Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
58 changes: 39 additions & 19 deletions PUBLIC-SOURCE-MANIFEST.json
Original file line number Diff line number Diff line change
Expand Up @@ -85,8 +85,8 @@
},
{
"path": "README.md",
"sha256": "sha256:99add28dff3199581edf264a67dcec85f6d6916cc495f27f7f6391f71b72d19d",
"size": 11544
"sha256": "sha256:229bd9e6238f53f0a49d58b02799e22875ada9becbc739e02cebe434b1a0a9bc",
"size": 11888
},
{
"path": "SECURITY.md",
Expand All @@ -100,8 +100,8 @@
},
{
"path": "catalog.json",
"sha256": "sha256:03aca7c9ded4d6506cf601623708ddd0226c0dad71a81728dd101f9dd9d8c142",
"size": 5544
"sha256": "sha256:b784828c0ae754be4bac9b7fb77fc520260491b61baaa2197b6f565384a4a987",
"size": 5893
},
{
"path": "cicd-operations/SKILL.md",
Expand Down Expand Up @@ -300,13 +300,13 @@
},
{
"path": "devops-core/references/capability-routing.md",
"sha256": "sha256:57496ffb3caf7bd313d474d49958164ad7c990c53bbd42f1417b22701da1bab6",
"size": 3427
"sha256": "sha256:f20149496123aee2bceb8dd6cf9c5372fb16336551650151417ce4d91f5b7c99",
"size": 3646
},
{
"path": "devops-core/references/control-plane-ownership.md",
"sha256": "sha256:73e19759752bd956245f023187f046801604c37d27d01597dae7fa8b1de5097b",
"size": 4029
"sha256": "sha256:61dd41229c5ffa4fb862dc5828a614da5eebe875f1e0babc76c889f37d443770",
"size": 4567
},
{
"path": "devops-core/references/enterprise-change-control.md",
Expand Down Expand Up @@ -375,8 +375,8 @@
},
{
"path": "devops-platform-contracts/catalog.json",
"sha256": "sha256:03aca7c9ded4d6506cf601623708ddd0226c0dad71a81728dd101f9dd9d8c142",
"size": 5544
"sha256": "sha256:b784828c0ae754be4bac9b7fb77fc520260491b61baaa2197b6f565384a4a987",
"size": 5893
},
{
"path": "devops-platform-contracts/module.yaml",
Expand Down Expand Up @@ -495,8 +495,8 @@
},
{
"path": "docs/architecture.md",
"sha256": "sha256:a8276a5646d525bb9e755463afdb94b033a850935b5578a04c4a3a0851389c1d",
"size": 7052
"sha256": "sha256:af1278513332df438ef232fe7dcbf803571b65664c3baee12422d36741a90e4e",
"size": 7259
},
{
"path": "docs/control-crosswalk.md",
Expand Down Expand Up @@ -623,6 +623,26 @@
"sha256": "sha256:775f455aae289a66f5c5d9c188e50e75c8d6f38c4504fa9d28e74ccd2982d0c9",
"size": 2807
},
{
"path": "identity-directory-operations/SKILL.md",
"sha256": "sha256:84dfee834ae5640bf5b53e1fac5d19e2438f0c221672b04223b8c2c48f08104c",
"size": 5829
},
{
"path": "identity-directory-operations/agents/openai.yaml",
"sha256": "sha256:b506fefe393f8d36db61701508cd3d2c2f5c78cb09a788a91d6dc23319c0f6fc",
"size": 223
},
{
"path": "identity-directory-operations/module.yaml",
"sha256": "sha256:197fe7f77f7637367aa4a17c5fb4018716813df6aa0b280b2f4cd4dd990b4a99",
"size": 3802
},
{
"path": "identity-directory-operations/references/ad-gpo-safety.md",
"sha256": "sha256:16f26fbd118b5547dbb2ae91d7d241642cbec1a8d98776e8d470e1f2804711e9",
"size": 2379
},
{
"path": "kubernetes-operations/SKILL.md",
"sha256": "sha256:3fbde07eb4d5366046f2e63bb9372d78b8ac8f9c60a123ef008d018c5d6f9c24",
Expand Down Expand Up @@ -815,8 +835,8 @@
},
{
"path": "tests/test_platform.py",
"sha256": "sha256:7e673ca0d2eb24d5b5216e951bfaecc81a9c0c2ce4339051a423f018d96c4c79",
"size": 31534
"sha256": "sha256:07235c6b4e88c48d74ff73e15666e2857cf2a8d6e4776dff14738a1bb54ccad7",
"size": 32639
},
{
"path": "tools/build_public_source.py",
Expand All @@ -840,8 +860,8 @@
},
{
"path": "windows-server-operations/SKILL.md",
"sha256": "sha256:08faee474c32c7f67940401857f277b68f893d3833a35bae087da47b2e2fbb2c",
"size": 3192
"sha256": "sha256:40a34b9a74397b699f357877cd1ccf978b916b91c73b76e8d815b03eaf871fc2",
"size": 3264
},
{
"path": "windows-server-operations/agents/openai.yaml",
Expand All @@ -850,13 +870,13 @@
},
{
"path": "windows-server-operations/module.yaml",
"sha256": "sha256:c2ab85f3f5384d7c8d94bbbe9a9edd789cf9346a55fb7a748328171d809bfb70",
"sha256": "sha256:bd12c8f497a05352e12a6bc3aee496763b058378fa15e300b69993f7bd418a8d",
"size": 601
},
{
"path": "windows-server-operations/references/module-handoffs.md",
"sha256": "sha256:e9c88c711c6489cf4b90120f1920c939e41d5614b28b0fc4ebdfdf57329f6874",
"size": 505
"sha256": "sha256:e92d615c1b89bfbe22a9097be284531b798f362325454385fec5b89dc144aa88",
"size": 566
},
{
"path": "windows-server-operations/references/services-events-recovery.md",
Expand Down
8 changes: 5 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

**Portfolio project · release candidate 0.3.0**

A modular, Codex-first platform for bounded, evidence-driven infrastructure work. It contains 20 composable skills under contract v2: a coordinator, a fail-closed policy and validation layer, and focused modules for hosts, containers, edge, delivery, data, cloud providers, Kubernetes, networking, access, reliability, and security governance.
A modular, Codex-first platform for bounded, evidence-driven infrastructure work. It contains 21 composable skills under contract v2: a coordinator, a fail-closed policy and validation layer, and focused modules for hosts, directory identity, containers, edge, delivery, data, cloud providers, Kubernetes, networking, access, reliability, and security governance.

This project demonstrates system administration and DevOps engineering practices: decomposing operational ownership, classifying risk, planning recovery, constraining privileged changes, validating packages, and collecting verification evidence. It is not a certification, a managed service, or an autonomous administrator.

Expand Down Expand Up @@ -60,6 +60,7 @@ flowchart LR
|---|---|---|
| Control plane | `devops-platform-contracts`, `devops-core` | Policy, schemas, compatibility, operation gate, routing, evidence |
| Hosts and workloads | `linux-operations`, `windows-server-operations`, `docker-operations`, `kubernetes-operations` | OS and workload lifecycle; Kubernetes is selected only when justified |
| Directory identity | `identity-directory-operations` | AD DS, OUs, principals, group governance, GPO planning and staged rollout; not Entra, secrets, or local host administration |
| Delivery and state | `iac-operations`, `cicd-operations`, `data-resilience-operations` | Reviewed plans, protected pipelines, restore-proven data operations |
| Edge and networks | `network-edge-operations`, `cloudflare-operations`, `enterprise-networking` | DNS/TLS/HTTP, Cloudflare control plane, VPN/BGP/hybrid routing |
| Cloud | `cloud-generic`, `cloud-aws`, `cloud-gcp`, `cloud-azure`, `cloud-selectel` | Provider discovery and bounded control-plane operations using current official docs |
Expand All @@ -76,14 +77,15 @@ Managed-service boundaries are normative in the [control-plane ownership matrix]
| `core` | Planning, policy, validation, and safe handoff |
| `web-linux` | Linux + Docker + HTTP edge + Cloudflare + reliability |
| `hybrid-server` | Linux/Windows hosts + Docker + HTTP edge + reliability |
| `identity-directory` | Active Directory and GPO work with Windows-host, privileged-access, and reliability handoffs |
| `delivery` | IaC, CI/CD, and secret/access boundaries |
| `data-safe` | Backup, restore, migration, reliability, and access controls |
| `cloud-foundation` | Provider-neutral cloud foundation with IaC, edge, reliability, and access |
| `kubernetes` | Kubernetes workload operations with Docker, edge, reliability, and access |
| `aws-platform`, `gcp-platform`, `azure-platform`, `selectel-platform` | Named provider plus IaC, CI/CD, containers, Kubernetes, data, network, access, and reliability handoffs |
| `hybrid-network` | Linux/Windows endpoints plus HTTP edge, VPN/BGP/hybrid networking, access, and reliability |
| `assurance` | Evidence-led security governance with access and reliability evidence sources |
| `all` | All 20 modules, including named provider and enterprise packs |
| `all` | All 21 modules, including directory identity, named provider, and enterprise packs |

Profiles are dependency-closed and validated against the embedded release catalog. `all` is intentionally broad; `devops-core` still loads the smallest capability set for each operation.

Expand All @@ -102,7 +104,7 @@ python devops-platform-contracts/scripts/validate_platform.py
python tools/install.py --profile web-linux
```

A successful validation reports `20/20 compatible installed skills`. The installer then prints each proposed destination and ends with `Dry-run only`. Review the [architecture](docs/architecture.md) next, or run the [shipped synthetic portfolio demo](examples/portfolio-demo/README.md) without connecting to a real target.
A successful validation reports `21/21 compatible installed skills`. The installer then prints each proposed destination and ends with `Dry-run only`. Review the [architecture](docs/architecture.md) next, or run the [shipped synthetic portfolio demo](examples/portfolio-demo/README.md) without connecting to a real target.

`tools/install.py` is dry-run by default. `--apply` writes to the selected skills directory, and `--apply --force` can replace existing skills; neither option is part of this safe evaluation.

Expand Down
12 changes: 11 additions & 1 deletion catalog.json
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,8 @@
"devops-platform-contracts": {"version": "0.3.0", "role": "policy-and-validation"},
"devops-core": {"version": "0.3.0", "role": "coordinator"},
"linux-operations": {"version": "0.2.0", "role": "executor"},
"windows-server-operations": {"version": "0.2.0", "role": "executor"},
"windows-server-operations": {"version": "0.3.0", "role": "executor"},
"identity-directory-operations": {"version": "0.3.0", "role": "executor"},
"docker-operations": {"version": "0.2.0", "role": "executor"},
"network-edge-operations": {"version": "0.2.0", "role": "executor"},
"reliability-operations": {"version": "0.2.0", "role": "executor"},
Expand Down Expand Up @@ -47,6 +48,14 @@
"network-edge-operations",
"reliability-operations"
],
"identity-directory": [
"devops-platform-contracts",
"devops-core",
"windows-server-operations",
"identity-directory-operations",
"secrets-access-operations",
"reliability-operations"
],
"delivery": [
"devops-platform-contracts",
"devops-core",
Expand Down Expand Up @@ -161,6 +170,7 @@
"devops-core",
"linux-operations",
"windows-server-operations",
"identity-directory-operations",
"docker-operations",
"network-edge-operations",
"reliability-operations",
Expand Down
1 change: 1 addition & 0 deletions devops-core/references/capability-routing.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@ Select the smallest installed set that covers the confirmed task. Read a module
|---|---|
| Linux hosts, SSH, systemd, ports, disks, logs | `linux-operations` |
| Windows Server, WinRM/RDP, Windows services, Event Logs, Windows Firewall | `windows-server-operations` |
| Active Directory DS, OUs, users, computers, groups, delegated administration, GPOs and policy links | `identity-directory-operations`; add Windows, access, reliability or Azure modules only for their owned boundary |
| Docker, Compose, images, registries, volumes | `docker-operations` |
| DNS, TLS, HTTP, reverse proxy, origin reachability | `network-edge-operations` |
| Cloudflare DNS, WAF, Tunnel, Access, Workers | `cloudflare-operations` |
Expand Down
2 changes: 2 additions & 0 deletions devops-core/references/control-plane-ownership.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,8 @@ Select modules by the state and API being changed. A tool, repository, or creden
| Schema/data migration, PITR, logical failover, backup, restore or retention | `data-resilience-operations` | Provider pack executes only the separately planned provider-native infrastructure/API fragment; `iac-operations` joins when state-managed |
| Image build/runtime and registry artifact | `docker-operations` | `cicd-operations` owns producer trust, immutable promotion and attestation; provider pack owns provider registry/IAM envelope |
| Release pipeline and protected deployment | `cicd-operations` | Every target executor verifies its own plan fragment and final state; `reliability-operations` owns user-path acceptance and observation window |
| Active Directory DS OUs, users, computers, groups, membership, delegation and GPO objects/links | `identity-directory-operations` | `secrets-access-operations` owns privileged-session, JIT/revocation and break-glass controls; `windows-server-operations` owns host membership and client-side policy result |
| GPO-driven production configuration or security baseline | `identity-directory-operations` | Owning host/workload executor validates safe application; `reliability-operations` verifies the service path and observation window |

## Combined-operation rules

Expand Down
12 changes: 11 additions & 1 deletion devops-platform-contracts/catalog.json
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,8 @@
"devops-platform-contracts": {"version": "0.3.0", "role": "policy-and-validation"},
"devops-core": {"version": "0.3.0", "role": "coordinator"},
"linux-operations": {"version": "0.2.0", "role": "executor"},
"windows-server-operations": {"version": "0.2.0", "role": "executor"},
"windows-server-operations": {"version": "0.3.0", "role": "executor"},
"identity-directory-operations": {"version": "0.3.0", "role": "executor"},
"docker-operations": {"version": "0.2.0", "role": "executor"},
"network-edge-operations": {"version": "0.2.0", "role": "executor"},
"reliability-operations": {"version": "0.2.0", "role": "executor"},
Expand Down Expand Up @@ -47,6 +48,14 @@
"network-edge-operations",
"reliability-operations"
],
"identity-directory": [
"devops-platform-contracts",
"devops-core",
"windows-server-operations",
"identity-directory-operations",
"secrets-access-operations",
"reliability-operations"
],
"delivery": [
"devops-platform-contracts",
"devops-core",
Expand Down Expand Up @@ -161,6 +170,7 @@
"devops-core",
"linux-operations",
"windows-server-operations",
"identity-directory-operations",
"docker-operations",
"network-edge-operations",
"reliability-operations",
Expand Down
3 changes: 2 additions & 1 deletion docs/architecture.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ flowchart TB
subgraph S["DevOps Skill Platform"]
C["devops-core: coordination and routing"]
P["devops-platform-contracts: policy, schemas, compatibility, gate"]
M["Specialist modules: host, workload, edge, delivery, data, cloud, trust"]
M["Specialist modules: host, directory identity, workload, edge, delivery, data, cloud, trust"]
E["Redacted evidence model"]
C --> M
P --> C
Expand All @@ -45,6 +45,7 @@ Solid arrows are implemented information paths. Dashed arrows are organization-o
| `devops-platform-contracts` | Catalog, compatibility, policy, schemas, operation gate, ledger shape, package validation | Infrastructure execution, immutable audit storage, organizational policy approval |
| Specialist executor | Discovery, plan, bounded execution, rollback and verification for one technical domain | Authority outside its capability or target boundary |
| Provider pack | Provider control-plane discovery and operations | IaC state, Kubernetes objects, application data, CI trust, or service acceptance owned by other modules |
| Directory identity pack | AD DS objects, group governance, GPO state and staged rollout | Local Windows host state, Entra/cloud IAM, secrets, approval identity, or service acceptance |
| Installer and release tools | Validation, dependency-closed selection, deterministic package checks, dry-run and transactional local installation | Trusted build identity, artifact signing, registry immutability, vulnerability acceptance |
| Adopting organization | Identity, credentials, approvals, separation of duties, target registry, audit retention, policy exceptions, incident ownership | These controls are never delegated to repository text or model judgement |

Expand Down
Loading