sh-mcp/docs
Adam Moussa 0d4bb39175 Fold in Gemini round-4 CI/CD + decoupling findings (with corrections)
- ARM64 markers (enable-qemu both files + platform:LINUX_ARM64) for Docker-bundled tier
  tasks -> Phase 0b build + exit (per reference_cicd_arm64_qemu).
- Node 24 / workflows: sh-agentforce keeps thin ci.yaml/deploy.yaml callers but they call
  the new cd-sfdx, NOT the AWS CDK templates (corrected the reviewer's framing).
- CR-1 decoupling: client/audience matrix injected as config (SSM/CDK env), not hardcoded
  into the transport-agnostic core; corrected reviewer's 'Secrets Manager' -> SSM (client_ids
  are non-sensitive). §6 #8d.
- Role isolation: new isolated githubdeploy-sh-agentforce (never reuse sh-mcp role), scoped
  only to read the JWT secret since deploy target is Salesforce not AWS.
Reviewer applied AWS/CDK conventions to a Salesforce-deploying repo; folded in with corrections.
2026-06-11 13:49:57 -04:00
..
agentforce-plan.md Fold in Gemini round-4 CI/CD + decoupling findings (with corrections) 2026-06-11 13:49:57 -04:00
design.md Initial commit: sh-mcp design and plan 2026-06-09 19:25:24 -04:00