| Both sides previous revision Previous revision Next revision | Previous revision |
| dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-001 [2026/07/20 07:08] – ↷ Links adapted because of a move operation nick_dido | dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-001 [2026/07/30 05:37] (current) – nick_dido |
|---|
| ===== Statement ===== | ===== Statement ===== |
| |
| [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL build a [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Image]]. | [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL build [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Images]]. |
| |
| ===== Source Statement ===== | ===== Derived From ===== |
| |
| > The system shall build virtual machine images. | This requirement derives from: |
| |
| ===== Source ===== | * Crucible System Requirements Specification, Version 1.1 Draft, Functional Requirements, FR-IMG-001 |
| |
| Crucible System Requirements Specification, Version 1.1 Draft, Functional Requirements, FR-IMG-001. | The Original Requirement states: |
| |
| ===== Assessment ===== | > //The system shall build virtual machine images.//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]] |
| |
| The source statement expresses a direct functional behavior but requires normalization of terminology. | FR-IMG-001: |
| |
| The following Specification, Discipline, and Authoring findings apply: | * Replaces **The system** with the defined system name [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] |
| | * Changes **shall** to the established uppercase normative form **SHALL** |
| | * Replaces **virtual machine images** with the defined term [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Images]] |
| |
| * **The system** does not use the defined system name | No other substantive normalization is required. |
| * **shall** does not follow the established uppercase normative convention | |
| * **virtual machine images** does not use the defined [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Image]] term | |
| * The source statement does not identify a particular image format, target platform, build tool, or build method | |
| * The source statement does not require image signing, image verification, image promotion, compliance assessment, or deployment | |
| | |
| The normalized Statement: | |
| | |
| * Replaces **The system** with [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] | |
| * Uses the direct and testable verb **build** | |
| * Replaces **virtual machine images** with the defined Machine Image term | |
| * Preserves the implementation independence of the source requirement | |
| * Retains one primary required behavior | |
| | |
| The normalized Statement does not add requirements for the contents, format, signing, verification, promotion, compliance, or deployment of the resulting Machine Image. Separate requirements define those obligations. | |
| |
| ===== Rationale ===== | ===== Rationale ===== |
| |
| A [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Image]] captures the software, configuration, and other image content required to instantiate a virtual machine. | A [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Image]] provides the software, configuration, and other image content required to instantiate a virtual machine. |
| | |
| Building Machine Images through [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] allows the Image Management workflow to create image [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]] for later verification, signing, promotion, distribution, and deployment. | |
| | |
| Machine Image building contributes to: | |
| | |
| * Repeatable image creation | |
| * Controlled image content | |
| * Consistent virtual machine instantiation | |
| * Automated image workflows | |
| * [[dido:99_annexes:annex-b-terms-and-definitions:r:reproducibility|Reproducibility]] | |
| * [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]] | |
| * [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] | |
| | |
| The build operation may consume: | |
| | |
| * A [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible_description|Crucible Description]] | |
| * One or more [[dido:99_annexes:annex-b-terms-and-definitions:i:image_layer|Image Layers]] | |
| * A selected [[dido:99_annexes:annex-b-terms-and-definitions:b:baseline|Baseline]] | |
| * Configuration values | |
| * Software packages | |
| * Operating-system content | |
| * Build scripts | |
| * Other controlled input [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]] | |
| |
| The applicable architecture and lower-level requirements determine which inputs apply to a particular Machine Image build. | Building Machine Images enables Crucible to produce image [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]] for use by separately governed verification, signing, promotion, distribution, and deployment activities. |
| |
| ===== Applies To ===== | ===== Applies To ===== |
| * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] | * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] |
| * [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Images]] | * [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Images]] |
| * Machine Image builds | * Machine Image build operations |
| * Machine Image build inputs | |
| * Machine Image build outputs | |
| * [[dido:99_annexes:annex-b-terms-and-definitions:i:image_layer|Image Layers]] | |
| * [[dido:99_annexes:annex-b-terms-and-definitions:b:baseline|Baselines]] | |
| * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible_description|Crucible Descriptions]] | |
| * Build tools | |
| * Build workflows | |
| * Virtual machine platforms | |
| * [[dido:99_annexes:annex-b-terms-and-definitions:c:ci_cd_pipeline|CI/CD Pipelines]] | |
| |
| ===== Verification ===== | ===== Verification ===== |
| |
| - Verification SHALL confirm that [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] executes a Machine Image build | Verification confirms that: |
| - Verification SHALL confirm that the build produces a [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Image]] | |
| |
| Verification may include: | - [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] executes a Machine Image build |
| | - The completed build produces a [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Image]] |
| * Machine Image build testing | - The resulting Machine Image can be identified as the output of the tested build |
| * Build-output inspection | |
| * Machine Image artifact inspection | |
| * Build-log inspection | |
| * Automated [[dido:99_annexes:annex-b-terms-and-definitions:c:ci_cd_pipeline|CI/CD Pipeline]] testing | |
| | |
| The verification record SHALL identify: | |
| | |
| - The tested Machine Image build | |
| - The resulting Machine Image | |
| - The build result | |
| - The observed output | |
| - The generated [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] | |
| | |
| ===== Outgoing Traceability ===== | |
| | |
| This requirement realizes: | |
| | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-001:start|MO-001]] | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-005|MO-005]] | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-006|MO-006]] | |
| | |
| This requirement relates to: | |
| | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-003|FR-IMG-003 — Immutable Infrastructure Workflows]] | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-004|FR-IMG-004 — Image Signing]] | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-005|FR-IMG-005 — Image Verification]] | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-006|FR-IMG-006 — Image Promotion Workflows]] | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-03-deployment-orchestration:fr-dep-002|FR-DEP-002 — Deploy Virtual Machines]] | |
| * [[dido:02-crusible:06-machine-images-and-image-layers:start|6. Machine Images and Image Layers]] | |
| * [[dido:02-crusible:10-reproducibility-provenance-and-traceability:start|10. Reproducibility, Provenance, and Traceability]] | |
| |
| ===== Referenced By ===== | ===== Referenced By ===== |
| |
| The wiki Backlinks function provides the current list of pages that reference ''FR-IMG-001''. | The following pages reference this requirement: |
| | |
| Incoming [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] should be derived dynamically from backlinks rather than maintained as a duplicate manual list. | |
| | |
| Backlinks identify incoming references but do not define the semantics of each relationship. Referencing pages should identify whether the relationship represents realization, refinement, verification, dependency, or another defined traceability relationship. | |
| | |
| ===== ConOps Relationship ===== | |
| | |
| The Crucible Concept of Operations describes a Phase 1 workflow in which a [[dido:99_annexes:annex-b-terms-and-definitions:c:ci_cd_pipeline|CI/CD Pipeline]] invokes [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] to compose selected inputs and build a hardened [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Image]]. | |
| | |
| FR-IMG-001 establishes the required Machine Image build behavior within that workflow. | |
| | |
| Requirements governing image composition, hardening, signing, verification, promotion, compliance, and deployment define separate behavior associated with the resulting Machine Image. | |
| | |
| ===== Delivery Phase ===== | |
| |
| Phase 1 | {{backlinks>.#dido:02-crusible}} |
| |
| ===== Implementation Status ===== | ===== Implementation Status ===== |
| |
| Not Assessed | Implemented and Verified |
| | |
| Implementation status requires verification that [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] builds a [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Image]]. | |
| |
| ===== Requirement Status ===== | ===== Requirement Status ===== |
| |
| Draft | <todo>Review and approve FR-IMG-001 as a leaf requirement.</todo> |
| |
| The source System Requirements Specification identifies Version 1.1 as a draft. | ---- |
| | ===== Issues ===== |
| | |
| | <todo>Determine whether separate requirements define the minimum required contents of a Machine Image.</todo> |
| |
| ---- | ---- |
| ===== Notes for Editors ===== | ===== Notes for Editors ===== |
| |
| This requirement page should retain the stable requirement identifier ''FR-IMG-001''. | This requirement page retains the stable requirement identifier ''FR-IMG-001''. |
| |
| Changes to the Statement SHALL preserve the approved intent of the source requirement. | This page is a leaf requirement page and omits a trailing '':start'' from its namespace. |
| |
| The Source Statement should preserve the original wording from the controlling System Requirements Specification. | The Statement preserves the approved source intent by requiring Crucible to build Machine Images. |
| |
| The Statement should remain limited to building a Machine Image. | Do not add image composition, hardening, signing, verification, promotion, compliance assessment, distribution, or deployment obligations to the Statement unless the controlling requirement changes through an approved requirements process. |
| | |
| Requirements for image composition, hardening, signing, verification, promotion, compliance assessment, distribution, and deployment should remain in their applicable requirement pages. | |
| | |
| Verification criteria should test only the behavior stated in the normalized Statement and should not introduce additional normative obligations. | |
| | |
| Incoming Traceability should use the wiki Backlinks function rather than a manually maintained list. | |
| |
| To reference this requirement Statement from another wiki page, insert: | To reference this requirement Statement from another wiki page, insert: |
| {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-001#Statement&noheader&nofooter&noeditbtn}} | {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:fr-img-001#Statement&noheader&nofooter&noeditbtn}} |
| </code> | </code> |
| |
| Do not rename this page after an external citation unless a redirect or move plan is in place. | |
| |
| ---- | ---- |