From 877739dece1fd7f2fb82185d7660e02e1dc1ef18 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Mon, 22 Jun 2026 17:25:02 -0400 Subject: [PATCH] =?UTF-8?q?docs(agent-team):=20close=20B1=20=E2=80=94=20de?= =?UTF-8?q?ploy-before-merge=20is=20a=20committed=20hard=20gate,=20not=20a?= =?UTF-8?q?=20manual=20fallback?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Round-3 re-review resolved B2-B6 but flagged B1 still-open: the prior wording left a 'enforced by hand until the check exists' escape hatch. Reframe B1 as a REQUIRED Phase-1 build deliverable that blocks the flip (no manual fallback), with the required-status-check + admin-bypass-disabled branch protection, and a dry-run faithfulness note (same workflow file/jobs as live, only the privileged if: differs). --- docs/provisioning/P3-LIVE-FLIP-PLAN.md | 24 ++++++++++++++++-------- 1 file changed, 16 insertions(+), 8 deletions(-) diff --git a/docs/provisioning/P3-LIVE-FLIP-PLAN.md b/docs/provisioning/P3-LIVE-FLIP-PLAN.md index 8ed2fe2..177be37 100644 --- a/docs/provisioning/P3-LIVE-FLIP-PLAN.md +++ b/docs/provisioning/P3-LIVE-FLIP-PLAN.md @@ -150,14 +150,22 @@ workflow (Phase 3), not only the inert version** (see Phase 3). - [ ] **Memory/doc update when denylist vectors change** (FIX): adding a denylist vector (here or later) updates `project_r720_agent_team` memory + the Confluence host page in the SAME change — the denied set is operational/security-critical, not tribal knowledge. -- [ ] **Deploy-before-merge enforcement — CONCRETE, CI-enforced (B1).** "Deploy" of this change - = the privileged path is *proven on the live box before the workflow PR merges*. Mechanism: - (a) the box exercises a **dispatch dry-run** of the apply/verify workflow (privileged steps - still `if:${{ false }}`) that emits a signed "exercised-on-box" artifact / status; (b) a - **required status check** on the workflow-file PR consumes that proof so the PR is - un-mergeable until the box has run it; (c) NO `--admin` bypass. This makes deploy-then-merge - a gate, not prose. (Until that check exists, deploy-before-merge is enforced by hand + - recorded in the PR — but the gate is the target.) +- [ ] **Deploy-before-merge enforcement — CONCRETE, CI-enforced (B1). REQUIRED Phase-1 + deliverable; the flip does not proceed without it (no manual fallback).** "Deploy" of this + change = the privileged path is *proven on the live box before the workflow PR merges*. + Build, in this phase: + - (a) the box exercises a **dispatch dry-run** of the apply/verify workflow (privileged steps + still `if:${{ false }}`) that emits a signed "exercised-on-box" artifact/status. **Dry-run + faithfulness (NIT):** it runs the SAME workflow file and the SAME untrusted build/verify + + pure-code-gate jobs as the live path — ONLY the privileged `if:` differs — so the dry-run + is a faithful proof of the path, not a separate mock. + - (b) a **required status check** on the workflow-file PR consumes that proof, so the PR is + un-mergeable until the box has run it. + - (c) branch-protection set so the required checks **cannot be bypassed by admins** ("do not + allow bypassing the above settings" / include-administrators) — **no `--admin` merge of the + privileged flip** (NIT). This setting is applied in Phase 2 with the rest of the env/protection. + This is the gate; until it is built+green, the flip is blocked. (Owner: 🤖 build; verified in + the Phase-1 `/sh-security-review` + cross-review hard stop.) - [ ] **Concrete "no write token on the box" audit (B-QUESTION → a real check):** a test/script asserting the box env + coordinator config hold no `pull-requests:write` / contents-write token (grep the live env names + assert the App token is only an Actions