docs: route Delivery through development skills

This commit is contained in:
2026-09-23 19:38:14 +00:00
parent 52bee5e227
commit 6190262538
3 changed files with 59 additions and 31 deletions
+1 -1
View File
@@ -104,7 +104,7 @@ the adopted project owns `corp-v1-<code>/corp-v1-<code>-base-images` as the reus
### Gondor runtime-resource placement
the adopted project CI jobs and developer workstations must not provision PostgreSQL, queues, object stores, caches, brokers, or other application runtime services. Provision every required development, integration-test, test, staging, preview, or production resource under the the adopted project application on Gondor through the `corp-v1-<code>/gondor-v1-tmpl-<code>` → `corp-v1-<code>/gondor-v1-<code>` GitOps chain.
The adopted project CI jobs and developer workstations must not provision PostgreSQL, queues, object stores, caches, brokers, or other application runtime services. Load `development-gitops-argo-cd-gondor-v1` before defining or changing Gondor desired state. Render the committed project template separately into one repository per environment; Delivery may update only the repository assigned to its non-production environment, while production remains outside Delivery authority unless an explicit project overlay says otherwise.
- Keep every non-production the adopted project environment—including development, integration, test, staging, and preview—and all of its resources isolated from production and from other non-production environments. Destructive or concurrent validation requires a per-run database/schema/role or explicit serialization; it must not reset shared data.
- CI may orchestrate exact-head validation, but it must not start application runtime-resource service containers or receive application-resource credentials. Harmless process-local test doubles and build tools are not runtime resources. Run resource-dependent tests through a restricted trigger as private in-cluster Jobs/Workflows; do not expose PostgreSQL or another internal resource through Ingress, NodePort, LoadBalancer, or a runner-accessible public endpoint.