Skip to content

Limits of the claim

Resilience Gate demonstrates a complete release-verification path for one owned testnet lab. The recorded release is meaningful within that boundary. Its success does not turn selected fault experiments into a universal guarantee, or a production-like namespace into public production.

Dev, staging, and prod share one zonal GKE Standard cluster with two recorded nodes. PostgreSQL and Redis are single-instance data dependencies per environment with persistent storage, not highly available clusters. Namespace separation helps scope workloads and experiments but does not isolate regional, node, or cluster failures.

The gate applies selected PostgreSQL, Redis, and signer pod-failure scenarios in sequence. It does not cover concurrent failures, arbitrary network partitions, control-plane outages, data corruption, long degradation, multi-region failover, restore from backup, or disaster recovery. Prometheus, Loki, Alloy, and Grafana are sized for a lab rather than highly available monitoring or compliant long-term retention.

A successful bounded recovery shows the configured target returned within its window. It does not establish sustainable capacity under unrestricted traffic. Staging load is deliberately small: at most three signer wallets/VUs and ten minutes through the manual runner. Prod-like smoke checks readiness/liveness without repeating paid load or chaos.

Identity does not supply every trust control

Section titled “Identity does not supply every trust control”

Digest-qualified images preserve selected bytes. Cosign signing and verification run in CI after publication. Kargo discovery and Kubernetes admission do not independently require verified signatures in the current implementation. An image pushed before a signing failure can remain discoverable. This is a documented trust boundary, not a claim of admission enforcement, SLSA certification, or an independently audited supply-chain program.

GitHub OIDC and GKE Workload Identity reduce reliance on long-lived cloud keys. External Secrets materializes references from Secret Manager. These mechanisms still require IAM and repository-protection review; source contracts do not establish an organization’s rotation policy, security incident response, or independent secret audit. The signer is a private-key service boundary, not an HSM, hardware wallet, custody platform, or production key-management system.

The application uses the owned Radius testnet network. There is no mainnet, public-production, regulated-payment, custody, or compliance claim. The recorded smoke observed unsigned 402, paid 201, redirect 302, and replay 409 for its bounded exercise. It does not verify every facilitator, RPC, finality, chain reorganization, or payer-funding failure.

Settlement and PostgreSQL persistence are not one distributed transaction. If settlement succeeds and URL persistence fails, reconciliation must use the settlement identity. A failure response cannot automatically imply that no payment occurred. A payment settled; the request failed explains this limit and the actual retry/replay behavior.

Wallet identities, payment headers, signatures, and transaction identifiers are removed from retained public summaries. That improves privacy and narrows independent verification: public readers cannot inspect the private testnet transaction from this repository.

The repository publishes selected earlier sanitized bundles. The detailed final campaign and fresh October 3 bundles are retained privately outside Git. Public report identities and screenshots are inspectable; unpublished raw scorecards are not. A schema-valid metadata record is an index and supplied status, not proof that every indexed artifact is publicly available or the status is true.

Historical October 2 dashboards remain tied to their own candidate and window. Screenshot capture time is separate from execution time. The October 3 screenshot audit confirms accepted image bytes, not a rerun of the gate. A live environment can drift after the recorded snapshot; any later candidate or infrastructure, controller, credential, dependency, or configuration change needs relevant new checks.

Additional fail-closed cases have deterministic source tests. Only the named retained records support live observations. The one-second manual deadline test does not prove default timeout behavior. The unreachable-loopback scorer test does not prove the shared monitoring deployment experienced an outage. Missing target and missing load source tests never reached fault scoring.

Public production would be a new scope with explicit decisions and evidence for highly available data/telemetry, regional isolation, capacity, backup/restore, network policy, key custody, payment reconciliation, SLOs, on-call response, incident handling, cost controls, and independent security review. Existing evidence should inform that work rather than be relabeled as its completion.

The maintained known-limitations document is the canonical boundary. Related source is Terraform topology, publication workflow, prod Stage, and payment implementation. Read how to interpret evidence to keep each conclusion proportional to its support.

Maintained by Satyam Agnihotri · DevOps & Cloud Engineer