Procedure

Validate deployment and product flows before production

Collect format, access, storage, security, and operational evidence in one technical-evaluation checklist.

Content statusEvaluation guidanceDocumentation versionLatest

Evidence-pack preparation

For every check, record the owner, environment, date, input, expected result, and evidence link.

  • Freeze in-scope organizations, projects, repositories, formats, clients, and user roles.
  • Test packages and SBOMs must not contain production data or secrets.
  • Retain correlation, job, and scan identities for both successful and rejected scenarios.

Acceptance sequence

  1. Run repository creation, Hosted publish, download, restore, and immutable-overwrite rejection.
  2. Verify proxy connection, cache, negative cache, Group first-match order, and the anonymous proxy-only boundary.
  3. Prove OSV full and incremental tasks, CycloneDX scanning, and PASS, WARN, BLOCK, and NOT_EVALUATED outcomes.
  4. Verify risk-acceptance creation, reevaluation, expiry or revocation, and immutable-history behavior.
  5. Complete cleanup dry-run, real execution, archive or restore, and storage-transfer checksum controls.
  6. Reconcile Audit, Package Usage, Operation, Outbound, and task records with input and output evidence.

Exit criteria

  • Every critical flow has happy-path, authorization-denial, validation, and recoverable-failure results.
  • Every open item is marked as a gap, not a capability, with an owner, target date, and required evidence.
  • Production approval is given only after test scope, rollback decision, and platform owners are signed off.

Evidence-record template

Using the same fields for every test result makes it easier for different teams to rerun evidence and compare releases.

  • Test identity, date and time, executor, and approving owner
  • Application image, chart, or source reference plus PostgreSQL, storage, and client versions
  • Prerequisite, redacted input, repeatable command or action, and expected result
  • Actual result, checksum, correlation, task, scan, or audit identity, and evidence link
  • For failure, impact, recovery or rollback step, owner, and retest date

Production decision

Summarize results in one closure record; do not present conditional acceptance as full acceptance without evidence.

  • Proceed: all critical criteria passed, rollback was rehearsed, and operational owners approved.
  • Conditional proceed: only low-impact open items remain, each with a time-bound risk owner and rollback trigger.
  • Do not proceed: evidence is missing for data integrity, authorization, recovery, a critical format, or observability.

Post-acceptance record

Retain the approved scope, source snapshot, and topology. Rerun affected checks whenever image or chart, database migrations, storage, ingress, identity provider, client, or policy behavior changes.