Skip to content

v0.2.0 — Identity, State & Signed Delivery

Choose a tag to compare

@fadyy2k fadyy2k released this 20 Sep 12:10
· 10 commits to main since this release
c2e00e3

Engineering intent

Replace static cloud credentials and mutable delivery assumptions with short-lived identity, protected state and signed artifacts.

Architecture delta

  • GitHub Actions → AWS OIDC federation design
  • separate scoped Terraform plan/apply roles
  • KMS-encrypted, versioned S3 Terraform state with native S3 locking
  • independent dev, staging and prod state/configuration
  • manual protected-environment apply workflow
  • project-owned Go demo service
  • GHCR build with BuildKit provenance and SBOM attestations
  • Trivy HIGH/CRITICAL image gate
  • Cosign keyless signing and workflow-identity verification
  • Kubernetes desired state pinned to a verified immutable digest

Evidence

The container supply-chain path was exercised in GitHub Actions and the signed digest was verified. Current reproducible links are collected in Engineering Evidence.

Evidence boundary

AWS bootstrap/apply remained an explicit operator action. This release did not create AWS infrastructure or claim a live OIDC-backed Terraform plan against an AWS account.