Skip to content

epic: enterprise hardening — trustworthy v0.4 release #305

Description

@m-khan-97

Goal

Make the next OpenShield release trustworthy, secure and operable for an enterprise deployment without adding product features for their own sake.

The current rule inventory is 95 unique rules with 95 matching playbooks. Rule count is not the release KPI: verified evidence coverage, explicit uncertainty, false-positive control and safe operation are.

Product boundary for this release

Recommended default: ship and document a securely enforced single-tenant enterprise deployment first. Do not claim multi-tenant SaaS until identity, ownership, tenant-scoped persistence and cross-tenant isolation tests exist.

Do not claim certification or "full compliance." Reports should describe versioned technical evidence coverage.

Phase 0 — containment and trust blockers

These block restoring or calling the current deployment enterprise-ready:

Phase 1 — durable enterprise core

Phase 2 — validate, then expand scanner coverage

Existing rule-pack work should remain reviewable, but it must consume the Phase 0 evaluation and collector contracts before merge:

Every repaired or new rule must include:

  • explicit applicability and PASS/FAIL/UNKNOWN/NOT_APPLICABLE behavior;
  • required permissions and 403/429/5xx/partial-collection tests;
  • real Azure SDK model contract tests and pagination coverage;
  • authoritative evidence source, version, timestamp and fingerprint;
  • false-positive analysis, exceptions and suppression expiry;
  • versioned framework mapping rationale;
  • preview-first, target-verified remediation with rollback and validation.

Enterprise release gates

The release stays blocked until all of the following are demonstrated:

  • No reusable credential is present in public frontend or website assets.
  • Authentication, RBAC and authorized subscription boundaries are integration-tested.
  • Failed or incomplete evidence cannot produce PASS, a clean scan, or score 100.
  • CRITICAL is consistent in scanner, database, APIs, reports and frontend.
  • The published image starts, reaches database-aware readiness, and completes a worker-backed real scan.
  • Required GitHub checks and two-person promotion are effective, not just documented.
  • Framework editions/mappings are versioned, reviewed and presented as technical evidence coverage.
  • SLOs, alerts, on-call ownership, backup restore and rollback drills have recorded evidence.
  • Existing 95 rules have an evidence/permission/SDK validation matrix.
  • No unresolved P0; every accepted P1 has named owner, rationale and expiry.

review model

  • Programme/risk/claim gate: named lead plus cross-stream reviewer.
  • Platform/release gate: named lead plus independent backup.
  • Scanner/evidence gate: named lead plus cross-stream reviewer.
  • Auth, scoring, compliance, infrastructure and release changes require review from two leads; authors do not self-approve.

Delivery order

  1. Contain credentials and unsafe public surfaces.
  2. Restore enforced merge controls.
  3. Repair scanner truth and severity semantics.
  4. Prove the runtime/deployment path end-to-end.
  5. Harden persistence, operations and evidence provenance.
  6. Validate all 95 rules.
  7. Resume rule expansion in small quality-gated batches.

Metadata

Metadata

Assignees

No one assigned

    Labels

    coreCore team ownership not for studentspriority: criticalMust be fixed immediately, breaks core functionality

    Type

    No type

    Projects

    Status
    📋 Backlog

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions