Skip to content
Public code lab · 01TypeScript · Pure decision core · 7 executable scenarios

A release should earnthe right to advance.

Change the evidence below and inspect every invariant. The gate has no warning state and no optimistic fallback. A candidate is ready only when identity, region, integrity, compatibility, runtime, tests, budget, and rollback all pass.

Sanitized reference implementation

This is newly written portfolio code that demonstrates the decision model. It contains no GolfJoy source, secrets, signing keys, proprietary schemas, or production endpoints. Cryptographic and storage adapters are intentionally outside the pure gate.

01 · Boundary design

Keep side effects outside the decision.

Adapters gather cryptographic, storage, runtime, and smoke-test evidence. The core remains a deterministic function, so the same inputs always produce the same decision and failure list.

01

Adapters

Crypto, storage, runtime, smoke tests

02

Pure gate

Manifest + evidence + policy + clock

03

Controller

Advance only on an explicit ready

02 · Interactive release gate

Break an invariant. Watch it fail closed.

Choose a preset or toggle individual evidence. The result is calculated in your browser by the downloadable TypeScript source shown below.

Evidence controls

Preset scenario

10/10 present

Release decision

READY

Every required invariant has evidence.

10/10

checks passed

Candidate identity

manifest rev-7f3a2c / evidence rev-7f3a2c

Target region

cn-prod must equal cn-prod

Artifact signature

cryptographic adapter reported a valid signature

Artifact hash

candidate bytes match the signed manifest

Content schema

schema v3; allowed: 3

Content age

20 minutes old; limit 60

Runtime proof

linux-x64-node22 proof must be present

Dependency budget

7.4 MB / 8.1 MB

Candidate smoke tests

3/3 checks passed

Rollback target

previous verified artifact is available

03 · Inspect the implementation

The demo and the download use the same source.

The decision core is small on purpose. Its job is to make every invariant explicit, preserve all failure reasons, reject empty evidence, and stay deterministic under test.

public/samples/release-gate.ts
/**
 * Sanitized reference implementation of a fail-closed release gate.
 *
 * This module contains no customer source, secrets, signing keys, proprietary
 * schemas, or production endpoints. I/O and cryptographic verification belong
 * in adapters. The gate consumes their evidence and makes one deterministic
 * decision: a candidate is ready, or it is rejected with explicit reasons.
 */

export type ReleaseStatus = "ready" | "rejected";

export type CheckCode =
  | "candidate_identity"
  | "target_region"
  | "artifact_signature"
  | "artifact_hash"
  | "content_schema"
  | "content_age"
  | "runtime_proof"
  | "dependency_budget"
  | "smoke_tests"
  | "rollback_target";

export type ReleaseManifest = {
  revision: string;
  buildId: string;
  region: string;
  schemaVersion: number;
  createdAt: string;
  runtimeProofs: readonly string[];
  dependencyBytes: number;
};

export type VerificationEvidence = {
  candidateRevision: string;
  signatureValid: boolean;
  hashMatches: boolean;
  smokeTests: readonly {
    name: string;
    passed: boolean;
  }[];
  rollbackTargetAvailable: boolean;
};

export type ReleasePolicy = {
  expectedRegion: string;
  allowedSchemaVersions: readonly number[];
  maxContentAgeMs: number;
  requiredRuntime: string;
  dependencyBudgetBytes: number;
  requireRollbackTarget: boolean;
};

export type ReleaseCheck = {
  code: CheckCode;
  label: string;
  passed: boolean;
  detail: string;
};

export type ReleaseDecision = {
  status: ReleaseStatus;
  checks: readonly ReleaseCheck[];
  failedCodes: readonly CheckCode[];
  evaluatedAt: string;
};

function check(
  code: CheckCode,
  label: string,
  passed: boolean,
  detail: string,
): ReleaseCheck {
  return { code, label, passed, detail };
}

function formatBytes(bytes: number): string {
  return `${(bytes / 1024 / 1024).toFixed(1)} MB`;
}

export function evaluateRelease(
  manifest: ReleaseManifest,
  evidence: VerificationEvidence,
  policy: ReleasePolicy,
  nowMs: number,
): ReleaseDecision {
  const createdAtMs = Date.parse(manifest.createdAt);
  const contentAgeMs = nowMs - createdAtMs;
  const hasValidTimestamp = Number.isFinite(createdAtMs);
  const contentAgeIsValid =
    hasValidTimestamp &&
    contentAgeMs >= 0 &&
    contentAgeMs <= policy.maxContentAgeMs;
  const allSmokeTestsPass =
    evidence.smokeTests.length > 0 &&
    evidence.smokeTests.every((test) => test.passed);

  const checks: readonly ReleaseCheck[] = [
    check(
      "candidate_identity",
      "Candidate identity",
      manifest.revision.length > 0 &&
        manifest.buildId.length > 0 &&
        manifest.revision === evidence.candidateRevision,
      `manifest ${manifest.revision || "missing"} / evidence ${
        evidence.candidateRevision || "missing"
      }`,
    ),
    check(
      "target_region",
      "Target region",
      manifest.region === policy.expectedRegion,
      `${manifest.region} must equal ${policy.expectedRegion}`,
    ),
    check(
      "artifact_signature",
      "Artifact signature",
      evidence.signatureValid,
      evidence.signatureValid
        ? "cryptographic adapter reported a valid signature"
        : "signature evidence is missing or invalid",
    ),
    check(
      "artifact_hash",
      "Artifact hash",
      evidence.hashMatches,
      evidence.hashMatches
        ? "candidate bytes match the signed manifest"
        : "candidate bytes do not match the signed manifest",
    ),
    check(
      "content_schema",
      "Content schema",
      policy.allowedSchemaVersions.includes(manifest.schemaVersion),
      `schema v${manifest.schemaVersion}; allowed: ${policy.allowedSchemaVersions.join(
        ", ",
      )}`,
    ),
    check(
      "content_age",
      "Content age",
      contentAgeIsValid,
      hasValidTimestamp
        ? `${Math.max(0, Math.round(contentAgeMs / 60_000))} minutes old; limit ${Math.round(
            policy.maxContentAgeMs / 60_000,
          )}`
        : "manifest timestamp is invalid",
    ),
    check(
      "runtime_proof",
      "Runtime proof",
      manifest.runtimeProofs.includes(policy.requiredRuntime),
      `${policy.requiredRuntime} proof must be present`,
    ),
    check(
      "dependency_budget",
      "Dependency budget",
      manifest.dependencyBytes <= policy.dependencyBudgetBytes,
      `${formatBytes(manifest.dependencyBytes)} / ${formatBytes(
        policy.dependencyBudgetBytes,
      )}`,
    ),
    check(
      "smoke_tests",
      "Candidate smoke tests",
      allSmokeTestsPass,
      `${evidence.smokeTests.filter((test) => test.passed).length}/${
        evidence.smokeTests.length
      } checks passed`,
    ),
    check(
      "rollback_target",
      "Rollback target",
      !policy.requireRollbackTarget || evidence.rollbackTargetAvailable,
      evidence.rollbackTargetAvailable
        ? "previous verified artifact is available"
        : "no verified rollback target is available",
    ),
  ];

  const failedCodes = checks
    .filter((item) => !item.passed)
    .map((item) => item.code);

  return {
    status: failedCodes.length === 0 ? "ready" : "rejected",
    checks,
    failedCodes,
    evaluatedAt: new Date(nowMs).toISOString(),
  };
}

Deterministic

Clock is injected. No hidden I/O or mutable global state.

Fail-closed

Missing, empty, stale, or mismatched evidence rejects the candidate.

Auditable

Every invariant returns a stable code, label, result, and detail.

From design judgment to working code

This is how I turn a reliability requirement into explicit, testable behavior.