# Implementation coverage

Generated from the reviewed control catalogue. Consistency is automated; semantic findings remain in the source audit.

| Component | Control | Explanation | Workflow | Evidence | Limitation |
|---|---|---|---|---|---|
| GitHub Actions PR jobs | pr-validation | release-journey/pr-validation | stage-pr | code inspection only | Scan coverage and ignores limit findings; Repository settings need separate inspection |
| Docker Buildx and Trivy | artifact-build | release-journey/build, security-design/digests | stage-build | ev-build-capture | No hermetic or reproducible build proof; Base and package resolution have mutable dependencies |
| GCP Workload Identity Federation | cloud-auth | security-design/identity, release-journey/cloud-identity | stage-cloud | code inspection only | Main-only authorization is in workflow conditions; CI verification receives the writer service account |
| Cosign, Fulcio and Rekor | keyless-signing | security-design/signatures, release-journey/keyless-signing | stage-sign | ev-build-capture, ev-attestation-capture, ev-wrong-trust | A compromised trusted workflow can sign malicious content; Cloud service account is not the Sigstore signer |
| Syft and Cosign | attestations | release-journey/attestations, security-design/signatures | stage-attest | ev-attestation-capture, ev-wrong-trust, ev-policy-inspected, ev-predicate-local | SBOM authenticity does not prove completeness; Provenance schema does not establish SLSA assurance level |
| Cosign and jq in verify.yml | ci-verification | release-journey/ci-verification, reference/verification-contract | stage-verify | ev-build-capture, ev-attestation-capture | Correlated signing/verification workflow compromise; Historical screenshots may precede stricter checks |
| Helm values and Argo CD | digest-promotion | release-journey/promotion, security-design/digests | stage-promote | ev-gitops-capture, ev-trusted-admit | Remote reviewer enforcement unconfirmed; Argo health is not signature verification |
| Kyverno | admission | security-design/admission-scope, release-journey/admission | stage-admit | ev-trusted-admit, ev-unsigned-deny, ev-wrong-trust, ev-init-deny, ev-policy-inspected, ev-predicate-local, ev-admission-gaps | No source commit/material predicate at admission; Ephemeral paths not independently established; Background reporting does not evict existing Pods |
| Falco modern eBPF and Falcosidekick | runtime-detection | security-design/prevention-detection, release-journey/runtime | stage-runtime | ev-runtime-shell, ev-alert-gap | Alerting Terraform is disabled by default; No recorded recovery/response exercise |
| Terraform modules and separately installed controllers | infrastructure | operate/bootstrap, reference/infrastructure | stage-cloud | code inspection only | Private nodes do not imply private API endpoint; Legacy Ratify is inactive; Remote infrastructure not inspected in this task |

## Component and source coverage

| Component | Classification | Pinned sources | Controls | Explanation routes | Workflow | Evidence | Limit |
|---|---|---|---|---|---|---|---|
| application: Small runtime workload and version context; /info signed field is a constant, not verification. | active | app/.rebuild-trigger, app/main.py, app/requirements.txt | artifact-build, runtime-detection | reference/application, release-journey/runtime | stage-build, stage-runtime | source inventory only | No hermetic or reproducible build proof; Base and package resolution have mutable dependencies; Alerting Terraform is disabled by default; No recorded recovery/response exercise |
| container-build: Construct runtime image, constrain packages/user, and maintain explicit image vulnerability exceptions. | active | .dockerignore, .trivyignore, Dockerfile | artifact-build | release-journey/build, reference/application | stage-build | ev-build-capture | No hermetic or reproducible build proof; Base and package resolution have mutable dependencies |
| pr-source-validation: Changed-path source/filesystem/policy validation without OIDC or publication. | active | .github/workflows/pr-check.yml, .github/workflows/security-scan.yml, .semgrepignore | pr-validation | release-journey/pr-validation, reference/workflows | stage-pr | source inventory only | Scan coverage and ignores limit findings; Repository settings need separate inspection |
| release-orchestration: PR local image scan; trusted main build-sign-verify sequencing with typed manual confirmation. | active | .github/workflows/deploy.yml | pr-validation, artifact-build, ci-verification | release-journey, reference/workflows | stage-pr, stage-build, stage-verify | ev-build-capture, ev-attestation-capture | Scan coverage and ignores limit findings; Repository settings need separate inspection; No hermetic or reproducible build proof; Base and package resolution have mutable dependencies; Correlated signing/verification workflow compromise; Historical screenshots may precede stricter checks |
| artifact-publication: Build and push image; hand off immutable digest; scan pushed final image. | active | .github/workflows/build-push.yml | artifact-build, cloud-auth | release-journey/build, release-journey/cloud-identity | stage-build, stage-cloud | ev-build-capture | No hermetic or reproducible build proof; Base and package resolution have mutable dependencies; Main-only authorization is in workflow conditions; CI verification receives the writer service account |
| cloud-ci-authentication: Repository-based GitHub federation and GSA registry access; source IAM lacks a main-ref condition. | active | .github/actions/gcp-auth/action.yml, infrastructure/environments/prod/supply-chain.tf | cloud-auth, infrastructure | release-journey/cloud-identity, reference/infrastructure | stage-cloud | source inventory only | Main-only authorization is in workflow conditions; CI verification receives the writer service account; Private nodes do not imply private API endpoint; Legacy Ratify is inactive; Remote infrastructure not inspected in this task |
| signing-and-statements: Sign immutable image and attach final-image SPDX plus workflow-generated provenance. | active | .github/actions/setup-cosign/action.yml, .github/actions/setup-syft/action.yml, .github/workflows/sign-attest.yml | keyless-signing, attestations | release-journey/keyless-signing, release-journey/attestations | stage-sign, stage-attest | ev-build-capture, ev-attestation-capture, ev-wrong-trust, ev-policy-inspected, ev-predicate-local | A compromised trusted workflow can sign malicious content; Cloud service account is not the Sigstore signer; SBOM authenticity does not prove completeness; Provenance schema does not establish SLSA assurance level |
| ci-verification: Verify digest/identity/types and source-aware provenance conjunction before candidate handoff. | active | .github/workflows/verify.yml | ci-verification | release-journey/ci-verification, reference/verification-contract | stage-verify | ev-build-capture, ev-attestation-capture | Correlated signing/verification workflow compromise; Historical screenshots may precede stricter checks |
| supplementary-sbom-vex: Independent source CycloneDX and advisory reachability reports outside signing dependency chain. | active | .github/workflows/sbom-vex.yml | attestations | release-journey/attestations, reference/workflows | stage-attest | source inventory only | SBOM authenticity does not prove completeness; Provenance schema does not establish SLSA assurance level |
| local-infrastructure-validation: Root-discovered Actions workflow does format/init-without-backend/validate only. | active | .github/workflows/infrastructure-terraform.yml | infrastructure | operate, reference/workflows | stage-cloud | source inventory only | Private nodes do not imply private API endpoint; Legacy Ratify is inactive; Remote infrastructure not inspected in this task |
| review-ownership: Owner routing definition; not proof of enforced remote review. | configuration | .github/CODEOWNERS | pr-validation | release-journey/pr-validation, security-design/shared-failures | stage-pr | source inventory only | Scan coverage and ignores limit findings; Repository settings need separate inspection |
| branch-ruleset: Ruleset source has enforcement active; historical notes say applying remote settings was deferred. | defined-not-confirmed-active | terraform/.gitignore, terraform/main.tf | pr-validation | release-journey/pr-validation, reference/decisions | stage-pr | source inventory only | Scan coverage and ignores limit findings; Repository settings need separate inspection |
| prod-bootstrap: Root provider/backend/input wiring and VPC→GKE→in-cluster provider dependency order. | active | infrastructure/environments/prod/.terraform.lock.hcl, infrastructure/environments/prod/README.md, infrastructure/environments/prod/main.tf, infrastructure/environments/prod/outputs.tf, infrastructure/environments/prod/terraform.tfvars.example, infrastructure/environments/prod/variables.tf, infrastructure/environments/prod/versions.tf | infrastructure | operate/bootstrap, operate/prerequisites, reference/infrastructure | stage-cloud | source inventory only | Private nodes do not imply private API endpoint; Legacy Ratify is inactive; Remote infrastructure not inspected in this task |
| network: VPC/subnets/NAT/firewall flow-log and IAP network foundation; examples are reference entrypoints. | active | infrastructure/vpc/README.md, infrastructure/vpc/examples/complete/main.tf, infrastructure/vpc/examples/complete/outputs.tf, infrastructure/vpc/examples/complete/variables.tf, infrastructure/vpc/main.tf, infrastructure/vpc/outputs.tf, infrastructure/vpc/terraform.tfvars.example, infrastructure/vpc/variables.tf, infrastructure/vpc/versions.tf | infrastructure | operate/bootstrap, reference/infrastructure | stage-cloud | source inventory only | Private nodes do not imply private API endpoint; Legacy Ratify is inactive; Remote infrastructure not inspected in this task |
| cluster: Private nodes, VPC-native addressing, Workload Identity, node roles/autoscaling; private-only API endpoint is not default. | active | infrastructure/gke/README.md, infrastructure/gke/examples/complete/main.tf, infrastructure/gke/examples/complete/outputs.tf, infrastructure/gke/examples/complete/variables.tf, infrastructure/gke/main.tf, infrastructure/gke/outputs.tf, infrastructure/gke/terraform.tfvars.example, infrastructure/gke/variables.tf, infrastructure/gke/versions.tf | infrastructure, cloud-auth | operate/bootstrap, reference/infrastructure, security-design/boundaries | stage-cloud | source inventory only | Main-only authorization is in workflow conditions; CI verification receives the writer service account; Private nodes do not imply private API endpoint; Legacy Ratify is inactive; Remote infrastructure not inspected in this task |
| optional-kubernetes-addons: Conditional metrics-server/ExternalDNS, neither an admission-engine nor Argo installer. | optional | infrastructure/kubernetes-addons/README.md, infrastructure/kubernetes-addons/examples/complete/main.tf, infrastructure/kubernetes-addons/examples/complete/outputs.tf, infrastructure/kubernetes-addons/examples/complete/variables.tf, infrastructure/kubernetes-addons/main.tf, infrastructure/kubernetes-addons/outputs.tf, infrastructure/kubernetes-addons/terraform.tfvars.example, infrastructure/kubernetes-addons/variables.tf, infrastructure/kubernetes-addons/versions.tf | infrastructure | reference/infrastructure, operate/wiring | stage-cloud | source inventory only | Private nodes do not imply private API endpoint; Legacy Ratify is inactive; Remote infrastructure not inspected in this task |
| legacy-ratify-credentials: Imported Ratify JSON-key compatibility resources gated enable_legacy_ratify=false; helper is not active Kyverno auth. | legacy-disabled | infrastructure/environments/prod/create-ratify-secret.sh, infrastructure/environments/prod/ratify-gar-auth.tf | none: inactive/configuration | reference/decisions, reference/infrastructure | not in release path | source inventory only | No active control claim is made for this configuration or historical/legacy component. |
| runtime-monitoring: Falco/Falcosidekick with eBPF and all-rule matching; custom shell rule detects behavior without checking signatures. | active | infrastructure/environments/prod/falco.tf, infrastructure/falco/README.MD, infrastructure/falco/main.tf, infrastructure/falco/outputs.tf, infrastructure/falco/variables.tf, infrastructure/falco/versions.tf | runtime-detection | release-journey/runtime, failure-cases/runtime-detection | stage-runtime | ev-runtime-shell | Alerting Terraform is disabled by default; No recorded recovery/response exercise |
| optional-runtime-alerting: Opt-in Pub/Sub/Function/Discord path; no owner delivery capture. | optional-disabled | infrastructure/environments/prod/falco-alerting.tf, infrastructure/falco-alerting/READM.md, infrastructure/falco-alerting/functions/discord-notifier/main.py, infrastructure/falco-alerting/functions/discord-notifier/requirements.txt, infrastructure/falco-alerting/main.tf, infrastructure/falco-alerting/outputs.tf, infrastructure/falco-alerting/variables.tf, infrastructure/falco-alerting/versions.tf | runtime-detection | release-journey/runtime, operate/wiring | stage-runtime | ev-alert-gap | Alerting Terraform is disabled by default; No recorded recovery/response exercise |
| admission-policy: Scoped signature/SPDX/provenance requirements with verifier KSA annotation; separate Helm installation. | active | policy/kyverno/block-unsigned-images.yaml, policy/kyverno/values.yaml | admission | release-journey/admission, security-design/admission-scope, reference/verification-contract | stage-admit | ev-trusted-admit, ev-unsigned-deny, ev-wrong-trust, ev-init-deny, ev-policy-inspected, ev-predicate-local, ev-admission-gaps | No source commit/material predicate at admission; Ephemeral paths not independently established; Background reporting does not evict existing Pods |
| policy-regression-checks: Identity drift and JMESPath predicate-fixture checks; not a webhook integration test. | active | policy/tests/check-identity-consistency.sh, policy/tests/fixtures/provenance-predicate.json, policy/tests/test_jmespath_conditions.py | pr-validation, admission | operate, reference/verification-contract | stage-pr, stage-admit | ev-predicate-local | Scan coverage and ignores limit findings; Repository settings need separate inspection; No source commit/material predicate at admission; Ephemeral paths not independently established; Background reporting does not evict existing Pods |
| admission-test-fixtures: Mixed/init unsigned and labelled combined wrong-trust negative fixtures; not production desired state. | test-only | policy/test-manifests/test-init-unsigned.yaml, policy/test-manifests/test-invalid-trust.yaml, policy/test-manifests/test-mixed-containers.yaml, policy/test-policies/invalid-trust-expectations.yaml | admission | failure-cases/container-fields, failure-cases/wrong-trust | stage-admit | ev-wrong-trust, ev-init-deny | No source commit/material predicate at admission; Ephemeral paths not independently established; Background reporting does not evict existing Pods |
| active-workload-chart: Two-replica digest-selected application, restricted privileges and health probes. | active | k8s/helm/supply-chain-demo/.helmignore, k8s/helm/supply-chain-demo/Chart.yaml, k8s/helm/supply-chain-demo/templates/_helpers.tpl, k8s/helm/supply-chain-demo/templates/deployment.yaml, k8s/helm/supply-chain-demo/templates/service.yaml, k8s/helm/supply-chain-demo/values.yaml | digest-promotion, artifact-build | release-journey/promotion, reference/application | stage-build, stage-promote | ev-build-capture, ev-gitops-capture, ev-trusted-admit | No hermetic or reproducible build proof; Base and package resolution have mutable dependencies; Remote reviewer enforcement unconfirmed; Argo health is not signature verification |
| gitops-applications: Canonical-main Helm reconcile with self-heal/prune; negative app deliberately manual. | active | argocd/supply-chain-demo-app.yaml, argocd/supply-chain-test-negative-app.yaml | digest-promotion | release-journey/promotion, operate/first-release | stage-promote | ev-gitops-capture, ev-trusted-admit | Remote reviewer enforcement unconfirmed; Argo health is not signature verification |
| legacy-admission: Historical Gatekeeper/Ratify verifier/templates; final GCP design uses Kyverno. | legacy-inactive | policy/gatekeeper/constraint-template.yaml, policy/gatekeeper/constraint.yaml, policy/gatekeeper/pod-hardening-constraint.yaml, policy/gatekeeper/pod-hardening-template.yaml, policy/gatekeeper/store-oras.yaml, policy/gatekeeper/verifier-cosign.yaml | none: inactive/configuration | reference/decisions | not in release path | source inventory only | No active control claim is made for this configuration or historical/legacy component. |
| legacy-workload-manifests: Older manifest target/replica configuration; not active Argo source. | legacy-inactive | k8s/manifests/deployment, k8s/manifests/deployment.yaml, k8s/manifests/service.yaml | none: inactive/configuration | reference/application | not in release path | source inventory only | No active control claim is made for this configuration or historical/legacy component. |
| legacy-docker-login: Unused historical composite login action; active GAR auth uses gcp-auth. | legacy-inactive | .github/actions/docker-login/action.yml | none: inactive/configuration | reference/workflows | not in release path | source inventory only | No active control claim is made for this configuration or historical/legacy component. |
| nested-upstream-workflow: Imported nested workflow is not discovered by root GitHub Actions; do not attribute its plan/apply/cost jobs to active CI. | legacy-inactive | infrastructure/.github/workflows/terraform.yml | none: inactive/configuration | reference/workflows | not in release path | source inventory only | No active control claim is made for this configuration or historical/legacy component. |
| imported-cost-and-editor-config: Retained governance/cost/editor context, not invoked by active root validation workflow. | auxiliary-inactive | infrastructure/.infracost/infracost.yml, infrastructure/.infracost/policies/governance.rego, infrastructure/.infracost/policies/tagging.rego, infrastructure/.vscode/settings.json | none: inactive/configuration | reference/infrastructure, reference/decisions | not in release path | source inventory only | No active control claim is made for this configuration or historical/legacy component. |
| owner-validation: Owner records dated 2026-08-23, no current environment assertion. | historical-owner-evidence | docs/my-validation/01-pr-security-gates.png, docs/my-validation/02-main-build-pipeline.png, docs/my-validation/03-gar-image-digest.png, docs/my-validation/03b-live-deployment-digest.png, docs/my-validation/04-cosign-verification.png, docs/my-validation/05-sbom-provenance.png, docs/my-validation/06-gke-workloads.png, docs/my-validation/07-argocd-healthy-details.png, docs/my-validation/07-argocd-healthy.png, docs/my-validation/08-trusted-admit.png, docs/my-validation/09-unsigned-blocked.png, docs/my-validation/10-invalid-trust-blocked.png, docs/my-validation/11-init-bypass-blocked.png, docs/my-validation/12-falco-runtime.png, docs/my-validation/README.md | pr-validation, artifact-build, keyless-signing, attestations, ci-verification, digest-promotion, admission, runtime-detection | failure-cases/catalogue, start-here/scope, failure-cases/screenshots | stage-pr, stage-build, stage-sign, stage-attest, stage-verify, stage-promote, stage-admit, stage-runtime | ev-build-capture, ev-attestation-capture, ev-gitops-capture, ev-trusted-admit, ev-unsigned-deny, ev-wrong-trust, ev-init-deny, ev-runtime-shell | Scan coverage and ignores limit findings; Repository settings need separate inspection; No hermetic or reproducible build proof; Base and package resolution have mutable dependencies; A compromised trusted workflow can sign malicious content; Cloud service account is not the Sigstore signer; SBOM authenticity does not prove completeness; Provenance schema does not establish SLSA assurance level; Correlated signing/verification workflow compromise; Historical screenshots may precede stricter checks; Remote reviewer enforcement unconfirmed; Argo health is not signature verification; No source commit/material predicate at admission; Ephemeral paths not independently established; Background reporting does not evict existing Pods; Alerting Terraform is disabled by default; No recorded recovery/response exercise |
| upstream-validation: Older retained evidence with distinct origin and sometimes different registries/environments. | historical-upstream-evidence | docs/evidence/deny-stage-violations.yaml, docs/evidence/excluded-namespace-allowed.txt, docs/evidence/init-container-gap-fix.md, docs/evidence/init-container-rejected.txt, docs/evidence/kyverno-init-container-rejected.txt, docs/evidence/kyverno-mixed-containers-rejected-gke.txt, docs/evidence/kyverno-mixed-containers-rejected.txt, docs/evidence/kyverno-signed-admitted.txt, docs/evidence/kyverno-tampered-rejected.txt, docs/evidence/kyverno-unsigned-rejected-gke.txt, docs/evidence/kyverno-unsigned-rejected.txt, docs/evidence/mixed-containers-rejected.txt, docs/evidence/tampered-rejected.txt, docs/evidence/unsigned-rejected.txt | admission | failure-cases, failure-cases/catalogue | stage-admit | source inventory only | No source commit/material predicate at admission; Ephemeral paths not independently established; Background reporting does not evict existing Pods |
| historical-architecture-records: Corroborated planning/status/decision/runbook claims; executable source wins where inconsistent. | historical-reference | README.md, docs/codex/00-REPO-AUDIT.md, docs/codex/01-IMPLEMENTATION-PLAN.md, docs/codex/02-PROJECT-STATUS.md, docs/codex/03-VALIDATION.md, docs/codex/04-DECISIONS.md, docs/codex/05-HANDOFF.md, docs/codex/06-RESOURCE-INVENTORY.md, docs/codex/07-COST-AND-CLEANUP.md, docs/codex/08-SCREENSHOT-CHECKLIST.md, docs/codex/09-RESUME-MATERIAL.md, docs/codex/10-INTERVIEW-GUIDE.md, docs/codex/11-CI-DEVSECOPS-AUDIT.md, docs/codex/11-COMPLETION-GUIDE.md, docs/codex/12-CI-GAP-MATRIX.md, docs/decisions/ratify-gcp-auth-tradeoff.md, docs/repository-merge.md, docs/runbooks/troubleshooting-gatekeeper-kyverno.md, infrastructure/README.md | none: inactive/configuration | start-here/scope, reference/decisions, operate/troubleshooting | not in release path | source inventory only | No active control claim is made for this configuration or historical/legacy component. |
| dependency-update-configuration: Update automation configuration; not proof updates were reviewed or a release is safe. | configuration | .github/dependabot.yml, renovate.json | none: inactive/configuration | reference/decisions | not in release path | source inventory only | No active control claim is made for this configuration or historical/legacy component. |
| repository-ignore-configuration: Ignore local/state/cache outputs; not proof history contains no sensitive material. | configuration | .gitignore, infrastructure/.gitignore | none: inactive/configuration | operate, reference/website-engineering | not in release path | source inventory only | No active control claim is made for this configuration or historical/legacy component. |
