Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 32 additions & 0 deletions .flux/README.adoc
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
= GitOps Configuration Promotion
:author: Jonathan D.A. Jewell

// SPDX-License-Identifier: PMPL-1.0-or-later

This directory contains Flux-compatible GitOps configuration for promoting
contractile-managed policies from staging to production.

== Structure

[source]
----
.flux/
├── clusters/
│ ├── staging/ # Staging environment configs
│ └── production/ # Production environment configs
└── README.adoc # This file
----

== Promotion Flow

1. Changes to `policy/policy.ncl` are applied to staging first
2. `must check` and `trust verify` run against staging
3. After verification, promote to production via PR
4. Flux reconciles the production cluster

== Integration with Contractiles

- `must check` validates policy before promotion
- `trust verify` ensures artifact integrity
- `dust rollback` provides recovery if promotion fails
- `intend check` tracks whether GitOps adoption is complete
18 changes: 18 additions & 0 deletions .machine_readable/root-allow.txt
Original file line number Diff line number Diff line change
Expand Up @@ -100,3 +100,21 @@ mise.toml # toolchain pin read by mise. Estate canon is .tool-v
# never written for it. Read from the estate-rules gate's own output.
.github/hooks/ # Top-level component directory of this project.
REQUIRES_INITIALISATION.md # Project documentation.

# ─── Declared 2026-10-09: landed from the vendored copy in reposystem ─────────
# These trees were vendored at reposystem@845679600b29^:contractiles/ and
# reached this repo only on 2026-10-09 (owner ruling: "get that stuff
# out"). Their paths are kept as vendored so the provenance stays
# traceable. Where they finally live is a question for RFC-0001
# ratification; the owner can move any of them in review.
cli/ # Rust workspace: crates contractile + contractile-core
mustfile/ # Mustfile runner project (Ada/SPARK + shell launchers)
runners/ # per-verb runner projects (must/, trust/, intend/, just/, bust/)
config/ # attestation, canary, policy, TPM and tracing configs
policy/ # policy.ncl + policy.json
keys/ # signing.pub
schema/ # version.txt
dustfile/ # dust-spec.adoc
intentfile/ # intent-spec.adoc
trustfile/ # trust-spec.adoc
.flux/ # README.adoc
Loading
Loading