docs(agent-team): fold round-2/3/4 plan-review findings into P3-live-flip plan #33
1 changed files with 7 additions and 2 deletions
|
|
@ -163,9 +163,14 @@ workflow (Phase 3), not only the inert version** (see Phase 3).
|
|||
un-mergeable until the box has run it.
|
||||
- (c) branch-protection set so the required checks **cannot be bypassed by admins** ("do not
|
||||
allow bypassing the above settings" / include-administrators) — **no `--admin` merge of the
|
||||
privileged flip** (NIT). This setting is applied in Phase 2 with the rest of the env/protection.
|
||||
privileged flip**. Applied in Phase 2; **no ordering window** because the flip (Phase 3) is
|
||||
gated on Phase 2 completion (the B4 precondition), so admin-bypass is already disabled before
|
||||
any flip is possible. The Phase-1 required-status-check (a/b) and the Phase-2 branch-protection
|
||||
(c) together are the gate; the flip cannot happen until BOTH are in place.
|
||||
This is the gate; until it is built+green, the flip is blocked. (Owner: 🤖 build; verified in
|
||||
the Phase-1 `/sh-security-review` + cross-review hard stop.)
|
||||
the Phase-1 `/sh-security-review` + cross-review hard stop. The check's implementation is itself
|
||||
a Phase-1 build task — that it is not yet physically built is expected for a pre-build plan; what
|
||||
matters is it is non-optional and flip-blocking, enforced at the Phase-1 hard stop.)
|
||||
- [ ] **Concrete "no write token on the box" audit (B-QUESTION → a real check):** a
|
||||
test/script asserting the box env + coordinator config hold no `pull-requests:write` /
|
||||
contents-write token (grep the live env names + assert the App token is only an Actions
|
||||
|
|
|
|||
Reference in a new issue