release

package
v1.0.0-rc.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: AGPL-3.0, AGPL-3.0-or-later Imports: 4 Imported by: 0

Documentation

Overview

Package release implements the pure taskman-release/0 release-control model. It performs no I/O and grants no publication or execution authority.

Index

Constants

View Source
const (
	OpCreate         = "RELEASE_CREATE"
	OpUpdate         = "RELEASE_UPDATE"
	OpCandidate      = "RELEASE_CANDIDATE"
	OpExternalAttest = "RELEASE_EXTERNAL_ATTEST"
	OpManualAttest   = "RELEASE_MANUAL_ATTEST"
	OpPromote        = "RELEASE_PROMOTE"
)
View Source
const (
	Blocked       = "BLOCKED"
	Unknown       = "UNKNOWN"
	ReadyAttested = "READY_ATTESTED"
	Manual        = "MANUAL_ATTESTATION"
	External      = "EXTERNAL_ATTESTATION"
)
View Source
const AttestationProfile = "taskman-release-attestation/0"
View Source
const MutationProfile = "taskman-release-mutation/0"
View Source
const Profile = "taskman-release/0"

Variables

View Source
var DefaultRoleMatrix = map[string][]string{
	"OWNER":    Operations,
	"OPERATOR": {OpCandidate, OpCreate, OpExternalAttest, OpUpdate},
}

Functions

func AttestationDigest

func AttestationDigest(a Attestation) wire.Digest

func Authorized

func Authorized(role, operation, provenance string, configured map[string][]string) bool

Authorized applies the policy-removable maximum role matrix. A configured role row may remove operations but can never add beyond the maximum.

func CandidateDigest

func CandidateDigest(c *Candidate) wire.Digest

func DefinitionDigest

func DefinitionDigest(r *Record) wire.Digest

func Encode

func Encode(r *Record) []byte

func PromotionDigest

func PromotionDigest(p *Promotion) wire.Digest

func ValidateGraph

func ValidateGraph(records []*Record) error

ValidateGraph checks the complete queue-scoped release DAG. It performs no I/O and does not treat graph validity as evidence that a release is ready.

Types

type Actor

type Actor struct{ ID, Role string }

type Attestation

type Attestation struct {
	AttestationID   string
	CandidateSha256 wire.Digest
	GateID          string
	Provenance      string
	Actor           string
	RecordedAt      wire.Timestamp
	Result          string
	Criteria        []wire.Count
	Evidence        []wire.Digest
	SourceIdentity  string
}

type Candidate

type Candidate struct {
	RepositoryIdentity string
	HeadCommit         string
	HeadTree           string
	SourceSha256       wire.Digest
	DefinitionSha256   wire.Digest
	PolicySha256       wire.Digest
	Tickets            []TicketBinding
	Predecessors       []PredecessorBinding
}

type Envelope

type Envelope struct {
	RequestID        string
	Actor            Actor
	QueueID          wire.QueueID
	ReleaseID        string
	ExpectedRevision *wire.Count
	Operation        string
	Payload          wire.Value
	IssuedAt         wire.Timestamp
	Raw              []byte
}

func DecodeEnvelope

func DecodeEnvelope(data []byte) (*Envelope, error)

func (*Envelope) Sha256

func (e *Envelope) Sha256() wire.Digest

type Gate

type Gate struct {
	GateID, Kind string
	Required     bool
}

type Observation

type Observation struct {
	HeadCommit                 string
	SourceSha256, PolicySha256 wire.Digest
	Tickets                    map[string]*ticket.Record
	TicketDigests              map[string]wire.Digest
	PredecessorPromotions      map[string]wire.Digest
}

type PredecessorBinding

type PredecessorBinding struct {
	ReleaseID       string
	PromotionSha256 wire.Digest
}

type Promotion

type Promotion struct {
	CandidateSha256    wire.Digest
	AttestationSha256s []wire.Digest
	Predecessors       []PredecessorBinding
	Actor              string
	RecordedAt         wire.Timestamp
}

type Readiness

type Readiness struct {
	State   string
	Missing []string
}

func Assess

func Assess(r *Record, gates []Gate, o Observation) Readiness

type Record

type Record struct {
	QueueID            wire.QueueID
	ReleaseID          string
	Revision           wire.Count
	PreviousSha256     *wire.Digest
	Version            string
	Title              string
	PredecessorIDs     []string
	TicketIDs          []wire.TicketID
	AcceptanceCriteria []string
	RequiredGates      []string
	Candidate          *Candidate
	Attestations       []Attestation
	Promotion          *Promotion
}

func Apply

func Apply(env *Envelope, binding Actor, current *Record, queue wire.QueueID, configured map[string][]string, tickets map[string]bool, now wire.Timestamp, observed *Candidate, gates []Gate, observation Observation) (*Record, error)

func Decode

func Decode(data []byte) (*Record, error)

type TicketBinding

type TicketBinding struct {
	TicketID           wire.TicketID
	RecordSha256       wire.Digest
	AcceptanceRevision wire.Count
}

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL