Procedure
Validate deployment and product flows before production
Collect format, access, storage, security, and operational evidence in one technical-evaluation checklist.
Evidence-pack preparation
For every check, record the owner, environment, date, input, expected result, and evidence link.
- Freeze in-scope organizations, projects, repositories, formats, clients, and user roles.
- Test packages and SBOMs must not contain production data or secrets.
- Retain correlation, job, and scan identities for both successful and rejected scenarios.
Acceptance sequence
- Run repository creation, Hosted publish, download, restore, and immutable-overwrite rejection.
- Verify proxy connection, cache, negative cache, Group first-match order, and the anonymous proxy-only boundary.
- Prove OSV full and incremental tasks, CycloneDX scanning, and PASS, WARN, BLOCK, and NOT_EVALUATED outcomes.
- Verify risk-acceptance creation, reevaluation, expiry or revocation, and immutable-history behavior.
- Complete cleanup dry-run, real execution, archive or restore, and storage-transfer checksum controls.
- Reconcile Audit, Package Usage, Operation, Outbound, and task records with input and output evidence.
Exit criteria
- Every critical flow has happy-path, authorization-denial, validation, and recoverable-failure results.
- Every open item is marked as a gap, not a capability, with an owner, target date, and required evidence.
- Production approval is given only after test scope, rollback decision, and platform owners are signed off.
Evidence-record template
Using the same fields for every test result makes it easier for different teams to rerun evidence and compare releases.
- Test identity, date and time, executor, and approving owner
- Application image, chart, or source reference plus PostgreSQL, storage, and client versions
- Prerequisite, redacted input, repeatable command or action, and expected result
- Actual result, checksum, correlation, task, scan, or audit identity, and evidence link
- For failure, impact, recovery or rollback step, owner, and retest date
Production decision
Summarize results in one closure record; do not present conditional acceptance as full acceptance without evidence.
- Proceed: all critical criteria passed, rollback was rehearsed, and operational owners approved.
- Conditional proceed: only low-impact open items remain, each with a time-bound risk owner and rollback trigger.
- Do not proceed: evidence is missing for data integrity, authorization, recovery, a critical format, or observability.
Post-acceptance record
Retain the approved scope, source snapshot, and topology. Rerun affected checks whenever image or chart, database migrations, storage, ingress, identity provider, client, or policy behavior changes.