Skip to content

Source coverage

This map records the meaningful source responsibilities covered by the website. It joins implementation, tests, canonical reader home, evidence boundary, and editorial review. It covers responsibilities rather than every YAML key. The explicit publication list is site/config/content-map.json; source documentation outside that list remains available as repository references.

The implementation baseline is the public devSatym/resilience-gate repository at 2420ff4c2a88b1fa4a19e413cb0752e271480081, read from the ignored .source/resilience-gate checkout. The standalone private documentation repository owns the reader articles and site engineering files. Source links below use logical paths resolved to their correct repository; the upstream root showcase is linked explicitly to avoid confusing it with this repository’s maintenance README.

Live observations retain their original 1–3 October 2026 identities and windows. “Source reviewed” below means implementation and applicable tests were read for the explanation; it does not claim another live campaign or independent public access to private evidence. Prior monorepo website tests remain under migration-evidence/monorepo-audit/; repository-separation results remain in docs/website/audit/migration/. Cloudflare local results and publication/HTTPS status are separately recorded under docs/website/audit/cloudflare/.

Subsystem / responsibility Canonical reader home Source Test contract / recorded boundary Review and discrepancy
Purpose, topology, reader journeys Overview, tour, paths Upstream root showcase, architecture Verification snapshot Source reviewed; upstream showcase unchanged. Snapshot is historical.
Application route/data behavior Application design, HTTP reference main.py Request tests, redirect tests Source reviewed; HTTP behavior derived from routes, not invented endpoints.
Health/startup and dependency recovery Health, dependency boundaries main.py, deployment probes Health, recovery Source reviewed; Redis required until first successful readiness, PostgreSQL throughout lifetime.
Cache fallback and Redis fault Redis workflow main.py, Redis fault Cache tests, Redis scoring, public card Source reviewed; ordinary cache misses alone do not prove outage.
Persistence failure/recovery PostgreSQL workflow, paid request main.py, PostgreSQL fault Database tests, PostgreSQL scoring Source reviewed; recovery does not establish backup restoration/HA.
x402 verification, settlement, replay Paid request, application design payment.py, payment contract Paid requests, replay, private historical paid smoke Source reviewed; settlement and persistence are not atomic; invalid fields in a facilitator object map to 402 while malformed JSON/non-object bodies map to 503; older prose broadly promises 5xx; public payment identities redacted.
Signer/API/Permit2 bootstrap Signer workflow, secrets main.py, permit2.py, signer deployment API, Permit2, signer scoring Source reviewed; signer loss can prevent useful paid client traffic while app health remains good.
App/signer/gate container contracts Delivery design, source validation App Dockerfile, signer Dockerfile, gate Dockerfile Container tests, CI contracts Source reviewed; runtime identities distinct from app source.
Source CI Source validation validate workflow, validate.sh, pytest.ini CI contracts; historical report counts separate Source reviewed; credential-free may download dependencies; integration check selected separately.
Image publication/OIDC/Cosign Artifact trust, release journey app publication, signer publication, gate publication CI tests, reviewed screenshot 03 Source reviewed; CI verifies after push, no independent Kargo/admission signature enforcement.
Terraform cluster/network/registry Delivery design, lab lifecycle GKE, network, registry, variables Infrastructure tests, October 3 fixed two-node snapshot Source reviewed; shared zonal cluster, no region/fleet/HA claim.
IAM, CI identity, workload identity Secrets and identity GitHub OIDC, IAM, Kargo identity, ESO Infra contracts, bootstrap secrets tests Source reviewed; mechanism does not establish organizational audit/rotation policy.
Phased bootstrap/public rendering Lab lifecycle, configuration bootstrap, renderer, phases 00–06 Bootstrap, render, Terraform phase Source reviewed; phase 06 registers contracts, does not promote/run load/chaos.
Read-only verifier and guarded teardown Lab lifecycle, commands 07-verify, lab-ops Verifier tests, lab operations Source reviewed; destroy-plan can read remote state; no teardown claimed.
Helm environments/dependency resources Configuration, integrated design chart values, dev, staging, prod Rendering, secrets Source reviewed; replica differences do not make stateful stores highly available.
External Secret references/materialization Secrets flow store, signer secret, loadgen secret, chart secret Helm secrets, final 9/9 Ready summary Source reviewed; website never reads Secret values or ignored config.
Argo CD root/ApplicationSet/ownership Controller ownership, delivery root app, AppProject, ApplicationSet Promotion contracts, reviewed fresh GitOps views Source reviewed; reconciles rendered output, distinct from release selection.
Kargo Freight discovery and rendering Release journey, promotion Warehouse, Project, Stages Warehouse, staging, prod Source reviewed; dev automatic, staging/prod manual; manual Freight approval is separate override.
Gate workflow/fault selectors/RBAC Bounded experiments, gate lifecycle workflow, RBAC, fault manifests Selectors, workflow Source reviewed; planned fault must have applied timestamps; selected sequential pod faults only.
Gate preflight, load, locking, cleanup Gate lifecycle, troubleshooting orchestrator Orchestrator, cleanup, retained direct boundary cases Source reviewed; pass requires paid preflight and cleanup; quiet counters insufficient for continuous signer-fault traffic. verify_absent treats any failed get as absence, including possible API/read failures.
Prometheus scoring/no-data rules Measurements, metrics/scoring, score→promotion scorer, scorecard schema Queries, no data, scorecard Source reviewed; or vector(0) intentionally exists for selected expressions; no blanket absence claim.
Dashboards, scraping, Loki/Alloy, annotations Gate/observability design, gallery Observability values, ServiceMonitor, Alloy, annotations Observability, annotation tests Source reviewed; lab sizing, no monitoring HA/retention/DR claim.
Paid staging and unpaid baseline load Load testing, formats loadgen.js, runner, baseline scorer Load contracts, runner, baseline score Source reviewed; older runbook omits baseline path; baseline and chaos have distinct formats.
Local Compose/unpaid smoke Local development Compose, smoke Local recovery, health/cache contracts Source reviewed; maintained smoke redirects before Redis loss, only health checks during loss.
Live request and sanitized evidence tools Promotion, publish request runner, collector, utils, metadata schema Tooling tests Source reviewed; accepted request/schema-valid supplied status is not verdict. chart_revision is rendered output.
Public evidence/history/availability Recorded release, historical cases, interpretation report, evidence index, selected public metadata/log/scorecards Oct 1–2 public subset; Oct 3 private 36-file/two-record bundles Source reviewed; privately retained raw records are unavailable to public readers.
Reviewed screenshot inventory Gallery, recorded release manifest, accepted PNG files, validator 34 reviewed captures, recorded SHA-256 audit at Oct 3 17:26:01Z Source reviewed; screenshot 26 predates fresh run; historical dashboards keep their own windows.
Integrated design and non-claims Integrated design, limitations design contracts, known limitations Source/test and named evidence boundaries above Source reviewed; no underlying application/platform capability added for website.
Static website mapping/build/Git-integrated Pages maintenance Website design, requirements, audit, publication site package, content map, upstream pin, preparation script, Pages local configuration, maintenance Historical monorepo, repository-separation, and Cloudflare records distinguished in audit report Static hosting adds no platform capability; configured/local/remote status and source identities remain separate.

The website adapts existing sources without changing operational behavior. It makes the following distinctions explicit:

  1. Recorded versus current: the final report’s platform and application sources differ. Historical test counts and resource snapshots are attributed to their recorded commits; a later documentation build does not repeat the campaign.
  2. Chart source versus rendered output: Freight’s chart-source commit is distinct from chart_revision in evidence metadata, which means observed rendered branch. Both remain visible in the release case.
  3. Trust versus identity: digest pinning preserves content; CI Cosign verification is not independent Kargo or admission enforcement. The pre-sign push/discovery gap is retained as a limit.
  4. Procedure versus proof: request acceptance, static rendering, a healthy target, operator-supplied pass status, and a screenshot each have narrower meaning than a completed gate plus cleanup.
  5. Public versus private: retained metadata can index unpublished extracts. Selected historical scorecards are public examples; fresh October 3 raw scorecards remain private.
  6. Old runbook versus current command: the source load runner includes an unpaid dev baseline path that the older staging runbook does not cover. The operator page documents both and links the implementation.
  7. Smoke versus recovery test: the local smoke checks a redirect before Redis loss and health during loss. Cache/recovery tests separately exercise fallback; the website does not overstate the smoke.

The publication boundary excludes ignored config.env, wallet material, raw diagnostics, private archive paths, Terraform state/plans, controller-owned rendered branch outputs, live dashboards, and external runtime content fetching. Operational guides describe existing guarded commands; implementation of the static website performs no live lab operations.

Maintained by Satyam Agnihotri · DevOps & Cloud Engineer