This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
orchestrator/docs/provisioning
Adam Moussa 2f7d12a431
docs(agent-team): fold GPT-4.1 plan-review findings into the P3-live-flip plan (#31)
REQUEST CHANGES from the cross-family plan-review (2026-06-22), dispositioned:
- expanded denylist (§4.2): submodules/.gitmodules, git hooks, .gitattributes filters,
  lockfile postinstall, generated artifacts
- runner-trust assertion (privileged jobs GitHub-hosted only)
- concrete diff-transport spec + threat model (signed artifact / branch-only token, nonce anti-replay)
- gate-weakening detection (noqa/skip/excludes/--no-verify)
- PR-metadata secret sanitization; ledger diff-hash anti-tamper
- Phase 1b: recovery for an accidentally-merged/applied privileged change + draft-PR rate
  monitoring + stale-PR cleanup
- required-check-name discovery; deploy-before-merge enforcement; no-write-token audit
Notes which BLOCK items are already implemented in PR #17's CI (Phase 1 verifies, not rebuilds).
2026-06-22 16:21:35 -04:00
..
DEPLOY-AUDIT.md feat(agent-team): deploy-readiness — serve starts Slack listener + systemd + provisioning docs (#23) 2026-06-18 16:56:21 -04:00
OPERATOR-RUNBOOK.md feat(agent-team): deploy-readiness — serve starts Slack listener + systemd + provisioning docs (#23) 2026-06-18 16:56:21 -04:00
P1-DEMO-SCRIPT.md feat(agent-team): deploy-readiness — serve starts Slack listener + systemd + provisioning docs (#23) 2026-06-18 16:56:21 -04:00
P3-LIVE-FLIP-PLAN.md docs(agent-team): fold GPT-4.1 plan-review findings into the P3-live-flip plan (#31) 2026-06-22 16:21:35 -04:00
PROVISIONING-RUNBOOK.md fix(agent-team): repair Slack listener block_actions matcher; add dedicated Slack app (#25) 2026-06-22 13:16:35 -04:00