Directories
¶
| Path | Synopsis |
|---|---|
|
api
|
|
|
cmd
|
|
|
api
command
Package main starts the release-api service.
|
Package main starts the release-api service. |
|
auth
command
Package main starts the release-auth service.
|
Package main starts the release-auth service. |
|
devseed
command
Command devseed seeds (or resets) the deterministic development fixture (REQ-065) through the formal public service seams.
|
Command devseed seeds (or resets) the deterministic development fixture (REQ-065) through the formal public service seams. |
|
docscheck
command
Command docscheck audits code citations in documentation: when the sentence next to a `file:line` citation names a symbol, the symbol should appear within a small window around the cited line.
|
Command docscheck audits code citations in documentation: when the sentence next to a `file:line` citation names a symbol, the symbol should appear within a small window around the cited line. |
|
e2e
command
Command e2e is the single entry point for the staged E2E runner.
|
Command e2e is the single entry point for the staged E2E runner. |
|
errcodecheck
command
Command errcodecheck checks that every stable error code a requirement asserts in its acceptance criteria is emittable by the implementation.
|
Command errcodecheck checks that every stable error code a requirement asserts in its acceptance criteria is emittable by the implementation. |
|
imagecheck
command
Command imagecheck validates a Docker image archive against an executable policy.
|
Command imagecheck validates a Docker image archive against an executable policy. |
|
installgate
command
Command installgate applies the time-bounded infrastructure quarantine policy for one Helm Install SDK gate failure.
|
Command installgate applies the time-bounded infrastructure quarantine policy for one Helm Install SDK gate failure. |
|
notification-sink
command
Package main starts the release-notification-sink service.
|
Package main starts the release-notification-sink service. |
|
notifier
command
Package main starts the release-notifier service.
|
Package main starts the release-notifier service. |
|
operator
command
Package main starts the release-operator service.
|
Package main starts the release-operator service. |
|
orchestrator
command
Package main starts the release-orchestrator service.
|
Package main starts the release-orchestrator service. |
|
reqcheck
command
Command reqcheck validates atomic requirement documents against the 10-section template (REQ-039).
|
Command reqcheck validates atomic requirement documents against the 10-section template (REQ-039). |
|
schemaparity
command
Command schemaparity compares the SQLite and PostgreSQL schema snapshots and fails on real drift (a same-named table whose column set or column type differs).
|
Command schemaparity compares the SQLite and PostgreSQL schema snapshots and fails on real drift (a same-named table whose column set or column type differs). |
|
sdkcheck
command
Command sdkcheck runs the SDK-only static analyzer on a Go module.
|
Command sdkcheck runs the SDK-only static analyzer on a Go module. |
|
store-migrate
command
Package main provides the store-migrate CLI for one-shot SQLite-to-PostgreSQL data migration.
|
Package main provides the store-migrate CLI for one-shot SQLite-to-PostgreSQL data migration. |
|
taskcheck
command
Command taskcheck validates the delivery ledger (vault Tasks/*.md) against the merge facts in git.
|
Command taskcheck validates the delivery ledger (vault Tasks/*.md) against the merge facts in git. |
|
webhook
command
Package main starts the release-webhook service.
|
Package main starts the release-webhook service. |
|
deploy
|
|
|
fixtures/cmd/server
command
Package main implements the release-manager dev fixture: a minimal static file server with health and version endpoints.
|
Package main implements the release-manager dev fixture: a minimal static file server with health and version endpoints. |
|
internal
|
|
|
api
Package api exposes HTTP-friendly read operations across domains.
|
Package api exposes HTTP-friendly read operations across domains. |
|
app
Package app provides centralized service lifecycle management.
|
Package app provides centralized service lifecycle management. |
|
audit
Package audit provides asynchronous audit event collection and persistence.
|
Package audit provides asynchronous audit event collection and persistence. |
|
auth
Package auth handles authentication and token management.
|
Package auth handles authentication and token management. |
|
authctx
Package authctx exposes the authenticated actor carried between interceptors and handlers.
|
Package authctx exposes the authenticated actor carried between interceptors and handlers. |
|
authorization
Package authorization implements the cross-service Authorization Snapshot consumer.
|
Package authorization implements the cross-service Authorization Snapshot consumer. |
|
config
Package config loads release-manager configuration.
|
Package config loads release-manager configuration. |
|
contracts
Package contracts provides shared cross-cutting contracts for the release-manager: request tracing, idempotency, error sanitization, and cursor pagination.
|
Package contracts provides shared cross-cutting contracts for the release-manager: request tracing, idempotency, error sanitization, and cursor pagination. |
|
contracts/interceptor
Package interceptor provides Connect interceptors for shared API contracts.
|
Package interceptor provides Connect interceptors for shared API contracts. |
|
devfixture
Package devfixture seeds and resets the deterministic development fixture (REQ-065) through the formal public Connect service seams.
|
Package devfixture seeds and resets the deterministic development fixture (REQ-065) through the formal public Connect service seams. |
|
jwtauth
Package jwtauth validates release-manager access tokens.
|
Package jwtauth validates release-manager access tokens. |
|
migration
Package migration implements a one-shot SQLite-to-PostgreSQL data migration with foreign-key-aware copying, time-column conversion, backfill, and validation.
|
Package migration implements a one-shot SQLite-to-PostgreSQL data migration with foreign-key-aware copying, time-column conversion, backfill, and validation. |
|
notifier
Package notifier dispatches notifications about release events.
|
Package notifier dispatches notifications about release events. |
|
operator
Package operator manages bidirectional gRPC streams with operator agents.
|
Package operator manages bidirectional gRPC streams with operator agents. |
|
operator/agent
Package agent executes commands received from the operator control stream.
|
Package agent executes commands received from the operator control stream. |
|
operator/bootstrap
Package bootstrap implements the operator agent identity bootstrap: it consumes a single-use enrollment token, generates an Ed25519 key and CSR, enrolls through the agent gateway, and durably persists the resulting identity so later restarts reconnect with the enrolled certificate instead of re-enrolling (REQ-015/REQ-044, TASK-075 plan v1 Step 6).
|
Package bootstrap implements the operator agent identity bootstrap: it consumes a single-use enrollment token, generates an Ed25519 key and CSR, enrolls through the agent gateway, and durably persists the resulting identity so later restarts reconnect with the enrolled certificate instead of re-enrolling (REQ-015/REQ-044, TASK-075 plan v1 Step 6). |
|
operator/ca
Package ca provides the persistent self-signed certificate authority for operator mTLS (ADR-017/ADR-018).
|
Package ca provides the persistent self-signed certificate authority for operator mTLS (ADR-017/ADR-018). |
|
operator/commandtype
Package commandtype defines durable command names shared by the orchestrator and operator.
|
Package commandtype defines durable command names shared by the orchestrator and operator. |
|
operator/helmengine
Package helmengine defines the Helm SDK adapter contract (REQ-041).
|
Package helmengine defines the Helm SDK adapter contract (REQ-041). |
|
operator/k8s
Package k8s resolves target-cluster Secret references without moving values across the control plane.
|
Package k8s resolves target-cluster Secret references without moving values across the control plane. |
|
operator/localstore
Package localstore provides a BoltDB-backed persistent command store for the operator agent.
|
Package localstore provides a BoltDB-backed persistent command store for the operator agent. |
|
operator/observer
Package observer watches Kubernetes workload rollouts using client-go list/watch semantics.
|
Package observer watches Kubernetes workload rollouts using client-go list/watch semantics. |
|
operator/preflight
Package preflight implements Cluster DryRun preflight for the operator agent.
|
Package preflight implements Cluster DryRun preflight for the operator agent. |
|
operator/secretmetadata
Package secretmetadata reads Kubernetes Secret metadata without exposing Secret values.
|
Package secretmetadata reads Kubernetes Secret metadata without exposing Secret values. |
|
orchestrator
Package orchestrator coordinates release publish workflows.
|
Package orchestrator coordinates release publish workflows. |
|
orchestrator/operation
Package operation implements the core Operation state machine (REQ-023).
|
Package operation implements the core Operation state machine (REQ-023). |
|
orchestrator/preflight
Package preflight implements the release preflight orchestration stage (REQ-019).
|
Package preflight implements the release preflight orchestration stage (REQ-019). |
|
postgres
Package postgres provides the shared PostgreSQL database infrastructure.
|
Package postgres provides the shared PostgreSQL database infrastructure. |
|
preflight
Package preflight validates release bundle artifacts before queueing an operation.
|
Package preflight validates release bundle artifacts before queueing an operation. |
|
quality/docscheck
Package docscheck implements the symbol-proximity audit for code citations in documentation: when the sentence next to a `file:line` citation names a symbol, the symbol should appear near the cited line.
|
Package docscheck implements the symbol-proximity audit for code citations in documentation: when the sentence next to a `file:line` citation names a symbol, the symbol should appear near the cited line. |
|
quality/errcodes
Package errcodes checks that every stable error code a requirement asserts in its acceptance criteria is actually emittable by the implementation.
|
Package errcodes checks that every stable error code a requirement asserts in its acceptance criteria is actually emittable by the implementation. |
|
quality/httpcollections
Package httpcollections validates the Kulala collections under api/kulala against the Connect contract in api/proto (TASK-093).
|
Package httpcollections validates the Kulala collections under api/kulala against the Connect contract in api/proto (TASK-093). |
|
quality/imagecheck
Package imagecheck validates a Docker image archive against an executable policy.
|
Package imagecheck validates a Docker image archive against an executable policy. |
|
quality/installgate
Package installgate defines infrastructure-failure quarantine policy for the Helm Install SDK integration gate.
|
Package installgate defines infrastructure-failure quarantine policy for the Helm Install SDK integration gate. |
|
quality/reqcheck
Package reqcheck validates atomic requirement documents against the project's REQ template.
|
Package reqcheck validates atomic requirement documents against the project's REQ template. |
|
quality/schemaparity
Package schemaparity compares the two schema sources this project keeps in parallel: the inline DDL that SQLite executes (internal/store/sqlite/db.go) and the PostgreSQL migrations under migrations/*.up.sql.
|
Package schemaparity compares the two schema sources this project keeps in parallel: the inline DDL that SQLite executes (internal/store/sqlite/db.go) and the PostgreSQL migrations under migrations/*.up.sql. |
|
quality/sdkcheck
Package sdkcheck provides a static analyzer that detects process execution paths which could invoke Helm, kubectl, or other forbidden command-line tools.
|
Package sdkcheck provides a static analyzer that detects process execution paths which could invoke Helm, kubectl, or other forbidden command-line tools. |
|
quality/taskcheck
Package taskcheck validates that the delivery ledger (the vault's Tasks/*.md cards) agrees with the merge facts in git.
|
Package taskcheck validates that the delivery ledger (the vault's Tasks/*.md cards) agrees with the merge facts in git. |
|
redact
Package redact provides dependency-free string sanitization for sensitive values (secrets, credentials, private keys) and bounded truncation for terminal error summaries.
|
Package redact provides dependency-free string sanitization for sensitive values (secrets, credentials, private keys) and bounded truncation for terminal error summaries. |
|
registry
Package registry provides domain navigation — service descriptors and atomic-requirement-to-service mappings per REQ-002.
|
Package registry provides domain navigation — service descriptors and atomic-requirement-to-service mappings per REQ-002. |
|
slicing
Package slicing defines atomicity rules for requirement-to-task decomposition.
|
Package slicing defines atomicity rules for requirement-to-task decomposition. |
|
store
Package store defines the persistence layer interfaces and domain types for the release-manager core pipeline.
|
Package store defines the persistence layer interfaces and domain types for the release-manager core pipeline. |
|
store/postgres
Package postgres implements the store.Store contracts on PostgreSQL.
|
Package postgres implements the store.Store contracts on PostgreSQL. |
|
store/redis
Package redisstore decorates the authoritative auth session store with Redis cache and refresh-token blacklist semantics.
|
Package redisstore decorates the authoritative auth session store with Redis cache and refresh-token blacklist semantics. |
|
store/sqlite
Package sqlite provides a SQLite-backed implementation of the store interfaces.
|
Package sqlite provides a SQLite-backed implementation of the store interfaces. |
|
trust
Package trust implements artifact trust verification and trust root lifecycle management.
|
Package trust implements artifact trust verification and trust root lifecycle management. |
|
values
Package values validates, canonicalizes, and digests immutable Helm values documents.
|
Package values validates, canonicalizes, and digests immutable Helm values documents. |
|
vulnerability
Package vulnerability implements SBOM-based vulnerability admission policy for the release-manager artifact preflight pipeline.
|
Package vulnerability implements SBOM-based vulnerability admission policy for the release-manager artifact preflight pipeline. |
|
Package migrations embeds the versioned PostgreSQL schema migrations.
|
Package migrations embeds the versioned PostgreSQL schema migrations. |
|
test
|
|
|
e2e
Package e2e provides a phased end-to-end test runner framework (REQ-066).
|
Package e2e provides a phased end-to-end test runner framework (REQ-066). |
|
e2e/livewire
Package livewire binds the formal Connect/Operator API to the narrow seams the E2E stages consume.
|
Package livewire binds the formal Connect/Operator API to the narrow seams the E2E stages consume. |
|
e2e/stages
Package stages contains the read-only adapters used by the E2E stage runner.
|
Package stages contains the read-only adapters used by the E2E stage runner. |
Click to show internal directories.
Click to hide internal directories.