castai-ci-integration

v2026.09.24

Build a fail-closed CI lane for CAST AI configuration without exposing production credentials to untrusted changes. Use when validating CAST AI Terraform, Helm values, workload annotations, or an authorized read-only API smoke test. Trigger with: "test CAST AI in CI", "gate CAST AI changes", "add a CAST AI contract job".

GitHub
安装命令
npx skhub add jeremylongshore/castai-ci-integration
Markdown
SKILL.md

CAST AI CI Contract Lane

Overview

Keep pull-request checks local and credential-free. Validate syntax, rendered Kubernetes objects, policy invariants, and destructive change boundaries before allowing a separately protected job to inspect a real CAST AI environment.

Prerequisites

  • The workflow, Terraform, Helm values, and workload manifest paths in scope
  • An explicit source of truth for each CAST AI setting
  • Maintainer approval for any protected live probe

Instructions

Step 1: Map the trust boundary

Use Read and Grep to identify fork execution, secret references, Terraform backends, generated plans, Helm values, kubeconfig use, and direct CAST AI calls. Classify each check as offline, protected read-only, or prohibited.

Step 2: Build the required offline lane

Use Bash(terraform:) for formatting, initialization without applying, validation, and a saved plan. Use Bash(helm:) to lint or template the pinned chart and Bash(kubectl:*) only for client-side schema validation against rendered manifests. Treat unexpected resource deletion, provider replacement, cluster disconnect, automation enablement, or HPA ownership transfer as review-blocking changes.

Step 3: Validate CAST AI policy invariants

Use Write or Edit to add deterministic checks for approved regions, cluster identifiers, policy names, node-template bounds, workload automation modes, protected namespaces, disruption budgets, and maximum CPU limits. Reject deprecated cluster minimum CPU settings and unreviewed wildcard scope.

Step 4: Isolate the optional live lane

If live evidence is required, place it in an independent protected-environment job that cannot run for forks. Use a dedicated read-only organization-scoped identity, a pinned CAST AI region, a fixed cluster allowlist, a short timeout, and redacted output. Prefer a documented status read; never enable automation or apply infrastructure from the probe.

Step 5: Prove negative behavior

Run the workflow with missing and sentinel credentials. Confirm the offline lane stays green, the live lane skips safely, logs contain no key or raw cluster inventory, and plan artifacts have restricted retention.

Tool Discipline

Use Read and Grep for workflow and configuration inspection. Use Write and Edit for checks and workflow changes. Use Bash(terraform:), Bash(helm:), Bash(kubectl:), and Bash(castctl:) only for their documented validation or dry-run operations; do not apply, connect, disconnect, or mutate a live cluster without a separate approved change window.

Output

  • A required credential-free validation job
  • A separately protected read-only smoke test, if justified
  • Policy, deletion, and secret-handling assertions
  • Negative-path and redaction receipts

Examples

A pull request renders the pinned CAST AI chart, validates Terraform, and rejects a new HPA ownership transfer. A release job may inspect one approved cluster only after environment approval and records status classes rather than raw API payloads.

Error Handling

FailureMeaningResponse
A fork can read a CAST AI keyCI trust boundary failedDisable the live job and rotate the exposed identity
A plan enables automation unexpectedlyChange exceeds reviewed intentBlock and require an explicit policy review
Offline checks need the networkRequired lane is nondeterministicPin fixtures and local schemas
A rendered object transfers HPA ownershipWorkload control may changeRequire workload-owner approval and rollback evidence

Resources

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

2026年9月24日

分类

未分类

许可证

MIT

源路径

skills/.curated/castai-ci-integration

默认分支

main

最新提交

e5a6c3b

Tree SHA

c2dc8e8