ADORSYS-GIS / ADORSYS-GIS/ai-helm

[Ticket]: E2E verification & documentation — project governance allow/deny, revocation latency, fail-mode

Đang mở
#573 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
Go Template
Star
3
Fork
1
Merge trung bình
19 giờ 24 phút
Pull request đã merge (30 ngày)
80

Mô tả

### Type

Verification / Documentation

Parent epic: #531. Intended labels: `ticket`, `governance`.

### Summary

Prove the epic's acceptance criteria end-to-end and document the system. This inherits the original spike's deliverable (deny/allow demonstration) at production scope.

### Test Plan

- Model allowlist: member of project P restricted to models X,Y → 200 on X/Y, 403 on Z — demonstrated on **both** planes (opencode external JWT; LibreChat forwarded user internal).
- Quota tiers: member at `t-xs` exhausts monthly bucket → 429; project envelope exhaustion 429s remaining members; existing plan buckets still compose.
- Revocation latency: lead removes a member → measure time until gateway denies (must be ≤ metadata cache TTL).
- Lead RBAC: lead of P attempts mutation on project Q → denied at API and MCP.
- Fail-mode: kill the resolve pod → observe the ADR-decided behavior; recovery clean.
- CI caller (GitHub OIDC, ADR-0047 path) inherits project context correctly.

### Acceptance Criteria

- [ ] All scenarios above evidenced (commands + responses) in the ticket.
- [ ] `docs/project-governance.md`: end-to-end flow, Mermaid diagram, operator runbook (provision project, set envelope, appoint lead), lead guide cross-link.
- [ ] Epic #531 checklist fully ticked; ADR status flipped to Accepted with evidence links.

### Human accountable owner

@Koufan-De-King

### AI Usage Declaration

- [x] Drafting the ticket
- [x] I have declared AI usage above (ticked the relevant items, or "Not used").

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.