fix: separate integrated regression from UAT verdict

This commit is contained in:
2026-09-25 09:38:47 +00:00
parent 105cf37d12
commit f3760d2115
2 changed files with 8 additions and 6 deletions
+5 -3
View File
@@ -1,7 +1,7 @@
---
name: corp-v1-channel-uat
description: Use when validating a deployed Corp v1 environment through UAT journeys.
version: 1.1.0
version: 1.1.1
author: Hermes Agent
license: MIT
metadata:
@@ -65,10 +65,12 @@ merge to the default `test` branch
├── repository validation
├── smoke journeys
├── complete regression journeys
└── immutable deployment-tuple evidence
└── structured regression evidence
```
Use one change workflow for both pre-PR branches and PR heads. A PR-open or PR-reopen event adds the first smoke-bearing run. Do not subscribe that workflow to `pull_request.synchronize`; later branch pushes are the single trigger and classify whether the exact commit is an open PR head. Cancel superseded runs for the same branch. Never run full regression on a PR, and never treat smoke as complete UAT. The integrated workflow runs only for the exact commit pushed to `test`, fails closed when its frozen deployment inputs are missing or unhealthy, and does not deploy or publish application artifacts.
Use one change workflow for both pre-PR branches and PR heads. A PR-open or PR-reopen event adds the first smoke-bearing run. Do not subscribe that workflow to `pull_request.synchronize`; later branch pushes are the single trigger and use the checkout credential only in the classification job to query Gitea for an open PR whose head branch and exact SHA both match. Never classify from retained `refs/pull/*` refs because Gitea keeps them after closure. Never print or persist the checkout credential, and do not pass it to validation jobs. Cancel superseded change runs for the same branch. Never run full regression on a PR, and never treat smoke as complete UAT.
Integrated regression runs only for exact commits pushed to `test`; they queue rather than cancel one another so every merged commit receives a result. This automatic run proves the integrated journey set against the configured non-production URL but does not issue `UAT_PASSED`. A release-facing UAT verdict requires a separately frozen Delivery handoff plus pre-run and post-run live verification of application commit, image digests, deployable GitOps commit, Argo CD revision/sync/health, environment, and base URL. Neither workflow deploys or publishes application artifacts.
## UAT verdicts