Compare commits
9
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8e6547659c | ||
|
|
794881e18b | ||
|
|
ac6f696f19 | ||
|
|
84225828bd | ||
|
|
e8ddf82040 | ||
|
|
6a181aa5d7 | ||
|
|
c08ca9c22d | ||
|
|
8015f8a2ef | ||
|
|
15e9b6cd70 |
@@ -1,7 +1,7 @@
|
||||
---
|
||||
name: corp-v1-channel-uat
|
||||
description: Use when validating a deployed Corp v1 environment through UAT journeys.
|
||||
version: 1.1.1
|
||||
version: 1.3.0
|
||||
author: Hermes Agent
|
||||
license: MIT
|
||||
metadata:
|
||||
@@ -42,13 +42,14 @@ If any identity is mutable, missing, or contradictory, record `BLOCKED` rather t
|
||||
|
||||
## Responsibilities
|
||||
|
||||
1. Maintain a dedicated pnpm E2E repository with versioned journeys.
|
||||
2. Execute journeys against the exact deployed environment supplied by Delivery.
|
||||
3. Collect machine-readable and human-reviewable evidence.
|
||||
4. Distinguish product failures, environment failures, and test defects.
|
||||
5. Return product/environment failures to Kanban and Delivery with reproducible evidence.
|
||||
6. Rerun the affected journey set after a verified redeployment.
|
||||
7. Hand a `UAT_PASSED` or `UAT_FAILED` verdict to Releases without implying release approval.
|
||||
1. Maintain a dedicated pnpm E2E repository as the authoritative home for functional non-unit tests and their fixtures, configuration, runner, and evidence contract.
|
||||
2. Keep application image/container/Helm build, rendering, publication, and static artifact validation in Delivery. The E2E repository must not build/publish application images, install Helm, render charts, or validate artifact publication.
|
||||
3. Execute source-coupled functional non-unit suites against an exact application-source checkout and black-box journeys against the exact deployed environment supplied by Delivery.
|
||||
4. Collect machine-readable and human-reviewable evidence.
|
||||
5. Distinguish product failures, environment failures, and test defects.
|
||||
6. Return product/environment failures to Kanban and Delivery with reproducible evidence.
|
||||
7. Rerun the affected journey set after a verified redeployment.
|
||||
8. Hand a `UAT_PASSED` or `UAT_FAILED` verdict to Releases without implying release approval.
|
||||
|
||||
## Required E2E repository pipeline
|
||||
|
||||
@@ -58,7 +59,7 @@ Every project UAT repository uses two Gitea Actions workflows:
|
||||
non-default branch push
|
||||
└── CI / Change Validation
|
||||
├── repository validation for every exact pushed commit
|
||||
└── smoke journeys only when that commit is an open PR head
|
||||
└── smoke journeys for explicit PR events or exact review-associated commits
|
||||
|
||||
merge to the default `test` branch
|
||||
└── UAT / Integrated Regression
|
||||
@@ -68,7 +69,7 @@ merge to the default `test` branch
|
||||
└── structured regression evidence
|
||||
```
|
||||
|
||||
Use one change workflow for both pre-PR branches and PR heads. A PR-open or PR-reopen event adds the first smoke-bearing run. Do not subscribe that workflow to `pull_request.synchronize`; later branch pushes are the single trigger and use the checkout credential only in the classification job to query Gitea for an open PR whose head branch and exact SHA both match. Never classify from retained `refs/pull/*` refs because Gitea keeps them after closure. Never print or persist the checkout credential, and do not pass it to validation jobs. Cancel superseded change runs for the same branch. Never run full regression on a PR, and never treat smoke as complete UAT.
|
||||
Use one change workflow for both pre-PR branches and PR heads. A PR-open or PR-reopen event adds the first smoke-bearing run. Do not subscribe that workflow to `pull_request.synchronize`; later branch pushes are the single trigger and compare the exact commit with Gitea pull-request head refs without exposing a broad API token to candidate-controlled code. Gitea retains those refs after closure, so an unchanged closed-PR head may conservatively receive smoke again; a new branch-only commit receives repository validation only. Cancel superseded change runs for the same branch. Never run full regression on a PR, and never treat smoke as complete UAT.
|
||||
|
||||
Integrated regression runs only for exact commits pushed to `test`; they queue rather than cancel one another so every merged commit receives a result. This automatic run proves the integrated journey set against the configured non-production URL but does not issue `UAT_PASSED`. A release-facing UAT verdict requires a separately frozen Delivery handoff plus pre-run and post-run live verification of application commit, image digests, deployable GitOps commit, Argo CD revision/sync/health, environment, and base URL. Neither workflow deploys or publishes application artifacts.
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# Journey repository contract
|
||||
|
||||
The UAT repository is a standalone pnpm/Playwright project. It contains no Kubernetes, Helm, Argo CD, application implementation, image publication, or deployment logic.
|
||||
The UAT repository is a standalone pnpm/Playwright project and the authoritative home for functional non-unit tests. It may contain source-coupled integration, browser, database-backed, performance, acceptance, and deployed-environment suites. It contains no application implementation, image/container publication validation, Helm installation/rendering, deployable Kubernetes/Helm desired state, image publication, Argo CD mutation, or deployment logic.
|
||||
|
||||
## Required baseline
|
||||
|
||||
@@ -36,7 +36,7 @@ A smaller standalone repository may keep `journeys/`, `fixtures/`, `helpers/`, a
|
||||
non-default branch push
|
||||
└── CI / Change Validation
|
||||
├── formatting, linting, type checks, contract tests, journey discovery, build when applicable
|
||||
└── smoke journeys only when the exact commit is an open PR head
|
||||
└── smoke journeys for explicit PR events or exact review-associated commits
|
||||
|
||||
PR opened or reopened
|
||||
└── CI / Change Validation
|
||||
@@ -51,6 +51,6 @@ push to test after merge
|
||||
└── structured regression evidence upload
|
||||
```
|
||||
|
||||
Use one change workflow rather than separate branch and PR workflow files. It subscribes to non-default `push` plus `pull_request` `opened` and `reopened`, but not `synchronize`; later branch pushes are the single trigger. The classification job queries Gitea using the checkout credential held only in memory and requires both the open PR head branch and exact SHA to match. Never infer open state from retained pull-request refs. Cancel superseded change runs for the same branch and expose one required aggregate result.
|
||||
Use one change workflow rather than separate branch and PR workflow files. It subscribes to non-default `push` plus `pull_request` `opened` and `reopened`, but not `synchronize`; later branch pushes are the single trigger. The classification job compares the exact commit with Gitea pull-request head refs without exposing a broad API token to candidate-controlled code. Because Gitea retains those refs after closure, an unchanged closed-PR head may conservatively receive smoke again; a new branch-only commit receives repository validation only. Cancel superseded change runs for the same branch and expose one required aggregate result.
|
||||
|
||||
The integrated workflow runs only on `push` to `test` and queues instead of cancelling older integrated commits. It requires an explicit non-production base URL and runtime-only authentication when the regression set requires it. Its artifacts are integrated regression evidence, not a release-facing UAT verdict. `UAT_PASSED` additionally requires the project UAT procedure to verify the immutable Delivery deployment tuple live before and after the run. Smoke is not complete UAT, and full regression does not run on a PR.
|
||||
|
||||
Reference in New Issue
Block a user