Stella Ops DevOps
Audience: release engineers and platform operators. Scope: the release, deployment, and migration playbooks that keep Stella Ops deterministic and offline-capable across environments.
The DevOps area collects the runbooks, CI contracts, and architecture guidance that govern how Stella Ops — the self-hosted DevOps vulnerability-scanner and release control plane — is built, signed, distributed, and upgraded on non-Kubernetes container estates.
Responsibilities
- Maintain CI pipelines, signing workflows, and release packaging steps.
- Operate shared runbooks for launch readiness, upgrades, and NuGet previews.
- Provide Offline Kit assembly guidance and tooling integration.
- Wrap observability and telemetry bootstrap flows for platform teams.
How this area is organised
- Architecture — architecture.md: the end-to-end blueprint for release trains, supply-chain signing, distribution, upgrades, and operations SLOs.
- Runbooks — step-by-step operational procedures under
runbooks/. - CI contracts — deterministic, offline-friendly pipeline definitions for the Console and Export Center surfaces (see below).
- Governance — governance-rules.md: the ratified platform rules that downstream sprints must not re-litigate.
Integrations & dependencies
- CI pipelines (Gitea, GitHub Actions) and artifact registries.
- Authority and Signer for supply-chain signing and proof-of-entitlement gating.
- Telemetry-stack bootstrap scripts.
Related resources
- architecture.md — DevOps release & operations blueprint.
- console-ci-contract.md — Console web-app CI contract.
- export-ci-contract.md — Export Center CI contract.
- governance-rules.md — platform governance rules anchor.
- policy-schema-export.md — Policy Engine schema export tool.
- runbooks/launch-readiness.md — launch readiness checklist.
- runbooks/launch-cutover.md — launch cutover rehearsal.
- runbooks/deployment-upgrade.md — deployment upgrade & rollback.
- runbooks/nuget-preview-bootstrap.md — NuGet preview bootstrap.
- Offline Kit packaging runbook — Offline bundle assembly.
Epic alignment
- Epic 1 – AOC enforcement: bake AOC verifier steps, CI guards, and schema validation into pipelines.
- Epic 9 – Orchestrator Dashboard: support operational dashboards, job-recovery runbooks, and rate-limit governance.
- Epic 10 – Export Center: manage signing workflows, Offline Kit packaging, and release promotion for exports.
- Epic 15 – Observability & Forensics: coordinate telemetry deployment, evidence retention, and forensic automation.
Working in this area
- Read AGENTS.md before picking up new work.
- Keep documentation, telemetry, and runbooks aligned with the latest sprint outcomes.
- Preserve deterministic behaviour and offline parity across releases; update the relevant runbook whenever release inventory, schemas, or guardrails change.
