A release should earnthe right to advance.
Change the evidence below and inspect every invariant. The gate has no warning state and no optimistic fallback. A candidate is ready only when identity, region, integrity, compatibility, runtime, tests, budget, and rollback all pass.
Sanitized reference implementation
This is newly written portfolio code that demonstrates the decision model. It contains no GolfJoy source, secrets, signing keys, proprietary schemas, or production endpoints. Cryptographic and storage adapters are intentionally outside the pure gate.
01 · Boundary design
Keep side effects outside the decision.
Adapters gather cryptographic, storage, runtime, and smoke-test evidence. The core remains a deterministic function, so the same inputs always produce the same decision and failure list.
Adapters
Crypto, storage, runtime, smoke tests
Pure gate
Manifest + evidence + policy + clock
Controller
Advance only on an explicit ready
02 · Interactive release gate
Break an invariant. Watch it fail closed.
Choose a preset or toggle individual evidence. The result is calculated in your browser by the downloadable TypeScript source shown below.
Evidence controls
Preset scenario
Release decision
READY
Every required invariant has evidence.
10/10
checks passed
Candidate identity
manifest rev-7f3a2c / evidence rev-7f3a2c
Target region
cn-prod must equal cn-prod
Artifact signature
cryptographic adapter reported a valid signature
Artifact hash
candidate bytes match the signed manifest
Content schema
schema v3; allowed: 3
Content age
20 minutes old; limit 60
Runtime proof
linux-x64-node22 proof must be present
Dependency budget
7.4 MB / 8.1 MB
Candidate smoke tests
3/3 checks passed
Rollback target
previous verified artifact is available
03 · Inspect the implementation
The demo and the download use the same source.
The decision core is small on purpose. Its job is to make every invariant explicit, preserve all failure reasons, reject empty evidence, and stay deterministic under test.
/**
* Sanitized reference implementation of a fail-closed release gate.
*
* This module contains no customer source, secrets, signing keys, proprietary
* schemas, or production endpoints. I/O and cryptographic verification belong
* in adapters. The gate consumes their evidence and makes one deterministic
* decision: a candidate is ready, or it is rejected with explicit reasons.
*/
export type ReleaseStatus = "ready" | "rejected";
export type CheckCode =
| "candidate_identity"
| "target_region"
| "artifact_signature"
| "artifact_hash"
| "content_schema"
| "content_age"
| "runtime_proof"
| "dependency_budget"
| "smoke_tests"
| "rollback_target";
export type ReleaseManifest = {
revision: string;
buildId: string;
region: string;
schemaVersion: number;
createdAt: string;
runtimeProofs: readonly string[];
dependencyBytes: number;
};
export type VerificationEvidence = {
candidateRevision: string;
signatureValid: boolean;
hashMatches: boolean;
smokeTests: readonly {
name: string;
passed: boolean;
}[];
rollbackTargetAvailable: boolean;
};
export type ReleasePolicy = {
expectedRegion: string;
allowedSchemaVersions: readonly number[];
maxContentAgeMs: number;
requiredRuntime: string;
dependencyBudgetBytes: number;
requireRollbackTarget: boolean;
};
export type ReleaseCheck = {
code: CheckCode;
label: string;
passed: boolean;
detail: string;
};
export type ReleaseDecision = {
status: ReleaseStatus;
checks: readonly ReleaseCheck[];
failedCodes: readonly CheckCode[];
evaluatedAt: string;
};
function check(
code: CheckCode,
label: string,
passed: boolean,
detail: string,
): ReleaseCheck {
return { code, label, passed, detail };
}
function formatBytes(bytes: number): string {
return `${(bytes / 1024 / 1024).toFixed(1)} MB`;
}
export function evaluateRelease(
manifest: ReleaseManifest,
evidence: VerificationEvidence,
policy: ReleasePolicy,
nowMs: number,
): ReleaseDecision {
const createdAtMs = Date.parse(manifest.createdAt);
const contentAgeMs = nowMs - createdAtMs;
const hasValidTimestamp = Number.isFinite(createdAtMs);
const contentAgeIsValid =
hasValidTimestamp &&
contentAgeMs >= 0 &&
contentAgeMs <= policy.maxContentAgeMs;
const allSmokeTestsPass =
evidence.smokeTests.length > 0 &&
evidence.smokeTests.every((test) => test.passed);
const checks: readonly ReleaseCheck[] = [
check(
"candidate_identity",
"Candidate identity",
manifest.revision.length > 0 &&
manifest.buildId.length > 0 &&
manifest.revision === evidence.candidateRevision,
`manifest ${manifest.revision || "missing"} / evidence ${
evidence.candidateRevision || "missing"
}`,
),
check(
"target_region",
"Target region",
manifest.region === policy.expectedRegion,
`${manifest.region} must equal ${policy.expectedRegion}`,
),
check(
"artifact_signature",
"Artifact signature",
evidence.signatureValid,
evidence.signatureValid
? "cryptographic adapter reported a valid signature"
: "signature evidence is missing or invalid",
),
check(
"artifact_hash",
"Artifact hash",
evidence.hashMatches,
evidence.hashMatches
? "candidate bytes match the signed manifest"
: "candidate bytes do not match the signed manifest",
),
check(
"content_schema",
"Content schema",
policy.allowedSchemaVersions.includes(manifest.schemaVersion),
`schema v${manifest.schemaVersion}; allowed: ${policy.allowedSchemaVersions.join(
", ",
)}`,
),
check(
"content_age",
"Content age",
contentAgeIsValid,
hasValidTimestamp
? `${Math.max(0, Math.round(contentAgeMs / 60_000))} minutes old; limit ${Math.round(
policy.maxContentAgeMs / 60_000,
)}`
: "manifest timestamp is invalid",
),
check(
"runtime_proof",
"Runtime proof",
manifest.runtimeProofs.includes(policy.requiredRuntime),
`${policy.requiredRuntime} proof must be present`,
),
check(
"dependency_budget",
"Dependency budget",
manifest.dependencyBytes <= policy.dependencyBudgetBytes,
`${formatBytes(manifest.dependencyBytes)} / ${formatBytes(
policy.dependencyBudgetBytes,
)}`,
),
check(
"smoke_tests",
"Candidate smoke tests",
allSmokeTestsPass,
`${evidence.smokeTests.filter((test) => test.passed).length}/${
evidence.smokeTests.length
} checks passed`,
),
check(
"rollback_target",
"Rollback target",
!policy.requireRollbackTarget || evidence.rollbackTargetAvailable,
evidence.rollbackTargetAvailable
? "previous verified artifact is available"
: "no verified rollback target is available",
),
];
const failedCodes = checks
.filter((item) => !item.passed)
.map((item) => item.code);
return {
status: failedCodes.length === 0 ? "ready" : "rejected",
checks,
failedCodes,
evaluatedAt: new Date(nowMs).toISOString(),
};
}
Deterministic
Clock is injected. No hidden I/O or mutable global state.
Fail-closed
Missing, empty, stale, or mismatched evidence rejects the candidate.
Auditable
Every invariant returns a stable code, label, result, and detail.
From design judgment to working code