Skip to content

[Production readiness] Close the evidence-backed Wardnet production gate #87

Description

@seonghobae

Current verdict — 2026-09-05

Wardnet is not production-ready on protected main@5829a0f08d78de464dd24393ce5d0f25fba9d126. GitHub Releases remains empty. Protected #159 is current workflow-control truth; candidate PRs, Draft heads, predecessor checks, readiness endpoints and mutable sibling repositories are evidence only until one exact protected release identity satisfies the complete gate below.

Immediate P0/P1 convergence graph

Control-plane and governance

Live organization ruleset 18156473 still targets ~DEFAULT_BRANCH, requires one generic approving review with no named required reviewer/team, requires current-thread resolution and central OpenCode/merge-scheduler/Security/Strix/Semgrep/Noema/CodeQL workflows, blocks deletion/non-fast-forward, and exposes OrganizationAdmin/always bypass. Self-approval and bot/model-as-human approval remain forbidden.

.github#772 owns the solo-maintainer policy repair. The central owner plane must reconcile its live policy assertions without weakening deterministic workflow/security/coverage/SBOM/provenance/thread/branch-integrity gates. Ordinary approval deadlock, queued scanners, OpenCode/provider wait, failed tests or release dependency wait are not guarded-bypass authority.

Runner/workflow acquisition remains .github#712 owner work. runner_id=0, steps=[], pre-checkout queueing, coverage materialization failure and model-review current-head timeout are non-passing control-plane evidence, not permission for rerun storms, selector churn, no-op source commits or false GREEN.

Context Fabric / EA release boundary

context-graph-contracts remains a contract-only Shared Kernel and enterprise-architecture-core remains the EA Decision Plane. Both still use develop as live default at the current read, have open owner stacks and no immutable GitHub Release. Branch topology/default/protection repair stays with Context Fabric/central governance. Wardnet does not modify their source or PR state.

External capability artifact/admission/activation grammar remains context-graph-contracts#27 owner work; EA external-capability adoption/risk/provenance remains enterprise-architecture-core#45. Wardnet findings/verdicts stay Wardnet authority. EA may retain verified evidence references but must not promote malware_verdict, artifact_risk_score or individual incident findings to authoritative architecture facts.

Production definition

Close this issue only after every mandatory gap above is protected truth and one exact immutable protected release candidate simultaneously proves fail-closed auth/tenant/security boundaries; shared DNSBL/threat-feed lifecycle correctness; proven WAF/IDS and deployed attack behavior; PostgreSQL authority/RLS/transaction/recovery; bounded multi-replica admission/effects; Keyverse-backed identity and human approval; owned production statement/branch/edge coverage and public docs; dependency/SAST/container/attack gates; immutable package/image/SBOM/signature/provenance/reproducibility; deployment and measured rollback/roll-forward; OTel/SLO/incident/restore evidence; released/versioned external-owner contracts; exact-current review/thread/governance evidence; and zero valid unresolved findings.

Do not close because a document, active PR, feature-branch artifact, predecessor check or mutable foreign head reports readiness. Guarded bypass is limited to a fully proven gate-repair chicken-and-egg with all runnable deterministic evidence terminal GREEN; ordinary queued scanners, review/provider timeout, failed tests, approval wait and release dependency wait never qualify.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: authAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: dependenciesDependency or lockfile maintenancearea: securitySecurity boundary, hardening, or vulnerability preventionpriority: mediumNormal-priority or P2 workscope: commercial-readinessProduction, enterprise, release, or commercial readinessstatus: triagedOpen issue has an organization taxonomy assignmenttype: featureNew or expanded product capability

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions