Repository navigation
S17 phase2-cncf-conformance: K8s AI conformance + supply-chain CI rows - #124
Merged
Merged
Conversation
Pal Lakatos-Toth (pallakatos)
force-pushed
the
phase2-s17-cncf-conformance
branch
from
April 30, 2026 02:24
55af05d to
9909c7e
Compare
Brings AzureClaw CRDs and Helm chart to CNCF Kubernetes AI Conformance v1.35+ minimum bar, and pins two new permanent supply-chain CI rows. Conformance gap-fixes: - ClawPairing: add status.conditions[] array (Rust + helm CRD) with the standard k8s condition shape, add a Ready printer column driven by .status.conditions[?(@.type=="Ready")].status, and add two x-kubernetes-validations CEL rules (slotsMax >= 1, tokenBudget >= 0). - All six split-file CRDs (a2aagent, claweval, clawmemory, inferencepolicy, mcpserver, toolpolicy) gain app.kubernetes.io/name=azureclaw and app.kubernetes.io/component=crd labels. Helm-drift comparison strips labels so no Rust schema change. - New operator-default-deny-networkpolicy.yaml installs an empty-podSelector default-deny policy in azureclaw-system with allow-list exceptions for kube-DNS, kube-apiserver, and Prometheus scrapes of :9091. New CI rows (permanent, required): - cargo-deny — runs cargo deny check against deny.toml with two documented advisory exceptions (RUSTSEC-2024-0370 proc-macro-error transitive via sigstore; RUSTSEC-2023-0071 rsa Marvin attack via jsonwebtoken/sigstore — neither call site does attacker-observable RSA decryption). - cosign-verify — keyless GitHub OIDC verification recipe pinned in CI; PR runs are dry-run with the verification command echoed into the run summary. Full recipe documented in docs/operations/supply-chain.md. Conformance suite: - New tests/cncf-conformance workspace crate. 15 conformance criteria and 17 cargo test cases gate every PR. Suite renders the helm chart with `helm template ac deploy/helm/azureclaw --namespace azureclaw-system` to avoid serde_yaml 0.9 hangs on Helm action blocks. - Binary writes tests/cncf-conformance/CONFORMANCE-REPORT.md and exits non-zero on failure. Status: 15/15 criteria pass. Docs: - docs/operations/supply-chain.md — image-tag convention + cosign recipe - docs/operations/branch-protection.md — required-checks list - docs/api/conditions.md — per-CRD reason taxonomy - docs/security-audits/2026-04-30-phase2-cncf-conformance.md — audit Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
… path deps Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Pal Lakatos-Toth (pallakatos)
force-pushed
the
phase2-s17-cncf-conformance
branch
from
April 30, 2026 03:14
ed6db69 to
3094ab6
Compare
Pal Lakatos-Toth (pallakatos)
added a commit
that referenced
this pull request
May 12, 2026
#124) * S17 phase2-cncf-conformance: K8s AI conformance + supply-chain CI rows Brings AzureClaw CRDs and Helm chart to CNCF Kubernetes AI Conformance v1.35+ minimum bar, and pins two new permanent supply-chain CI rows. Conformance gap-fixes: - ClawPairing: add status.conditions[] array (Rust + helm CRD) with the standard k8s condition shape, add a Ready printer column driven by .status.conditions[?(@.type=="Ready")].status, and add two x-kubernetes-validations CEL rules (slotsMax >= 1, tokenBudget >= 0). - All six split-file CRDs (a2aagent, claweval, clawmemory, inferencepolicy, mcpserver, toolpolicy) gain app.kubernetes.io/name=azureclaw and app.kubernetes.io/component=crd labels. Helm-drift comparison strips labels so no Rust schema change. - New operator-default-deny-networkpolicy.yaml installs an empty-podSelector default-deny policy in azureclaw-system with allow-list exceptions for kube-DNS, kube-apiserver, and Prometheus scrapes of :9091. New CI rows (permanent, required): - cargo-deny — runs cargo deny check against deny.toml with two documented advisory exceptions (RUSTSEC-2024-0370 proc-macro-error transitive via sigstore; RUSTSEC-2023-0071 rsa Marvin attack via jsonwebtoken/sigstore — neither call site does attacker-observable RSA decryption). - cosign-verify — keyless GitHub OIDC verification recipe pinned in CI; PR runs are dry-run with the verification command echoed into the run summary. Full recipe documented in docs/operations/supply-chain.md. Conformance suite: - New tests/cncf-conformance workspace crate. 15 conformance criteria and 17 cargo test cases gate every PR. Suite renders the helm chart with `helm template ac deploy/helm/azureclaw --namespace azureclaw-system` to avoid serde_yaml 0.9 hangs on Helm action blocks. - Binary writes tests/cncf-conformance/CONFORMANCE-REPORT.md and exits non-zero on failure. Status: 15/15 criteria pass. Docs: - docs/operations/supply-chain.md — image-tag convention + cosign recipe - docs/operations/branch-protection.md — required-checks list - docs/api/conditions.md — per-CRD reason taxonomy - docs/security-audits/2026-04-30-phase2-cncf-conformance.md — audit Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * phase2(s17): unblock cargo-deny — add RUSTSEC-2025-0134 + version-pin path deps Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Brings AzureClaw to CNCF Kubernetes AI Conformance v1.35+ minimum bar, and pins two new permanent supply-chain CI rows so that neither can be silently dropped.
Surveyed gaps
ClawPairinglacked astatus.conditions[]array (criterion C3) and any CEL validation rule (C5).app.kubernetes.io/namelabel (C10).azureclaw-systemhad no default-denyNetworkPolicy(C8).cargo-auditran withcontinue-on-error: true; nocargo-denystep; nocosign-verifyrecipe in CI (C14).Additions
ClawPairing.status.conditions[]+Readyprinter column + two CEL rules; added recommended labels to all split-file CRDs; addedoperator-default-deny-networkpolicy.yamltemplate (emptypodSelector, bothpolicyTypes, allow-list for kube-DNS / kube-apiserver / Prometheus :9091).tests/cncf-conformance/workspace crate — 15 criteria, 17cargo testcases, binary writesCONFORMANCE-REPORT.mdand exits non-zero on failure. Suite renders the helm chart withhelm template ac deploy/helm/azureclaw --namespace azureclaw-system.deny.tomlat workspace root — advisories / licenses / bans / sources, with two documented advisory exceptions (RUSTSEC-2024-0370 unmaintained proc-macro-error via sigstore; RUSTSEC-2023-0071 rsa Marvin via jsonwebtoken/sigstore — neither call site does attacker-observable RSA decryption).New permanent CI rows (
.github/workflows/ci.yml)cargo-deny— required, runscargo deny check.cosign-verify— required, pins keyless GitHub OIDC verification recipe; PR runs are dry-run with the command echoed into the run summary.Docs
docs/operations/supply-chain.md— image-tag convention, cosign recipe, deny.toml posture.docs/operations/branch-protection.md— canonical required-checks list.docs/api/conditions.md— per-CRD reason taxonomy (Ready/Progressing/Degraded).docs/security-audits/2026-04-30-phase2-cncf-conformance.md— audit narrative.CHANGELOG.md—### S17 phase2-cncf-conformanceentry under[Unreleased] — Phase 2.Conformance status
15 / 15 criteria pass. Run
cargo run -p azureclaw-cncf-conformance --bin cncf-conformanceto regeneratetests/cncf-conformance/CONFORMANCE-REPORT.md.Verification
cargo test --all— 17 conformance + ~600 existing tests, all green.cargo deny check— advisories ok, bans ok, licenses ok, sources ok.helm lint deploy/helm/azureclaw— clean.cargo clippy --all-targets -- -D warnings— clean.cd cli && npm run lint && npm run typecheck— clean.Notes
:latestimage-tag convention is preserved; C9 was scoped to "every image declares an explicit tag or digest" (catches untagged refs only). Documented indocs/operations/supply-chain.md.image-cache-publish.ymland CRD doc-gen are tracked as follow-ups in the audit doc.Co-authored-by: Copilot 223556219+Copilot@users.noreply.github.com