Skip to content

Require peer-review in the env policy, and make integration-tests a control - #44

Merged
sami-alajrami merged 1 commit into
mainfrom
integration-tests-and-peer-review-controls
Aug 26, 2026
Merged

sami-alajrami merged 1 commit into
mainfrom
integration-tests-and-peer-review-controls

Conversation

@sami-alajrami

Copy link
Copy Markdown
Contributor

Summary

  • secure-development.yml (staging + production) now names peer-review-decision explicitly via the schema's for_control field on a decision-type rule, instead of relying only on implicit trail-compliance coverage. Also names sbom explicitly.
  • integration-tests moves off the last remaining "jq rules on the attestation type decide compliance" pattern and becomes a control, the same shape as peer-review:
    • New kosli/policies/integration-tests.rego judges the report (same three conditions the old jq rules checked).
    • report-integration-test-result.yml now evaluates the report and records the verdict as a trail-level decision attestation via kosli attest decision --control integration-tests, instead of binding it to the orders-api fingerprint.
    • production-readiness.yml requires it via for_control: integration-tests.
    • The now-unused custom:integration-test attestation type and its schema are removed; bootstrap_kosli.sh gains an integration-tests control block alongside peer-review's.

Test plan

  • Run the Bootstrap Kosli workflow and confirm both controls (peer-review, integration-tests) and the updated policies apply cleanly
  • Push to main, confirm peer-review-decision and the new integration-tests-decision land on the trail, and that publish-gate/release-gate still evaluate correctly against the updated secure-development.yml/production-readiness.yml
  • Confirm for_control actually satisfies the policy against a trail-level decision attestation in a live assert (already confirmed by the customer per conversation, but worth re-checking on this specific run)

…ontrol

secure-development.yml (staging + production) now names peer-review-decision
explicitly via the schema's for_control field on a decision-type rule, rather
than relying only on implicit trail-compliance coverage - confirmed live that
for_control matches a trail-level decision attestation. Also names sbom.

integration-tests moves off the last remaining "jq rules on the attestation
type decide compliance" pattern and becomes a control, the same shape as
peer-review: kosli/policies/integration-tests.rego judges the report, the
verdict is recorded as a trail-level decision attestation instead of being
bound to the orders-api artifact, and production-readiness.yml requires it
via for_control. The now-unused custom:integration-test type and its schema
are removed.
@sami-alajrami
sami-alajrami merged commit e0d5072 into main Aug 26, 2026
1 check passed
@sami-alajrami
sami-alajrami deleted the integration-tests-and-peer-review-controls branch August 26, 2026 13:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants