Skip to content

feat(security): add Brio runtime observer - #11

Open
kaanyagci wants to merge 6 commits into
chore/postgres-credential-syncfrom
feat/brio-runtime-observer
Open

feat(security): add Brio runtime observer#11
kaanyagci wants to merge 6 commits into
chore/postgres-credential-syncfrom
feat/brio-runtime-observer

Conversation

@kaanyagci

Copy link
Copy Markdown
Member

Summary

  • install a locked, forced-command SSH observer for the Brio release runner
  • attest the exact running PostgreSQL image, image ID, version, health, lifecycle, and container identity
  • run the observer hardening contract through the existing complete CI harness

Validation

  • ./scripts/run-ci.sh
  • bash scripts/test-brio-runtime-observer.sh
  • shellcheck scripts/brio-runtime-observe.sh scripts/install-brio-runtime-observer.sh scripts/test-brio-runtime-observer.sh
  • git diff --check

Stacked on PR #10 so the Proton/GitHub provider contract remains the source of credential truth.

@kaanyagci
kaanyagci force-pushed the feat/brio-runtime-observer branch from becea64 to eb8b9fd Compare September 5, 2026 08:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant