====== C.3.8 DevSecOps Integration ====== [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:start|Go to Crucible Functional Requirements]] The [[dido:99_annexes:annex-b-terms-and-definitions:d:devsecops|Development, Security, and Operations (DevSecOps)]] Integration [[dido:99_annexes:annex-b-terms-and-definitions:f:functional_requirement|requirements]] define how [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] participates in Git-based workflows, applies GitOps practices, operates as part of a [[dido:99_annexes:annex-b-terms-and-definitions:c:ci_cd_pipeline|CI/CD Pipeline]], and performs automated build, deployment, and validation activities. Together, these requirements establish noninteractive and automated workflow behavior within a [[dido:99_annexes:annex-b-terms-and-definitions:d:devops|Development and Operations (DevOps)]] lifecycle. The requirements integrate security-related activities into development and operational workflows and contribute to controlled change, repeatable execution, [[dido:99_annexes:annex-b-terms-and-definitions:r:reproducibility|Reproducibility]], [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]], and [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]]. ===== Contents ===== {{indexmenu>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-08-devsecops-integration#1|js navbar nocookie maxjs#1 id#crucible_devsecops_integration_requirements_nav}} ===== Requirement Status ===== Review and approve the DevSecOps Integration requirement set. Review and approve FR-DSO-001 through FR-DSO-006 as leaf requirements. ---- ===== Issues ===== Confirm that the requirement set distinguishes Git-based workflow integration, GitOps workflow integration, and CI/CD Pipeline integration without overlapping normative behavior. Confirm that the automated build, deployment, and validation requirements identify independently verifiable operations. Confirm that controlled Terms and Definitions entries exist for all architectural concepts used by the leaf requirements. ---- ===== Notes for Editors ===== This page is a non-leaf requirement page and therefore retains a trailing '':start'' in its namespace. The namespace for this page is: ''dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-08-devsecops-integration:start'' Use the following controlling Terms and Definitions entries: * [[dido:99_annexes:annex-b-terms-and-definitions:d:devsecops|Development, Security, and Operations (DevSecOps)]] * [[dido:99_annexes:annex-b-terms-and-definitions:d:devops|Development and Operations (DevOps)]] * [[dido:99_annexes:annex-b-terms-and-definitions:c:ci_cd_pipeline|CI/CD Pipeline]] The individual requirement pages retain the stable identifiers ''FR-DSO-001'' through ''FR-DSO-006''. Individual requirement pages are leaf nodes nested beneath the DevSecOps Integration namespace and omit a trailing '':start''. The Derived From section on each leaf requirement page preserves the original wording from the controlling System Requirements Specification. Normalized Statements use direct, testable behavior and identify the repository state, workflow event, [[dido:99_annexes:annex-b-terms-and-definitions:c:ci_cd_pipeline|CI/CD Pipeline]] operation, input [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifact]], or required result only when the controlling source establishes that information. Verification criteria test only the behavior stated in the normalized Statement and do not introduce additional normative obligations. Incoming [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] uses the wiki Backlinks function rather than a manually maintained list. Each leaf requirement page includes its actual namespace in the DokuWiki section-transclusion example. Do not use a placeholder namespace in a completed leaf requirement page. Do not rename a requirement page after an external citation unless a redirect or move plan is in place. ---- © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.