Enforce SBOM
Add an SBOM Policy Enforcement (SscaEnforcement / CdSscaEnforcement) step to an existing
Harness pipeline. The step verifies SBOM attestations (when enabled) and evaluates SBOM OPA policy
sets against the artifact's bill of materials.
This skill only works with existing pipelines — do not create standalone enforcement-only pipelines.
Prerequisites: An SBOM must already exist for the artifact (typically from SscaOrchestration via
/create-sbom or SBOM ingestion). SBOM policy sets must exist (/create-policy).
Supported stages: CI, CD (Deployment), and Security — same as SBOM Orchestration. CD requires a
containerized step group with container-based execution.
Guide the user through a step-by-step interactive wizard (same UX as /create-sbom):
- Wizard:
references/interactive-wizard-flow.md
- UI ↔ YAML:
references/sbom-enforcement-step.md
- CD containerized step groups (new or existing Deploy stage):
skills/create-sbom/references/cd-containerized-step-group.md
Interaction model (mandatory)
- One question per turn — use
AskQuestion when available; otherwise numbered options with (Recommended).
- Opening message — add SBOM Policy Enforcement to an existing pipeline; mention SBOM + policy set prerequisites.
- Progress breadcrumb — after pipeline fetch:
Pipeline · Placement · Source · Details · Verify · Policy · Submit
- Record answers — running summary; do not re-ask unless the user changes direction.
- Fetch before configure —
harness_get before placement/source questions.
- Show pipeline structure — list stages/steps; highlight
SscaOrchestration and connectors.
- Infer source from orchestration — when one SBOM generation step exists, reuse its
source and image.
- Never guess image tags — default to orchestration step image; ask if ambiguous.
- Confirm before write — summary +
harness_update only after user confirms.
- Stop after update — after successful
harness_update, provide a configuration summary and
point the user to /run-pipeline to execute. Do not call harness_execute, poll
executions, or run harness_diagnose in this skill (same pattern as /configure-repo-scan).
- CD placement without an existing Deploy stage — if the user chooses CD enforcement (
cd_before_deploy, add_cd_stage, or similar) on a CI-only pipeline, do not reject or force CI-only. Run Phase 3b to add a Deployment stage with a containerized step group and CdSscaEnforcement before deploy (same prerequisites as /create-sbom).
- Never block CD on “no Deployment stage” — warn in Phase 2, then proceed via Phase 3b when the user wants CD.
Full phase prompts: references/interactive-wizard-flow.md.
Instructions
Wizard phases (user-facing)
After Phase 10 confirm → insert step, harness_update, then provide summary (do not run the pipeline).
Supported stage types
CD edge case (mandatory workflow)
Use when Placement targets CD (cd_before_deploy, add_cd_stage, or an existing Deployment stage).
Phase 2 — CI-only pipeline
If there is no type: Deployment stage, note it in the structure table and add:
This pipeline has no CD Deploy stage yet. You can still enforce SBOM in CD — we will add a Deployment stage with a containerized step group and place SBOM Policy Enforcement before the deploy step.
Do not tell the user CD is invalid for this pipeline. If they chose CD in Phase 3, continue to Phase 3b.
Phase 3b — CD prerequisites (no Deploy stage yet)
Mirror /create-sbom Phase 3b — one topic per turn:
Append a Deploy stage with containerized group containing CdSscaEnforcement before K8sRollingDeploy. Full YAML patterns: skills/create-sbom/references/cd-containerized-step-group.md (use CdSscaEnforcement instead of SscaOrchestration).
CD image / source: prefer <+artifact.image> from the service primary artifact; reuse connector from CI SscaOrchestration or service artifact source. Verify attestation must match the CI generation step (e.g. keyless Harness OIDC).
Step id: use enforce_sbom_cd when CI already has enforce_sbom.
After the wizard — backend steps
Check prerequisites
- SBOM generation — pipeline YAML contains
SscaOrchestration (or user confirms SBOM was ingested).
- Policy sets —
harness_list(resource_type="policy_set", org_id, project_id). If empty, direct user to /create-policy (SBOM entity, onstep event) before continuing.
From SscaOrchestration (if present), copy:
spec.source (type + spec)
spec.attestation (use matching verifyAttestation when user chooses verify)
connector / image / registry
From build/push steps: connectorRef in BuildAndPushDockerRegistry, Run, Plugin.