feat(iwooos): 新增 K8s ArgoCD 事故回讀 gate
This commit is contained in:
@@ -2,8 +2,8 @@
|
||||
|
||||
| 項目 | 內容 |
|
||||
|------|------|
|
||||
| 日期 | 2026-06-14 |
|
||||
| 狀態 | 草案;P0 governance 總帳已建立;高價值配置 Owner Packet count sync 已完成 |
|
||||
| 日期 | 2026-06-15 |
|
||||
| 狀態 | 草案;P0 governance 總帳已建立;高價值配置 Owner Packet count sync 與 K8s / ArgoCD 事故後回讀投影已完成 |
|
||||
| Schema | `docs/schemas/iwooos_posture_projection_v1.schema.json` |
|
||||
| Snapshot | `docs/security/iwooos-posture-projection.snapshot.json` |
|
||||
| 模式 | `mirror_only` |
|
||||
@@ -23,6 +23,12 @@
|
||||
|
||||
此同步只代表 committed read-only projection 與前台顯示對齊;`request_sent_count`、`received_response_count`、`accepted_response_count`、`runtime_gate_count` 與 action buttons 仍全部維持 `0`,不代表 Nginx reload、certbot renew、DNS / TLS probe、workflow 修改、secret rotation、host write、active scan、production write 或 runtime gate。
|
||||
|
||||
## 1.2 2026-06-15 K8s / ArgoCD 事故後回讀投影
|
||||
|
||||
`k8s_argocd_post_incident_readback_plan_v1` 已投影到 `iwooos-posture-projection.snapshot.json` 與前台 marker。固定 `candidate_count=4`、`c0_candidate_count=3`、`write_capable_candidate_count=4`、`required_readback_field_count=31`、`reviewer_check_count=28`、`outcome_lane_count=10`、`blocked_action_count=41`,並讓 `k8s_production_gitops_coverage_percent=66`。
|
||||
|
||||
此同步只代表前端可以顯示 K8s / ArgoCD 事故後回讀計畫與邊界;`post_incident_readback_received_count`、`post_incident_readback_accepted_count`、`argocd_api_read_authorized_count`、`argocd_sync_authorized_count`、`kubectl_action_authorized_count`、`runtime_gate_count` 與 `action_button_count` 仍全部維持 `0`。不得把 ArgoCD `Synced`、route 200、Pod Running、CD success 或 smoke pass 視為資安驗收。
|
||||
|
||||
## 2. 來源
|
||||
|
||||
IwoooS 首版只讀取或對齊以下已提交 evidence:
|
||||
@@ -33,6 +39,7 @@ IwoooS 首版只讀取或對齊以下已提交 evidence:
|
||||
| `security_rollout_policy_v1` | 7 條 low-friction non-blocking lanes |
|
||||
| `source_control_owner_response_validation_rollup_v1` | owner response 仍為 0、S4.9 下一個收件候選 |
|
||||
| `source_control_primary_readiness_gate_v1` | GitHub primary readiness 仍為 0、候選 repo 與切換前置缺口 |
|
||||
| `k8s_argocd_post_incident_readback_plan_v1` | K8s / ArgoCD 事故後回讀計畫、66% 子項成熟度、31 個必填欄位、41 類 blocked action、runtime gate 0 |
|
||||
| `kali_integration_status_v1` | Kali 112 observe-only 整合態勢 |
|
||||
| `vibework_iwooos_onboarding_handoff_v1` | VibeWork repo / product / surface / owner / evidence refs / 獨立產品邊界只讀 handoff |
|
||||
| `docs/LOGBOOK.md` | 部署 marker、Gitea run 與 rollout risk 邊界紀錄 |
|
||||
@@ -103,6 +110,7 @@ IwoooS 首版只讀取或對齊以下已提交 evidence:
|
||||
56. 16 個 SSH / network access repo-only inventory surfaces、owner response acceptance 與端口 / 防火牆變更證據驗收只讀帳本,顯示 SSH target、known_hosts workflow、CI deploy SSH、monitoring SSH、backup SSH capture、sudoers wrapper、NetworkPolicy、NodePort、WireGuard runbook 與 alert SSH action catalog 的第一層清冊;write-capable surface `6`、NetworkPolicy `2`、NodePort `2`、sudoers `1`、WireGuard `1`,acceptance candidate `16`、change evidence candidate `14`、reviewer check `21`、outcome lane `9`、blocked action `28`,讓 SSH / network 類別成熟度從 `58%` 推進到 `62%`;owner response、change evidence、actor、before / after state、service health impact、operator notification、cross-project sync、post-check evidence、maintenance window、rollback owner、runtime gate 與 action button 仍全部為 `0`,不代表 SSH、sudo、firewall、port close / open、NetworkPolicy、NodePort、WireGuard、route smoke 或 known_hosts patch 已授權。
|
||||
56d. 14 個 SSH / network / firewall post-incident readback 候選,顯示端口關閉、firewall / NetworkPolicy / NodePort / WireGuard policy、deploy SSH、sudo 與 alert action 事故後必須回讀 actor、before / after、service / public route / AI provider / monitoring impact、operator notification、cross-project sync、restoration evidence、post-check、recurrence guard 與 no-false-green attestation;write-capable candidate `6`、policy / exposure candidate `5`、required readback field `24`、reviewer check `24`、outcome lane `10`、blocked action `34`,讓 SSH / network 類別成熟度從 `62%` 推進到 `64%`;readback received / accepted、actor accepted、before / after accepted、impact accepted、notification accepted、sync accepted、restoration accepted、recurrence guard accepted、runtime gate 與 action button 仍全部為 `0`。
|
||||
56a. 4 個 K8s / ArgoCD GitOps 變更證據驗收候選,顯示 production manifests、ArgoCD app、Velero、monitoring manifests 的 proposed commit、rendered manifest diff、ArgoCD app / sync revision、health before / after、rollout、route smoke、metrics / alert、secret metadata parity、blast radius、maintenance window、rollback revision 與 postcheck owner 收件規則;C0 candidate `3`、write-capable candidate `4`、reviewer check `18`、outcome lane `8`、blocked action `28`,讓 K8s / ArgoCD 類別成熟度從 `62%` 推進到 `64%`;change evidence、runtime approval package、ArgoCD API read、ArgoCD sync、kubectl action、Helm upgrade、NetworkPolicy / NodePort / RBAC change、production write、runtime gate 與 action button 仍全部為 `0`。
|
||||
56a.1. 4 個 K8s / ArgoCD post-incident readback 候選,顯示 ArgoCD app health、sync status、Degraded / Pending、image pull / scheduling、rollout before / after、event / metrics / alert、drift scanner、CronJob、NetworkPolicy / RBAC / Secret metadata、public/admin route、AI provider / monitoring、backup / restore、operator notification、cross-project sync、postcheck、recurrence guard 與 no-false-green attestation 的事故後回讀規則;C0 candidate `3`、write-capable candidate `4`、required readback field `31`、reviewer check `28`、outcome lane `10`、blocked action `41`,讓 K8s / ArgoCD 類別成熟度從 `64%` 推進到 `66%`;readback received / accepted、ArgoCD API read、ArgoCD sync、live cluster read、kubectl、Helm、NetworkPolicy / NodePort / RBAC change、route smoke、production write、runtime gate 與 action button 仍全部為 `0`。
|
||||
56b. 5 個 CD / Runner / Secret 注入變更證據驗收候選,顯示 CD pipeline、程式碼審查、部署通知、執行器證明與 repository secret name parity / injection owner 的 metadata-only 收件規則;C0 candidate `4`、write-capable candidate `5`、local workflow file `33`、referenced secret name `42`、runner label `5`、reviewer check `19`、outcome lane `8`、blocked action `32`,讓 secret metadata 類別成熟度從 `66%` 推進到 `68%`,讓 Gitea workflow / runner 類別成熟度從 `70%` 推進到 `72%`;workflow diff、runner attestation、secret name parity、secret injection route、deploy marker readback、guard result、postcheck evidence、runtime approval package、workflow modification、runner change、repo secret change、secret rotation、Gitea action dispatch、production deploy、runtime gate 與 action button 仍全部為 `0`。
|
||||
56c. 8 個 AI provider / model routing owner response acceptance 候選,顯示 AI router provider policy、Ollama proxy gateway、fallback order / circuit breaker、cost budget / quota、privacy / data egress、benchmark / dry-run、model card / version inventory 與 agent replacement candidate boundary 的 metadata-only 收件規則;write-capable candidate `5`、paid-provider candidate `5`、data-egress candidate `6`、owner field `24`、reviewer check `24`、outcome lane `10`、blocked action `38`,讓 AI provider / model routing 類別成熟度從 `60%` 推進到 `64%`;owner response、fallback order、dry-run、benchmark、cost review、privacy review、prompt redaction、quality gate、provider switch、external provider call、paid provider call、prompt send、live endpoint probe、secret collection、SDK install、shadow / canary、runtime gate 與 action button 仍全部為 `0`。
|
||||
57. 38 個 Backup / restore / escrow / retention repo-only inventory surfaces,顯示 backup orchestration、service backup scripts、restic retention、offsite sync、credential escrow、Velero restore drill、backup health alert 與 cold-start / DR runbook 的第一層清冊;write-capable surface `27`、restore drill surface `4`、offsite / escrow surface `8`,owner response、live evidence、restore drill、offsite sync、credential escrow、retention change、runtime gate 與 action button 仍全部為 `0`,不代表 backup、restore、offsite sync、remote delete、restic prune、escrow marker write、rclone config 或 Velero restore 已授權。
|
||||
|
||||
Reference in New Issue
Block a user