ADORSYS-GIS / ADORSYS-GIS/ai-helm
[Ticket]: E2E verification & documentation — project governance allow/deny, revocation latency, fail-mode
- Ngôn ngữ chính
- Go Template
- Star
- 3
- Fork
- 1
- Merge trung bình
- 19 giờ 24 phút
- Pull request đã merge (30 ngày)
- 80
Mô tả
### Type
Verification / Documentation
Parent epic: #531. Intended labels: `ticket`, `governance`.
### Summary
Prove the epic's acceptance criteria end-to-end and document the system. This inherits the original spike's deliverable (deny/allow demonstration) at production scope.
### Test Plan
- Model allowlist: member of project P restricted to models X,Y → 200 on X/Y, 403 on Z — demonstrated on **both** planes (opencode external JWT; LibreChat forwarded user internal).
- Quota tiers: member at `t-xs` exhausts monthly bucket → 429; project envelope exhaustion 429s remaining members; existing plan buckets still compose.
- Revocation latency: lead removes a member → measure time until gateway denies (must be ≤ metadata cache TTL).
- Lead RBAC: lead of P attempts mutation on project Q → denied at API and MCP.
- Fail-mode: kill the resolve pod → observe the ADR-decided behavior; recovery clean.
- CI caller (GitHub OIDC, ADR-0047 path) inherits project context correctly.
### Acceptance Criteria
- [ ] All scenarios above evidenced (commands + responses) in the ticket.
- [ ] `docs/project-governance.md`: end-to-end flow, Mermaid diagram, operator runbook (provision project, set envelope, appoint lead), lead guide cross-link.
- [ ] Epic #531 checklist fully ticked; ADR status flipped to Accepted with evidence links.
### Human accountable owner
@Koufan-De-King
### AI Usage Declaration
- [x] Drafting the ticket
- [x] I have declared AI usage above (ticked the relevant items, or "Not used").
Hướng dẫn đóng góp
Đánh giá
Issue này chưa được đánh giá.