Skip to content

feat: repo-to-runtime intent, drift, policy, and evidence contract #110

Description

@teckedd-code2save

Goal

Turn GroundControl's existing live topology + Loop foundation into a machine-readable repo-to-runtime control contract.

Why now

GroundControl already sees the real host state and has change ledger, journeys, evidence-backed investigation, approvals, and recovery concepts. The next step is to make repository intent and action policy explicit so agents can safely compare desired state with live reality and produce evidence-backed repair plans.

First slice

Add a declarative manifest, e.g. groundcontrol.yaml, with:

  • app/project identity
  • services
  • image/build source
  • ports
  • domains/routes
  • health checks
  • dependency edges
  • environment variable references (never values)
  • storage
  • deployment target
  • rollout/rollback hints
  • action policy / approval requirements

Add commands/API primitives equivalent to:

  • plan: repo intent vs live state
  • drift: explain mismatches with evidence
  • apply: execute only approved changes
  • verify: prove the intended customer/runtime outcome

Policy

Actions should have typed risk classes, not shell-command-string prompts. Examples:

  • inspect/log/read: allowed
  • restart/redeploy: policy-controlled
  • DNS/proxy mutation: approval-required by default
  • secrets read/delete volume/cross-project access: denied or explicit break-glass

Evidence

Every plan/drift item should cite the observed source:
repo file, container inspect, proxy config, DNS response, health probe, journey result, deployment record, etc.

Acceptance criteria

  • Parse and validate one manifest schema.
  • Build an intent graph from the manifest.
  • Map at least Docker Compose services/ports/health checks into the existing live graph.
  • Produce deterministic drift findings for port, missing service, route/domain, and health mismatch.
  • Each drift item includes evidence and a proposed reversible action.
  • Applying a high-risk action requires approval.
  • Verification records proof after the action.
  • No secret values are written into the manifest or evidence log.

Non-goal

Do not replace Loop. This should become the declarative input and policy/evidence spine Loop can reason over.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions