state-hub/api
tegwick 85181cd3e4
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Build and Publish Multi-Context Image / build-and-push (push) Successful in 25s
feat(forge): report unreadable repositories as unreadable (STATE-WP-0084-T01)
A private repository failed derivation the same way a broken one did, so
"cannot read" and "does not exist" were indistinguishable from outside.
They authorise opposite things: only the second can justify retiring a
record.

- ForgeUnreadableError (a ForgeDeriveError, so old callers still catch it)
  for permission-shaped clone failures, including Forgejo's 404 for an
  unauthenticated private repo — indistinguishable here, and the safe
  reading of an ambiguous answer cannot destroy a record.
- GIT_TERMINAL_PROMPT=0: an unattended pass must fail, not block on a
  username prompt. Failing is what makes the case observable.
- DerivedProjection.retirement_eligible separates "no records found" from
  "no records exist". A checkout with no workplans/ directory cannot
  evidence an absence — the empty-clone path that would have proposed
  every record in a repository for retirement.
- Retirement from an ineligible source is refused even when acknowledged.
- Fleet keeps unreadable out of the error bucket.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 3377672@bnt-lap001
Assistant-Session: 15463ccf-238f-4e13-b163-93aa25c6d166
2026-08-26 21:45:03 +02:00
..
edge feat(edge): add offline read cache for allowlisted State Hub GET routes 2026-07-09 01:04:15 +02:00
events chore: update standalone state hub wiring 2026-05-17 20:01:21 +02:00
models feat(tasks): give task rows a canonical record identifier 2026-08-26 02:05:51 +02:00
routers feat(deploy): run migrations as part of the release, and report schema state 2026-08-26 00:00:09 +02:00
schemas fix(classification): harden registration updates 2026-08-23 11:30:36 +02:00
services feat(forge): report unreadable repositories as unreadable (STATE-WP-0084-T01) 2026-08-26 21:45:03 +02:00
classification.py fix(classification): allow the allowed-values path to be configured 2026-08-24 23:34:34 +02:00
config.py fix(config): bind the instance-identity settings to the env vars the chart sets 2026-08-25 12:55:11 +02:00
database.py Add state-hub v0.1 — local-first state service for the Custodian 2026-02-24 17:47:49 +01:00
doi_engine.py Production todo-md scan: sweep hostname + deploy tag main-d8808bf 2026-07-08 14:38:07 +02:00
flow_defs.py Complete workplan state model cleanup 2026-05-18 01:31:36 +02:00
main.py fix(retirement): close projection and launch contract gaps 2026-08-23 00:52:18 +02:00
task_status.py feat(tasks): adopt canonical task statuses 2026-05-26 01:32:50 +02:00
workplan_status.py feat(classification-spine): implement STATE-WP-0065 repo-anchored model 2026-06-22 13:52:13 +02:00