Skip to content

[Epic]: k8s-aibom — registry-only component adoption (ADR-019) #2234

Description

@mchmarny

Goal

Admit GoogleCloudPlatform/k8s-aibom into the AICR component registry as an optional, provider-neutral Helm component, per ADR-019.

Scope is registry-only: the component exists in recipes/registry.yaml, custom and external recipes may opt in explicitly, and no stock recipe references it. Stock adoption and any runtime-observation evidence predicate are separate future decisions, explicitly out of scope here.

Acceptance bar: a user can add k8s-aibom to a custom recipe and get a digest-pinned, secure-by-default, health-checked deployment that renders identically through every supported deployer, while every stock recipe resolves to the same bytes it does today.

Status: complete

All seven sub-issues are closed. Both phases are delivered. ADR-019 moved from Proposed to Accepted on 2026-08-19.

Phase 2 landed atomically in #2259, merged 2026-08-19 at af9099fd.

The acceptance bar is met on main:

Acceptance claim Where it is proven
Registry entry, digest-pinned to the qualified set recipes/registry.yaml (chart 1.2.0, oci://ghcr.io/googlecloudplatform/charts, namespace k8s-aibom-system, aliases k8saibom/aibom)
Secure-by-default values recipes/components/k8s-aibom/values.yaml (no sink, no credentials, label-gated namespace discovery, readiness.strictConfig: true, non-root, read-only rootfs, all capabilities dropped)
Health check recipes/checks/k8s-aibom/health-check.yaml, gated on updatedReplicas and observedGeneration rather than availableReplicas alone
Renders identically across deployers pkg/bundler/k8s_aibom_render_parity_test.go; hasSelfRefCRDs: true handles the helm-diff REST-mapper case for Helmfile
Stock recipes unchanged pkg/bundler/testdata/stock_render_golden.yaml, pkg/recipe/testdata/catalog_parity_golden.yaml; no overlay or mixin references k8s-aibom
Produces a correct AIBOM tools/k8s-aibom-test/ Kind integration test with validate-bom
Mirror / air-gap discovery pkg/mirror/k8s_aibom_discover_test.go
Documented docs/user/component-catalog.md, docs/user/container-images.md, THIRD_PARTY_NOTICES.md

Nothing further is outstanding. The three issues this work surfaced are pre-existing AICR gaps, tracked separately, and listed below.

Qualified release

All four ADR-019 upstream gates passed on 2026-08-19 against this final immutable artifact set:

Item Qualified value
Source tag v1.2.0 at 4aa7638b08ab9927bfa8df85c46c80234b9996f9
Image ghcr.io/googlecloudplatform/k8s-aibom@sha256:b5040d14a20b4e890956d5f47b78445dac6c871eb5799586d9011c48ce71c198, multi-arch amd64/arm64
Chart oci://ghcr.io/googlecloudplatform/charts/k8s-aibom:1.2.0 at sha256:164ba4eeb8b2d3e817917cd3e312994030e4cda24046419d899fdcad4bcf6244; archive SHA-256 534d05b540bf82a0d8279e342a82606be187bca9480ff25e274d4f11bae00097
Attestations Image: SLSA provenance + CycloneDX SBOM; chart: SLSA provenance. Subjects bind the exact digests, use the upstream release workflow on a GitHub-hosted runner, and are transparency-logged. Observed SLSA Build Level 2.
Verification gh attestation verify constrained by upstream repo, release workflow, refs/tags/v1.2.0, source digest, predicate type, and --deny-self-hosted-runners
API aibom.k8saibom.dev/v1alpha1, experimental
Namespace k8s-aibom-system
Required AICR value readiness.strictConfig: true
Operational envelope 60s reconciliation/Kubernetes deadlines, 30s sink deadlines. At 1,000 workloads: 14s convergence, 230.4 mCPU / 47.5 MiB burst. Requests 50m/128Mi, limits 1 CPU/256Mi.
Upstream Kubernetes support 1.27-1.35. AICR's Kind 1.36.1 run is additional observed evidence, not an extension of upstream support. Registry documentation states this boundary.

Per ADR-019 Decision 4, AICR qualifies chart, image, CRDs, and the public status contract as one versioned set. A change to any of them requires requalification against the new exact release and digests.

Phase 1 findings and upstream responses are recorded in GoogleCloudPlatform/k8s-aibom#8.

Sequence

The supply-chain gate established the exact artifact identity every later gate reviewed, so it ran first. The other three gates were then independent and parallel. No implementation issue started until all four closed, per ADR-019.

#2235 supply chain                          [done]
  |-- #2236 Helm and Kubernetes lifecycle --+ [done]
  |-- #2237 security, RBAC, and privacy ----+ [done]
  |-- #2238 operational safety -------------+ [done]
                                            |
                                            v
                                      #2239 component                        [done]
                                        |-- #2240 deployer/vendor/mirror parity [done]
                                        |-- #2241 Kind AIBOM integration test    [done]

Sub-issues

Phase 1 - upstream qualification gates: complete. Findings work, no AICR code. Each closed with a recorded verdict and the commands that produced it.

# Title ADR gate Status
#2235 qualify the v1.2.0 release and supply chain Release and supply chain Closed 2026-08-18
#2236 qualify Helm and Kubernetes lifecycle Helm and Kubernetes lifecycle Closed 2026-08-18
#2237 qualify rendered RBAC, pod security, and privacy defaults Security and privacy, Decisions 5 and 6 Closed 2026-08-18
#2238 qualify the operational safety envelope Operational safety Closed 2026-08-19

Phase 2 - AICR implementation: complete. All three closed by #2259, landed as one PR so registry admission, cross-deployer qualification, and behavioral proof are atomic.

# Title ADR gate Status
#2239 add the registry entry, secure values, health check, and docs Implementation Deliverables, Decisions 1, 2, 5, 7 Closed 2026-08-19
#2240 prove deployer, vendoring, mirror, and stock-recipe parity AICR qualification Closed 2026-08-19
#2241 add the dedicated Kind AIBOM integration test AICR qualification Closed 2026-08-19

Target

AICR releases every other Monday. Target was the Sep 7 train. The work landed on main 2026-08-19, one train early, and rides the next release.

Surfaced by this epic, deliberately not fixed here

Qualification exercised bundler, mirror, and docs paths hard enough to expose three pre-existing AICR gaps. None is a k8s-aibom defect and none blocks this epic. Filed separately so the trail is not lost:

  • #2264 - Flux HelmRelease omits spec.upgrade, so existing CRDs are never updated on upgrade. Affects every component delivered via Flux, helm, and helmfile; Argo CD diverges. Elevated impact for the hasSelfRefCRDs set, which now includes k8s-aibom. feat(recipes): add qualified k8s-aibom component #2259 documented the behavior in one component's catalog entry, which is the wrong altitude for a fleet-wide property.
  • #2261 - pkg/mirror's Lister.Discover treats a values-load failure as a warning, so a component can contribute zero images to an air-gap mirror list while the command exits 0. Found while adding mirror coverage in k8s-aibom: prove deployer, vendoring, mirror, and stock-recipe parity #2240.
  • #2266 - 103 shell-block lines across 18 docs files use bare <placeholder> syntax that bash lexes as redirection.

Out of scope

Per ADR-019 Non-Goals:

  • Adding k8s-aibom to recipes/overlays/base.yaml, a leaf overlay, a mixin, or any stock recipe.
  • A new AICR evidence predicate for AIBOM output, or any change to ADR-007.
  • Making the component required for recipe generation, bundling, or validation when a recipe does not declare it.
  • Treating a bundle-time --set k8s-aibom:enabled=false as a recipe selection contract.
  • Implementing k8s-aibom as an AICR validator Job, forking its chart, or reimplementing its scrapers.
  • Consuming the upstream signature verifier. It is interesting, but it is not a dependency for registry-only adoption; revisit at stock-recipe adoption.
  • Provisioning sinks, buckets, webhook receivers, identities, credentials, or retention policies.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions