chore: adopt engineering standard v1.0.0
Some checks failed
ci / standards-gate (pull_request) Has been cancelled
Some checks failed
ci / standards-gate (pull_request) Has been cancelled
Adopt the org engineering standard (its-consulting/standards @ v1.0.0).
Adds baseline governance/CI/policy files rendered from the standard's
templates and pins .standards-version=1.0.0. Vendored OPA/Rego policies
under .standards/policies/ so CI runs the gate locally (no cross-repo dep).
Placeholders ({{ORG}}/{{REPO}}/{{OWNER_HANDLE}}/{{MAINTAINER_EMAIL}}) filled in.
Existing files that differ were left untouched by the adopter.
Automated rollout. Files created: 15.
This commit is contained in:
parent
b4ac82a071
commit
ebeb65f23f
25 changed files with 1846 additions and 0 deletions
66
.standards/policies/ci/pipeline_contract.rego
Normal file
66
.standards/policies/ci/pipeline_contract.rego
Normal file
|
|
@ -0,0 +1,66 @@
|
|||
# Pipeline contract: both CI adapters (GitHub Actions and Woodpecker) must implement
|
||||
# the SAME canonical stage sequence, so a pipeline is portable between them.
|
||||
#
|
||||
# Enforces: docs/adr/0002-dual-target-ci.md
|
||||
# SOP: sops/SOP-001-branch-and-merge.md (the merge gate runs this contract)
|
||||
# Input: a pipeline descriptor listing the stages it defines:
|
||||
# {
|
||||
# "ci": "github",
|
||||
# "stages": ["static-checks", "test", "build", "policy_check",
|
||||
# "security-scan", "publish", "deploy-staging"]
|
||||
# }
|
||||
# Stage names may use the adapter's own spelling; `deploy` is satisfied by either
|
||||
# `deploy-staging` or `deploy-prod`.
|
||||
#
|
||||
# Rules:
|
||||
# deny - any REQUIRED canonical stage is missing from the descriptor
|
||||
package standards.ci.pipeline
|
||||
|
||||
import rego.v1
|
||||
|
||||
# Only evaluate inputs that are actually pipeline descriptors (carry a `stages` list).
|
||||
# Keeps the package silent under conftest --all-namespaces for unrelated inputs.
|
||||
_is_pipeline_input if {
|
||||
is_array(input.stages)
|
||||
}
|
||||
|
||||
# The canonical, ordered set of stages every pipeline must implement. `deploy` is a
|
||||
# logical stage satisfied by a concrete deploy-staging or deploy-prod stage.
|
||||
required_stages := ["static-checks", "test", "build", "policy_check", "security-scan", "publish", "deploy"]
|
||||
|
||||
# The set of stage names the descriptor actually declares, lower-cased.
|
||||
declared_stages contains s if {
|
||||
some raw in input.stages
|
||||
is_string(raw)
|
||||
s := lower(raw)
|
||||
}
|
||||
|
||||
# --- A required stage is missing --------------------------------------------
|
||||
|
||||
deny contains msg if {
|
||||
_is_pipeline_input
|
||||
some required in required_stages
|
||||
not _stage_satisfied(required)
|
||||
msg := sprintf("pipeline is missing required stage '%v'; both CI adapters must implement the canonical contract %v (ADR-0002, SOP-001)", [required, required_stages])
|
||||
}
|
||||
|
||||
# --- helpers ----------------------------------------------------------------
|
||||
|
||||
# _stage_satisfied(req) is true when the descriptor declares the required stage.
|
||||
# The logical `deploy` stage is satisfied by deploy-staging OR deploy-prod.
|
||||
_stage_satisfied(req) if {
|
||||
req != "deploy"
|
||||
declared_stages[req]
|
||||
}
|
||||
|
||||
_stage_satisfied("deploy") if {
|
||||
declared_stages["deploy-staging"]
|
||||
}
|
||||
|
||||
_stage_satisfied("deploy") if {
|
||||
declared_stages["deploy-prod"]
|
||||
}
|
||||
|
||||
_stage_satisfied("deploy") if {
|
||||
declared_stages["deploy"]
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue