fix: separate integrated regression from UAT verdict
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
---
|
||||
name: corp-v1-channel-uat
|
||||
description: Use when validating a deployed Corp v1 environment through UAT journeys.
|
||||
version: 1.1.0
|
||||
version: 1.1.1
|
||||
author: Hermes Agent
|
||||
license: MIT
|
||||
metadata:
|
||||
@@ -65,10 +65,12 @@ merge to the default `test` branch
|
||||
├── repository validation
|
||||
├── smoke journeys
|
||||
├── complete regression journeys
|
||||
└── immutable deployment-tuple evidence
|
||||
└── structured regression evidence
|
||||
```
|
||||
|
||||
Use one change workflow for both pre-PR branches and PR heads. A PR-open or PR-reopen event adds the first smoke-bearing run. Do not subscribe that workflow to `pull_request.synchronize`; later branch pushes are the single trigger and classify whether the exact commit is an open PR head. Cancel superseded runs for the same branch. Never run full regression on a PR, and never treat smoke as complete UAT. The integrated workflow runs only for the exact commit pushed to `test`, fails closed when its frozen deployment inputs are missing or unhealthy, and does not deploy or publish application artifacts.
|
||||
Use one change workflow for both pre-PR branches and PR heads. A PR-open or PR-reopen event adds the first smoke-bearing run. Do not subscribe that workflow to `pull_request.synchronize`; later branch pushes are the single trigger and use the checkout credential only in the classification job to query Gitea for an open PR whose head branch and exact SHA both match. Never classify from retained `refs/pull/*` refs because Gitea keeps them after closure. Never print or persist the checkout credential, and do not pass it to validation jobs. Cancel superseded change runs for the same branch. Never run full regression on a PR, and never treat smoke as complete UAT.
|
||||
|
||||
Integrated regression runs only for exact commits pushed to `test`; they queue rather than cancel one another so every merged commit receives a result. This automatic run proves the integrated journey set against the configured non-production URL but does not issue `UAT_PASSED`. A release-facing UAT verdict requires a separately frozen Delivery handoff plus pre-run and post-run live verification of application commit, image digests, deployable GitOps commit, Argo CD revision/sync/health, environment, and base URL. Neither workflow deploys or publishes application artifacts.
|
||||
|
||||
## UAT verdicts
|
||||
|
||||
|
||||
@@ -48,9 +48,9 @@ push to test after merge
|
||||
├── exact integrated-commit validation
|
||||
├── smoke journeys
|
||||
├── complete regression journeys
|
||||
└── deployment-bound evidence validation and upload
|
||||
└── structured regression evidence upload
|
||||
```
|
||||
|
||||
Use one change workflow rather than separate branch and PR workflow files. It subscribes to non-default `push` plus `pull_request` `opened` and `reopened`, but not `synchronize`; later branch pushes are the single trigger. The workflow detects whether the exact pushed commit is an open PR head and conditionally adds smoke. Cancel superseded runs for the same branch and expose one required aggregate result.
|
||||
Use one change workflow rather than separate branch and PR workflow files. It subscribes to non-default `push` plus `pull_request` `opened` and `reopened`, but not `synchronize`; later branch pushes are the single trigger. The classification job queries Gitea using the checkout credential held only in memory and requires both the open PR head branch and exact SHA to match. Never infer open state from retained pull-request refs. Cancel superseded change runs for the same branch and expose one required aggregate result.
|
||||
|
||||
The integrated workflow runs only on `push` to `test`. It requires an exact frozen deployment tuple, healthy synchronized Argo CD state, explicit non-production base URL, and runtime-only authentication when the regression set requires it. Missing or contradictory inputs fail closed. Smoke is not complete UAT, and full regression does not run on a PR.
|
||||
The integrated workflow runs only on `push` to `test` and queues instead of cancelling older integrated commits. It requires an explicit non-production base URL and runtime-only authentication when the regression set requires it. Its artifacts are integrated regression evidence, not a release-facing UAT verdict. `UAT_PASSED` additionally requires the project UAT procedure to verify the immutable Delivery deployment tuple live before and after the run. Smoke is not complete UAT, and full regression does not run on a PR.
|
||||
|
||||
Reference in New Issue
Block a user