Tags

Tags give the ability to mark specific points in history as being important
  • v1.1.0

    v1.1.0 — secrets management, ADR citation integrity, and a stated segmentation boundary
    
    The freeze point. Supersedes v1.0.0, which froze the platform with its most
    exposed gap open: no secrets management.
    
    SECRETS MANAGEMENT (ADR-028), proven 2026-08-29 on a dev cluster rebuilt from
    empty. AWS Secrets Manager, the External Secrets Operator over IRSA, an
    ExternalSecret template in every chart and in the generator's template, and an
    application that consumes a plain environment variable and knows nothing about
    any of it. The ClusterSecretStore reached Valid, the value arrived in a pod
    with a digest matching one computed off-cluster, rotation propagated
    (0282788e -> b28844aa), and a read one path outside the environment prefix was
    refused. Two live defects fixed: ESO's webhook defaults to the kubelet's port
    10250, fatal on Fargate; and the bootstrap raced its own CA-bundle injection.
    
    ADR CITATION INTEGRITY (ADR-027). Three places cited ADR-027 while no such
    record existed. scripts/adr-check.py now fails the build on any ADR-NNN
    citation without a decision record, negative-tested rather than merely
    observed passing, and the missing record was written.
    
    POD NETWORK SEGMENTATION (ADR-029) — recorded as NOT_SUPPORTED, nothing built.
    NetworkPolicy cannot be enforced on Fargate: AWS applies it to EC2 Linux nodes
    only, and enforcement lives in a DaemonSet Fargate will not run. Manifests
    would have been accepted by the API server and enforced nothing, which is
    worse than a documented absence. The boundary is now stated in the registry
    and on the website instead.
    
    29 ADRs, 7 Terraform modules, 3 services, 31 evidence files.
    Registry: 15 PROVEN / 8 PARTIALLY_PROVEN / 3 NOT_SUPPORTED across 26.
    AWS is fully torn down; nothing is billing.
  • v1.0.0

    v1.0.0 — PlatformBox reference Internal Developer Platform, closed
    
    Freeze point. The evidence behind the 14-day IDP proposition.
    
      26 ADRs · 24 evidence files · 6 Terraform modules · 3 services
      6 environment tiers: local -> preview -> dev -> qa -> uat -> prod
      25 capabilities: 14 PROVEN / 9 PARTIALLY_PROVEN / 2 NOT_SUPPORTED
    
    Proven end-to-end: a service created by the platform's own generator
    reached production, promoted by immutable digest from UAT's approved
    build with no rebuild, reconciled by ArgoCD, and health-checked from
    inside the private production cluster. Two gated approvals, one digest
    identical at every tier, and a real production rollback demonstrated.
    
    Known limits, stated deliberately: no secrets management, no alerting,
    no log aggregation, and the platform has been reproduced twice by the
    same engineer — never independently. See docs/capability-registry.md.