# cad-atlas — Inception Sprint Oath The acceptance contract for standing up cad-atlas. The sprint is finalized only when this Oath holds. Methodology: brain `wiki/homelab/decisions/inception-sprint-and-oath.md`. > **Status of enforcement:** `var-go/oath` gates a real candidate (`oathcandidate/`, #8 — parses > the committed CI workflow, TDD'd pass/fail-closed) and is now **required by branch protection** > on `main` (verified green on a real PR). Direct pushes remain allowlisted for `mathias` per this > repo's TBD convention. ## General clauses (any inception sprint) | # | Clause | Status | Evidence | |---|--------|--------|----------| | G1 | Repo born from template on Gitea, dispatch-eligible | ✅ | `create_project_from_template`, `.dispatch-allow`, dispatch-allowlisted | | G2 | Self-contained context + brain deep-links + external refs | ✅ | `.context/PROJECT.md`, `README.md` | | G3 | Green CI on main: build · vet · lint · test (TDD) | ✅ | Genuinely green from run 19 (commit 68adfe7). NOTE: runs 16–18 were *hollow* — a template guard bug (template-go-web#9) skipped every job; fixed here. `internal/web/handler_test.go` | | G4 | Genesis learning persisted to brain, linked from repo | ✅ | `wiki/homelab/decisions/cad-atlas-audit-chain-is-viz-data.md` | | G5 | Discovered findings filed as tracker issues | ✅ | template-go-web#8, local-dev#20 | | G6 | SemVer tag marks the milestone (closing act) | ✅ | `v0.1.0` | | G7 | Agent-ready spec issue for the next increment | ✅ | #1 | ## Specific clauses (cad-atlas) | # | Clause | Status | Evidence | |---|--------|--------|----------| | S1 | Atlas served at `/`, renders all 9 stages signal→pod | ✅ | `internal/web/handler.go` + `static/cad-atlas.html` | | S2 | Oath covered in the viz (stages 03 + 06) | ✅ | var-go Oath nodes in the atlas | | S3 | `var-go/oath` enforces cad-atlas's own PRs | ✅ | `oathcandidate/` gates the real `.gitea/workflows/cd.yml` (TDD green: passes real file, fails closed on a fixture missing the job) via swedsl's sandboxed `SubprocessGate` (swedsl#35/#38). Branch protection on `main` now requires `var-go/oath`, confirmed holding on a real PR (#8). | ## Deployment Live at **https://atlas.d-ma.be** (Authentik forward-auth — authed users only) on koala k3s: namespace `cad-atlas`, 1 replica, `cad-atlas:80 → :8080` (manifests in `mathias/infra` `k3s/apps/cad-atlas/`, reconciled by Flux). CI `deploy` job **auto-deploys** on every main push — `INFRA_DEPLOY_KEY` (write deploy-key `cad-atlas-ci` on infra) is wired (#2 done). ## The honesty rule A clause blocked by an external dependency is **descoped and tracked, never marked satisfied** — a self-lying Oath is a rubber stamp, the exact failure the Oath exists to prevent. S3 is now fully enforced: real candidate wired and branch-protection-required (#8), confirmed on a real PR. The `DMABE_GITEA_API_TOKEN` Actions secret is pre-provisioned so #1 and #8 both landed without a secret-write. Also surfaced by #8: this file's own "Oath (advisory form)" below predates the discovery that var-go's parser requires single-line, period-separated sentences with no `Given`/`Then`/`And` keyword stripping — it has never been machine-gated and would need reformatting first if it ever is. ## The Oath (advisory form) ```var Given a new software thing is being stood up as an inception sprint Then its repo is born from template on Gitea and is dispatch-eligible And its context is self-contained with brain deep-links and external references And CI on main is green across build, vet, lint and test And the genesis learning is persisted to brain and linked from the repo And every discovered finding is filed as a tracker issue And an agent-ready spec issue exists for the next increment And a SemVer tag marks the milestone as the closing act And any clause blocked by an external dependency is descoped and tracked, never claimed ```