diff --git a/docs/activity-core-release-admission.md b/docs/activity-core-release-admission.md index c570965..99f15f0 100644 --- a/docs/activity-core-release-admission.md +++ b/docs/activity-core-release-admission.md @@ -12,9 +12,14 @@ identities. Public source reads need no repository credential. A general reposit write PAT cannot enforce image-only changes by itself: the executor must validate the exact before/after commits and authenticated receipts before writing, while protected branches and required checks prevent bypass. Restrict its repository -membership to the release repository and its ArgoCD role to get/sync the single -`activity-core/activity-core` application. No root sync, application spec updates, -project updates, exec, prune, overrides, secrets or other applications. +membership to the release repository and reconciliation to the single +`activity-core/activity-core` application. This installation is ArgoCD Core: +there is no ArgoCD API-server role/token lane to reuse. Kubernetes RBAC cannot +restrict Application patch access to only the operation fields. Use a narrowly +implemented sync broker with admission enforcement before granting such patch +access; an Application-scoped Kubernetes Role alone is insufficient. No root-wide +sync, arbitrary application spec updates, project updates, exec, prune, overrides, +secrets or other applications. The present parent Application pins the child's source revision in the platform repository. Therefore an app-only ArgoCD sync grant alone cannot perform durable diff --git a/workplans/RPF-WP-0048-activity-core-gitops-adoption.md b/workplans/RPF-WP-0048-activity-core-gitops-adoption.md index c64f008..8d336c0 100644 --- a/workplans/RPF-WP-0048-activity-core-gitops-adoption.md +++ b/workplans/RPF-WP-0048-activity-core-gitops-adoption.md @@ -100,3 +100,17 @@ Credential routing inspection found no ready scoped unattended ArgoCD/Forgejo release lane. ACTIVITY-WP-0041-T03 remains the authority/admission owner; no broad operator token was copied or delegated. Its concrete executor contract is in `docs/activity-core-release-admission.md`. + +The production worker currently mounts an older platform checkout's script +(SHA256 0baacfd07b74ddd4317f79aa0de818c25186e15303a67c08d29edc73ad74a870). +Deploy the new script as a pinned GitOps projection, verify worker readback and a +non-destructive planner fixture, then close T03. Do not silently overwrite the +host checkout: it is outside the newly adopted nine-resource projection. Current +baseline aliases remain protected; no prune was executed during verification. + +ArgoCD Core has no API-server token/role lane. T02 admission must prove a broker +that restricts both the platform child revision update and Kubernetes Application +sync operation; resource-name RBAC alone cannot restrict patch fields. This is +concrete implementation work retained here and in ACTIVITY-WP-0041-T03, not a +reason to ask the founder to approve each release. Tests in the owner checkout: +20 passed across retention and additive inventory suites.