ADORSYS-GIS / ADORSYS-GIS/ai-helm
[Ticket]: E2E verification & documentation — project governance allow/deny, revocation latency, fail-mode
- Lenguaje dominante
- Go Template
- Estrellas
- 3
- Forks
- 1
- Merge medio
- 19 h 24 min
- PR fusionados (30 d)
- 80
Descripción
### Type
Verification / Documentation
Parent epic: #531. Intended labels: `ticket`, `governance`.
### Summary
Prove the epic's acceptance criteria end-to-end and document the system. This inherits the original spike's deliverable (deny/allow demonstration) at production scope.
### Test Plan
- Model allowlist: member of project P restricted to models X,Y → 200 on X/Y, 403 on Z — demonstrated on **both** planes (opencode external JWT; LibreChat forwarded user internal).
- Quota tiers: member at `t-xs` exhausts monthly bucket → 429; project envelope exhaustion 429s remaining members; existing plan buckets still compose.
- Revocation latency: lead removes a member → measure time until gateway denies (must be ≤ metadata cache TTL).
- Lead RBAC: lead of P attempts mutation on project Q → denied at API and MCP.
- Fail-mode: kill the resolve pod → observe the ADR-decided behavior; recovery clean.
- CI caller (GitHub OIDC, ADR-0047 path) inherits project context correctly.
### Acceptance Criteria
- [ ] All scenarios above evidenced (commands + responses) in the ticket.
- [ ] `docs/project-governance.md`: end-to-end flow, Mermaid diagram, operator runbook (provision project, set envelope, appoint lead), lead guide cross-link.
- [ ] Epic #531 checklist fully ticked; ADR status flipped to Accepted with evidence links.
### Human accountable owner
@Koufan-De-King
### AI Usage Declaration
- [x] Drafting the ticket
- [x] I have declared AI usage above (ticked the relevant items, or "Not used").
Guía de contribución
Línea de trabajo
Start by reviewing epic #531, ADR-0047, and the project-governance implementation, then map the verification plan across the API, MCP, opencode JWT, LibreChat forwarded-user, and GitHub OIDC paths. Document the end-to-end flow in docs/project-governance.md with the requested Mermaid diagram and operator runbook; done means every scenario has commands and responses, the epic checklist is complete, and the ADR links to evidence.
Escrito por el modelo de indexación a partir del texto del issue.
Evaluación
- Stack tecnológico
- github-actions, helm, kubernetes
- Área
- authorization, devops, documentation, infrastructure, security, testing
- Tipo de issue
- Documentación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Estado de actividad
- Tranquilo
- Claridad
- Bastante claro
- Aptitud para principiantes
- 45/100