feat(secrev): wire full Plane-1 roster into checker coordinator + fix fixture SAM (#22)
* feat(secrev): wire full Plane-1 roster into the checker coordinator registry Register doc-drift, aws-posture, plan-groomer, confluence-doc (weekly cadence) alongside compliance-drift + dependency-cve (nightly). The coordinator canary suite now runs all 6 roles' canaries (all PASS) under the one shared budget + versioned rotation/coverage state; --squeeze-dry-run still proves defer-not-drop + COVERAGE alarm. Central integration after the parallel Phase-3/4 PRs landed. * fix(secrev): valid SAM in doc-drift fixture templates (cfn-lint E0001) The doc-drift sample-stack fixtures declared AWS::Serverless::Function with no Properties; cfn-lint's SAM transform errored (HIGH). Added minimal valid Properties (Handler/Runtime/InlineCode). Pre-existing on main — #19 pushed with --no-verify (xargs overflow) and CI runs no cfn-lint, so it slipped through. doc-drift still detects the stack (keys on template presence).
This commit is contained in:
parent
94ed6ea224
commit
95e481890a
3 changed files with 18 additions and 1 deletions
|
|
@ -8,7 +8,8 @@
|
||||||
# budget-squeeze dry-run to prove deferral-not-drop + COVERAGE ALARM").
|
# budget-squeeze dry-run to prove deferral-not-drop + COVERAGE ALARM").
|
||||||
#
|
#
|
||||||
# WHAT IT DOES:
|
# WHAT IT DOES:
|
||||||
# Orchestrates the Plane-1 Tier-1 checkers (compliance-drift, dependency-cve) under ONE shared
|
# Orchestrates the Plane-1 checkers (compliance-drift, dependency-cve, doc-drift, aws-posture,
|
||||||
|
# plan-groomer, confluence-doc) under ONE shared
|
||||||
# budget + versioned rotation/coverage state. Nightly it (mirrors nightly_sweep + §5):
|
# budget + versioned rotation/coverage state. Nightly it (mirrors nightly_sweep + §5):
|
||||||
# 1) loads the shared budget ledger + the versioned rotation/coverage state (integrity-checked)
|
# 1) loads the shared budget ledger + the versioned rotation/coverage state (integrity-checked)
|
||||||
# 2) runs the CANARY SUITE FIRST — each role's checker with --canary; a miss is a COMPLACENCY
|
# 2) runs the CANARY SUITE FIRST — each role's checker with --canary; a miss is a COMPLACENCY
|
||||||
|
|
@ -128,6 +129,10 @@ fi
|
||||||
declare -a ROLES=(
|
declare -a ROLES=(
|
||||||
"compliance-drift|$CHECKERS_DIR/compliance-drift.sh|0.00|1"
|
"compliance-drift|$CHECKERS_DIR/compliance-drift.sh|0.00|1"
|
||||||
"dependency-cve|$CHECKERS_DIR/dependency-cve.sh|0.00|1"
|
"dependency-cve|$CHECKERS_DIR/dependency-cve.sh|0.00|1"
|
||||||
|
"doc-drift|$CHECKERS_DIR/doc-drift.sh|0.00|7"
|
||||||
|
"aws-posture|$CHECKERS_DIR/aws-posture.sh|0.00|7"
|
||||||
|
"plan-groomer|$CHECKERS_DIR/plan-groomer.sh|0.00|7"
|
||||||
|
"confluence-doc|$CHECKERS_DIR/confluence-doc.sh|0.00|7"
|
||||||
)
|
)
|
||||||
role_field() { echo "$1" | cut -d'|' -f"$2"; }
|
role_field() { echo "$1" | cut -d'|' -f"$2"; }
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -3,3 +3,9 @@ Transform: AWS::Serverless-2016-10-31
|
||||||
Resources:
|
Resources:
|
||||||
IngestFn:
|
IngestFn:
|
||||||
Type: AWS::Serverless::Function
|
Type: AWS::Serverless::Function
|
||||||
|
Properties:
|
||||||
|
Handler: app.handler
|
||||||
|
Runtime: python3.12
|
||||||
|
InlineCode: |
|
||||||
|
def handler(event, context):
|
||||||
|
return {"statusCode": 200}
|
||||||
|
|
|
||||||
|
|
@ -3,3 +3,9 @@ Transform: AWS::Serverless-2016-10-31
|
||||||
Resources:
|
Resources:
|
||||||
ChargeFn:
|
ChargeFn:
|
||||||
Type: AWS::Serverless::Function
|
Type: AWS::Serverless::Function
|
||||||
|
Properties:
|
||||||
|
Handler: app.handler
|
||||||
|
Runtime: python3.12
|
||||||
|
InlineCode: |
|
||||||
|
def handler(event, context):
|
||||||
|
return {"statusCode": 200}
|
||||||
|
|
|
||||||
Reference in a new issue