diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index ff3d8a1..ef5a6ab 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -7,7 +7,7 @@ on: pull_request: branches: [main, master] schedule: - - cron: '0 6 * * 1' + - cron: '0 6 1 * *' # monthly 1st 06:00 UTC # Estate guardrail: cancel superseded runs so re-pushes / rebased PR # updates do not pile up queued runs against the shared account-wide diff --git a/.machine_readable/6a2/AGENTIC.a2ml b/.machine_readable/descriptiles/AGENTIC.a2ml similarity index 100% rename from .machine_readable/6a2/AGENTIC.a2ml rename to .machine_readable/descriptiles/AGENTIC.a2ml diff --git a/.machine_readable/6a2/ECOSYSTEM.a2ml b/.machine_readable/descriptiles/ECOSYSTEM.a2ml similarity index 100% rename from .machine_readable/6a2/ECOSYSTEM.a2ml rename to .machine_readable/descriptiles/ECOSYSTEM.a2ml diff --git a/.machine_readable/6a2/META.a2ml b/.machine_readable/descriptiles/META.a2ml similarity index 100% rename from .machine_readable/6a2/META.a2ml rename to .machine_readable/descriptiles/META.a2ml diff --git a/.machine_readable/6a2/NEUROSYM.a2ml b/.machine_readable/descriptiles/NEUROSYM.a2ml similarity index 100% rename from .machine_readable/6a2/NEUROSYM.a2ml rename to .machine_readable/descriptiles/NEUROSYM.a2ml diff --git a/.machine_readable/6a2/PLAYBOOK.a2ml b/.machine_readable/descriptiles/PLAYBOOK.a2ml similarity index 100% rename from .machine_readable/6a2/PLAYBOOK.a2ml rename to .machine_readable/descriptiles/PLAYBOOK.a2ml diff --git a/.machine_readable/6a2/STATE.a2ml b/.machine_readable/descriptiles/STATE.a2ml similarity index 100% rename from .machine_readable/6a2/STATE.a2ml rename to .machine_readable/descriptiles/STATE.a2ml diff --git a/TOPOLOGY.adoc b/TOPOLOGY.adoc index d9cbfd0..7c80145 100644 --- a/TOPOLOGY.adoc +++ b/TOPOLOGY.adoc @@ -156,13 +156,13 @@ All machine-readable metadata lives here (never in root). [width="100%",cols="40%,60%",options="header",] |=== |Path |Purpose -|`+.machine_readable/6a2/STATE.a2ml+` |Project state: scaffold phase, 5% +|`+.machine_readable/descriptiles/STATE.a2ml+` |Project state: scaffold phase, 5% complete -|`+.machine_readable/6a2/META.a2ml+` |Architecture decisions: +|`+.machine_readable/descriptiles/META.a2ml+` |Architecture decisions: iser-pattern, ABI-FFI standard, RSR template -|`+.machine_readable/6a2/ECOSYSTEM.a2ml+` |Ecosystem position: -iser +|`+.machine_readable/descriptiles/ECOSYSTEM.a2ml+` |Ecosystem position: -iser family, siblings (typedqliser, chapeliser, verisimiser) |`+.machine_readable/CLADE.a2ml+` |Clade taxonomy classification diff --git a/container/README.adoc b/container/README.adoc index 7a2ef6c..546e6b5 100644 --- a/container/README.adoc +++ b/container/README.adoc @@ -154,8 +154,8 @@ For k9-svc managed deployments: [source,bash] ---- -# Validate the deployment component -nickel typecheck container/deploy.k9.ncl +# Validate the deployment component (strip its required K9! marker first) +nickel typecheck <(tail -n +2 container/deploy.k9.ncl) # Deploy (requires Hunt-level authorisation) k9-svc deploy container/deploy.k9.ncl --env production diff --git a/container/deploy.k9.ncl b/container/deploy.k9.ncl index 0ad0d04..5f950c8 100644 --- a/container/deploy.k9.ncl +++ b/container/deploy.k9.ncl @@ -1,3 +1,4 @@ +K9! # SPDX-License-Identifier: MPL-2.0 # deploy.k9.ncl — {{PROJECT_NAME}} deployment component (Hunt level) # @@ -8,7 +9,7 @@ # It requires explicit authorisation via the Leash system. # # Usage: -# nickel typecheck container/deploy.k9.ncl +# nickel typecheck <(tail -n +2 container/deploy.k9.ncl) # k9-svc validate container/deploy.k9.ncl # k9-svc deploy container/deploy.k9.ncl --env production @@ -143,7 +144,12 @@ echo "K9: Rollback complete." # Export the component { - pedigree = component_pedigree, + pedigree = component_pedigree & { + name = "{{SERVICE_NAME}}-deploy", + version = "{{VERSION}}", + leash = 'Hunt, + signature = "PLACEHOLDER-SIGNATURE-REQUIRED-FOR-HUNT", + }, deployment = deployment, scripts = scripts,