Record Core authorization boundary and pending GitOps tool projection
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 6s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
codex 2026-09-27 16:01:33 +02:00
parent 743def17be
commit ff34d596f9
2 changed files with 22 additions and 3 deletions

View file

@ -100,3 +100,17 @@ Credential routing inspection found no ready scoped unattended ArgoCD/Forgejo
release lane. ACTIVITY-WP-0041-T03 remains the authority/admission owner; no broad
operator token was copied or delegated. Its concrete executor contract is in
`docs/activity-core-release-admission.md`.
The production worker currently mounts an older platform checkout's script
(SHA256 0baacfd07b74ddd4317f79aa0de818c25186e15303a67c08d29edc73ad74a870).
Deploy the new script as a pinned GitOps projection, verify worker readback and a
non-destructive planner fixture, then close T03. Do not silently overwrite the
host checkout: it is outside the newly adopted nine-resource projection. Current
baseline aliases remain protected; no prune was executed during verification.
ArgoCD Core has no API-server token/role lane. T02 admission must prove a broker
that restricts both the platform child revision update and Kubernetes Application
sync operation; resource-name RBAC alone cannot restrict patch fields. This is
concrete implementation work retained here and in ACTIVITY-WP-0041-T03, not a
reason to ask the founder to approve each release. Tests in the owner checkout:
20 passed across retention and additive inventory suites.