Skip to content

S17 phase2-cncf-conformance: K8s AI conformance + supply-chain CI rows - #124

Merged
Pal Lakatos-Toth (pallakatos) merged 2 commits into
devfrom
phase2-s17-cncf-conformance
Apr 30, 2026
Merged

Pal Lakatos-Toth (pallakatos) merged 2 commits into
devfrom
phase2-s17-cncf-conformance

Conversation

@pallakatos

Copy link
Copy Markdown
Collaborator

Brings AzureClaw to CNCF Kubernetes AI Conformance v1.35+ minimum bar, and pins two new permanent supply-chain CI rows so that neither can be silently dropped.

Surveyed gaps

  • ClawPairing lacked a status.conditions[] array (criterion C3) and any CEL validation rule (C5).
  • Six of eight CRDs (a2aagent / claweval / clawmemory / inferencepolicy / mcpserver / toolpolicy) lacked the recommended app.kubernetes.io/name label (C10).
  • The operator namespace azureclaw-system had no default-deny NetworkPolicy (C8).
  • cargo-audit ran with continue-on-error: true; no cargo-deny step; no cosign-verify recipe in CI (C14).

Additions

  • Conformance gap-fixes: added ClawPairing.status.conditions[] + Ready printer column + two CEL rules; added recommended labels to all split-file CRDs; added operator-default-deny-networkpolicy.yaml template (empty podSelector, both policyTypes, allow-list for kube-DNS / kube-apiserver / Prometheus :9091).
  • tests/cncf-conformance/ workspace crate — 15 criteria, 17 cargo test cases, binary writes CONFORMANCE-REPORT.md and exits non-zero on failure. Suite renders the helm chart with helm template ac deploy/helm/azureclaw --namespace azureclaw-system.
  • deny.toml at workspace root — advisories / licenses / bans / sources, with two documented advisory exceptions (RUSTSEC-2024-0370 unmaintained proc-macro-error via sigstore; RUSTSEC-2023-0071 rsa Marvin via jsonwebtoken/sigstore — neither call site does attacker-observable RSA decryption).

New permanent CI rows (.github/workflows/ci.yml)

  • cargo-deny — required, runs cargo deny check.
  • cosign-verify — required, pins keyless GitHub OIDC verification recipe; PR runs are dry-run with the command echoed into the run summary.

Docs

  • docs/operations/supply-chain.md — image-tag convention, cosign recipe, deny.toml posture.
  • docs/operations/branch-protection.md — canonical required-checks list.
  • docs/api/conditions.md — per-CRD reason taxonomy (Ready / Progressing / Degraded).
  • docs/security-audits/2026-04-30-phase2-cncf-conformance.md — audit narrative.
  • CHANGELOG.md — ### S17 phase2-cncf-conformance entry under [Unreleased] — Phase 2.

Conformance status

15 / 15 criteria pass. Run cargo run -p azureclaw-cncf-conformance --bin cncf-conformance to regenerate tests/cncf-conformance/CONFORMANCE-REPORT.md.

ID Criterion Result
C1 Every CRD has a served + storage version ✅
C2 Every CRD has additional printer columns ✅
C3 Every CRD status declares a conditions[] array ✅
C4 Every CRD spec is a structural schema ✅
C5 Every CRD ships at least one CEL x-kubernetes-validations rule ✅
C6 Every CRD declares a status subresource ✅
C7 Every Deployment has liveness + readiness probes ✅
C8 Operator namespace has a default-deny NetworkPolicy ✅
C9 Every image ref declares an explicit tag or digest (no implicit :latest) ✅
C10 Every CRD carries app.kubernetes.io/name label ✅
C11 Every CRD declares a valid scope ✅
C12 Every CRD exposes a status-state printer column ✅
C13 Every Deployment runs non-root with a seccompProfile ✅
C14 ci.yml wires the supply-chain rows (cargo-deny, trivy, npm audit, cosign-verify) ✅
C15 deny.toml configures advisories/licenses/bans/sources ✅

Verification

  • cargo test --all — 17 conformance + ~600 existing tests, all green.
  • cargo deny check — advisories ok, bans ok, licenses ok, sources ok.
  • helm lint deploy/helm/azureclaw — clean.
  • cargo clippy --all-targets -- -D warnings — clean.
  • cd cli && npm run lint && npm run typecheck — clean.

Notes

  • The repo :latest image-tag convention is preserved; C9 was scoped to "every image declares an explicit tag or digest" (catches untagged refs only). Documented in docs/operations/supply-chain.md.
  • SBOM wiring into image-cache-publish.yml and CRD doc-gen are tracked as follow-ups in the audit doc.

Co-authored-by: Copilot 223556219+Copilot@users.noreply.github.com

Brings AzureClaw CRDs and Helm chart to CNCF Kubernetes AI Conformance
v1.35+ minimum bar, and pins two new permanent supply-chain CI rows.

Conformance gap-fixes:
- ClawPairing: add status.conditions[] array (Rust + helm CRD) with the
  standard k8s condition shape, add a Ready printer column driven by
  .status.conditions[?(@.type=="Ready")].status, and add two
  x-kubernetes-validations CEL rules (slotsMax >= 1, tokenBudget >= 0).
- All six split-file CRDs (a2aagent, claweval, clawmemory,
  inferencepolicy, mcpserver, toolpolicy) gain
  app.kubernetes.io/name=azureclaw and app.kubernetes.io/component=crd
  labels. Helm-drift comparison strips labels so no Rust schema change.
- New operator-default-deny-networkpolicy.yaml installs an
  empty-podSelector default-deny policy in azureclaw-system with
  allow-list exceptions for kube-DNS, kube-apiserver, and Prometheus
  scrapes of :9091.

New CI rows (permanent, required):
- cargo-deny — runs cargo deny check against deny.toml with two
  documented advisory exceptions (RUSTSEC-2024-0370 proc-macro-error
  transitive via sigstore; RUSTSEC-2023-0071 rsa Marvin attack via
  jsonwebtoken/sigstore — neither call site does attacker-observable
  RSA decryption).
- cosign-verify — keyless GitHub OIDC verification recipe pinned in
  CI; PR runs are dry-run with the verification command echoed into
  the run summary. Full recipe documented in docs/operations/supply-chain.md.

Conformance suite:
- New tests/cncf-conformance workspace crate. 15 conformance criteria
  and 17 cargo test cases gate every PR. Suite renders the helm chart
  with `helm template ac deploy/helm/azureclaw --namespace azureclaw-system`
  to avoid serde_yaml 0.9 hangs on Helm action blocks.
- Binary writes tests/cncf-conformance/CONFORMANCE-REPORT.md and
  exits non-zero on failure.

Status: 15/15 criteria pass.

Docs:
- docs/operations/supply-chain.md — image-tag convention + cosign recipe
- docs/operations/branch-protection.md — required-checks list
- docs/api/conditions.md — per-CRD reason taxonomy
- docs/security-audits/2026-04-30-phase2-cncf-conformance.md — audit

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
… path deps

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pallakatos
Pal Lakatos-Toth (pallakatos) merged commit 4e91abf into dev Apr 30, 2026
19 of 20 checks passed
Pal Lakatos-Toth (pallakatos) added a commit that referenced this pull request May 12, 2026
#124)

* S17 phase2-cncf-conformance: K8s AI conformance + supply-chain CI rows

Brings AzureClaw CRDs and Helm chart to CNCF Kubernetes AI Conformance
v1.35+ minimum bar, and pins two new permanent supply-chain CI rows.

Conformance gap-fixes:
- ClawPairing: add status.conditions[] array (Rust + helm CRD) with the
  standard k8s condition shape, add a Ready printer column driven by
  .status.conditions[?(@.type=="Ready")].status, and add two
  x-kubernetes-validations CEL rules (slotsMax >= 1, tokenBudget >= 0).
- All six split-file CRDs (a2aagent, claweval, clawmemory,
  inferencepolicy, mcpserver, toolpolicy) gain
  app.kubernetes.io/name=azureclaw and app.kubernetes.io/component=crd
  labels. Helm-drift comparison strips labels so no Rust schema change.
- New operator-default-deny-networkpolicy.yaml installs an
  empty-podSelector default-deny policy in azureclaw-system with
  allow-list exceptions for kube-DNS, kube-apiserver, and Prometheus
  scrapes of :9091.

New CI rows (permanent, required):
- cargo-deny — runs cargo deny check against deny.toml with two
  documented advisory exceptions (RUSTSEC-2024-0370 proc-macro-error
  transitive via sigstore; RUSTSEC-2023-0071 rsa Marvin attack via
  jsonwebtoken/sigstore — neither call site does attacker-observable
  RSA decryption).
- cosign-verify — keyless GitHub OIDC verification recipe pinned in
  CI; PR runs are dry-run with the verification command echoed into
  the run summary. Full recipe documented in docs/operations/supply-chain.md.

Conformance suite:
- New tests/cncf-conformance workspace crate. 15 conformance criteria
  and 17 cargo test cases gate every PR. Suite renders the helm chart
  with `helm template ac deploy/helm/azureclaw --namespace azureclaw-system`
  to avoid serde_yaml 0.9 hangs on Helm action blocks.
- Binary writes tests/cncf-conformance/CONFORMANCE-REPORT.md and
  exits non-zero on failure.

Status: 15/15 criteria pass.

Docs:
- docs/operations/supply-chain.md — image-tag convention + cosign recipe
- docs/operations/branch-protection.md — required-checks list
- docs/api/conditions.md — per-CRD reason taxonomy
- docs/security-audits/2026-04-30-phase2-cncf-conformance.md — audit

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* phase2(s17): unblock cargo-deny — add RUSTSEC-2025-0134 + version-pin path deps

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pallakatos
Pal Lakatos-Toth (pallakatos) deleted the phase2-s17-cncf-conformance branch June 1, 2026 14:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant