Skip to content

CI-001 — Establish trustworthy quality gates and protected deployment #105

Description

@daliu

Outcome

Create a trustworthy delivery pipeline in which non-mutating lint, frontend tests/build, Functions lint/tests, Firestore Rules tests, dependency/secret checks, and exact-commit staging evidence gate any deployment. Remove service-account material from frontend builds and move toward least-privilege OIDC/WIF with protected approval.

Why this is a tracker

This is cross-boundary delivery and external IAM work. Assign only atomic children.

Children

System acceptance

  • The exact commit cannot deploy until every required check passes.
  • Lint never rewrites files or hides failures.
  • Frontend builds receive no server credential.
  • Missing deployment authority/config fails visibly.
  • Backend/rules/index changes precede dependent frontend code.
  • Production requires named approval and staging evidence.

Dependencies

SAFETY-001 (#99) is the local-safety foundation. External IAM/environment work requires an authorized owner.

Claim rule

Do not claim this tracker. Claim exactly one dependency-ready child, assign it, and post the repository-standard timestamped CLAIMED marker before editing.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:ciContinuous integration and deploymentneeds-external-configRequires provider console or external configurationpriority:P0Launch blocker or urgent security risksize:LLarge cross-boundary issuestatus:proposedDesigned but dependencies or decisions remaintype:securitySecurity or privacy boundarytype:testingTest infrastructure and quality gates

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions