Appendix: internal enablement checklist
This page is the enablement metric (Q20). It is scored after the workshop. It is not a Check on the claim, not a Validate Job, and not a live customer proof-of-value.
Lab Checks on tracks 1–7 prove the consultant can operate this claim. Passing this rubric is a separate sitting: same seven-track outcomes, plus they can point at a playbook for every engagement activity they did not click.
Nothing to pass during the two days. Instructors: two-day grouping still runs the event; this page is what you score afterward.
How to score
-
When: after the event, not as a Day-2 exam and not on a customer site.
-
Who: practice lead or instructor. The consultant may walk their own claim artifacts. Do not invent an instructor Solve.
-
Enabled: every row in Seven tracks is Pass, and the SoW mapping row is Pass. A failed track means not enabled — there is no partial badge.
-
Notes: record gaps on every row (including Pass). Weak evidence, Konflux-name slips, or “they clicked it but cannot explain it” still go in Notes even when the overall result is Enabled.
-
Evidence: live objects, git history, or files they kept (settings, report, dest digest). Do not grade screenshots of the Showroom Check section. Do not paste secrets (
LW_*,student_password,cosign.key). -
Not this page: unassisted customer PoV; Epic D (second Python app, Artifactory install, hosted Konflux, bootc/Satellite hands-on, dual-arch exercise, SIEM, physical diode).
Lab pedagogy (fresh-claim negatives, worked-example fail, report keys) stays on the gated pages and in-cluster Validate Jobs. Do not re-score those here.
Seven tracks
| Track | Pass when | Evidence to show | Lab pages |
|---|---|---|---|
1 Hummingbird |
They filled the trust policy and they ran oc-mirror. |
Trust-policy file is not the seeded placeholder. ImageSet has no |
|
2 Lightwell |
They authored |
|
|
3 Source |
Learner-owned Gitea app: runtime |
|
|
4 Konflux-class build |
They wired forbid-list, prefetch, and build-ns NetworkPolicy, then produced a BuildConfig image and SBOM. Known-bad public fetches still fail. |
Active Dockerfile/ |
|
5 Signed image |
Keyless RHTAS on the app digest, Conforma they tightened (fail then pass), and 5.3 key-based verify with a TUF root they placed. Cluster stayed networked; they do not claim a physical air-gap. |
|
|
6 Production |
Admission denies unsigned. They committed the signed digest to the prod GitOps remote. Prod Argo is Healthy from that remote, not still tracking stage. Rolling is the scored strategy; VM / canary / blue-green stay callouts. |
Throwaway unsigned tag is denied ( |
|
7 Compliance |
Promoted-app SBOM is in TPA. Blast-radius report uses Lightwell GAV-bound VEX for the Track 2 pin ( |
TPA document for the promoted digest. ConfigMap |
SoW mapping (required)
| Row | Pass when | Evidence |
|---|---|---|
Playbook for what they did not click |
For every engagement activity they did not run on this claim, they can name the treatment and the page (scored / callout / mapping / playbook / not on this claim). They do not over-claim hosted Konflux, a data diode, Artifactory-on-the-claim, or an unassisted customer PoV. |
Walk Consultant delivery map and Konflux mapping. Fail if they rename cluster Tasks to Konflux product names or treat 5.3 as a physical air-gap. |
Python pip / +rhlw. and Artifactory remote/virtual/include are *callouts on the Java pages. Reciting those sentences is not a ninth track. Installing Artifactory or scaffolding FastAPI fails this rubric (those are later work, not v2 enablement).
Scoring sheet
Copy this table (spreadsheet, issue comment, or print). Fill Pass/Fail and Notes on every row. Overall Enabled only if every track is Pass and SoW mapping is Pass.
| Row | Pass / Fail | Notes (gaps) |
|---|---|---|
1 Hummingbird |
||
2 Lightwell |
||
3 Source |
||
4 Konflux-class build |
||
5 Signed image |
||
6 Production |
||
7 Compliance |
||
SoW mapping |
||
Overall |
Enabled / Not enabled |
Do not leave Notes blank on a Pass row if they used the wrong product name, skipped a callout they should be able to state, or showed cluster state without being able to explain the change.
What not to do
-
Do not score this during the two-day envelope as a live PoV.
-
Do not add a Showroom lock, Solve Job, or attempt cap for this page.
-
Do not require a customer site, a second RHDP claim, or wall-clock minutes.
-
Do not treat finishing 7.2 as sufficient by itself — this rubric is the enablement gate.
Related
-
Workshop home — learner map; this checklist is after, not a Day-1 exam
-
Instructor two-day grouping — when the event runs
-
Consultant delivery map — SoW row
-
Konflux mapping — names they must not install