor

🤖 Generated by the Agentic Engineer

Summary

  • Bind the template's signed publisher to Platform's private GHCR credential and cosign-verifying OCI source.
  • Prove both KRO-generated and manual registrations keep the same credential, source, and Flux handoff.
  • Keep the contract live against Platform main and fail closed when any producer, credential, or trust edge drifts.

Why

The scaffold already proves admission, RBAC, namespace, and network compatibility, but it could still pass green while a new tenant could not pull its private artifact or while the accepted signing identity widened. This closes that remaining day-one delivery seam.

Security and developer experience

The trusted artifact producer and private pull-credential chain can no longer widen or disconnect silently. Adoption remains unchanged: this adds validation only, with no new tenant setting, secret, workflow, or runtime component.

Fixes #97
Part of #6

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

Readiness evidence — 571c7336408fca0334010311909c914b916713d2

  • TDD evidence: the new structural contract first failed because the Platform runtime lacked external-secret.yaml; a second RED mutation then proved that deleting the .dockerconfigjson mapping was not detected. Both failures were closed before GREEN.
  • Programmatic validation: the complete scaffold suite is green locally and at this exact head, including actionlint, ShellCheck, offline zizmor, 12 structural mutations, and 48 independent producer-to-reconciler behavior mutations against Platform 6b67c9454e73fe7faf94d3be39bf874ba194b8e1.
  • User-path evaluation: invoked the validator from /tmp against an exact Platform checkout, outside either repository. The workflow publication contract, GHCR credential handoff, service-account pull secret, OCI authentication, cosign identity, and both Flux source references passed as a connected path; the default tenant render remained unchanged.
  • Security and DevEx: the validator fails closed when any trust or credential seam drifts while requiring no new tenant inputs or operator steps.

The hosted checks are green at this head. Requesting the required exact-head review next.

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 21, 2026

Copy link
Copy Markdown

@devantler: Starting a review of the exact PR head and its signed-artifact handoff validation.

✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai

coderabbitai Bot commented Jul 21, 2026

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

The tenant-envelope validation now checks the pinned publish workflow, GHCR credential wiring, cosign OIDC verification, OCIRepository source references, Flux targeting, and both KRO and manual registration paths. Mutation tests cover missing or altered resources, widened artifact trust, broken source bindings, and unsafe publisher workflow changes. README and workflow comments document the expanded validation scope.

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Linked Issues check ✅ Passed The updated tests cover the publisher, GHCR credential, cosign verification, Flux references, and fail-closed mutations required by #97.
Out of Scope Changes check ✅ Passed The changes appear in scope as workflow comments, README guidance, and test validation for the signed handoff contract.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check ✅ Passed The title is concise and accurately summarizes the signed tenant artifact handoff validation.
Description check ✅ Passed The description matches the changeset and explains the new signed artifact handoff validation.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

CodeRabbit could not perform the requested exact-head review because its organization quota is exhausted for another 13 minutes. Requesting the independent review lane at 571c7336408fca0334010311909c914b916713d2.

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 571c733640

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/platform-tenant-envelope.test.sh
Comment thread scripts/platform-tenant-envelope.test.sh
Comment thread scripts/platform-tenant-envelope-contract.test.sh
Comment thread scripts/platform-tenant-envelope.test.sh
Comment thread scripts/platform-tenant-envelope.test.sh
Comment thread scripts/platform-tenant-envelope.test.sh
@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

The six exact-head Codex findings were fixed at 1ee92a30432768241b27d5e7560034b90e8b73a2; 57 behavioral and 13 structural negative controls are green locally and in hosted CI. The prior CodeRabbit quota retry window has elapsed.

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 21, 2026

Copy link
Copy Markdown

@devantler: Starting a review of the updated PR head, including the signed tenant-artifact handoff validation and the reported fixes.

✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

Genuine-readiness evidence — final exact head

Exact head: 1ee92a30432768241b27d5e7560034b90e8b73a2

  • Programmatically tested: every exact-head check is green (the draft-only auto-merge job is skipped as designed), including Platform Admissibility, Validate Scaffold, Pod Security and tenant RBAC, CodeQL, dependency review, action scanning, and the required-check aggregator. Local actionlint, ShellCheck, offline zizmor, render, and git diff --check also pass. The signed-artifact runtime rejects 57 behavioral mutations and its structural contract rejects 13 mutations against Platform 6b67c9454e73fe7faf94d3be39bf874ba194b8e1.
  • Reviewed: green_review=coderabbit@1ee92a3043 via CodeRabbit run 4515c5f3-9e78-4f32-90f7-236243312233, which reviewed all four changed files and reported no actionable comments. Its supported pre-merge evaluator is exact-head 5/5. All six earlier Codex findings were fixed, answered, and resolved; unresolved=0.
  • Tried and evaluated as a user: invoked the complete validator from /tmp against the exact Platform checkout, outside either repository. The pinned publisher, private GHCR credential, service-account pull identity, cosign OIDC verification, OCI source, and both Flux consumers passed as one connected handoff; the default tenant render remained unchanged.
  • Security and DevEx: branch publication, parallel privileged publishers, removable baseline validation, cross-namespace source overrides, key-based verification overrides, and suspended sources now fail closed without adding tenant inputs or operator steps.

Project 5 is moving to 🚀 Ready to Merge.

@devantler
devantler marked this pull request as ready for review July 21, 2026 22:03
@devantler
devantler requested a review from a team as a code owner July 21, 2026 22:03
@devantler
devantler merged commit 7058469 into main Jul 21, 2026
14 checks passed
@devantler
devantler deleted the codex/security-signed-artifact-handoff-97 branch July 21, 2026 22:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Validate the signed tenant artifact handoff

1 participant