Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -66,6 +66,7 @@ The Enterprise Lab Cockpit provides controlled lab evidence, local reproducibili
- Source-name guard allowlist review checklist: [`docs/SOURCE_NAME_GUARD_ALLOWLIST_REVIEW_CHECKLIST.md`](docs/SOURCE_NAME_GUARD_ALLOWLIST_REVIEW_CHECKLIST.md) gives reviewers docs/test-only allowlist candidate review criteria before any allowlist file or implementation without adding source scanning, report generation, JSON/YAML/TOML output files, CI workflow changes, PR comment/report artifact behavior, runtime naming enforcement, source-name guard enforcement, class renames, package moves, ArchUnit, Maven build changes, or enforcement claims.
- Source-name guard allowlist sample plan: [`docs/SOURCE_NAME_GUARD_ALLOWLIST_SAMPLE_PLAN.md`](docs/SOURCE_NAME_GUARD_ALLOWLIST_SAMPLE_PLAN.md) gives reviewers docs/test-only static examples for future allowlist entry shapes before any allowlist file or implementation without adding source scanning, report generation, JSON/YAML/TOML output files, CI workflow changes, PR comment/report artifact behavior, runtime naming enforcement, source-name guard enforcement, class renames, package moves, ArchUnit, Maven build changes, or enforcement claims.
- Source-name guard allowlist lifecycle plan: [`docs/SOURCE_NAME_GUARD_ALLOWLIST_LIFECYCLE_PLAN.md`](docs/SOURCE_NAME_GUARD_ALLOWLIST_LIFECYCLE_PLAN.md) gives reviewers docs/test-only future allowlist lifecycle rules before any allowlist file or implementation without adding source scanning, report generation, JSON/YAML/TOML output files, CI workflow changes, PR comment/report artifact behavior, runtime naming enforcement, source-name guard enforcement, class renames, package moves, ArchUnit, Maven build changes, or enforcement claims.
- Source-name guard allowlist exit criteria plan: [`docs/SOURCE_NAME_GUARD_ALLOWLIST_EXIT_CRITERIA_PLAN.md`](docs/SOURCE_NAME_GUARD_ALLOWLIST_EXIT_CRITERIA_PLAN.md) gives reviewers docs/test-only exit criteria for the allowlist planning lane before any allowlist file or implementation without adding source scanning, report generation, JSON/YAML/TOML output files, CI workflow changes, PR comment/report artifact behavior, runtime naming enforcement, source-name guard enforcement, class renames, package moves, ArchUnit, Maven build changes, or enforcement claims.
- Decision Vector contract: [`docs/ENTERPRISE_LAB_DECISION_VECTOR.md`](docs/ENTERPRISE_LAB_DECISION_VECTOR.md); read-only Dominant Factor Analysis lane: [`docs/ENTERPRISE_LAB_DOMINANT_FACTOR_ANALYSIS.md`](docs/ENTERPRISE_LAB_DOMINANT_FACTOR_ANALYSIS.md); read-only Decision Delta Analysis lane: [`docs/ENTERPRISE_LAB_DECISION_DELTA_ANALYSIS.md`](docs/ENTERPRISE_LAB_DECISION_DELTA_ANALYSIS.md); read-only Decision Replay Snapshot lane: [`docs/ENTERPRISE_LAB_DECISION_REPLAY_SNAPSHOT.md`](docs/ENTERPRISE_LAB_DECISION_REPLAY_SNAPSHOT.md); read-only Decision Replay Reconstruction Trace lane: [`docs/ENTERPRISE_LAB_DECISION_REPLAY_RECONSTRUCTION_TRACE.md`](docs/ENTERPRISE_LAB_DECISION_REPLAY_RECONSTRUCTION_TRACE.md); read-only Decision Replay Capsule lane: [`docs/ENTERPRISE_LAB_DECISION_REPLAY_CAPSULE.md`](docs/ENTERPRISE_LAB_DECISION_REPLAY_CAPSULE.md); read-only Decision Replay Readiness Checklist lane: [`docs/ENTERPRISE_LAB_DECISION_REPLAY_READINESS_CHECKLIST.md`](docs/ENTERPRISE_LAB_DECISION_REPLAY_READINESS_CHECKLIST.md); read-only Decision Replay Evidence Source Map lane: [`docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_SOURCE_MAP.md`](docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_SOURCE_MAP.md); read-only Decision Replay Evidence Boundary Summary lane: [`docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_BOUNDARY_SUMMARY.md`](docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_BOUNDARY_SUMMARY.md); read-only Decision Replay Evidence Field Inventory lane: [`docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_FIELD_INVENTORY.md`](docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_FIELD_INVENTORY.md); read-only Decision Evidence Null-Safety Summary lane: [`docs/ENTERPRISE_LAB_DECISION_EVIDENCE_NULL_SAFETY_SUMMARY.md`](docs/ENTERPRISE_LAB_DECISION_EVIDENCE_NULL_SAFETY_SUMMARY.md); read-only Decision Evidence Status Rollup lane: [`docs/ENTERPRISE_LAB_DECISION_EVIDENCE_STATUS_ROLLUP.md`](docs/ENTERPRISE_LAB_DECISION_EVIDENCE_STATUS_ROLLUP.md); read-only Decision Replay Evidence Lane Navigation Summary lane: [`docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_LANE_NAVIGATION_SUMMARY.md`](docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_LANE_NAVIGATION_SUMMARY.md); read-only Decision Replay Evidence Lane Dependency Map lane: [`docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_LANE_DEPENDENCY_MAP.md`](docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_LANE_DEPENDENCY_MAP.md); read-only Decision Replay Evidence Lane Reference Index lane: [`docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_LANE_REFERENCE_INDEX.md`](docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_LANE_REFERENCE_INDEX.md); read-only Decision Replay Evidence Lane Dependency Summary lane: [`docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_LANE_DEPENDENCY_SUMMARY.md`](docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_LANE_DEPENDENCY_SUMMARY.md); read-only Decision Replay Evidence Lane Consistency Summary lane: [`docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_LANE_CONSISTENCY_SUMMARY.md`](docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_LANE_CONSISTENCY_SUMMARY.md); read-only Decision Replay Evidence Reviewer Snapshot lane: [`docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_REVIEWER_SNAPSHOT.md`](docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_REVIEWER_SNAPSHOT.md); read-only Decision Replay Evidence Reviewer Guidance lane: [`docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_REVIEWER_GUIDANCE.md`](docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_REVIEWER_GUIDANCE.md); read-only Decision Replay Evidence Reviewer Handoff Summary lane: [`docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_REVIEWER_HANDOFF_SUMMARY.md`](docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_REVIEWER_HANDOFF_SUMMARY.md); read-only Decision Replay Evidence Reviewer Closure Summary lane: [`docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_REVIEWER_CLOSURE_SUMMARY.md`](docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_REVIEWER_CLOSURE_SUMMARY.md); read-only Decision Replay Evidence Closure Rollup lane: [`docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_CLOSURE_ROLLUP.md`](docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_CLOSURE_ROLLUP.md); read-only Decision Replay Evidence Closure Checklist lane: [`docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_CLOSURE_CHECKLIST.md`](docs/ENTERPRISE_LAB_DECISION_REPLAY_EVIDENCE_CLOSURE_CHECKLIST.md).

LoadBalancerPro is becoming **LoadBalancerPro Enterprise Lab**: a Java 17 / Spring Boot lab for adaptive-routing scenarios, deterministic replay, LASE shadow/influence comparison, policy gates, scorecards, evidence export, SRE walkthroughs, and a carefully bounded Production Gateway Candidate track.
Expand Down
1 change: 1 addition & 0 deletions docs/ENTERPRISE_READINESS_AUDIT.md
Original file line number Diff line number Diff line change
Expand Up @@ -98,6 +98,7 @@ The transition is mostly complete at the current reviewer-entry level:
- `docs/SOURCE_NAME_GUARD_ALLOWLIST_REVIEW_CHECKLIST.md` records a docs/test-only allowlist review checklist for evaluating future source-name guard allowlist candidates without adding allowlist files, source scanning, dry-run report generation, JSON/YAML/TOML output files, CI workflow changes, PR comment/report artifact behavior, source-name guard enforcement, runtime naming enforcement, ArchUnit or package-boundary tooling, Maven build changes, routing/scoring/strategy/proxy behavior changes, or claiming production readiness.
- `docs/SOURCE_NAME_GUARD_ALLOWLIST_SAMPLE_PLAN.md` records a docs/test-only allowlist sample plan with static examples for future source-name guard allowlist entries without adding allowlist files, source scanning, dry-run report generation, JSON/YAML/TOML output files, CI workflow changes, PR comment/report artifact behavior, source-name guard enforcement, runtime naming enforcement, ArchUnit or package-boundary tooling, Maven build changes, routing/scoring/strategy/proxy behavior changes, or claiming production readiness.
- `docs/SOURCE_NAME_GUARD_ALLOWLIST_LIFECYCLE_PLAN.md` records a docs/test-only allowlist lifecycle plan for future source-name guard allowlist entries without adding allowlist files, source scanning, dry-run report generation, JSON/YAML/TOML output files, CI workflow changes, PR comment/report artifact behavior, source-name guard enforcement, runtime naming enforcement, ArchUnit or package-boundary tooling, Maven build changes, routing/scoring/strategy/proxy behavior changes, or claiming production readiness.
- `docs/SOURCE_NAME_GUARD_ALLOWLIST_EXIT_CRITERIA_PLAN.md` records a docs/test-only allowlist exit criteria plan for deciding when the source-name guard allowlist planning lane is complete enough to consider a separately approved implementation sprint later without adding allowlist files, source scanning, dry-run report generation, JSON/YAML/TOML output files, CI workflow changes, PR comment/report artifact behavior, source-name guard enforcement, runtime naming enforcement, ArchUnit or package-boundary tooling, Maven build changes, routing/scoring/strategy/proxy behavior changes, or claiming production readiness.
- `docs/PRODUCTION_READINESS_SUMMARY.md` says production-candidate rather than production-certified.
- `docs/REVIEWER_TRUST_MAP.md` gives reviewer paths for lab workflow, controlled policy evidence, observability, the combined measured performance plus auth proof lane, CI evidence gate readiness/prototype, performance, mocked auth proof, and release evidence.
- Static documentation tests guard against production-ready gateway and certification overclaims.
Expand Down
2 changes: 2 additions & 0 deletions docs/REVIEWER_TRUST_MAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -53,6 +53,7 @@ Recommended first paths:
- I want to review future source-name guard allowlist candidates before implementation: start with [`SOURCE_NAME_GUARD_ALLOWLIST_REVIEW_CHECKLIST.md`](SOURCE_NAME_GUARD_ALLOWLIST_REVIEW_CHECKLIST.md). It is a docs/test-only allowlist review checklist, not an allowlist file, source scanning, rule implementation, report generation, JSON/YAML/TOML output, CI workflow change, PR comment/report artifact behavior, source-name guard enforcement, runtime naming enforcement, package-boundary enforcement, or production-readiness proof.
- I want to see static examples of future source-name guard allowlist entries before implementation: start with [`SOURCE_NAME_GUARD_ALLOWLIST_SAMPLE_PLAN.md`](SOURCE_NAME_GUARD_ALLOWLIST_SAMPLE_PLAN.md). It is a docs/test-only allowlist sample plan, not an allowlist file, source scanning, rule implementation, report generation, JSON/YAML/TOML output, CI workflow change, PR comment/report artifact behavior, source-name guard enforcement, runtime naming enforcement, package-boundary enforcement, or production-readiness proof.
- I want to understand future source-name guard allowlist entry lifecycle rules before implementation: start with [`SOURCE_NAME_GUARD_ALLOWLIST_LIFECYCLE_PLAN.md`](SOURCE_NAME_GUARD_ALLOWLIST_LIFECYCLE_PLAN.md). It is a docs/test-only allowlist lifecycle plan, not an allowlist file, source scanning, rule implementation, report generation, JSON/YAML/TOML output, CI workflow change, PR comment/report artifact behavior, source-name guard enforcement, runtime naming enforcement, package-boundary enforcement, or production-readiness proof.
- I want to know when the source-name guard allowlist planning lane is complete enough to consider implementation later: start with [`SOURCE_NAME_GUARD_ALLOWLIST_EXIT_CRITERIA_PLAN.md`](SOURCE_NAME_GUARD_ALLOWLIST_EXIT_CRITERIA_PLAN.md). It is a docs/test-only allowlist exit criteria plan, not an allowlist file, source scanning, rule implementation, report generation, JSON/YAML/TOML output, CI workflow change, PR comment/report artifact behavior, source-name guard enforcement, runtime naming enforcement, package-boundary enforcement, or production-readiness proof.
- I want the current enterprise-readiness verdict: start with [`ENTERPRISE_READINESS_AUDIT.md`](ENTERPRISE_READINESS_AUDIT.md), then use [`PRODUCTION_READINESS_SUMMARY.md`](PRODUCTION_READINESS_SUMMARY.md) for the production-candidate snapshot.
- I want the reviewer-ready trust-hardening sprint packet: start with [`ENTERPRISE_LAB_TRUST_HARDENING_SPRINT.md`](ENTERPRISE_LAB_TRUST_HARDENING_SPRINT.md).
- I want to review repo-side governance ownership and manual settings recommendations: start with [`MANUAL_GITHUB_GOVERNANCE_HARDENING.md`](MANUAL_GITHUB_GOVERNANCE_HARDENING.md).
Expand Down Expand Up @@ -403,6 +404,7 @@ Safety boundaries preserved by this path:
| How should reviewers evaluate future source-name guard allowlist candidates before implementation? | Source-Name Guard Allowlist Review Checklist | [`SOURCE_NAME_GUARD_ALLOWLIST_REVIEW_CHECKLIST.md`](SOURCE_NAME_GUARD_ALLOWLIST_REVIEW_CHECKLIST.md), `SourceNameGuardAllowlistReviewChecklistDocumentationTest` | Docs/test-only allowlist review checklist for candidate review, rationale review, scope/path review, rule-category review, re-review triggers, suppression review, privacy/secret-safety, misuse risks, and approval gates before allowlist implementation | Reviewers can decide whether a future allowlist candidate is narrow, specific, auditable, rationale-backed, privacy-safe, and explicitly non-proving before any allowlist file, source scanning, report generation, JSON/YAML/TOML output, CI workflow changes, PR comment/report artifact behavior, or enforcement exists | Source-name guard allowlist implementation, allowlist files, source-name guard rule implementation, source scanning, dry-run report generation, JSON/YAML/TOML output files, CI workflow changes, PR comment/report artifact behavior, runtime naming enforcement, source-name guard enforcement, package-boundary enforcement, ArchUnit tooling, class renames, package moves, routing/scoring/strategy/proxy behavior changes, production readiness, production certification, live-cloud validation, or real-tenant validation |
| How could reviewers read examples of future source-name guard allowlist entries before implementation? | Source-Name Guard Allowlist Sample Plan | [`SOURCE_NAME_GUARD_ALLOWLIST_SAMPLE_PLAN.md`](SOURCE_NAME_GUARD_ALLOWLIST_SAMPLE_PLAN.md), `SourceNameGuardAllowlistSamplePlanDocumentationTest` | Docs/test-only allowlist sample plan with static examples for narrow entries, documentation-clarification-preferred outcomes, rename-preferred outcomes, suppression-review-required outcomes, stale re-review, invalid entries, privacy constraints, and misuse cautions before allowlist files or scanning exist | Reviewers can rehearse evaluating allowlist entry shapes before any allowlist file, source scanning, report generation, JSON/YAML/TOML output, CI workflow changes, PR artifact behavior, or enforcement exists | Source-name guard allowlist implementation, allowlist files, source-name guard implementation/rule implementation, source scanning, dry-run report generation, JSON/YAML/TOML output files, CI workflow changes, PR comment/report artifact behavior, runtime naming enforcement, source-name guard enforcement, package-boundary enforcement, ArchUnit tooling, class renames, package moves, routing/scoring/strategy/proxy behavior changes, production readiness, production certification, live-cloud validation, or real-tenant validation |
| How should future source-name guard allowlist entries be created, re-reviewed, expired, retired, migrated, and audited before implementation? | Source-Name Guard Allowlist Lifecycle Plan | [`SOURCE_NAME_GUARD_ALLOWLIST_LIFECYCLE_PLAN.md`](SOURCE_NAME_GUARD_ALLOWLIST_LIFECYCLE_PLAN.md), `SourceNameGuardAllowlistLifecyclePlanDocumentationTest` | Docs/test-only allowlist lifecycle plan for future states, creation, re-review, expiration, retirement, migration, audit, stale-entry risk handling, privacy/secret-safety, and implementation gates before allowlist files or scanning exist | Reviewers can reason about entry lifecycle and stale-risk handling before any allowlist file, source scanning, report generation, JSON/YAML/TOML output, CI workflow changes, PR artifact behavior, or enforcement exists | Source-name guard allowlist implementation, allowlist files, source-name guard implementation/rule implementation, source scanning, dry-run report generation, JSON/YAML/TOML output files, CI workflow changes, PR comment/report artifact behavior, runtime naming enforcement, source-name guard enforcement, package-boundary enforcement, ArchUnit tooling, class renames, package moves, routing/scoring/strategy/proxy behavior changes, production readiness, production certification, live-cloud validation, or real-tenant validation |
| When is the source-name guard allowlist planning lane complete enough to consider a separately approved implementation sprint later? | Source-Name Guard Allowlist Exit Criteria Plan | [`SOURCE_NAME_GUARD_ALLOWLIST_EXIT_CRITERIA_PLAN.md`](SOURCE_NAME_GUARD_ALLOWLIST_EXIT_CRITERIA_PLAN.md), `SourceNameGuardAllowlistExitCriteriaPlanDocumentationTest` | Docs/test-only allowlist exit criteria plan for documentation completeness, review readiness, privacy/secret-safety, determinism, allowlist quality, misuse-risk criteria, implementation-readiness gates, and non-exit conditions before allowlist files or scanning exist | Reviewers can decide whether the allowlist planning lane has enough non-proving, privacy-safe, deterministic, reviewable criteria to consider a separately approved implementation sprint later | Source-name guard allowlist implementation, allowlist files, source-name guard implementation/rule implementation, source scanning, dry-run report generation, JSON/YAML/TOML output files, CI workflow changes, PR comment/report artifact behavior, runtime naming enforcement, source-name guard enforcement, package-boundary enforcement, ArchUnit tooling, class renames, package moves, routing/scoring/strategy/proxy behavior changes, production readiness, production certification, live-cloud validation, or real-tenant validation |
| Is `v2.5.0` published and verified? | Post-release verification note | [`V2_5_0_POST_RELEASE_VERIFICATION.md`](V2_5_0_POST_RELEASE_VERIFICATION.md), [`RELEASE_NOTES_v2.5.0.md`](RELEASE_NOTES_v2.5.0.md) | Exact tag `v2.5.0`, exact release commit recorded in the note, release workflow success, exact asset set, checksum verification, SBOM JSON/XML presence, and artifact attestation verification | Reviewers can confirm the JAR/docs-first GitHub Release exists and its evidence chain passed | Production deployment certification, real IdP tenant proof, production TLS/IAM/ingress/monitoring, container publication, or container signing |
| Should distribution stay JAR/docs-first or become container-based? | Two-track release decision summary | [`RELEASE_READINESS_DECISION_SUMMARY.md`](RELEASE_READINESS_DECISION_SUMMARY.md), [`V2_5_0_POST_RELEASE_VERIFICATION.md`](V2_5_0_POST_RELEASE_VERIFICATION.md), [`RELEASE_NOTES_v2.5.0.md`](RELEASE_NOTES_v2.5.0.md), [`CONTAINER_REGISTRY_SIGNING_ROLLOUT.md`](CONTAINER_REGISTRY_SIGNING_ROLLOUT.md) | Verified `v2.5.0` JAR/docs-first release evidence, container rollout cost/gates, release notes, and remaining non-certification limits | Reviewers can use the released JAR/docs bundle now or defer container distribution until registry/signing gates are implemented | Container publication or production certification |
| Can a release candidate be rehearsed without publishing? | Dry-run packet and checklist | [`RELEASE_CANDIDATE_DRY_RUN_PACKET.md`](RELEASE_CANDIDATE_DRY_RUN_PACKET.md), [`RELEASE_INTENT_REVIEW.md`](RELEASE_INTENT_REVIEW.md), [`V2_5_0_RELEASE_AUTHORIZATION_CHECKLIST.md`](V2_5_0_RELEASE_AUTHORIZATION_CHECKLIST.md), [`RELEASE_CANDIDATE_DRY_RUN.md`](RELEASE_CANDIDATE_DRY_RUN.md) | Current-main packet script, release-intent review packet, exact-version authorization checklist, reviewer packet template, go/no-go table | CI artifacts, local verification, SBOM, checksums, security gates, jar smoke, status UI, demos, and the recommended `v2.5.0` JAR/docs-first human decision map into ignored review evidence | Any tag, GitHub Release, asset upload, registry image, or container signature |
Expand Down
Loading
Loading