Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions MANIFEST.txt
Original file line number Diff line number Diff line change
Expand Up @@ -54,6 +54,8 @@ docs/architecture/ops-ingestion-and-measurement-plane.md
docs/architecture/runtime-control-plane-telemetry-alignment.md
docs/architecture/support-and-premium-support-ai4it-loop.md
docs/architecture/telemetry-surface-profile.md
docs/competitive/superiority-march.md
docs/competitive/where-we-stand.md
docs/devops/ci-validation-gate.md
docs/devops/client-runtime-dump-exposure.md
docs/devops/devops-process-open.md
Expand Down Expand Up @@ -97,12 +99,15 @@ open-ai4it-spec/modules/story_services/README.md
open-ai4it-spec/modules/story_services/incident_similarity/scorer.py
profiles/browser-telemetry-risk-profile.v0.yaml
profiles/client-runtime-dump-exposure-profile.v0.yaml
profiles/competitive-landscape-profile.v0.yaml
profiles/github-footprint-itops-expansion.yaml
profiles/operational-exhaust-fusion-profile.v0.yaml
requirements.txt
schemas/competitive-landscape.schema.json
schemas/github-footprint-itops-generated.schema.json
serve.py
source_inputs/README.md
source_inputs/competitive-intel/landscape.v0.yaml
source_inputs/institutional-account/account-hierarchy.v0.json
source_inputs/integration-planes/ops-integration-map.v0.json
source_inputs/ontogenesis/module-map.v0.json
Expand All @@ -113,6 +118,7 @@ third_party/ibm-itops/GLO_V1-profile-excerpt.ttl
third_party/ibm-itops/IMPORT-MANIFEST.v2.json
third_party/ibm-itops/LICENSE.Apache-2.0
third_party/ibm-itops/UPSTREAM.md
tools/generate_competitive_gap_register.py
tools/generate_github_footprint_itops_projection.py
tools/mesh_consume.py
tools/tests/fixtures/client-runtime-dump-exposure/allowed-synthetic.txt
Expand All @@ -128,6 +134,7 @@ tools/tests/test_resource_contract_verdict.py
tools/tests/test_serve.py
tools/tests/test_service_desk_metrics.py
tools/validate_client_runtime_dump_exposure.py
tools/validate_competitive_landscape.py
tools/validate_github_footprint_itops.py
tools/validate_incident_similarity.py
tools/validate_manifest.py
Expand Down
43 changes: 43 additions & 0 deletions docs/competitive/superiority-march.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
# The Superiority March

> The plan to answer [`where-we-stand.md`](where-we-stand.md): close **every** capability gap, but
> do each one **faster, more secure, more ergonomic, and fully open** than the incumbent — so a gap
> becomes a differentiated win, not parity. Generated register is the scoreboard; this is the march.

## Doctrine (how "we win, and open" is different from "we catch up")

Every incumbent capability we're behind on is either (a) SaaS/closed, (b) advisory not enforced, or
(c) audit-logged but not cryptographically verifiable. Our answer to each is the same shape:

- **Faster** — scale-to-zero, event-driven, deterministic-first (the model is a thin edge, not the gate).
- **More secure** — fail-closed by default; every action pre-gated by policy AND sealed into evidence.
- **More ergonomic** — agent-native (MCP) + one-command golden paths; the platform is drivable by an agent.
- **Fully open** — MIT, self-hosted, our own Gitea/zot/runners; no external SaaS, no lock-in, and
**standards-based** provenance (cosign/SLSA/in-toto) so trust is externally verifiable, not self-issued.

## The sequenced moves (dependency order; each closes ranked gaps)

| # | Move | Closes (gap register) | Our open edge over the leader | Status |
|---|------|----------------------|-------------------------------|--------|
| 1 | **Governed MCP ops surface** on the control plane | `agent-native-mcp-ops-surface` (#1, 8 ahead) | Qovery/Port gate pre-exec + audit-log (SaaS). We add **fail-closed + hash-sealed receipts on every tool call**, fully open, scale-to-zero. | **executing** |
| 2 | **Wire observability** (Prometheus/Grafana/Loki/Tempo behind the OTel collector) | keystone for #2/chaos/autoscale | Open OTel stack, self-hosted; unblocks metric-gated everything. | next |
| 3 | **Metric-gated progressive delivery** (canary/blue-green + auto-rollback + our sealed promotion gate) | `progressive-delivery-auto-rollback` (#2, 6 ahead) | Argo Rollouts analysis, but **gated by our sealed APPROVE verdict** and evidenced — auto-rollback *and* provenance. | sequenced |
| 4 | **Standards-based attestation** (emit cosign/SLSA/in-toto via our `zot`) alongside receipts | `attestation-provenance-slsa`, and repairs the "self-issued receipts" weakness | **Externally verifiable** provenance (public-log-compatible) + our governed enforcement wrapper on top. | sequenced |
| 5 | **Service mesh** (Istio mTLS + gateway; MeshSpace-style header routing) | mesh net-new (diagrams) | Open Istio, sovereign; enables canary traffic-shifting. | sequenced |
| 6 | **Autonomous fix-and-verify remediation** (re-vendor executor + reviewer → propose+validate fix) | `autonomous-remediation-agents`, `malicious-package-detection` | Endor/Harness fix (SaaS). Ours: sealed, fail-closed, open; add reachability + malicious-package signal to the loop. | sequenced |
| 7 | **Broad-ecosystem dependency intelligence** (reachability + confidence + malicious-package) | `vuln-db-broad-scanning`, `reachability-exploitability`, `broad-ecosystem-dep-automation` | Consume OSS advisory data (OSV) + reachability; keep it sovereign + receipted. | sequenced |
| 8 | **Developer portal + inner-loop dev-environments** (Nocalhost-style DevSpace + web console) | `web-ui-developer-portal`, dev-env diagrams | Open catalog + golden paths over CapD; agent-driven via move #1. | sequenced |
| 9 | **Compliance evidence automation** (map sealed receipts + attestations → SOC2/FedRAMP controls) | `compliance-certifications` | Turn our provenance into audit evidence; open control mappings. | sequenced |

## Meet-or-beat on the reference diagrams

- **Nocalhost DevSpace/MeshSpace, Istio mesh** → moves #5, #8 (we're behind; open Istio + DevSpace).
- **Sovereign Agentic Cloud-Shell, Agent Governance Architecture** → move #1 realizes these; they are *our* design — the march makes them real and shipped.
- **Karpathy wiki pipeline** → already realized: this intelligence suite *is* structured-knowledge + generated projections.
- **prophet-platform readiness (Have/Partial/Net-new)** → observability keystone = move #2; mesh/canary/chaos = moves #3/#5.

## Non-skimp clause

Each move ships the nice-to-haves that make it ergonomic, not just the minimum: MCP tool schemas +
elicitation, one-command golden paths, sealed receipts on every action, and standards-based
attestation — because "more ergonomic and fully open" is the whole point of the march.
Loading
Loading