Skip to main content

Schema-backed conformance runner for Astraform remote-domain.v1 services

Project description

astraform-remote-domain-conformance

This is the reusable Python conformance harness for remote-domain.v1.

Brutal truth: if every partner team needs a platform engineer on Zoom to prove their service is valid, you do not have a platform. You have consultancy with a protocol document attached.

This package exercises the real lifecycle:

  • manifest
  • prepare
  • status
  • execute-work
  • inspection
  • shutdown

And it validates payloads against the versioned schema from the pinned remote-domain.v1 release bundle, not just happy-path demo assertions.

It also includes a lightweight remote Policy Wind Tunnel provider conformance path for /policy-wind-tunnel/... routes. That path checks pack metadata, domain/report labels, outcomeSchema, CEL-compatible policyExpressions, presets, run creation, status, lifecycle control, the generic policy_wind_tunnel_bundle.v1 envelope, artifact, and evidence-pack availability. A weak bundle that only returns schemaVersion and runId is not conformant; it must expose the domain, pack, preset, branches, metrics, segments, timeline, decision gates, artifacts, and domain payload that the dashboard and outcome report can render without custom frontend code.

Install

Current status: the published PyPI baseline is astraform-remote-domain-conformance==0.1.3. The workspace release target is 0.1.4, which adds signed DSSE/in-toto worker-profile conformance.

pip install astraform-remote-domain-conformance==0.1.4

For repo-local conformance changes beyond the published 0.1.3 baseline, use a repo-local editable install or a private pre-release wheel.

Repo-local development:

pip install -e './remote-domain-conformance-python[test]'

Run Against A Live Service

remote-domain-conformance \
  --base-url http://localhost:8092 \
  --domain-id my-domain

Require Population Builder catalog conformance:

remote-domain-conformance \
  --base-url http://localhost:8092 \
  --domain-id my-domain \
  --population-catalog

Validate a catalog file before the provider serves it:

remote-domain-conformance \
  --domain-id my-domain \
  --population-catalog-file ./population_catalog.json

Run Against A Local ASGI App

remote-domain-conformance \
  --app my_remote_domain.main:app \
  --domain-id my-domain

Baseline conformance performs the published v1 lifecycle once. To prove the stronger async worker transport/effect boundary, pass an explicit out-of-band profile:

remote-domain-conformance \
  --app my_remote_domain.main:app \
  --domain-id my-domain \
  --opportunity-worker-profile conformance/opportunity-worker-profile.json \
  --provider-artifact-digest "sha256:<64 lowercase hex characters>" \
  > build/conformance-run-report.json

Extract the nested opportunityWorkerConformanceReport, then sign that file in a separate protected job which runs no provider or repository code:

remote-domain-conformance \
  --sign-conformance-report build/opportunity-worker-conformance-report.json \
  --opportunity-worker-profile conformance/opportunity-worker-profile.json \
  --attestation-private-key /secure/release-ed25519-private-key.pem \
  --attestation-key-id partner-release \
  --attestation-output build/opportunity-worker-attestation.dsse.json

The protected signer recomputes the supplied profile digest and requires exactly one matching passing result for every classified tool. The signed conformanceReportDigest covers the report's passing baseline lifecycle, cross-attempt replay, and per-tool probe outcomes, plus its exact OCI subject binding. The public report schema is shipped in the opportunity-worker contract profile. Release automation must fail when the protected signer is unavailable; an ephemeral-key fallback is not a release proof.

The profile schema version is remote_domain_opportunity_worker_conformance_profile.v1; it contains exact toolEffects, one safe probe per tool, and optional personaConfiguration. It is not part of the remote-domain.v1 manifest schema.

Run Policy Wind Tunnel Provider Conformance

remote-domain-conformance \
  --wind-tunnel \
  --base-url http://localhost:8092 \
  --pack-id my-domain-policy-pack \
  --preset-id conformance-proof

Python Usage

import asyncio

from astraform.remote_domain.conformance.runner import ConformanceScenario
from astraform.remote_domain.conformance.runner import OpportunityWorkerConformanceProfile
from astraform.remote_domain.conformance.runner import PolicyWindTunnelConformanceScenario
from astraform.remote_domain.conformance.runner import ToolProbe
from astraform.remote_domain.conformance.runner import run_conformance
from astraform.remote_domain.conformance.runner import run_opportunity_worker_conformance
from astraform.remote_domain.conformance.runner import run_policy_wind_tunnel_conformance


report = asyncio.run(
    run_conformance(
        base_url="http://localhost:8092",
        scenario=ConformanceScenario(domain_id="my-domain"),
    )
)

print(report.to_dict())

worker_report = asyncio.run(
    run_opportunity_worker_conformance(
        base_url="http://localhost:8092",
        scenario=ConformanceScenario(domain_id="my-domain"),
        profile=OpportunityWorkerConformanceProfile(
            tool_effects={"lookup_case": "READ_ONLY"},
            tool_probes=(ToolProbe("lookup_case", {"caseId": "case-1"}),),
        ),
        provider_artifact_digest="sha256:<64 lowercase hex characters>",
    )
)

wind_tunnel_report = asyncio.run(
    run_policy_wind_tunnel_conformance(
        base_url="http://localhost:8092",
        scenario=PolicyWindTunnelConformanceScenario(
            pack_id="my-domain-policy-pack",
            preset_id="conformance-proof",
        ),
    )
)

print(wind_tunnel_report.to_dict())

Publishing Status

Release validation starts with the standalone package tests:

pytest remote-domain-author-kit-python/tests remote-domain-conformance-python/tests

PyPI artifacts are immutable. Do not rerun a publish for an already published version; run smoke-only verification or bump the SDK version.

Public package note: PyPI distributions expose this SDK implementation. Keep host runtime internals and domain-private logic out of this package.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

astraform_remote_domain_conformance-0.1.4.tar.gz (34.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

File details

Details for the file astraform_remote_domain_conformance-0.1.4.tar.gz.

File metadata

File hashes

Hashes for astraform_remote_domain_conformance-0.1.4.tar.gz
Algorithm Hash digest
SHA256 ef5618a36f2c1093808ec68fb86ddcaa2c907f69ffc17b7fb92a54f08f952f98
MD5 fa1e3b79ed8f26d85746f30e3f512e91
BLAKE2b-256 01fbe9199df4d465d9303726c2fb8fea79e0b29af69154ee3156a91d2854350b

See more details on using hashes here.

Provenance

The following attestation bundles were made for astraform_remote_domain_conformance-0.1.4.tar.gz:

Publisher: release.yml on astraform/remote-domain-sdk-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file astraform_remote_domain_conformance-0.1.4-py3-none-any.whl.

File metadata

File hashes

Hashes for astraform_remote_domain_conformance-0.1.4-py3-none-any.whl
Algorithm Hash digest
SHA256 eb9ad35f7920f39e434ad61d0e9457627146ae3558d2d7b28eba107a5d517b2f
MD5 b65a12d53e8af5214f5dc96a0fd609bc
BLAKE2b-256 342e0795d43f5aa87eb9baa474082cdccac6f8019a8e25d2cf029f01b30e7e64

See more details on using hashes here.

Provenance

The following attestation bundles were made for astraform_remote_domain_conformance-0.1.4-py3-none-any.whl:

Publisher: release.yml on astraform/remote-domain-sdk-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page