fix(security): 補高價值配置 Gate P0 路徑覆蓋 [skip ci]
This commit is contained in:
@@ -1,26 +1,5 @@
|
||||
{
|
||||
"changed_files": [
|
||||
{
|
||||
"categories": [
|
||||
{
|
||||
"category_id": "security_evidence_tooling",
|
||||
"control_tier": "C3",
|
||||
"label": "Security evidence / snapshot / guard tooling",
|
||||
"priority": "P3",
|
||||
"required_gate": "security_evidence_owner_review_required",
|
||||
"required_validation": [
|
||||
"snapshot_parse",
|
||||
"guard_smoke",
|
||||
"doc_secret_sanity",
|
||||
"no_runtime_gate_increase"
|
||||
]
|
||||
}
|
||||
],
|
||||
"matched": true,
|
||||
"path": "docs/LOGBOOK.md",
|
||||
"strongest_priority": "P3",
|
||||
"strongest_tier": "C3"
|
||||
},
|
||||
{
|
||||
"categories": [
|
||||
{
|
||||
@@ -42,48 +21,6 @@
|
||||
"strongest_priority": "P3",
|
||||
"strongest_tier": "C3"
|
||||
},
|
||||
{
|
||||
"categories": [
|
||||
{
|
||||
"category_id": "security_evidence_tooling",
|
||||
"control_tier": "C3",
|
||||
"label": "Security evidence / snapshot / guard tooling",
|
||||
"priority": "P3",
|
||||
"required_gate": "security_evidence_owner_review_required",
|
||||
"required_validation": [
|
||||
"snapshot_parse",
|
||||
"guard_smoke",
|
||||
"doc_secret_sanity",
|
||||
"no_runtime_gate_increase"
|
||||
]
|
||||
}
|
||||
],
|
||||
"matched": true,
|
||||
"path": "docs/security/HIGH-VALUE-CONFIG-OWNER-PACKET.md",
|
||||
"strongest_priority": "P3",
|
||||
"strongest_tier": "C3"
|
||||
},
|
||||
{
|
||||
"categories": [
|
||||
{
|
||||
"category_id": "security_evidence_tooling",
|
||||
"control_tier": "C3",
|
||||
"label": "Security evidence / snapshot / guard tooling",
|
||||
"priority": "P3",
|
||||
"required_gate": "security_evidence_owner_review_required",
|
||||
"required_validation": [
|
||||
"snapshot_parse",
|
||||
"guard_smoke",
|
||||
"doc_secret_sanity",
|
||||
"no_runtime_gate_increase"
|
||||
]
|
||||
}
|
||||
],
|
||||
"matched": true,
|
||||
"path": "docs/security/IWOOOS-CONFIG-CONTROL-INVENTORY.md",
|
||||
"strongest_priority": "P3",
|
||||
"strongest_tier": "C3"
|
||||
},
|
||||
{
|
||||
"categories": [
|
||||
{
|
||||
@@ -108,23 +45,71 @@
|
||||
{
|
||||
"categories": [
|
||||
{
|
||||
"category_id": "security_evidence_tooling",
|
||||
"control_tier": "C3",
|
||||
"label": "Security evidence / snapshot / guard tooling",
|
||||
"priority": "P3",
|
||||
"required_gate": "security_evidence_owner_review_required",
|
||||
"category_id": "nginx_public_gateway",
|
||||
"control_tier": "C0",
|
||||
"label": "Nginx / reverse proxy / public route",
|
||||
"priority": "P0",
|
||||
"required_gate": "public_gateway_owner_response_required",
|
||||
"required_validation": [
|
||||
"snapshot_parse",
|
||||
"guard_smoke",
|
||||
"doc_secret_sanity",
|
||||
"no_runtime_gate_increase"
|
||||
"rendered_diff",
|
||||
"nginx_t",
|
||||
"affected_route_smoke",
|
||||
"admin_route_smoke_if_affected",
|
||||
"acme_path_smoke_if_affected",
|
||||
"rollback_ref"
|
||||
]
|
||||
}
|
||||
],
|
||||
"matched": true,
|
||||
"path": "docs/security/high-value-config-owner-packet.snapshot.json",
|
||||
"strongest_priority": "P3",
|
||||
"strongest_tier": "C3"
|
||||
"path": "k8s/nginx/awoooi-prod.conf",
|
||||
"strongest_priority": "P0",
|
||||
"strongest_tier": "C0"
|
||||
},
|
||||
{
|
||||
"categories": [
|
||||
{
|
||||
"category_id": "dns_tls_certbot",
|
||||
"control_tier": "C0",
|
||||
"label": "DNS / TLS / certbot / certificate path",
|
||||
"priority": "P0",
|
||||
"required_gate": "domain_tls_owner_response_required",
|
||||
"required_validation": [
|
||||
"domain_inventory",
|
||||
"certificate_path_check",
|
||||
"renewal_window",
|
||||
"acme_path_smoke",
|
||||
"public_https_smoke",
|
||||
"rollback_ref"
|
||||
]
|
||||
}
|
||||
],
|
||||
"matched": true,
|
||||
"path": "scripts/ops/188-registry-certbot-fix.sh",
|
||||
"strongest_priority": "P0",
|
||||
"strongest_tier": "C0"
|
||||
},
|
||||
{
|
||||
"categories": [
|
||||
{
|
||||
"category_id": "dns_tls_certbot",
|
||||
"control_tier": "C0",
|
||||
"label": "DNS / TLS / certbot / certificate path",
|
||||
"priority": "P0",
|
||||
"required_gate": "domain_tls_owner_response_required",
|
||||
"required_validation": [
|
||||
"domain_inventory",
|
||||
"certificate_path_check",
|
||||
"renewal_window",
|
||||
"acme_path_smoke",
|
||||
"public_https_smoke",
|
||||
"rollback_ref"
|
||||
]
|
||||
}
|
||||
],
|
||||
"matched": true,
|
||||
"path": "scripts/ops/fix-188-registry-certbot-renewal.sh",
|
||||
"strongest_priority": "P0",
|
||||
"strongest_tier": "C0"
|
||||
},
|
||||
{
|
||||
"categories": [
|
||||
@@ -146,27 +131,6 @@
|
||||
"path": "scripts/security/high-value-config-change-gate.py",
|
||||
"strongest_priority": "P3",
|
||||
"strongest_tier": "C3"
|
||||
},
|
||||
{
|
||||
"categories": [
|
||||
{
|
||||
"category_id": "security_evidence_tooling",
|
||||
"control_tier": "C3",
|
||||
"label": "Security evidence / snapshot / guard tooling",
|
||||
"priority": "P3",
|
||||
"required_gate": "security_evidence_owner_review_required",
|
||||
"required_validation": [
|
||||
"snapshot_parse",
|
||||
"guard_smoke",
|
||||
"doc_secret_sanity",
|
||||
"no_runtime_gate_increase"
|
||||
]
|
||||
}
|
||||
],
|
||||
"matched": true,
|
||||
"path": "scripts/security/high-value-config-owner-packet.py",
|
||||
"strongest_priority": "P3",
|
||||
"strongest_tier": "C3"
|
||||
}
|
||||
],
|
||||
"control_category_inventory": [
|
||||
@@ -177,6 +141,7 @@
|
||||
"path_patterns": [
|
||||
"infra/ansible/roles/nginx/templates/*.j2",
|
||||
"infra/ansible/playbooks/nginx-sync.yml",
|
||||
"k8s/nginx/**",
|
||||
"ops/nginx/**",
|
||||
"docs/runbooks/disaster-recovery/DR-Nginx.md"
|
||||
],
|
||||
@@ -210,6 +175,8 @@
|
||||
"docs/runbooks/REGISTRY-CERTBOT-188.md",
|
||||
"docs/runbooks/**/*CERTBOT*.md",
|
||||
"docs/runbooks/**/*TLS*.md",
|
||||
"scripts/ops/**/*cert*",
|
||||
"scripts/ops/**/*tls*",
|
||||
"ops/**/*cert*",
|
||||
"ops/**/*tls*",
|
||||
"infra/**/*cert*",
|
||||
@@ -636,7 +603,7 @@
|
||||
],
|
||||
"diff": {
|
||||
"base": null,
|
||||
"changed_file_count": 8,
|
||||
"changed_file_count": 6,
|
||||
"head": "HEAD"
|
||||
},
|
||||
"execution_boundaries": {
|
||||
@@ -650,9 +617,39 @@
|
||||
"ssh_executed": false,
|
||||
"workflow_modified": false
|
||||
},
|
||||
"generated_at": "2026-06-11T13:00:00+08:00",
|
||||
"git_commit": "ccf87213",
|
||||
"generated_at": "2026-06-14T17:13:00+08:00",
|
||||
"git_commit": "168bd777",
|
||||
"impacted_categories": [
|
||||
{
|
||||
"category_id": "dns_tls_certbot",
|
||||
"control_tier": "C0",
|
||||
"label": "DNS / TLS / certbot / certificate path",
|
||||
"priority": "P0",
|
||||
"required_gate": "domain_tls_owner_response_required",
|
||||
"required_validation": [
|
||||
"domain_inventory",
|
||||
"certificate_path_check",
|
||||
"renewal_window",
|
||||
"acme_path_smoke",
|
||||
"public_https_smoke",
|
||||
"rollback_ref"
|
||||
]
|
||||
},
|
||||
{
|
||||
"category_id": "nginx_public_gateway",
|
||||
"control_tier": "C0",
|
||||
"label": "Nginx / reverse proxy / public route",
|
||||
"priority": "P0",
|
||||
"required_gate": "public_gateway_owner_response_required",
|
||||
"required_validation": [
|
||||
"rendered_diff",
|
||||
"nginx_t",
|
||||
"affected_route_smoke",
|
||||
"admin_route_smoke_if_affected",
|
||||
"acme_path_smoke_if_affected",
|
||||
"rollback_ref"
|
||||
]
|
||||
},
|
||||
{
|
||||
"category_id": "security_evidence_tooling",
|
||||
"control_tier": "C3",
|
||||
@@ -714,15 +711,15 @@
|
||||
],
|
||||
"schema_version": "high_value_config_change_gate_v1",
|
||||
"summary": {
|
||||
"changed_file_count": 8,
|
||||
"impacted_c0_category_count": 0,
|
||||
"changed_file_count": 6,
|
||||
"impacted_c0_category_count": 2,
|
||||
"impacted_c1_category_count": 0,
|
||||
"impacted_category_count": 1,
|
||||
"matched_high_value_file_count": 8,
|
||||
"impacted_category_count": 3,
|
||||
"matched_high_value_file_count": 6,
|
||||
"owner_evidence_complete": false,
|
||||
"owner_evidence_provided": false,
|
||||
"runtime_execution_authorized": false,
|
||||
"strongest_priority": "P3",
|
||||
"strongest_tier": "C3"
|
||||
"strongest_priority": "P0",
|
||||
"strongest_tier": "C0"
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user