v37 · 2026-07-28
canonical Dagger remote-delivery foundation
Admin master be7f119 passed CI run 30410114094. Its live SpiceDB suite opts into HTTP only for the digest-pinned ephemeral CI service through exact `ADMIN_INSECURE=true`; production TLS defaults and negative tests remain unchanged.
Root, Protocol, Research, Market, Sandbox, Cloud, Admin, SDK, Site, and Infrastructure produced green hosted evidence during this migration. Brand's replacement canonical-action run remained non-terminal when polling stopped; no success is claimed for it.
This burst performed no Cloudflare, Neon, DNS, Terraform apply, package publication, GitHub environment mutation, or 1Password write. Site and Infrastructure production changes remain review- and evidence-gated.
v36 · 2026-07-20
Authenticated Admin and evidence-bound CI mesh
Production now composes the existing server-side OIDC/session/RBAC layer through a credential-free same-origin client. Navigation and direct routes are permission guarded; refresh failure invalidates the whole browser session; logout and reauthentication remain CSRF protected.
Backend selection remains exclusively server-owned through `ADMIN_BINDING`; the browser receives only sanitized runtime receipts for SpiceDB, Keto, or Cloud.
The schema route lazy-loads exact-pinned Monaco 0.55.1, connects authenticated Frauthy Script completion, hover, definition, and diagnostics to the same-origin LSP bridge, disposes resources, escapes untrusted hover content, and retains a visible accessible textarea fallback.
A real OIDC client/provider, backend credentials, and runtime deployment remain external activation prerequisites. This code closure does not claim a live production identity or backend.
Every sibling caller is pinned to reviewed DevOps dispatch workflow commit `d39572723b2815bd1175546210325959883c3200`, waits for its real terminal CI DAG, and removes the legacy inline `FRAUTHY_CI_TOKEN` / `peter-evans` sender.
No secret was created, copied, printed, or persisted. No Cloudflare or Neon account was assumed to exist; no Terraform apply, DNS change, deployment, image publication, or SDK/UI package publication occurred.
All implementation used isolated worktrees. Active UI and product checkouts, including untracked Project Management UI work, were preserved.
v35 · 2026-07-20
Terraform-owned topology and Dagger master delivery
No Cloudflare or Neon account was assumed to exist. No Terraform apply, DNS mutation, Pages deployment, database creation, secret write, container publication, or SDK/UI package publication occurred.
Active product and UI worktrees were preserved. This program used isolated worktrees and exact-master ancestry checks so concurrent work was not overwritten.
v34 · 2026-07-19
Infrastructure-owned Site Pages contract
No live Cloudflare API mutation, Terraform apply, Pages deployment, GitHub secret write, DNS change, or cache pruning occurred in this version.
v33 · 2026-07-19
Authenticated workspace installs and gated Site delivery
Active Root, Site, and Project Management UI checkouts were preserved. The untracked `research/packages/ui/ui` tree and all product UI SDK surfaces were untouched.
v32 · 2026-07-16
Site typed content architecture
No public UI SDK package changed or was published. The active Site, Brand, and Research UI checkouts were not modified; implementation and ledger ingestion used isolated latest-master worktrees.
v31 · 2026-07-16
Site production quality gates and interactive GP.Family lab
No package was published, no production deployment occurred, and no active Brand or Research UI checkout was modified. Work was performed in isolated latest-master worktrees to preserve concurrent frontend changes.
v30 · 2026-07-16
Portal quality program assessment
ADM-1 remains open for OIDC, sessions, and RBAC; ADM-5 remains open for runtime backend selection.
ADM-3 remains open because accessible editor and LSP-oriented scaffolding do not yet constitute the complete Monaco/LSP client bridge required by the gap.
v29 · 2026-07-15
CI mesh completion and Market container contract
This burst stayed outside the concurrent frontend program's ownership: no Brand, Site UI, Admin web, Cloud web, Market web, DevOps Portal, Research UI, or product `packages/ui` implementation was changed.
v25 · 2026-07-15
data-plane, authentication, and persistence burst
The non-UI `/ws/lsp` bridge now owns one `frauthy-lsp` process per connection, incrementally translates bounded Content-Length frames, enforces a browser-origin allowlist, and propagates shutdown in both directions. A real protocol binary completed initialize and returned entity/backend completions. ADM-3 remains open for the concurrently owned Monaco and schema-page composition.
v24 · 2026-07-15
deconflicted backend gap burst
Cloud SSE watch now handles framing, cursor resume, filters, aborts, and failures; the TUI adds RFC 8628 login, secure session persistence/refresh, token/cloud overrides, and a shell-free schema editor workflow. Concurrently owned web paths were untouched.
v23 · 2026-07-15
Cloud runtime contract moved to Cloudflare
Runtime hosting decisions are now standardized on Cloudflare. Provider-specific deployment and persistence requirements should use Cloudflare primitives; prior Kubernetes/AWS/provider-selection placeholders are no longer authoritative.
v19 · 2026-07-14
Wave 14 Protocol platform and app initialization
Wave 14 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol CLI code, tests, documentation, its gap checklist, and this Research ledger event changed; no UI-owned surface, product packages/ui, Portal, registry publication, release tag, or concurrent UI branch was touched.
v18 · 2026-07-14
Wave 13 Protocol mapping completion
Wave 13 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol mapping/lifecycle code, tests, dependency metadata, its gap checklist, and this Research ledger event changed; no UI-owned, product packages/ui, Portal, registry publication, or tag path was touched.
v17 · 2026-07-14
Frontend SDK federation prerelease gate
Product UI PR 1 merged as 5295a57. The published @frauthy/admin-ui@1.0.0-next.0 tag tree is byte-identical to merged master under packages/ui.
Frontend SDK Federation automated prerelease gate complete: seven Internal @frauthy/*-ui packages at 1.0.0-next.0, exact immutable tags and registry versions, seven verified Brand Portal libraries, 240 public components, and 634 catalog previews. Stable 1.0.0 promotion remains blocked only on the planned manual VoiceOver, NVDA, and TalkBack/touch-AT evidence.
v16 · 2026-07-14
Wave 12 Protocol LSP completion
Wave 12 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol LSP code/tests/documentation and the Research ledger changed; no UI-owned, product packages/ui, Portal, registry publication, or tag path was touched.
v15 · 2026-07-14
Wave 11 Protocol async contracts
Wave 11 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol core/backend contracts, Protocol tests/documentation, and the Research ledger changed; no UI-owned, product packages/ui, Portal, registry publication, or tag path was touched.
v14 · 2026-07-14
Wave 10 Protocol dev runner
Wave 10 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol CLI, Protocol documentation, and the Research ledger changed; no UI-owned, package publication, registry, or tag path was touched.
v13 · 2026-07-14
Wave 9 Protocol-SDK type contract
Wave 9 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Protocol and core SDK are wholly Gap Closure-owned; no Brand, packages/ui, frontend composition, Portal, product UI, registry publication, or tag path changed.
v12 · 2026-07-14
Wave 8 Protocol release readiness
Wave 8 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Protocol is wholly Gap Closure-owned; no Brand, packages/ui, frontend composition, Portal, or product UI path changed.
v11 · 2026-07-14
Wave 7 branch protection
Wave 7 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. No Brand, packages/ui, frontend composition, DevOps Portal, Research UI, or Sandbox UI path changed.
v10 · 2026-07-14
Wave 6 Protocol and SDK coverage gates
Wave 6 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. No Brand, packages/ui, frontend composition, DevOps Portal, Research UI, or Sandbox UI path changed.
GitHub Actions billing is restored; all Protocol, SDK, and DevOps master workflows in this wave received runners and completed successfully.
v9 · 2026-07-14
Wave 5 coverage producers verified
GitHub Packages authentication was verified through the local gh credential. Brand packages are available at 1.0.0-next.1 and all seven product UI packages at 1.0.0-next.0 with internal visibility.
Verification remained inside the ownership boundary in root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md; no Brand, packages/ui, web composition, Portal, Research UI, or Sandbox UI path changed.
v8 · 2026-07-14
Wave 5 Cloud and Market coverage producers
Local gates passed: Cloud 208 tests with 30 live-service tests gated, Market 176 tests with 29 live-service tests gated, and DevOps 132 tests; all three typechecks passed.
GitHub marked the DevOps, Cloud, and Market jobs failed without starting a runner because recent account payments failed or the spending limit must be increased. This is recorded as a human-gated infrastructure blocker, not as code verification.
Wave 5 remained inside the ownership boundary in root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md; no Brand, packages/ui, web composition, Portal, Research UI, or Sandbox UI path changed.
v7 · 2026-07-13
Wave 4 Rust telemetry and real CI enforcement
Admin is the first sibling to upload a real coverage artifact into the tokenless reusable DevOps gate. Missing reports now fail this caller instead of silently passing.
Wave 4 followed root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. No Brand, product packages/ui, web composition, DevOps Portal, Research UI, or Sandbox UI path was changed.
GitHub Packages publication and UI release coordination remain owned by the concurrent Frontend SDK Federation.
v6 · 2026-07-13
Wave 3 cross-backend verification and observability
Wave 3 followed root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Brand, Site, product packages/ui, Cloud/Market web migration, Admin editor composition, DevOps Portal, Research UI, and Sandbox UI were intentionally untouched.
GitHub Packages publication remains blocked on a registry-compatible PAT in the concurrent federation session; no package publication is claimed here.
v5 · 2026-07-12
Wave 2 deconflicted backend and CI mesh
The WebSocket LSP client contract and MemAdminClient mock landed. ADM-3 remains open because Monaco integration, the server bridge, preview/apply, and permission enforcement are UI-owned and incomplete.
Wave 2 followed root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Brand, Site, product packages/ui, Cloud/Market web migration, Admin editor composition, DevOps Portal, Research UI, and Sandbox UI were intentionally untouched.
GitHub Packages publication remains blocked on a registry-compatible PAT in the concurrent federation session; no package publication is claimed here.
v4 · 2026-07-12
Wave 1 remote CI gate
Remote gate complete: SDK CI, infrastructure CI/image build, sandbox tokenless integration, and the manually-dispatched SDK staleness workflow are green.
v3 · 2026-07-12
Wave 1 deconflicted backend lanes
SecretStore-backed key management and the full Keto AdminClient binding are implemented with offline coverage.
NDJSON watch and the expanded TUI landed, while their deferred Cloud SSE and editor-suspension acceptance items keep ADM-2 and ADM-4 open.
Wave 1 was deconflicted from the concurrent Frontend SDK Federation. Brand, site, root, research UI, and all owned web/portal surfaces were intentionally untouched.
v1 · 2026-07-12
Baseline — workspace-wide gap audit
Seeded from the 2026-07-12 twelve-agent audit of all eleven repos plus the Cuitty capability catalog. Eleven gap-closure specs written; orchestration plan at root/specs/06-GAP-CLOSURE-ORCHESTRATION.md.