Version v0.1 of the documentation is no longer actively maintained. The site that you are currently viewing is an archived snapshot. For up-to-date documentation, see the latest version.

Acceptance matrix

Evidence expected for the initial secure template release.
RequirementEvidence
Versioned strict contractsSchema and positive/negative fixture tests
Visible wrapper commandsCLI, runner, lifecycle, and adapter tests
No template hardcodingContract-driven discovery and fixtures
Pinned Hetzner templateProvider lock, image enum, validation
Secure SSH and keysSchema, policy, plan, and host tests
Safe stateBackend capability validation
Secret-free outputStrict schema, redaction, Gitleaks
Local validation gatesscripts/validate-all, scripts/test-all
Standalone Rust productNo Python package; installed-shell no-tool test
Disposable lifecycleApproved live apply, idempotence, and teardown
Clear portfolio boundariesREADME and architecture review
No unsafe donor behaviorNegative policy and plan tests
No GitHub workflowsRepository-policy test

Every release criterion maps to an automated local check or documented manual verification with sanitized evidence. A claim without one of those forms of evidence remains unverified.