Find the implementation
Use this map to move from a behavior question to the source that owns it, the tests that exercise it, and the page that explains it. Reading a manifest tells you intended configuration; tests establish supplied contracts; retained evidence records observed executions. Compare all three when reviewing a release claim.
Application and payment path
Section titled “Application and payment path”| Question | Implementation and tests | Explanation |
|---|---|---|
| Where are routes, startup, readiness, database, cache, and metrics? | app/main.py, health tests, database tests, cache tests | Application/data design, health and recovery |
| Where are x402 verification, settlement, and payment failures? | app/payment.py, paid creation tests, replay tests, facilitator tests | Paid request, HTTP reference |
| Where do payer keys and Permit2 signing live? | signer/main.py, signer/permit2.py, API tests, Permit2 tests | Signer failure, secrets flow |
| How is useful load generated? | loadgen.js, runner, contract tests, runner tests | Load testing |
Delivery, infrastructure, and controllers
Section titled “Delivery, infrastructure, and controllers”| Responsibility | Source and tests | Explanation |
|---|---|---|
| Publish/sign application image | build-push.yaml, CI tests | Artifact trust, release journey |
| Publish supporting images | signer workflow, gate workflow, gate Dockerfile | Delivery design |
| Cluster, network, registry, IAM/OIDC | GKE configuration, network, GitHub OIDC, infra tests | Delivery design, limitations |
| Bootstrap and public identifier rendering | bootstrap.sh, render_config.py, bootstrap tests, render tests | Lab lifecycle |
| Application resources and environment differences | chart values, deployment template, render tests | Public configuration, integrated design |
| Secret materialization and access references | ESO Terraform, ClusterSecretStore, secret tests | Secrets and identity flow |
| Kargo discovery/render/verification policy | Warehouse, Project, staging Stage, promotion tests | Controller ownership, promotion |
| Argo CD reconciliation ownership | root app, ApplicationSet, GitOps tests | Release journey |
Gate, telemetry, and evidence
Section titled “Gate, telemetry, and evidence”| Responsibility | Source and tests | Explanation |
|---|---|---|
| Gate preflight, load, Workflow, timing, cleanup | orchestrate.sh, workflow.yaml, orchestrator tests, cleanup tests | Gate lifecycle, gate design |
| Prometheus query validation and rules | score_experiment.py, query tests, no-data tests | Measurements, metrics/scoring |
| Grafana annotations and dashboards | annotate.py, observability values, observability tests | Gate/observability design |
| Baseline scoring | score-baseline.py, baseline tests | Load testing, formats |
| Safe requests and collection | validate-live.sh, collect-evidence.sh, evidence_utils.py, tooling tests | Publish evidence |
| Public execution record | verification report, evidence index, screenshot manifest | Recorded release, historical cases |
The exhaustive editorial audit is content coverage. Website routes and source membership are explicit in content-map.json; generated site content is a build output. See website software design for how mapped repository links and reviewed assets become a static site.
Maintained by Satyam Agnihotri · DevOps & Cloud Engineer