feat(secrev): wire full Plane-1 roster into the checker coordinator registry

Register doc-drift, aws-posture, plan-groomer, confluence-doc (weekly cadence)
alongside compliance-drift + dependency-cve (nightly). The coordinator canary
suite now runs all 6 roles' canaries (all PASS) under the one shared budget +
versioned rotation/coverage state; --squeeze-dry-run still proves defer-not-drop
+ COVERAGE alarm. Central integration after the parallel Phase-3/4 PRs landed.
This commit is contained in:
Adam Moussa 2026-06-18 16:27:12 -04:00
parent 94ed6ea224
commit faa00a7cac

View file

@ -8,7 +8,8 @@
# budget-squeeze dry-run to prove deferral-not-drop + COVERAGE ALARM").
#
# WHAT IT DOES:
# Orchestrates the Plane-1 Tier-1 checkers (compliance-drift, dependency-cve) under ONE shared
# Orchestrates the Plane-1 checkers (compliance-drift, dependency-cve, doc-drift, aws-posture,
# plan-groomer, confluence-doc) under ONE shared
# budget + versioned rotation/coverage state. Nightly it (mirrors nightly_sweep + §5):
# 1) loads the shared budget ledger + the versioned rotation/coverage state (integrity-checked)
# 2) runs the CANARY SUITE FIRST — each role's checker with --canary; a miss is a COMPLACENCY
@ -128,6 +129,10 @@ fi
declare -a ROLES=(
"compliance-drift|$CHECKERS_DIR/compliance-drift.sh|0.00|1"
"dependency-cve|$CHECKERS_DIR/dependency-cve.sh|0.00|1"
"doc-drift|$CHECKERS_DIR/doc-drift.sh|0.00|7"
"aws-posture|$CHECKERS_DIR/aws-posture.sh|0.00|7"
"plan-groomer|$CHECKERS_DIR/plan-groomer.sh|0.00|7"
"confluence-doc|$CHECKERS_DIR/confluence-doc.sh|0.00|7"
)
role_field() { echo "$1" | cut -d'|' -f"$2"; }