Skip to content

docs(codeq): execution-era CODEQ_DEPLOYMENT.md sections (#25–#29)#42

Merged
Kenny-Heitritter merged 5 commits into
docs/codeq-deployment-anchorfrom
codeq/deployment-doc-sections
Jul 24, 2026
Merged

docs(codeq): execution-era CODEQ_DEPLOYMENT.md sections (#25–#29)#42
Kenny-Heitritter merged 5 commits into
docs/codeq-deployment-anchorfrom
codeq/deployment-doc-sections

Conversation

@Kenny-Heitritter

Copy link
Copy Markdown
Member

What

Adds the execution-era sections to CODEQ_DEPLOYMENT.md, on top of the anchor doc published in #30 (#23). One commit per ticket, appended in dependency order:

Merge order

Stacked on #30 (base = docs/codeq-deployment-anchor). Merge #30 first; GitHub will retarget this PR to dev.

Notes

Closes #27. Part of #16.

Documents the passive-convergence SLA (staging 30m / prod 45m idle-cull,
no max-server-lifetime cap), the security-critical break-glass drain
runbook, and the deliberate no-banner / no-automated-drain stance.

Part of #27 (doc portion). Ref #16, decision #21.
Adds the authoritative registry of fields update-codeq-token.sh re-asserts
(env-injected + migrations), the user-owned fields it must not touch, the
retired-ids/renamed-fields list, the scoped codeq-owes-Dstacks contract, and
the release-checklist line. Names qbraid-lab-base as canonical.

Part of #26 (doc portion). Ref #16, decision #20.
…ner)

Documents the one-claim smoke-test (bucket manifest sha == codeq --version
sha on lab-base:latest), the operator verify-codeq-rollout.sh one-liner with
its pass/fail criterion, the image-correct-implies-live-for-all-users
definition, and that running-pod convergence is by-construction (not gated).

Part of #25 (doc portion). Ref #16, decision #22.
Records the trigger-lab-base-rebuild step appended to opencode-staging-branch,
the dedicated single-purpose SA + scoped impersonation (Cloud Build has no
trigger-level IAM), the anti-cascade guardrails, and #24/#25 observability.

Part of #28 (doc portion). Ref #16, decision #19 Phase 1.
…ild)

Records the prod auto-rebuild as provably inert (commented step + withheld
IAM), the three go-live gates (lab-base Trivy exit-code=1 [cross-repo],
rollout smoke-test [#25], prod bucket versioning confirmed), the exact
confirm/enable commands, and the flip procedure.

Part of #29 (doc portion). Ref #16, decision #19 Phase 2.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant