v0.2.0 — Identity, State & Signed Delivery
Engineering intent
Replace static cloud credentials and mutable delivery assumptions with short-lived identity, protected state and signed artifacts.
Architecture delta
- GitHub Actions → AWS OIDC federation design
- separate scoped Terraform plan/apply roles
- KMS-encrypted, versioned S3 Terraform state with native S3 locking
- independent
dev,stagingandprodstate/configuration - manual protected-environment apply workflow
- project-owned Go demo service
- GHCR build with BuildKit provenance and SBOM attestations
- Trivy HIGH/CRITICAL image gate
- Cosign keyless signing and workflow-identity verification
- Kubernetes desired state pinned to a verified immutable digest
Evidence
The container supply-chain path was exercised in GitHub Actions and the signed digest was verified. Current reproducible links are collected in Engineering Evidence.
Evidence boundary
AWS bootstrap/apply remained an explicit operator action. This release did not create AWS infrastructure or claim a live OIDC-backed Terraform plan against an AWS account.