Skip to content

gitlab_components — Requirements Extraction from OPERATIONS.md

Source: OPERATIONS.md (archived 2026-05-07 — stale as of 2026-02-15)

Archival MR: !724 (chore/root-cleanup-20260503 → release/v0.1.x)

Extracted by: containment review pass

STATUS

OPERATIONS.md classified: STALE / ASPIRATIONAL Archived to: docs/archive/OPERATIONS.md (via !724) Do not treat any metric or health status in source doc as verified.


UNVERIFIED CLAIMS — DO NOT RELY ON

Claim Status
"97.3% overall pipeline success rate" UNVERIFIED — no source, no date range
"12/12 NAS services healthy" UNVERIFIED — no probe timestamp
"8/8 K8s deployments healthy" UNVERIFIED — no probe timestamp
"2/2 Oracle Cloud healthy" UNVERIFIED — no probe timestamp
"40+ agents active" UNVERIFIED — not cross-referenced to OSSA registry
"47 MRs reviewed by agents last 7 days" UNVERIFIED — no pipeline evidence
"31 production-ready components" UNVERIFIED — inventory shows ~46 templates, mixed states

MISSING / UNRESOLVED COMPONENTS

Referenced in OPERATIONS.md but NOT found in templates/ on release/v0.1.x:

Component Status
ci-health-check MISSING — not in templates/
deploy-k8s MISSING — not in templates/ (templates/caas-evaluate-gate and caas-iac-promote exist but are not the same)
test-php MISSING — not in templates/
component-safety MISSING — not in templates/
golden EXISTS in templates/ — verify line count and inputs

DURABLE REQUIREMENTS (still valid, not implemented)

1. Agent orchestration via GitLab pipelines

  • Requirement: pipelines must be able to spawn/coordinate agents programmatically
  • Current state: buildkit-commands template exists but not validated as working
  • Owner: agent-buildkit team
  • Action needed: verify buildkit-commands inputs and runner compatibility

2. K8s deploy component

  • Requirement: deploy K8s manifests via GitLab Agent (kas / kagent)
  • Current state: MISSING from templates/
  • Source in _review: k8s-deploy/template.yml (see bluefly-iac-gitlab-ultimate review)
  • Action needed: promote k8s-deploy from _review into components/deploy/ (Batch 2)

3. Terraform component suite

  • Requirement: Terraform plan/apply for Cloudflare, GitLab config, OCI
  • Current state: MISSING from templates/
  • Sources in _review:
  • terraform-cloudflare/template.yml
  • terraform-gitlab/template.yml
  • terraform-oci/template.yml
  • Action needed: promote to components/infra/ (Batch 2+)

4. Domain validation component

  • Requirement: validate domains.yaml as single source of routing truth
  • Current state: MISSING from templates/
  • Source in _review: domains-validate/template.yml
  • Action needed: promote to components/validation/ (Batch 2)

5. Package publish components

  • Requirement: publish npm and composer packages to GitLab Package Registry
  • Current state: build-npm exists; no dedicated publish-only component
  • Sources in _review:
  • package-publish-npm/template.yml
  • package-publish-composer/template.yml
  • Action needed: evaluate vs existing build-npm; promote if distinct

6. Secret scan component (Bluefly-specific)

  • Requirement: enhanced secret detection beyond GitLab catalog (verify no .env files, no keys on disk)
  • Current state: secret-detection.yml exists as flat file in templates/ (loose — should be in templates/secret-detection/ or use catalog component)
  • Source in _review: secret-scan/template.yml
  • Action needed: consolidate; prefer gitlab.com/components/secret-detection@~latest + bluefly overlay

7. Chainguard image validation

  • Requirement: validate Chainguard base images in Dockerfiles + mirror to registry
  • Current state: MISSING from templates/
  • Source in _review: chainguard-images/template.yml
  • Action needed: promote to components/security/ or components/docker/

8. Oracle deploy (exists, needs consolidation)

  • Requirement: deploy Docker Compose profile to Oracle via oracle-vm runner
  • Current state: EXISTS as templates/oracle-deploy/ AND _review/oracle-deploy/template.yml
  • Action needed: verify _review version is not diverged; consolidate under components/deploy/oracle-deploy/

9. Self-healing pipeline / auto-remediation

  • Requirement: detect and auto-fix pipeline failures (ci-health-check)
  • Current state: advanced/self-healing/self-healing.yml exists at root (misplaced)
  • Action needed: move to components/advanced/self-healing/ (Batch 2)

10. DORA metrics via OTEL

  • Requirement: deployment frequency, MTTR, change failure rate via OpenTelemetry
  • Current state: otel-instrument template exists
  • Action needed: verify otel-instrument covers DORA metrics or needs extension

CATALOG COMPARISON

From _review catalog.yml vs templates/ inventory:

_review component In templates/? Action
domains-validate NO Promote to components/validation/
terraform-cloudflare NO Promote to components/infra/
terraform-gitlab NO Promote to components/infra/
terraform-oci NO Promote to components/infra/
oracle-deploy YES (templates/oracle-deploy/) Consolidate
chainguard-images NO Promote to components/security/
package-publish-npm NO (build-npm is similar) Evaluate + promote
package-publish-composer NO Promote to components/drupal/ or infra/
k8s-deploy NO Promote to components/deploy/
secret-scan PARTIAL (loose secret-detection.yml) Consolidate

DEPRECATED PER SOURCE DOC (v0.2.0 target)

  • drupal-simple — source doc flags as deprecated (17 projects using — verify before removal)
  • drupalorg-release — source doc flags as deprecated (1 project using)
  • oracle-deploy-buildkit — already marked DEPRECATED inside template file

LAYOUT DECISION NEEDED (from _review catalog)

The _review catalog defines components at flat root level (k8s-deploy/, oracle-deploy/, etc.) The canonical target layout uses components///. Decision required: does the _review catalog become the basis for the catalog.yml rewrite when templates/ → components/ migration is complete?