ADORSYS-GIS / ADORSYS-GIS/ai-helm

[Ticket]: E2E verification & documentation — project governance allow/deny, revocation latency, fail-mode

Abierto
#573 0 comentarios 0 reacciones 0 asignados Ver en GitHub
Lenguaje dominante
Go Template
Estrellas
3
Forks
1
Merge medio
19 h 24 min
PR fusionados (30 d)
80

Descripción

### Type

Verification / Documentation

Parent epic: #531. Intended labels: `ticket`, `governance`.

### Summary

Prove the epic's acceptance criteria end-to-end and document the system. This inherits the original spike's deliverable (deny/allow demonstration) at production scope.

### Test Plan

- Model allowlist: member of project P restricted to models X,Y → 200 on X/Y, 403 on Z — demonstrated on **both** planes (opencode external JWT; LibreChat forwarded user internal).
- Quota tiers: member at `t-xs` exhausts monthly bucket → 429; project envelope exhaustion 429s remaining members; existing plan buckets still compose.
- Revocation latency: lead removes a member → measure time until gateway denies (must be ≤ metadata cache TTL).
- Lead RBAC: lead of P attempts mutation on project Q → denied at API and MCP.
- Fail-mode: kill the resolve pod → observe the ADR-decided behavior; recovery clean.
- CI caller (GitHub OIDC, ADR-0047 path) inherits project context correctly.

### Acceptance Criteria

- [ ] All scenarios above evidenced (commands + responses) in the ticket.
- [ ] `docs/project-governance.md`: end-to-end flow, Mermaid diagram, operator runbook (provision project, set envelope, appoint lead), lead guide cross-link.
- [ ] Epic #531 checklist fully ticked; ADR status flipped to Accepted with evidence links.

### Human accountable owner

@Koufan-De-King

### AI Usage Declaration

- [x] Drafting the ticket
- [x] I have declared AI usage above (ticked the relevant items, or "Not used").

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Start by reviewing epic #531, ADR-0047, and the project-governance implementation, then map the verification plan across the API, MCP, opencode JWT, LibreChat forwarded-user, and GitHub OIDC paths. Document the end-to-end flow in docs/project-governance.md with the requested Mermaid diagram and operator runbook; done means every scenario has commands and responses, the epic checklist is complete, and the ADR links to evidence.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
github-actions, helm, kubernetes
Área
authorization, devops, documentation, infrastructure, security, testing
Tipo de issue
Documentación
Dificultad
4/5
Tiempo estimado
3-5 días
Estado de actividad
Tranquilo
Claridad
Bastante claro
Aptitud para principiantes
45/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.