| Next revision | Previous revision |
| dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-08-devsecops-integration:start [2026/07/17 00:21] – created nick_dido | dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-08-devsecops-integration:start [2026/07/31 05:25] (current) – nick_dido |
|---|
| [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:start|Go to Crucible Functional Requirements]] | [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:start|Go to Crucible Functional Requirements]] |
| |
| The DevSecOps Integration [[dido:99_annexes:annex-b-terms-and-definitions:f:functional_requirement|requirements]] define how [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] participates in Git-based workflows, applies GitOps practices, operates as part of a [[dido:99_annexes:annex-b-terms-and-definitions:c:ci_cd_pipeline|CI/CD Pipeline]], and performs automated build, deployment, and validation activities. | The [[dido:99_annexes:annex-b-terms-and-definitions:d:devsecops|Development, Security, and Operations (DevSecOps)]] Integration [[dido:99_annexes:annex-b-terms-and-definitions:f:functional_requirement|requirements]] define how [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] participates in Git-based workflows, applies GitOps practices, operates as part of a [[dido:99_annexes:annex-b-terms-and-definitions:c:ci_cd_pipeline|CI/CD Pipeline]], and performs automated build, deployment, and validation activities. |
| |
| Together, these requirements establish noninteractive and automated workflow behavior that contributes to controlled change, repeatable execution, [[dido:99_annexes:annex-b-terms-and-definitions:r:reproducibility|Reproducibility]], [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]], and [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]]. | Together, these requirements establish noninteractive and automated workflow behavior within a [[dido:99_annexes:annex-b-terms-and-definitions:d:devops|Development and Operations (DevOps)]] lifecycle. The requirements integrate security-related activities into development and operational workflows and contribute to controlled change, repeatable execution, [[dido:99_annexes:annex-b-terms-and-definitions:r:reproducibility|Reproducibility]], [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]], and [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]]. |
| |
| ===== Contents ===== | ===== Contents ===== |
| {{indexmenu>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-08-devsecops-integration#1|js navbar nocookie maxjs#1 id#crucible_devsecops_integration_requirements_nav}} | {{indexmenu>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-08-devsecops-integration#1|js navbar nocookie maxjs#1 id#crucible_devsecops_integration_requirements_nav}} |
| |
| | ===== Requirement Status ===== |
| | |
| | <todo>Review and approve the DevSecOps Integration requirement set.</todo> |
| | |
| | <todo>Review and approve FR-DSO-001 through FR-DSO-006 as leaf requirements.</todo> |
| | |
| | ---- |
| | ===== Issues ===== |
| | |
| | <todo>Confirm that the requirement set distinguishes Git-based workflow integration, GitOps workflow integration, and CI/CD Pipeline integration without overlapping normative behavior.</todo> |
| | |
| | <todo>Confirm that the automated build, deployment, and validation requirements identify independently verifiable operations.</todo> |
| | |
| | <todo>Confirm that controlled Terms and Definitions entries exist for all architectural concepts used by the leaf requirements.</todo> |
| | |
| | ---- |
| ===== Notes for Editors ===== | ===== Notes for Editors ===== |
| |
| The individual requirement pages should retain the stable identifiers ''FR-DSO-001'' through ''FR-DSO-006''. | This page is a non-leaf requirement page and therefore retains a trailing '':start'' in its namespace. |
| | |
| | The namespace for this page is: |
| | |
| | ''dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-08-devsecops-integration:start'' |
| |
| Individual requirement pages are leaf nodes and should not include a trailing '':start'' in their namespaces. | Use the following controlling Terms and Definitions entries: |
| |
| The Source Statement on each requirement page should preserve the original wording from the controlling System Requirements Specification. | * [[dido:99_annexes:annex-b-terms-and-definitions:d:devsecops|Development, Security, and Operations (DevSecOps)]] |
| | * [[dido:99_annexes:annex-b-terms-and-definitions:d:devops|Development and Operations (DevOps)]] |
| | * [[dido:99_annexes:annex-b-terms-and-definitions:c:ci_cd_pipeline|CI/CD Pipeline]] |
| |
| Normalized Statements should use direct, testable behavior and should identify the applicable repository state, workflow event, [[dido:99_annexes:annex-b-terms-and-definitions:c:ci_cd_pipeline|CI/CD Pipeline]] operation, input [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifact]], and required result. | The individual requirement pages retain the stable identifiers ''FR-DSO-001'' through ''FR-DSO-006''. |
| |
| Verification criteria should test only the behavior stated in the normalized Statement and should not introduce additional normative obligations. | Individual requirement pages are leaf nodes nested beneath the DevSecOps Integration namespace and omit a trailing '':start''. |
| |
| Incoming [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] should use the wiki Backlinks function rather than a manually maintained list. | The Derived From section on each leaf requirement page preserves the original wording from the controlling System Requirements Specification. |
| |
| To reference a requirement Statement from another wiki page, insert: | Normalized Statements use direct, testable behavior and identify the repository state, workflow event, [[dido:99_annexes:annex-b-terms-and-definitions:c:ci_cd_pipeline|CI/CD Pipeline]] operation, input [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifact]], or required result only when the controlling source establishes that information. |
| |
| <code dokuwiki> | Verification criteria test only the behavior stated in the normalized Statement and do not introduce additional normative obligations. |
| {{section><namespace>#Statement&noheader&nofooter&noeditbtn}} | |
| </code> | |
| |
| Replace ''<namespace>'' with the namespace of the requirement leaf page. | Incoming [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] uses the wiki Backlinks function rather than a manually maintained list. |
| |
| The section name following ''#'' SHALL match the section heading verbatim on the requirement page. | Each leaf requirement page includes its actual namespace in the DokuWiki section-transclusion example. Do not use a placeholder namespace in a completed leaf requirement page. |
| |
| Do not rename a requirement page after an external citation unless a redirect or move plan is in place. | Do not rename a requirement page after an external citation unless a redirect or move plan is in place. |