Choose a reading path
Choose the route that matches the decision you need to make. Each route reaches a useful conclusion without requiring every chapter. Return to the glossary when a term interrupts the reasoning.
Project reviewer
Section titled “Project reviewer”You want to know whether implementation and evidence support the project’s claims.
- Read scope and revisions to establish exactly which source and execution records are being evaluated.
- Take the guided tour to follow an image digest into deployment and runtime observation.
- Compare CI and admission verification to understand what each boundary actually checks.
- Inspect trusted versus unsigned results and the combined wrong-trust experiment for evidence strength and limitations.
- Read known gaps before drawing a conclusion about coverage.
Useful review output: identify which properties are source-backed, which have recorded execution, and which remain assumptions. In particular, distinguish configured CODEOWNERS/rulesets from enforced remote repository settings, and distinguish a newer verified image from the image selected in Git.
Security deep dive
Section titled “Security deep dive”You want to understand why the controls exist and how they interact.
- Begin with assets and threats and trust boundaries.
- Separate identity and authority from artifact identity.
- Study the claims carried by signatures and attestations, then why verification happens twice.
- Examine shared failure dependencies and admission scope.
- Cross the gap between admission and runtime.
Useful analysis output: for a concrete attacker, name the asset, unsafe assumption, enforcing actor, input checked, and remaining path to compromise. A tool name alone is not a security property.
Hands-on historical reproduction
Section titled “Hands-on historical reproduction”You want an owned environment in which to inspect or repeat the design deliberately.
- Run safe local inspection before obtaining cloud access.
- Read reproduction prerequisites, including cost ownership and repository/ref rebinding.
- Follow bootstrap dependencies and identity/GitOps wiring.
- Use first release and evidence collection to record source, artifact, selected desired state, and observed result separately.
- Prepare boundary-based troubleshooting and cleanup with evidence retention before cloud mutation.
Useful operational output: a written map of identities and configuration expected in your own environment. Checking out final-gcp-commit is insufficient because its certificate expectations and Argo source bind to canonical main. The website does not authorize running historical workflows against the original owner’s project.
All paths ultimately return to the source-backed workflow and historical evidence record. Use both: source describes the contract; observations describe particular executions.