Skip to content
About

Contribution and attribution

This handbook is maintained and documented under Satyam Agnihotri’s public identity, devSatym. That attribution identifies responsibility for the handbook; it does not assign original ownership of every system, tool, or capture it describes. The public profile is available on the About page.

Original implementation and upstream provenance

Section titled “Original implementation and upstream provenance”

The edition explains devSatym/gcp-supply-chain-security at the preserved GCP revision. The pinned merge record attributes the application/security component to musaumakau/supply-chain-security and the infrastructure/runtime component to musaumakau/gcp-infrastructure-modules. These links preserve upstream provenance without claiming that current upstream branches equal the reviewed baseline.

The documented canonical history combines those component histories. Adaptation, integration, and subsequent maintenance are different contributions from originally creating the upstream components. Existing license and attribution notices remain applicable to their respective source and dependencies. This website adds no blanket ownership claim to third-party work.

The handbook adds a responsibility-based explanation of the system rather than reproducing a file inventory. It traces the artifact across build, statements, verification, manual digest promotion, admission, and runtime observation. It also records the fields checked by each verifier, scope exclusions, optional or inactive paths, failure cases, and evidence gaps.

The independent static website adds reader navigation, production search, typed catalogues, source links pinned to full revisions, accessible SVG diagrams with text equivalents, and classified evidence panels. Its author/project model keeps verified destinations separate from proposed hostnames. The website build and publication process have their own trust model; they receive no protection from the historical cluster’s admission policy.

The actual handbook repository is the private devSatym/gcp-security-handbook, with its own Git history. Editing this website does not edit the original cloud implementation. Current documentation checks and publication state are recorded in the website engineering reports, including actual revisions and validation limits. They must not be inferred from this attribution page.

The original source project’s merge record documents the combination of application and infrastructure components, their parent histories, and the preserved nested infrastructure workflows. The handbook explains this topology and the executable root workflow graph; a retained nested workflow is provenance material rather than an active root GitHub Actions job.

Reviewed original Git history supports specific adaptation and integration work. It includes canonical monorepo identity wiring, PR scan handling, stricter verification, verifier registry access, and digest promotion. These changes support narrow contribution claims rather than sole original authorship of the whole system.

The edition is anchored to cbbc807c0c150e106affa89fbb1b9e8349005749. The source project’s reviewed current main is Azure, while this handbook teaches the preserved GCP implementation. Neither the author’s name nor the website’s hosting provider changes that baseline boundary. Checking out a historical tag or fork also does not reproduce canonical main-bound signing and GitOps identities without deliberate owned-environment changes.

The original project’s personal validation record reports a collection dated 23 August 2026; the capture commit records that addition. Its provenance differs from the older upstream material under docs/evidence/. The handbook preserves that distinction and explains the recorded context, expected and actual observations, and limits in acceptance evidence.

Those records describe historical artifact verification, cluster/GitOps status, admission rejection, and a controlled Falco event. They do not establish that a cluster exists or is healthy today. The combined wrong-trust experiment changes multiple trust fields; the mixed-container fixture exercises an unsigned init container beside a signed regular container. Neither observation should be expanded into tests that were not recorded. Optional Discord alert delivery remains an evidence gap.

Website builds, link audits, browser screenshots, and accessibility checks validate the handbook itself. They are separate from historical cloud execution and from remote publication. This page claims no employment impact metrics, production adoption, original authorship of upstream projects, or execution of the historical runbooks during website development.