-
Notifications
You must be signed in to change notification settings - Fork 724
Automated Governance: does the TAG want it back as an initiative, and where do its documents live? #2301
Copy link
Copy link
Open
Labels
needs-groupIndicates an issue or PR that has not been assigned a group (toc or tag/foo label applied)Indicates an issue or PR that has not been assigned a group (toc or tag/foo label applied)needs-kindIndicates an issue or PR that is missing an issue type or kind (a kind/foo label)Indicates an issue or PR that is missing an issue type or kind (a kind/foo label)needs-triageIndicates an issue or PR that has not been triaged yet (has a 'triage/foo' label applied)Indicates an issue or PR that has not been triaged yet (has a 'triage/foo' label applied)tag/security-and-complianceTAG Security and ComplianceTAG Security and Compliance
Description
Activity
Metadata
Metadata
Assignees
Labels
needs-groupIndicates an issue or PR that has not been assigned a group (toc or tag/foo label applied)Indicates an issue or PR that has not been assigned a group (toc or tag/foo label applied)needs-kindIndicates an issue or PR that is missing an issue type or kind (a kind/foo label)Indicates an issue or PR that is missing an issue type or kind (a kind/foo label)needs-triageIndicates an issue or PR that has not been triaged yet (has a 'triage/foo' label applied)Indicates an issue or PR that has not been triaged yet (has a 'triage/foo' label applied)tag/security-and-complianceTAG Security and ComplianceTAG Security and Compliance
Type
Projects
- StatusShow more project fieldsNew
- StatusShow more project fieldsNo status
- StatusShow more project fieldsNo status
- StatusShow more project fieldsNo status
- StatusShow more project fieldsNo status
- StatusShow more project fieldsNo status
Automated Governance has a finished deliverable and no longer has a home in the tree. The working group's README and the Automated Governance Maturity Model both sit in cncf/tag-security, archived and last pushed 2025-12-08. The controls catalog and supply-chain work that succeeded it sit in
cncf/toc/tags/tag-security-and-compliance/.The maturity model is about eighteen kilobytes of finished text. It gives an organization a scale for the maturity of the controls an automated governance programme needs, without scoring a specific implementation.
Does the TAG want Automated Governance back as an initiative, and where do its documents live now the source repository is archived? If the answer to the first is yes, I will do the carry-across. That means porting the maturity model to the new location, opening the PR, and taking the initiative's maintenance.
The scale has a shipped consumer: four admission rails, OPA rego, Kyverno CEL, Kyverno JMESPath and CUE, run in CI at https://github.com/probityai/agent-evidence-admission
Edited 2026-09-22: updated a repository URL to its current path, and split one long sentence in two.