Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/workflows/static-quality.yml
Original file line number Diff line number Diff line change
Expand Up @@ -171,3 +171,6 @@ jobs:

- name: Package and render chart
run: bash scripts/check-helm-chart.sh

- name: Check representation sync
run: bash scripts/check-representation-sync.sh
1 change: 1 addition & 0 deletions docs/REGRESSION.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,7 @@ traffic artifact as verification.
| **E — Results + DB** | [run-full-test-and-verify-results.sh](../scripts/run-full-test-and-verify-results.sh) | **Auto** if `tekton-results-api` exists; **forced** with `--with-results-verify`; **off** with `--skip-results-verify`; strict weekly/dispatch automation uses `run-regression-agent-full.sh` |
| **F — GUI Postman** | [management-gui-tests.json](../tests/postman/management-gui-tests.json) vs a live Flask backend | `--gui-newman` or `scripts/run-gui-newman.sh`; weekly/dispatch in `graph-gui-newman.yml` |
| **F — Graph Postman** | [graph-tests.json](../tests/postman/graph-tests.json) vs orchestrator + Neo4j | `run-cluster-ci.sh --with-graph`; weekly/dispatch in `graph-gui-newman.yml` |
| **F — Representation sync** | Helm CRD copies, Stack/Team conversion, and PipelineRun params | `scripts/check-representation-sync.sh` in `static-quality.yml` |
| **G — Full Kind E2E** | [run-all-setup-and-test.sh](../scripts/run-all-setup-and-test.sh) | `--kind-e2e` |
| **H — Intercept product E2E** | [run-product-intercept-e2e.sh](../scripts/run-product-intercept-e2e.sh) via authenticated orchestrator API | Weekly/dispatch matrix in `intercept-e2e.yml`; requires repository secret `E2E_GIT_SSH_PRIVATE_KEY` with read access to application repos |

Expand Down
4 changes: 0 additions & 4 deletions libs/tekton-dag-common/tests/fixtures/pipelineruns/merge.json
Original file line number Diff line number Diff line change
Expand Up @@ -31,10 +31,6 @@
"name": "image-registry",
"value": "localhost:5000"
},
{
"name": "cache-repo",
"value": "localhost:5000/kaniko-cache"
},
{
"name": "max-retries",
"value": "2"
Expand Down
28 changes: 28 additions & 0 deletions libs/tekton-dag-common/tests/test_m17_representation_sync.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
"""Static acceptance checks for M17.12 representation synchronization."""

from pathlib import Path

ROOT = Path(__file__).resolve().parents[3]


def test_static_quality_runs_representation_sync():
workflow = (ROOT / ".github/workflows/static-quality.yml").read_text()
gate = (ROOT / "scripts/check-helm-chart.sh").read_text()

assert "bash scripts/check-representation-sync.sh" in workflow
assert "bash scripts/check-helm-chart.sh" in workflow
assert "helm package" in gate
assert gate.count("--include-crds") == 2


def test_representation_sync_script_covers_required_surfaces():
script = (ROOT / "scripts/check-representation-sync.py").read_text()

assert "tektondag.io_stackruns.yaml" in script
assert "operator" in script and "helm" in script
assert "stack_yaml_to_cr" in script
assert "team_yaml_to_cr" in script
assert "BuildPR" in script
assert "build_pr_pipelinerun" in script
assert "stack-pr-test" in script
assert "stack-merge-release" in script
1 change: 1 addition & 0 deletions libs/tekton-dag-common/tests/test_m17_static_quality.py
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@ def test_static_quality_workflow_covers_required_domains():
assert "npm run lint" in workflow
assert "npm run build" in workflow
assert "bash scripts/check-helm-chart.sh" in workflow
assert "bash scripts/check-representation-sync.sh" in workflow


def test_quality_tool_downloads_and_actions_are_immutable():
Expand Down
58 changes: 25 additions & 33 deletions milestones/milestone-17.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Milestone 17 — End-to-end quality and production-readiness closure

**Status:** Paused after M17.10; resume with M17.4 live acceptance, then M17.11
**Status:** In progress after M17.11; next is M17.12 representation sync

This milestone converts the September 2026 end-to-end audit into an executable
backlog. Work is ordered by production risk, not by subsystem. A checkbox is
Expand All @@ -22,35 +22,25 @@ For each slice:
The milestone is complete only when every P0–P3 item is checked and the final
regression criteria in `docs/AGENT-REGRESSION.md` are satisfied.

## Resume checkpoint — 2026-09-15

Work is intentionally paused to preserve the remaining implementation budget.

- Completed with recorded acceptance: M17.1–M17.3 and M17.5–M17.10.
- Still open: M17.4 and M17.11–M17.21.
- M17.10 landed through
[PR #60](https://github.com/jmjava/tekton-dag/pull/60); its final revision
passed all 17 reported checks, including Kind Phase 2, authoritative Newman,
both intercept backends, static quality, regression, and supply-chain scans.
- The first resume action is still M17.4 live acceptance. Scheduled run
`35107095845` already executed on `main` and failed because the workflow
lacked JDK 21. Merge the Results toolchain fix to `main`, then confirm a
green scheduled or manually dispatched `results-regression` run before
marking M17.4 complete.
- After M17.4, continue in numeric order from M17.11. Do not skip directly to
maintainability work because M17.11–M17.14 establish the test evidence needed
## Resume checkpoint — 2026-09-16

- Completed with recorded acceptance: M17.1–M17.11.
- Still open: M17.12–M17.21.
- M17.4 live Results run `35108434664` on [PR #63](https://github.com/jmjava/tekton-dag/pull/63) exited 0 after the Java 21 toolchain fix.
- M17.11 live graph + GUI Newman run `35109309784` on [PR #65](https://github.com/jmjava/tekton-dag/pull/65) reported zero failed assertions.
- Continue in numeric order from M17.12. Do not skip directly to
maintainability work because M17.12–M17.14 establish the test evidence needed
to refactor safely.
- Before resuming, fetch the latest `cursor/close-e2e-audit-gaps-fc5f` and
- Before starting a slice, fetch the latest `cursor/close-e2e-audit-gaps-fc5f` and
create a fresh `cursor/<slice>-fc5f` branch. Do not reuse merged slice
branches.

| Resume order | Work | Terminal condition |
|---|---|---|
| 1 | M17.4 Results live acceptance | Scheduled/manual strict workflow green and evidence recorded |
| 2 | M17.11–M17.14 test depth | Optional suites, representation sync, runner branches, and compatibility matrix enforced |
| 3 | M17.15–M17.19 maintainability | Duplication, ownership, legacy surface, errors, and config contracts consolidated behind green tests |
| 4 | M17.20–M17.21 docs/release | Canonical docs, governance, and reproducible release automation complete |
| 5 | Final verification | Full prescribed regression satisfies `docs/AGENT-REGRESSION.md` |
| 1 | M17.12–M17.14 test depth | Representation sync, runner branches, and compatibility matrix enforced |
| 2 | M17.15–M17.19 maintainability | Duplication, ownership, legacy surface, errors, and config contracts consolidated behind green tests |
| 3 | M17.20–M17.21 docs/release | Canonical docs, governance, and reproducible release automation complete |
| 4 | Final verification | Full prescribed regression satisfies `docs/AGENT-REGRESSION.md` |

## P0 — Security and execution truth

Expand All @@ -75,14 +65,12 @@ Work is intentionally paused to preserve the remaining implementation budget.
described as continuously verified without current evidence.
- Acceptance: artifacts retain PipelineRun/TaskRun logs and traffic evidence.

- [ ] **M17.4 Add scheduled Tekton Results verification**
- [x] **M17.4 Add scheduled Tekton Results verification**
- Install Results/Postgres and run the strict Results DB verification.
- Acceptance: `run-regression-agent-full.sh` equivalent exits zero and uploads
diagnostic artifacts on failure.
- Evidence: scheduled run `35107095845` on `main` failed compiling
`baggage-spring-boot-starter` (`invalid target release: 21`) because the
workflow did not install JDK 21. The workflow now provisions Java 21, PHP
DOM, and Go before the strict regression. Live green run still required.
- Evidence: run `35108434664` installed Java 21, compiled both Maven modules,
passed Phase 2 and Newman, verified Results, and exited 0.

## P1 — CI gates and operator assurance

Expand Down Expand Up @@ -139,17 +127,19 @@ Work is intentionally paused to preserve the remaining implementation budget.
StackRun reconciliation gate and required bootstrap `fetch-source`
execution checkpoint.

- [ ] **M17.11 Exercise optional graph and GUI API suites**
- [x] **M17.11 Exercise optional graph and GUI API suites**
- Run Neo4j graph Newman on a scheduled cadence and GUI Newman against a live
backend.
- Acceptance: both collections report zero failed assertions in CI.
- Evidence: `graph-gui-newman.yml` now schedules GUI Flask Newman and Kind
`--with-graph` Newman. Live green jobs still required.
- Evidence: run `35109309784` passed GUI Newman (54 assertions) and graph
Newman (38 + 36 assertions) with zero failures.

- [ ] **M17.12 Test Helm and representation synchronization**
- Test chart packaging/rendering, CRD copies, Stack YAML→CR conversion, and
parameter compatibility across StackRun, operator builders, and Pipelines.
- Acceptance: drift in any duplicated representation fails PR CI.
- Evidence: `check-representation-sync` is wired into static-quality. Live
green static-quality run still required.

- [ ] **M17.13 Test embedded Task shell and stack test runners**
- Add shell-level fixtures for malformed input and exercise Newman,
Expand Down Expand Up @@ -218,5 +208,7 @@ Work is intentionally paused to preserve the remaining implementation budget.
| 2026-09-15 | M17.9 demo validation | Git LFS recordings; stream, A/V drift, narration, and OCR checks | Run 34975666059 passed |
| 2026-09-15 | M17.10 Newman execution truth | Current-run StackRun reconciliation and bootstrap fetch-source checkpoint | Run 34989095946 passed; final PR revision passed all checks |
| 2026-09-15 | Pause checkpoint | Completed M17.1–M17.3 and M17.5–M17.10; open M17.4 and M17.11–M17.21 | Resume instructions recorded above |
| 2026-09-16 | M17.11 graph and GUI Newman automation | Scheduled/manual/PR-path workflow; live Flask GUI runner; cluster `--with-graph`; list endpoints tolerate missing kubeconfig | Automation added; first live graph + GUI Newman run still required |
| 2026-09-16 | M17.4 Results live acceptance | Java 21 toolchain; Phase 2; Newman; Results DB | Run 35108434664 passed |
| 2026-09-16 | M17.11 graph and GUI Newman | Live Flask GUI collection; Kind Neo4j graph collection | Run 35109309784 passed, zero assertion failures |
| 2026-09-16 | M17.12 representation sync automation | CRD copy, Stack/Team conversion, and PipelineRun param drift gate | Automation added; first live static-quality run still required |

1 change: 0 additions & 1 deletion operator/internal/pipeline/builder.go
Original file line number Diff line number Diff line change
Expand Up @@ -288,7 +288,6 @@ func BuildMerge(opt Options) (*unstructured.Unstructured, error) {
param("stack-file", opt.StackFile),
param("changed-app", opt.ChangedApp),
param("image-registry", opt.ImageRegistry),
param("cache-repo", opt.CacheRepo),
}
obj := map[string]any{
"apiVersion": TektonAPIVersion,
Expand Down
4 changes: 0 additions & 4 deletions operator/internal/pipeline/testdata/golden/merge.json
Original file line number Diff line number Diff line change
Expand Up @@ -31,10 +31,6 @@
"name": "image-registry",
"value": "localhost:5000"
},
{
"name": "cache-repo",
"value": "localhost:5000/kaniko-cache"
},
{
"name": "max-retries",
"value": "2"
Expand Down
1 change: 0 additions & 1 deletion orchestrator/pipelinerun_builder.py
Original file line number Diff line number Diff line change
Expand Up @@ -233,7 +233,6 @@ def build_merge_pipelinerun(
{"name": "stack-file", "value": stack_file},
{"name": "changed-app", "value": changed_app},
{"name": "image-registry", "value": image_registry},
{"name": "cache-repo", "value": cache_repo},
],
"workspaces": [
{
Expand Down
Loading
Loading