Skip to content

chore(governance): configure protected production environment #40

Description

@seonghobae

Problem and current boundary

Noema protected source can fail closed when production-environment governance evidence is missing or weakened, but repository source cannot manufacture GitHub Environment reviewers, self-review prevention, protected-ref policy, administrator-bypass configuration, environment secrets, Cloudflare account authority or deployment approval. Those remain live control-plane facts distinct from PR checks, source tests, release identity and runtime KPI evidence.

Current protected source — 2026-09-09 KST

Protected Noema is GitHub-verified main@8108bae1128c20b92d79dacaf65c3d9e3d55b758, after normal #559 documentation convergence and #562 dependency integration. Protected source retains the fail-closed production:governance verification path together with release/readiness/acquisition evidence commands.

Current source/documentation/maintenance work is carried by five Draft PRs: #564, #566, #569, #570 and Dependabot #571. None is a production Environment, deployment, immutable release or authenticated production KPI receipt. #569 is the current protected dependency-security foundation and has application CI/reviewer-ci/Security Scan GREEN while its exact image build is still running. #566's authenticated cache-transport image build/smoke succeeded on its stale base and then failed only at the inherited protected Vitest CVE; #564 and #570 reached the same inherited post-build SBOM RED. #571 is not a verified #569 successor and fails dependency materialization because it omits the required WASI/static-validator contract.

The available GitHub connector still exposes no authoritative repository Environment configuration read/write operation. Current reviewer identities, self-review prevention, protected-branch deployment policy, administrator bypass, environment variables/secrets and deployment approvals therefore cannot be truthfully asserted from this lane. Do not convert source expectations into a fake live PASS.

The GitHub Release collection is separately verified and remains empty. Protected immutable-release workflow source does not itself prove immutable-release enforcement or an actual published release. No PR head or mutable branch is eligible for production deployment under diligence.

#561 remains the next Noema State / Checkpoint / Recovery source gap for durable append-only external-extension lifecycle evidence after current security/maintenance convergence. It does not provide production Environment or deployment evidence.

Acceptance criteria

Live GitHub Environment authority

  • Create or update the GitHub production Environment through an authorized owner path.
  • Configure at least one concrete eligible User/Team required deployment reviewer if that remains the approved control design.
  • Enable and independently verify Prevent self-review.
  • Restrict deployment branches/tags to the approved protected-ref policy and verify custom branch-policy behavior explicitly.
  • Independently verify administrator/break-glass bypass policy; do not infer it from repository rulesets or source audit.
  • Record environment owner, reviewer ownership and audited break-glass procedure in access-controlled evidence.
  • Configure environment-scoped Cloudflare/exchange/KPI variables and secret rotation ownership without copying values into source, issues, prompts or public artifacts.

Repository-owned verification

  • Protected source retains fail-closed production:governance verification rather than treating configuration prose as proof.
  • Execute the protected-source governance operator under an authorized credential after live environment configuration exists and retain exact protected-source/run evidence.
  • Missing, malformed, stale or weakened live configuration must remain FAIL before credential-bearing deployment steps.

Immutable deployment evidence

  • Finish fix(security): remove CVE-2026-84373 from Vitest lock #569 and current maintenance convergence on exact terminal-success gates without weakening scanner or merge authority.
  • Satisfy feat(release): enforce immutable durable buyer releases #36 with one immutable Noema SemVer release bound to exact tag/source/package/image/SBOM/provenance/reproducibility/rollback evidence.
  • Dispatch the protected production-deployment path for that immutable release, not a PR head or mutable branch.
  • Retain exact workflow/run/deployment/environment/release identities and bounded long-lived deployment evidence.
  • Prove a non-approved ref cannot deploy and the initiator cannot satisfy any required independent approval by self-action.
  • Exercise rollback/recovery and retain exact evidence.

Buyer / KPI handoff

Current blocker classification

Live Environment provisioning/inspection is an external-control blocker for this lane with the available connector, so status: blocked remains valid for production Environment/deployment evidence only. It does not block current Noema-owned PR review/repair/integration, #561 preparation, #36 release-source verification, patch-validator supply-chain repair or other buyer-gap work.

Related: #3, #5, #27, #29, #36, #66, #227, #545, #561, #564, #566, #568, #569, #570, #571.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: apiAPI, protocol, event, or external contractarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: securitySecurity boundary, hardening, or vulnerability preventionbugSomething isn't workingmaintenancepriority: mediumNormal-priority or P2 workstatus: blockedBlocked by conflict, dependency, or required prerequisitetype: bugDefect or incorrect behaviortype: maintenanceMaintenance, build, dependency, or operational upkeep

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions