← Files OpsTruthARCHIVED FILE
contracts/action-request.schema.json
6.63 KB · Oct 4, 2026 · 12:31 UTC
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "urn:opstruth:schema:action-request:1.0.0",
"title": "OpsTruth ActionRequest v1",
"type": "object",
"additionalProperties": false,
"required": [
"schema",
"schemaVersion",
"requestId",
"createdAt",
"expiresAt",
"issuer",
"subject",
"findingRefs",
"requestedOutcome",
"permittedOperations",
"forbiddenOperations",
"constraints",
"approvalRequirement",
"idempotencyKey",
"digest"
],
"properties": {
"schema": { "const": "opstruth.action-request" },
"schemaVersion": { "const": "1.0.0" },
"requestId": { "$ref": "#/$defs/urn" },
"createdAt": { "$ref": "#/$defs/timestamp" },
"expiresAt": { "$ref": "#/$defs/timestamp" },
"issuer": { "$ref": "#/$defs/identity" },
"subject": { "$ref": "#/$defs/subject" },
"findingRefs": {
"type": "array",
"minItems": 1,
"maxItems": 100,
"uniqueItems": true,
"items": { "$ref": "#/$defs/reference" }
},
"requestedOutcome": {
"type": "object",
"additionalProperties": false,
"required": ["description", "assertions"],
"properties": {
"description": { "type": "string", "minLength": 3, "maxLength": 2000 },
"assertions": {
"type": "array",
"minItems": 1,
"maxItems": 100,
"items": { "$ref": "#/$defs/assertion" }
}
}
},
"permittedOperations": {
"type": "array",
"minItems": 1,
"maxItems": 20,
"uniqueItems": true,
"items": { "$ref": "#/$defs/operationType" }
},
"forbiddenOperations": {
"type": "array",
"maxItems": 20,
"uniqueItems": true,
"items": { "$ref": "#/$defs/operationType" }
},
"constraints": { "$ref": "#/$defs/constraints" },
"approvalRequirement": {
"type": "object",
"additionalProperties": false,
"required": ["required", "minimumApprovals", "allowedApproverIds"],
"properties": {
"required": { "const": true },
"minimumApprovals": { "const": 1 },
"allowedApproverIds": {
"type": "array",
"minItems": 1,
"maxItems": 50,
"uniqueItems": true,
"items": { "$ref": "#/$defs/urn" }
}
}
},
"idempotencyKey": { "type": "string", "minLength": 16, "maxLength": 200, "pattern": "^[A-Za-z0-9._:-]+$" },
"digest": { "$ref": "#/$defs/digest" }
},
"$defs": {
"urn": { "type": "string", "minLength": 8, "maxLength": 300, "pattern": "^urn:[A-Za-z0-9][A-Za-z0-9:._-]+$" },
"timestamp": { "type": "string", "format": "date-time" },
"digest": { "type": "string", "pattern": "^sha256:[a-f0-9]{64}$" },
"identity": {
"type": "object",
"additionalProperties": false,
"required": ["id", "type"],
"properties": {
"id": { "$ref": "#/$defs/urn" },
"type": { "enum": ["service", "human", "policy"] }
}
},
"subject": {
"type": "object",
"additionalProperties": false,
"required": ["provider", "repositoryId", "baselineCommitSha"],
"properties": {
"provider": { "enum": ["github"] },
"repositoryId": { "type": "string", "minLength": 1, "maxLength": 100 },
"repositoryName": { "type": "string", "minLength": 3, "maxLength": 240 },
"baselineCommitSha": { "type": "string", "pattern": "^[a-f0-9]{40}$" },
"environment": { "type": "string", "minLength": 1, "maxLength": 100 }
}
},
"reference": {
"type": "object",
"additionalProperties": false,
"required": ["id", "digest"],
"properties": {
"id": { "$ref": "#/$defs/urn" },
"digest": { "$ref": "#/$defs/digest" }
}
},
"assertion": {
"type": "object",
"additionalProperties": false,
"required": ["assertionId", "description", "target", "predicate", "expected", "evidenceRequirements"],
"properties": {
"assertionId": { "type": "string", "minLength": 1, "maxLength": 100, "pattern": "^[A-Za-z0-9._:-]+$" },
"description": { "type": "string", "minLength": 3, "maxLength": 1000 },
"target": {
"type": "object",
"additionalProperties": false,
"required": ["nodeType", "field", "match"],
"properties": {
"nodeType": { "enum": ["repository", "commit", "ci_run", "artifact", "deployment", "runtime_observation", "configuration"] },
"field": { "enum": ["exists", "sha", "headCommitSha", "contentDigest", "commitSha", "status", "ok"] },
"match": {
"type": "object",
"additionalProperties": false,
"properties": {
"path": { "type": "string", "minLength": 1, "maxLength": 200, "pattern": "^/" },
"environment": { "type": "string", "minLength": 1, "maxLength": 100 },
"id": { "type": "string", "minLength": 1, "maxLength": 300 },
"current": { "type": "boolean" }
}
}
}
},
"predicate": { "enum": ["equals", "exists", "absent", "matches_digest", "status_in", "reachable"] },
"expected": true,
"evidenceRequirements": {
"type": "array",
"minItems": 1,
"maxItems": 20,
"uniqueItems": true,
"items": { "enum": ["repository", "commit", "ci_run", "artifact", "deployment", "runtime_observation", "configuration"] }
}
}
},
"operationType": {
"enum": [
"modify_source",
"run_declared_checks",
"create_commit",
"push_branch",
"open_pull_request",
"deploy",
"rollback",
"update_configuration",
"rotate_secret"
]
},
"constraints": {
"type": "object",
"additionalProperties": false,
"required": ["allowedPaths", "deniedPaths", "allowedEnvironments", "networkPolicy", "maxDurationSeconds", "maxOperations"],
"properties": {
"allowedPaths": { "type": "array", "maxItems": 200, "uniqueItems": true, "items": { "type": "string", "minLength": 1, "maxLength": 300 } },
"deniedPaths": { "type": "array", "maxItems": 200, "uniqueItems": true, "items": { "type": "string", "minLength": 1, "maxLength": 300 } },
"allowedEnvironments": { "type": "array", "maxItems": 20, "uniqueItems": true, "items": { "type": "string", "minLength": 1, "maxLength": 100 } },
"networkPolicy": { "enum": ["disabled", "dependency_acquisition_only", "allowlisted"] },
"maxDurationSeconds": { "type": "integer", "minimum": 1, "maximum": 86400 },
"maxOperations": { "type": "integer", "minimum": 1, "maximum": 1000 }
}
}
}
}
SHA-256: 4ffeab46684d9f3a8114c794158bb52ae1776d741d3ed191de267c8d3e999c6c