Skip to content

P2: reconcile deep-audit documentation and evidence-contract drift #311

Description

@gnanirahulnutakki

Problem

A committed-tree review of origin/main...origin/dev found several documentation statements that lag the implemented and landed contracts. The only runtime artifact affected is static alert annotation text; alert evaluation remains unchanged.

Required corrections

  • ADR-0012: state the exact per-field per-fact OpenCost magnitude, the 4096-fact aggregate bound, the derived aggregate maximum, and that all fifteen cost fields are accumulated independently.
  • Worker-pool session: repair the duplicated wording for the one-second parallel timeout wave.
  • Kubeconfig race session: distinguish rejected absolute or relative executable paths from supported bare commands resolved through PATH.
  • Argo CD session records: replace stale pre-landing checkpoints for Application facts (P2 E12 W1: Normalize Argo CD Application facts into the four-lens graph #206/feat(connector): project Argo applications into graph facts #208) and the sync-failure rule (P1 E14 R8: detect Argo CD sync failures without guessing root cause #270/feat(brain): detect Argo CD sync failures honestly #271) with exact issue, PR, feature commit, merge commit, hosted checks, and post-merge proof while preserving their historical checkpoints.
  • E2 integration spec: preserve the existing connector-wave scope and describe the Wave-1 core R6 boundary as detection plus Prometheus quantification; cloud-autoscaler facts remain required for confidence.
  • README audit paging: distinguish online per-page database and response-egress cost from offline local verification, which performs no network I/O.
  • Architecture model: include immutable approval expiry and the exact half-open consumption interval.
  • F10.4g alert documentation and static annotation: say that the freshness guard proves a recent scraped sample from the preinitialized accepted series, not an accepted authentication event.

Acceptance criteria

  • Every changed statement matches current implementation, tests, and live merge evidence.
  • No alert firing expression, roadmap priority, connector-wave scope, IAM, cloud resource, or recurring-cost change.
  • Markdown and repository contract checks pass.
  • Independent exact-diff review reports no unresolved finding.

Explicit non-findings

  • ADR-0012 stale-input rejection already exists in the generic graph fact contract and rollup tests.
  • The chart already documents the browser OIDC session-private.pem requirement.
  • The alert suite already proves that one accepted authentication suppresses refusal-only traffic and that absent or stale accepted telemetry stays quiet.

Security and cost

This is evidence-contract repair plus a static annotation precision fix. It does not widen IAM, networking, secret access, telemetry cardinality, egress, storage, or recurring cost.

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentation

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions