Appendix: internal enablement checklist

This page is the enablement metric (Q20). It is scored after the workshop. It is not a Check on the claim, not a Validate Job, and not a live customer proof-of-value.

Lab Checks on tracks 1–7 prove the consultant can operate this claim. Passing this rubric is a separate sitting: same seven-track outcomes, plus they can point at a playbook for every engagement activity they did not click.

Nothing to pass during the two days. Instructors: two-day grouping still runs the event; this page is what you score afterward.

How to score

  • When: after the event, not as a Day-2 exam and not on a customer site.

  • Who: practice lead or instructor. The consultant may walk their own claim artifacts. Do not invent an instructor Solve.

  • Enabled: every row in Seven tracks is Pass, and the SoW mapping row is Pass. A failed track means not enabled — there is no partial badge.

  • Notes: record gaps on every row (including Pass). Weak evidence, Konflux-name slips, or “they clicked it but cannot explain it” still go in Notes even when the overall result is Enabled.

  • Evidence: live objects, git history, or files they kept (settings, report, dest digest). Do not grade screenshots of the Showroom Check section. Do not paste secrets (LW_*, student_password, cosign.key).

  • Not this page: unassisted customer PoV; Epic D (second Python app, Artifactory install, hosted Konflux, bootc/Satellite hands-on, dual-arch exercise, SIEM, physical diode).

Lab pedagogy (fresh-claim negatives, worked-example fail, report keys) stays on the gated pages and in-cluster Validate Jobs. Do not re-score those here.

Seven tracks

Track Pass when Evidence to show Lab pages

1 Hummingbird

They filled the trust policy and they ran oc-mirror. cosign verify succeeds on the internal dest digest they recorded, not only the published pin.

Trust-policy file is not the seeded placeholder. ImageSet has no REPLACE_ME. Dest digest in Job logs / notes. cosign verify against dest, not only registry.access.redhat.com.

1.1, 1.2

2 Lightwell

They authored settings.xml (not the worked-example URL) and pinned the scored .rhlw- as the *default pom property. Maven resolves that GAV from Nexus Remediated.

stub-03-enterprise-proxy / ~/track-2-1-settings.xml shows in-cluster Nexus host. ConfigMap stub-04-remediated-pin default <commons.lang3.version> is 3.14.0.rhlw-00001 (not an unused profile, not LW-DEMO-0001 / spring-core).

2.1, 2.2

3 Source

Learner-owned Gitea app: runtime FROM the dest Hummingbird digest they mirrored, default Lightwell pin committed, and they merged a renovate-bot PR on lightwell-pins.properties (not a student hand-edit).

lw-student/spring-boot-lw-poc remote. Runtime FROM is dest + digest. Merge author is renovate-bot. Pins file moved off rhlw-00000 / all-zero digest.

3.1, 3.2, 3.3

4 Konflux-class build

They wired forbid-list, prefetch, and build-ns NetworkPolicy, then produced a BuildConfig image and SBOM. Known-bad public fetches still fail.

Active Dockerfile/pom have no public FROM / Central / curl. Dockerfile.known-bad still exists. Pipeline includes Task prefetch-dependencies. build-egress on lw-poc-build is not the too-open seed. Image + SBOM artifacts exist.

4.1, 4.2, 4.3, 4.4

5 Signed image

Keyless RHTAS on the app digest, Conforma they tightened (fail then pass), and 5.3 key-based verify with a TUF root they placed. Cluster stayed networked; they do not claim a physical air-gap.

cosign-sign-keyless succeeded. Tightened Conforma ConfigMap in lw-poc-build (not the weak seed). 5.3 verify uses --key and the learner TUF path.

5.1, 5.2, 5.3

6 Production

Admission denies unsigned. They committed the signed digest to the prod GitOps remote. Prod Argo is Healthy from that remote, not still tracking stage. Rolling is the scored strategy; VM / canary / blue-green stay callouts.

Throwaway unsigned tag is denied (ImagePullBackOff / policy). Prod repo commit is the signed digest. Application lw-poc-prod does not still follow stage.

6.1, 6.2

7 Compliance

Promoted-app SBOM is in TPA. Blast-radius report uses Lightwell GAV-bound VEX for the Track 2 pin (LW-DEMO-0002): CVE remediated via the Lightwell pin. ACS image check is on (not skipped). Hummingbird/CSAF is the OS-layer callout, not this pass.

TPA document for the promoted digest. ConfigMap stub-18-blast-radius has LW-DEMO-0002, 3.14.0.rhlw-00001, via-lightwell-pin. acs-image-check is passed or failed, not skipped.

7.1, 7.2

SoW mapping (required)

Row Pass when Evidence

Playbook for what they did not click

For every engagement activity they did not run on this claim, they can name the treatment and the page (scored / callout / mapping / playbook / not on this claim). They do not over-claim hosted Konflux, a data diode, Artifactory-on-the-claim, or an unassisted customer PoV.

Walk Consultant delivery map and Konflux mapping. Fail if they rename cluster Tasks to Konflux product names or treat 5.3 as a physical air-gap.

Python pip / +rhlw. and Artifactory remote/virtual/include are *callouts on the Java pages. Reciting those sentences is not a ninth track. Installing Artifactory or scaffolding FastAPI fails this rubric (those are later work, not v2 enablement).

Scoring sheet

Copy this table (spreadsheet, issue comment, or print). Fill Pass/Fail and Notes on every row. Overall Enabled only if every track is Pass and SoW mapping is Pass.

Row Pass / Fail Notes (gaps)

1 Hummingbird

2 Lightwell

3 Source

4 Konflux-class build

5 Signed image

6 Production

7 Compliance

SoW mapping

Overall

Enabled / Not enabled

Do not leave Notes blank on a Pass row if they used the wrong product name, skipped a callout they should be able to state, or showed cluster state without being able to explain the change.

What not to do

  • Do not score this during the two-day envelope as a live PoV.

  • Do not add a Showroom lock, Solve Job, or attempt cap for this page.

  • Do not require a customer site, a second RHDP claim, or wall-clock minutes.

  • Do not treat finishing 7.2 as sufficient by itself — this rubric is the enablement gate.