Make S1 handoff read-only by default
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02994-7685-7940-bf34-3555b8256018
This commit is contained in:
parent
24b799ec59
commit
40e295e3bd
16 changed files with 637 additions and 46 deletions
|
|
@ -116,3 +116,8 @@ baseline state.
|
|||
This includes admin user setup, SSH hardening, firewall rules, essential tooling, and secret handling.
|
||||
|
||||
📖 See the full guide here: [Convergence Documentation](docs/convergence.md)
|
||||
|
||||
Routine `make verify` and `make s1-handoff` runs are read-only on managed
|
||||
hosts. Updating the installed Goss surface is deliberately separate and
|
||||
requires an exact `APPROVE_VERIFY_REFRESH` value; see
|
||||
[Server Verification](docs/verification.md).
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue