Skip to content

AP-SPEC-066 Epic 5: launch gate and operator qualification simulation - #206

Draft
bordumb wants to merge 76 commits into
mainfrom
codex/recipe-qualification
Draft

bordumb wants to merge 76 commits into
mainfrom
codex/recipe-qualification

Conversation

@bordumb

@bordumb bordumb commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

First production qualification previously required its own existing attestation. This adds purpose-separated, finite commissioning authority on the private operator path while ordinary clients retain the production qualification gate. Signed permits bind the exact native actor/actions, production tuple, source, disposable resources and protected run; PostgreSQL budgets and separately retained host floors prevent renewal or restore from resetting consumption.

The change also pins the offline qualification root and public ceremony, adds native credential-free request review and independent Stripe/Airtable references, separates commissioning from ordinary qualified-client evidence, and compares fresh response/doctor witnesses without wildcard expectations. Actual custody and HTTP boundaries expose private process-scoped measurements; closed execution traces remain available for redaction/audit. Release readiness derives from verified current qualifications for the exact candidate.

Independent operator work includes the source-free native simulation kit, real development-provider journeys with an installed Python wheel, and resumable resource lifecycle CLIs. The latest local Docker rehearsal created and fully retired one Stripe test payment and one dedicated Airtable record. Stripe uses platform-account test refunds without Connect.

Validation: local provider rehearsals passed; generated semantic identities/closure are current. Hosted validation is pending on the latest head. Development evidence explicitly excludes protected production qualification.

Before merging Epic 5: complete admitted family corpora and protected commissioning → first record → ordinary live orchestration, obtain signed protected closure, and pass CI. Shared-environment changes/provider-secret uploads were rejected by automatic approval review and remain unapplied. PR #207 and the actual GitHub release installation follow qualification completion.

bordumb and others added 28 commits October 5, 2026 21:05
auths-gateway support-bundle writes one bounded archive: versions,
digests, the deployment and credential-store kinds, the qualification
state and code, the connection state a serving gateway reports, and the
digest and stage of each stored attempt. It is built from a struct with
no member that holds text, so a proof, action, body, credential,
location, account, resource identifier, or header has no way in.

Both attempt stores gain a bounded listing of attempt keys. A test
installs a gateway whose credential and account label are the custody
fixture's canaries, leaves the other nine beside the installation and
in the environment, and scans the archive for all eleven; the assertion
that the gateway had no support bundle is retired.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Source-SHA: 71a85bf

Workflow-Run: 37414864276
@bordumb
bordumb had a problem deploying to gateway-custody-live October 6, 2026 19:58 — with GitHub Actions Error
@bordumb
bordumb had a problem deploying to gateway-custody-live October 6, 2026 19:58 — with GitHub Actions Error
bordumb and others added 30 commits October 7, 2026 01:51
Source-SHA: 47dfc3c

Workflow-Run: 37575326551

This branch is waiting to be deployed

1 waiting (outdated) deployment
gateway-custody-live — 71909013 Waiting Oct 6, 2026 by bordumb via gateway journey on the production credential store #37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant