Automated Governance: does the TAG want it back as an initiative, and where do its documents live?
- Dominant language
- HTML
- Stars
- 1.9k
- Forks
- 724
- Avg merge
- 6d 12h
- Merged PRs (30d)
- 4
Description
Automated Governance has a finished deliverable and no longer has a home in the tree. The working group's README and the Automated Governance Maturity Model both sit in cncf/tag-security, archived and last pushed 2025-12-08. The controls catalog and supply-chain work that succeeded it sit in `cncf/toc/tags/tag-security-and-compliance/`.
The maturity model is about eighteen kilobytes of finished text. It gives an organization a scale for the maturity of the controls an automated governance programme needs, without scoring a specific implementation.
Does the TAG want Automated Governance back as an initiative, and where do its documents live now the source repository is archived? If the answer to the first is yes, I will do the carry-across: porting the maturity model to the new location, opening the PR, and taking the initiative's maintenance.
The scale has a shipped consumer: four admission rails, OPA rego, Kyverno CEL, Kyverno JMESPath and CUE, run in CI at https://github.com/astrogilda/agent-evidence-admission
Contributor guide
Research direction
Read the archived working group's README and Automated Governance Maturity Model in cncf/tag-security, then inspect the successor materials under cncf/toc/tags/tag-security-and-compliance/. Confirm the TAG's decision on whether the initiative returns and where its documents should live; done means that decision is recorded, with a carry-across PR only if requested.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100