feat: add static production promotion permit verifier - #802
Open
mindburnlabs wants to merge 8 commits into
Open
Conversation
|
Strix is installed on this repository, but we couldn't run this PR security review because this workspace's trial has ended. Add a card to resume code reviews here. |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
peycheff-com
force-pushed
the
codex/helm-473-promotion-verifier
branch
from
August 6, 2026 16:38
1450376 to
b4c1d36
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
production_candidateor canonicalproduction_released), platform and apps overlay refs/hashes, protected environment, and explicit apps-empty intentDEPLOY_PRODUCTION_ACTIVATEeffectTrust and production boundary
--verification-contextsupplies verification keys, policy constraints, the current fence, and connector-release state. That context is intentionally not self-authenticating: this verifier validates artifacts against the supplied context, while an integration must load it from a base-owned trust source. That source and its provenance are outside this slice and remain a required production gate.This is a source verifier slice for HELM-473. It creates no signer, approval, connector authority, deployment, or production mutation. Production Alpha remains NO-GO and undeployed until a base-owned trust source, source-owned apply connector, GitOps inputs, and an actual human promotion exist.
Validation
make quality-prgo testandgo vetfor./core/pkg/promotionpermitand./core/cmd/promotion-permit-verifygit diff --checkChecklist
Review boundary
Independent authority/security review is required before merge. Leave this PR open after CI; do not merge from this task.