name: KBX Release Readiness on: workflow_dispatch: inputs: environment: description: Target environment (Staging or Production) required: true default: Staging jobs: release-readiness: runs-on: ubuntu-latest steps: - name: Checkout immutable candidate uses: actions/checkout@v4 - name: Validate KBX contracts and configuration governance run: node scripts/validate-kbx.mjs - name: Verify generated configuration/deployment artifacts run: git diff --exit-code -- generated/configuration-manifest.json packages/kbx-contracts/src/generated/configurationCatalog.ts backend/Shared/Configuration/Generated/KbxConfigurationCatalog.g.cs deploy/kbx/ - name: Build/test when host repository is available shell: bash run: | shopt -s nullglob solutions=( *.sln *.slnx ) if [ ${#solutions[@]} -gt 0 ]; then dotnet restore "${solutions[0]}" dotnet build "${solutions[0]}" --no-restore -c Release dotnet test "${solutions[0]}" --no-build -c Release else echo "Starter: host build is deferred." fi - name: Configuration validation gate run: echo "Host must bind target-environment secrets/config and call KbxConfigurationStartupValidator.ValidateOrThrow before promotion." - name: Database migration dry-run gate run: echo "Host must execute DbUp validation/dry-run against an environment-equivalent database before applying migrations." - name: Migration application policy run: echo "Production migrations are pre-deploy; application startup schema mutation is forbidden."