| Next revision | Previous revision |
| dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-001:mo-001c [2026/07/20 07:55] – created nick_dido | dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-001:mo-001c [2026/07/30 05:20] (current) – nick_dido |
|---|
| ===== Statement ===== | ===== Statement ===== |
| |
| [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL produce equivalent [[dido:99_annexes:annex-b-terms-and-definitions:i:infrastructure_environment|Infrastructure Environments]] from equivalent [[dido:99_annexes:annex-b-terms-and-definitions:c:controlled_input|Controlled Inputs]] according to the applicable comparison criteria. | [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL reproduce an [[dido:99_annexes:annex-b-terms-and-definitions:i:infrastructure_environment|Infrastructure Environment]] from the same [[dido:99_annexes:annex-b-terms-and-definitions:c:controlled_input|Controlled Inputs]] in accordance with the defined equivalence criteria. |
| |
| ===== Derived From ===== | ===== Derived From ===== |
| > //Crucible SHALL enable rapid creation of repeatable, compliant, and secure infrastructure environments.//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]] | > //Crucible SHALL enable rapid creation of repeatable, compliant, and secure infrastructure environments.//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]] |
| |
| MO-001c preserves the portion of the Original Requirement that characterizes Infrastructure Environment creation as **repeatable**. | MO-001c preserves the portion of the Original Requirement that characterizes Infrastructure Environment creation as **repeatable** by requiring [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] to reproduce an Infrastructure Environment from the same Controlled Inputs. |
| |
| The separate requirements derived from MO-001 address: | The separate requirements derived from MO-001 address: |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-001:mo-001d|MO-001d — Security Baseline Conformance]] | * [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-001:mo-001d|MO-001d — Security Baseline Conformance]] |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-001:mo-001e|MO-001e — Compliance Baseline Conformance]] | * [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-001:mo-001e|MO-001e — Compliance Baseline Conformance]] |
| |
| ===== Assessment ===== | |
| |
| The Original Requirement uses **repeatable** without identifying: | |
| |
| * The inputs that remain controlled between executions | |
| * The criteria used to determine whether inputs are equivalent | |
| * The criteria used to determine whether resulting Infrastructure Environments are equivalent | |
| * The characteristics included in the comparison | |
| * The characteristics excluded from the comparison | |
| * The operational conditions under which the comparison occurs | |
| |
| The term **repeatable** therefore does not support objective verification. | |
| |
| MO-001c: | |
| |
| * Replaces **repeatable** with the defined concept [[dido:99_annexes:annex-b-terms-and-definitions:r:reproducibility|Reproducibility]] | |
| * Identifies [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] as the responsible actor | |
| * Identifies equivalent Controlled Inputs as the basis for repeated execution | |
| * Identifies equivalent Infrastructure Environments as the required outcome | |
| * Requires the equivalence determination to use applicable comparison criteria | |
| * Separates Reproducibility from environment creation, deployment duration, security, and compliance outcomes | |
| |
| ===== Rationale ===== | ===== Rationale ===== |
| |
| [[dido:99_annexes:annex-b-terms-and-definitions:r:reproducibility|Reproducibility]] enables an organization to recreate an Infrastructure Environment without relying on undocumented manual actions, uncontrolled inputs, or individual operator knowledge. | Reproducibility allows an organization to recreate an Infrastructure Environment from the same Controlled Inputs and determine whether the resulting environments satisfy defined equivalence criteria. |
| |
| Equivalent Controlled Inputs provide a stable basis for repeated execution. Controlled Inputs include identified versions and representations of the descriptions, baselines, configurations, packages, Machine Images, Image Layers, and other [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]] required to create the Infrastructure Environment. | The phrase **the same Controlled Inputs** requires reuse of the same identified input artifacts, configurations, baselines, revisions, and other controlled material. |
| |
| The applicable comparison criteria determine whether two Infrastructure Environments are equivalent. The comparison criteria identify the characteristics that require equality or permitted equivalence, including applicable: | The equivalence criteria determine which characteristics of the reproduced Infrastructure Environment must match the characteristics of the reference Infrastructure Environment. Exact byte-for-byte identity may not be required for every environment component, but any permitted variation must be defined. |
| |
| * Infrastructure resources | Reproducibility supports: |
| * Installed software | |
| * Software versions | |
| * Configuration values | |
| * Security settings | |
| * Network settings | |
| * Enabled services | |
| * Environment state | |
| * Artifact identifiers and revisions | |
| * Cryptographic digests | |
| * Deployment outputs | |
| |
| Some characteristics can differ without preventing equivalence when the comparison criteria explicitly permit the difference. Examples include generated identifiers, timestamps, assigned network addresses, hardware-specific values, and environment-specific secrets. | * Consistent environment creation |
| | * Controlled comparison of Infrastructure Environments |
| | * [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]] |
| | * [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] |
| | * Configuration control |
| | * Defect investigation |
| | * Recovery and replacement |
| | * Independent evaluation of security and compliance outcomes |
| |
| This requirement does not require every bit or runtime value in two Infrastructure Environments to be identical. It requires equivalence according to identified and applicable comparison criteria. | This requirement does not establish a deployment-duration threshold, [[dido:99_annexes:annex-b-terms-and-definitions:s:security_baseline|Security Baseline]], or [[dido:99_annexes:annex-b-terms-and-definitions:c:compliance_baseline|Compliance Baseline]]. The other requirements derived from MO-001 address those outcomes. |
| | |
| Separating Reproducibility from MO-001a permits Crucible to create an Infrastructure Environment successfully while independently passing or failing the Reproducibility requirement. | |
| |
| ===== Applies To ===== | ===== Applies To ===== |
| |
| * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] | * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] |
| * [[dido:99_annexes:annex-b-terms-and-definitions:r:reproducibility|Reproducibility]] | |
| * [[dido:99_annexes:annex-b-terms-and-definitions:i:infrastructure_environment|Infrastructure Environments]] | * [[dido:99_annexes:annex-b-terms-and-definitions:i:infrastructure_environment|Infrastructure Environments]] |
| | * Reference Infrastructure Environments |
| | * Reproduced Infrastructure Environments |
| * [[dido:99_annexes:annex-b-terms-and-definitions:c:controlled_input|Controlled Inputs]] | * [[dido:99_annexes:annex-b-terms-and-definitions:c:controlled_input|Controlled Inputs]] |
| | * Controlled Input identifiers and revisions |
| | * Defined equivalence criteria |
| * [[dido:99_annexes:annex-b-terms-and-definitions:d:declarative_description|Declarative Descriptions]] | * [[dido:99_annexes:annex-b-terms-and-definitions:d:declarative_description|Declarative Descriptions]] |
| * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible_description|Crucible Descriptions]] | * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible_description|Crucible Descriptions]] |
| * [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Images]] | * [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Images]] |
| * [[dido:99_annexes:annex-b-terms-and-definitions:i:infrastructure_configuration|Infrastructure Configurations]] | * [[dido:99_annexes:annex-b-terms-and-definitions:i:infrastructure_configuration|Infrastructure Configurations]] |
| * [[dido:99_annexes:annex-b-terms-and-definitions:i:infrastructure_deployment|Infrastructure Deployments]] | * [[dido:99_annexes:annex-b-terms-and-definitions:i:infrastructure_deployment|Infrastructure Deployment]] |
| * [[dido:99_annexes:annex-b-terms-and-definitions:p:provisioning|Provisioning]] | * [[dido:99_annexes:annex-b-terms-and-definitions:p:provisioning|Provisioning]] |
| * [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]] | * [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] |
| * [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]] | * [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]] |
| * [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] | * [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] |
| * [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] | |
| |
| ===== Verification ===== | ===== Verification ===== |
| Verification confirms that: | Verification confirms that: |
| |
| - Two or more executions use equivalent Controlled Inputs | - The reference Infrastructure Environment is identified |
| - Each execution creates an Infrastructure Environment | - The Controlled Inputs used to create the reference Infrastructure Environment are identified |
| - The applicable comparison criteria identify the characteristics included in the equivalence determination | - The same Controlled Inputs, including their identifiers and revisions, are used to create the reproduced Infrastructure Environment |
| - The applicable comparison criteria identify any permitted differences | - [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] creates the reproduced Infrastructure Environment |
| - The resulting Infrastructure Environments satisfy the applicable comparison criteria | - The equivalence criteria identify the characteristics compared between the reference and reproduced Infrastructure Environments |
| | - The reference and reproduced Infrastructure Environments satisfy the defined equivalence criteria |
| Verification includes: | - Any permitted differences between the reference and reproduced Infrastructure Environments conform to the equivalence criteria |
| | - The verification record preserves [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] among the Controlled Inputs, the reference Infrastructure Environment, the reproduced Infrastructure Environment, and the equivalence evaluation |
| * Controlled Input comparison | |
| * Input identifier and revision inspection | |
| * Artifact Representation comparison | |
| * Cryptographic digest inspection | |
| * Repeated Machine Image build tests | |
| * Repeated Infrastructure Deployment tests | |
| * Infrastructure state comparison | |
| * Software inventory comparison | |
| * Configuration comparison | |
| * Service-state comparison | |
| * Security-setting comparison | |
| * Network-configuration comparison | |
| * Deployment-output comparison | |
| * Provenance inspection | |
| * Traceability inspection | |
| | |
| The verification record identifies: | |
| | |
| - Each execution | |
| - The Controlled Inputs used for each execution | |
| - The input identifiers and revisions | |
| - The applicable Artifact Representations | |
| - The comparison criteria | |
| - The characteristics included in the comparison | |
| - The permitted differences | |
| - The resulting Infrastructure Environments | |
| - The comparison results | |
| - The observed result | |
| - The generated Evidence | |
| | |
| ===== Requirements Realized By ===== | |
| | |
| This requirement is realized by: | |
| | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-002|OR-002 — Deployment Environments]] | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003|OR-003 — Classified and Unclassified Environments]] | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-004|OR-004 — Concurrent Environment Management]] | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-005|OR-005 — Distributed Environment Management]] | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-01-configuration-management:start|FR-CFG-001 through FR-CFG-005]] | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:start|FR-IMG-001 through FR-IMG-006]] | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-03-deployment-orchestration:start|FR-DEP-001 through FR-DEP-007]] | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-08-devsecops-integration:start|FR-DSO-001 through FR-DSO-006]] | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-09-baseline-composition-and-workspace:start|FR-BAS-001 through FR-BAS-004]] | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-10-dependency-capture-and-offline-transfer:start|FR-DEPC-001 through FR-DEPC-005]] | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:13-key-value-proposition-requirements:kvp-003|KVP-003 — Improve Deployment Repeatability]] | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:13-key-value-proposition-requirements:kvp-005|KVP-005 — Reduce Configuration Drift]] | |
| | |
| ===== Related Architecture Sections ===== | |
| | |
| * [[dido:02-crusible:05-descriptions-composition-and-baselines:start|5. Descriptions, Composition, and Baselines]] | |
| * [[dido:02-crusible:06-machine-images-and-image-layers:start|6. Machine Images and Image Layers]] | |
| * [[dido:02-crusible:07-infrastructure-and-deployment:start|7. Infrastructure and Deployment]] | |
| * [[dido:02-crusible:08-dependencies-and-air-gap-operations:start|8. Dependencies and Air Gap Operations]] | |
| * [[dido:02-crusible:10-reproducibility-provenance-and-traceability:start|10. Reproducibility, Provenance, and Traceability]] | |
| |
| ===== Referenced By ===== | ===== Referenced By ===== |
| ===== Delivery Phase ===== | ===== Delivery Phase ===== |
| |
| Phase 1 and subsequent phases | Implemented and Verified |
| |
| ===== Implementation Status ===== | ===== Implementation Status ===== |
| |
| Not Assessed | <todo>Assess whether the current Crucible implementation reproduces Infrastructure Environments from the same Controlled Inputs in accordance with the defined equivalence criteria.</todo> |
| | |
| Implementation status requires repeated execution of the current Crucible implementation and comparison of the resulting Infrastructure Environments according to the applicable comparison criteria. | |
| |
| ===== Requirement Status ===== | ===== Requirement Status ===== |
| |
| Draft | <todo>Review and accept MO-001c as a proposed derived requirement created from the evaluation and decomposition of MO-001 in the Crucible System Requirements Specification, Version 1.1 Draft.</todo> |
| |
| This requirement derives from MO-001 in the Crucible System Requirements Specification, Version 1.1 Draft. | ---- |
| | ===== Issues ===== |
| | |
| | The following unresolved issues affect this requirement: |
| | |
| | <todo>Identify the controlling source that defines the equivalence criteria for reproduced Infrastructure Environments.</todo> |
| | |
| | <todo>Identify the Infrastructure Environment characteristics that must remain equivalent across repeated creation.</todo> |
| | |
| | <todo>Identify any permitted differences between the reference and reproduced Infrastructure Environments.</todo> |
| | |
| | <todo>Determine whether reproducibility requires identical Controlled Input revisions or permits controlled substitution of equivalent inputs.</todo> |
| |
| ---- | ---- |
| This page is a leaf requirement page and omits a trailing '':start'' from its namespace. | This page is a leaf requirement page and omits a trailing '':start'' from its namespace. |
| |
| Changes to the Statement SHALL preserve the Reproducibility intent derived from MO-001. | The parent MO-001 page is a non-leaf page and retains a trailing '':start'' in its namespace. |
| | |
| | Changes to the Statement should preserve: |
| |
| The applicable comparison criteria should identify: | * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] as the responsible actor |
| | * Reproduction of an [[dido:99_annexes:annex-b-terms-and-definitions:i:infrastructure_environment|Infrastructure Environment]] as the required outcome |
| | * Reuse of the same [[dido:99_annexes:annex-b-terms-and-definitions:c:controlled_input|Controlled Inputs]] |
| | * Evaluation of the reproduced Infrastructure Environment against defined equivalence criteria |
| |
| * The Controlled Inputs subject to comparison | The unresolved equivalence criteria should remain recorded in the Issues section until a controlling source defines them. |
| * The required input equivalence | |
| * The Infrastructure Environment characteristics subject to comparison | |
| * The required result equivalence | |
| * Permitted differences | |
| * Comparison methods | |
| * Acceptance thresholds | |
| * Required Evidence | |
| |
| Material changes should receive review and should update the related verification criteria, requirements realization, related architecture sections, and source records. | Material changes should receive review and should update the verification criteria, source records, and Issues section. |
| |
| To reference this requirement Statement from another wiki page, insert: | To reference this requirement Statement from another wiki page, insert: |