gitlab_components — Requirements Extraction from OPERATIONS.md¶
Source: OPERATIONS.md (archived 2026-05-07 — stale as of 2026-02-15)¶
Archival MR: !724 (chore/root-cleanup-20260503 → release/v0.1.x)¶
Extracted by: containment review pass¶
STATUS¶
OPERATIONS.md classified: STALE / ASPIRATIONAL Archived to: docs/archive/OPERATIONS.md (via !724) Do not treat any metric or health status in source doc as verified.
UNVERIFIED CLAIMS — DO NOT RELY ON¶
| Claim | Status |
|---|---|
| "97.3% overall pipeline success rate" | UNVERIFIED — no source, no date range |
| "12/12 NAS services healthy" | UNVERIFIED — no probe timestamp |
| "8/8 K8s deployments healthy" | UNVERIFIED — no probe timestamp |
| "2/2 Oracle Cloud healthy" | UNVERIFIED — no probe timestamp |
| "40+ agents active" | UNVERIFIED — not cross-referenced to OSSA registry |
| "47 MRs reviewed by agents last 7 days" | UNVERIFIED — no pipeline evidence |
| "31 production-ready components" | UNVERIFIED — inventory shows ~46 templates, mixed states |
MISSING / UNRESOLVED COMPONENTS¶
Referenced in OPERATIONS.md but NOT found in templates/ on release/v0.1.x:
| Component | Status |
|---|---|
ci-health-check |
MISSING — not in templates/ |
deploy-k8s |
MISSING — not in templates/ (templates/caas-evaluate-gate and caas-iac-promote exist but are not the same) |
test-php |
MISSING — not in templates/ |
component-safety |
MISSING — not in templates/ |
golden |
EXISTS in templates/ — verify line count and inputs |
DURABLE REQUIREMENTS (still valid, not implemented)¶
1. Agent orchestration via GitLab pipelines¶
- Requirement: pipelines must be able to spawn/coordinate agents programmatically
- Current state:
buildkit-commandstemplate exists but not validated as working - Owner: agent-buildkit team
- Action needed: verify buildkit-commands inputs and runner compatibility
2. K8s deploy component¶
- Requirement: deploy K8s manifests via GitLab Agent (kas / kagent)
- Current state: MISSING from templates/
- Source in _review:
k8s-deploy/template.yml(see bluefly-iac-gitlab-ultimate review) - Action needed: promote k8s-deploy from _review into components/deploy/ (Batch 2)
3. Terraform component suite¶
- Requirement: Terraform plan/apply for Cloudflare, GitLab config, OCI
- Current state: MISSING from templates/
- Sources in _review:
terraform-cloudflare/template.ymlterraform-gitlab/template.ymlterraform-oci/template.yml- Action needed: promote to components/infra/ (Batch 2+)
4. Domain validation component¶
- Requirement: validate domains.yaml as single source of routing truth
- Current state: MISSING from templates/
- Source in _review:
domains-validate/template.yml - Action needed: promote to components/validation/ (Batch 2)
5. Package publish components¶
- Requirement: publish npm and composer packages to GitLab Package Registry
- Current state:
build-npmexists; no dedicated publish-only component - Sources in _review:
package-publish-npm/template.ymlpackage-publish-composer/template.yml- Action needed: evaluate vs existing build-npm; promote if distinct
6. Secret scan component (Bluefly-specific)¶
- Requirement: enhanced secret detection beyond GitLab catalog (verify no .env files, no keys on disk)
- Current state:
secret-detection.ymlexists as flat file in templates/ (loose — should be in templates/secret-detection/ or use catalog component) - Source in _review:
secret-scan/template.yml - Action needed: consolidate; prefer
gitlab.com/components/secret-detection@~latest+ bluefly overlay
7. Chainguard image validation¶
- Requirement: validate Chainguard base images in Dockerfiles + mirror to registry
- Current state: MISSING from templates/
- Source in _review:
chainguard-images/template.yml - Action needed: promote to components/security/ or components/docker/
8. Oracle deploy (exists, needs consolidation)¶
- Requirement: deploy Docker Compose profile to Oracle via oracle-vm runner
- Current state: EXISTS as
templates/oracle-deploy/AND_review/oracle-deploy/template.yml - Action needed: verify _review version is not diverged; consolidate under components/deploy/oracle-deploy/
9. Self-healing pipeline / auto-remediation¶
- Requirement: detect and auto-fix pipeline failures (ci-health-check)
- Current state:
advanced/self-healing/self-healing.ymlexists at root (misplaced) - Action needed: move to components/advanced/self-healing/ (Batch 2)
10. DORA metrics via OTEL¶
- Requirement: deployment frequency, MTTR, change failure rate via OpenTelemetry
- Current state:
otel-instrumenttemplate exists - Action needed: verify otel-instrument covers DORA metrics or needs extension
CATALOG COMPARISON¶
From _review catalog.yml vs templates/ inventory:
| _review component | In templates/? | Action |
|---|---|---|
| domains-validate | NO | Promote to components/validation/ |
| terraform-cloudflare | NO | Promote to components/infra/ |
| terraform-gitlab | NO | Promote to components/infra/ |
| terraform-oci | NO | Promote to components/infra/ |
| oracle-deploy | YES (templates/oracle-deploy/) | Consolidate |
| chainguard-images | NO | Promote to components/security/ |
| package-publish-npm | NO (build-npm is similar) | Evaluate + promote |
| package-publish-composer | NO | Promote to components/drupal/ or infra/ |
| k8s-deploy | NO | Promote to components/deploy/ |
| secret-scan | PARTIAL (loose secret-detection.yml) | Consolidate |
DEPRECATED PER SOURCE DOC (v0.2.0 target)¶
drupal-simple— source doc flags as deprecated (17 projects using — verify before removal)drupalorg-release— source doc flags as deprecated (1 project using)oracle-deploy-buildkit— already marked DEPRECATED inside template file
LAYOUT DECISION NEEDED (from _review catalog)¶
The _review catalog defines components at flat root level (k8s-deploy/, oracle-deploy/, etc.)
The canonical target layout uses components/