← Files OpsTruthARCHIVED FILE

contracts/action-request.schema.json

6.63 KB · Oct 3, 2026 · 06:32 UTC

↓ Download file

{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "$id": "urn:opstruth:schema:action-request:1.0.0",
  "title": "OpsTruth ActionRequest v1",
  "type": "object",
  "additionalProperties": false,
  "required": [
    "schema",
    "schemaVersion",
    "requestId",
    "createdAt",
    "expiresAt",
    "issuer",
    "subject",
    "findingRefs",
    "requestedOutcome",
    "permittedOperations",
    "forbiddenOperations",
    "constraints",
    "approvalRequirement",
    "idempotencyKey",
    "digest"
  ],
  "properties": {
    "schema": { "const": "opstruth.action-request" },
    "schemaVersion": { "const": "1.0.0" },
    "requestId": { "$ref": "#/$defs/urn" },
    "createdAt": { "$ref": "#/$defs/timestamp" },
    "expiresAt": { "$ref": "#/$defs/timestamp" },
    "issuer": { "$ref": "#/$defs/identity" },
    "subject": { "$ref": "#/$defs/subject" },
    "findingRefs": {
      "type": "array",
      "minItems": 1,
      "maxItems": 100,
      "uniqueItems": true,
      "items": { "$ref": "#/$defs/reference" }
    },
    "requestedOutcome": {
      "type": "object",
      "additionalProperties": false,
      "required": ["description", "assertions"],
      "properties": {
        "description": { "type": "string", "minLength": 3, "maxLength": 2000 },
        "assertions": {
          "type": "array",
          "minItems": 1,
          "maxItems": 100,
          "items": { "$ref": "#/$defs/assertion" }
        }
      }
    },
    "permittedOperations": {
      "type": "array",
      "minItems": 1,
      "maxItems": 20,
      "uniqueItems": true,
      "items": { "$ref": "#/$defs/operationType" }
    },
    "forbiddenOperations": {
      "type": "array",
      "maxItems": 20,
      "uniqueItems": true,
      "items": { "$ref": "#/$defs/operationType" }
    },
    "constraints": { "$ref": "#/$defs/constraints" },
    "approvalRequirement": {
      "type": "object",
      "additionalProperties": false,
      "required": ["required", "minimumApprovals", "allowedApproverIds"],
      "properties": {
        "required": { "const": true },
        "minimumApprovals": { "const": 1 },
        "allowedApproverIds": {
          "type": "array",
          "minItems": 1,
          "maxItems": 50,
          "uniqueItems": true,
          "items": { "$ref": "#/$defs/urn" }
        }
      }
    },
    "idempotencyKey": { "type": "string", "minLength": 16, "maxLength": 200, "pattern": "^[A-Za-z0-9._:-]+$" },
    "digest": { "$ref": "#/$defs/digest" }
  },
  "$defs": {
    "urn": { "type": "string", "minLength": 8, "maxLength": 300, "pattern": "^urn:[A-Za-z0-9][A-Za-z0-9:._-]+$" },
    "timestamp": { "type": "string", "format": "date-time" },
    "digest": { "type": "string", "pattern": "^sha256:[a-f0-9]{64}$" },
    "identity": {
      "type": "object",
      "additionalProperties": false,
      "required": ["id", "type"],
      "properties": {
        "id": { "$ref": "#/$defs/urn" },
        "type": { "enum": ["service", "human", "policy"] }
      }
    },
    "subject": {
      "type": "object",
      "additionalProperties": false,
      "required": ["provider", "repositoryId", "baselineCommitSha"],
      "properties": {
        "provider": { "enum": ["github"] },
        "repositoryId": { "type": "string", "minLength": 1, "maxLength": 100 },
        "repositoryName": { "type": "string", "minLength": 3, "maxLength": 240 },
        "baselineCommitSha": { "type": "string", "pattern": "^[a-f0-9]{40}$" },
        "environment": { "type": "string", "minLength": 1, "maxLength": 100 }
      }
    },
    "reference": {
      "type": "object",
      "additionalProperties": false,
      "required": ["id", "digest"],
      "properties": {
        "id": { "$ref": "#/$defs/urn" },
        "digest": { "$ref": "#/$defs/digest" }
      }
    },
    "assertion": {
      "type": "object",
      "additionalProperties": false,
      "required": ["assertionId", "description", "target", "predicate", "expected", "evidenceRequirements"],
      "properties": {
        "assertionId": { "type": "string", "minLength": 1, "maxLength": 100, "pattern": "^[A-Za-z0-9._:-]+$" },
        "description": { "type": "string", "minLength": 3, "maxLength": 1000 },
        "target": {
          "type": "object",
          "additionalProperties": false,
          "required": ["nodeType", "field", "match"],
          "properties": {
            "nodeType": { "enum": ["repository", "commit", "ci_run", "artifact", "deployment", "runtime_observation", "configuration"] },
            "field": { "enum": ["exists", "sha", "headCommitSha", "contentDigest", "commitSha", "status", "ok"] },
            "match": {
              "type": "object",
              "additionalProperties": false,
              "properties": {
                "path": { "type": "string", "minLength": 1, "maxLength": 200, "pattern": "^/" },
                "environment": { "type": "string", "minLength": 1, "maxLength": 100 },
                "id": { "type": "string", "minLength": 1, "maxLength": 300 },
                "current": { "type": "boolean" }
              }
            }
          }
        },
        "predicate": { "enum": ["equals", "exists", "absent", "matches_digest", "status_in", "reachable"] },
        "expected": true,
        "evidenceRequirements": {
          "type": "array",
          "minItems": 1,
          "maxItems": 20,
          "uniqueItems": true,
          "items": { "enum": ["repository", "commit", "ci_run", "artifact", "deployment", "runtime_observation", "configuration"] }
        }
      }
    },
    "operationType": {
      "enum": [
        "modify_source",
        "run_declared_checks",
        "create_commit",
        "push_branch",
        "open_pull_request",
        "deploy",
        "rollback",
        "update_configuration",
        "rotate_secret"
      ]
    },
    "constraints": {
      "type": "object",
      "additionalProperties": false,
      "required": ["allowedPaths", "deniedPaths", "allowedEnvironments", "networkPolicy", "maxDurationSeconds", "maxOperations"],
      "properties": {
        "allowedPaths": { "type": "array", "maxItems": 200, "uniqueItems": true, "items": { "type": "string", "minLength": 1, "maxLength": 300 } },
        "deniedPaths": { "type": "array", "maxItems": 200, "uniqueItems": true, "items": { "type": "string", "minLength": 1, "maxLength": 300 } },
        "allowedEnvironments": { "type": "array", "maxItems": 20, "uniqueItems": true, "items": { "type": "string", "minLength": 1, "maxLength": 100 } },
        "networkPolicy": { "enum": ["disabled", "dependency_acquisition_only", "allowlisted"] },
        "maxDurationSeconds": { "type": "integer", "minimum": 1, "maximum": 86400 },
        "maxOperations": { "type": "integer", "minimum": 1, "maximum": 1000 }
      }
    }
  }
}

SHA-256: 4ffeab46684d9f3a8114c794158bb52ae1776d741d3ed191de267c8d3e999c6c