v37 · 2026-07-28
canonical Dagger remote-delivery foundation
Root, Protocol, Research, Market, Sandbox, Cloud, Admin, SDK, Site, and Infrastructure produced green hosted evidence during this migration. Brand's replacement canonical-action run remained non-terminal when polling stopped; no success is claimed for it.
This burst performed no Cloudflare, Neon, DNS, Terraform apply, package publication, GitHub environment mutation, or 1Password write. Site and Infrastructure production changes remain review- and evidence-gated.
v36 · 2026-07-20
Authenticated Admin and evidence-bound CI mesh
Every sibling caller is pinned to reviewed DevOps dispatch workflow commit `d39572723b2815bd1175546210325959883c3200`, waits for its real terminal CI DAG, and removes the legacy inline `FRAUTHY_CI_TOKEN` / `peter-evans` sender.
No secret was created, copied, printed, or persisted. No Cloudflare or Neon account was assumed to exist; no Terraform apply, DNS change, deployment, image publication, or SDK/UI package publication occurred.
All implementation used isolated worktrees. Active UI and product checkouts, including untracked Project Management UI work, were preserved.
v35 · 2026-07-20
Terraform-owned topology and Dagger master delivery
No Cloudflare or Neon account was assumed to exist. No Terraform apply, DNS mutation, Pages deployment, database creation, secret write, container publication, or SDK/UI package publication occurred.
Active product and UI worktrees were preserved. This program used isolated worktrees and exact-master ancestry checks so concurrent work was not overwritten.
v34 · 2026-07-19
Infrastructure-owned Site Pages contract
No live Cloudflare API mutation, Terraform apply, Pages deployment, GitHub secret write, DNS change, or cache pruning occurred in this version.
v33 · 2026-07-19
Authenticated workspace installs and gated Site delivery
Active Root, Site, and Project Management UI checkouts were preserved. The untracked `research/packages/ui/ui` tree and all product UI SDK surfaces were untouched.
v32 · 2026-07-16
Site typed content architecture
No public UI SDK package changed or was published. The active Site, Brand, and Research UI checkouts were not modified; implementation and ledger ingestion used isolated latest-master worktrees.
v31 · 2026-07-16
Site production quality gates and interactive GP.Family lab
No package was published, no production deployment occurred, and no active Brand or Research UI checkout was modified. Work was performed in isolated latest-master worktrees to preserve concurrent frontend changes.
v30 · 2026-07-16
Portal quality program assessment
The control-plane portal now uses same-origin services, traces, metrics, alerts, projects, keys, billing, and audit APIs while fixture states remain explicit.
GitHub Packages authentication stays on the CI runner; Docker receives the tested portal plus the public backend dependency graph and no registry credential.
v29 · 2026-07-15
CI mesh completion and Market container contract
This burst stayed outside the concurrent frontend program's ownership: no Brand, Site UI, Admin web, Cloud web, Market web, DevOps Portal, Research UI, or product `packages/ui` implementation was changed.
v26 · 2026-07-15
autonomous Cloud observability closure
Alert evaluation now runs immediately and every 60 seconds over completed minute buckets, persists restart-safe targets and deduplicated firings under PostgreSQL RLS, and isolates target failures. A pinned OpenTelemetry Collector now accepts authenticated OTLP/gRPC on :4317, preserves per-request authorization metadata through batching, forwards uncompressed OTLP/JSON, and stores a queryable five-span Frauthy lifecycle trace. The parser groups standard multi-resourceSpans envelopes and accepts OTLP/JSON int64 strings. Local Compose evidence and Cloud CI run 29459113423 cover the bridge; no UI or deployment paths changed.
v25 · 2026-07-15
data-plane, authentication, and persistence burst
Tenant eject now produces owner-gated asynchronous archives with source/compiled schema, store tuples, all retained OTLP traces, and recursively redacted configuration. Schema POST/GET compiles through the real frauthyc boundary, applies through the provisioned store gateway, persists under forced tenant RLS, and tracks lifecycle failures. Minute metrics, alert CRUD/history, threshold evaluation, and explicit route scopes are implemented; CLOUD-6 remains open for the unattended 60-second evaluator and live migration evidence.
v24 · 2026-07-15
deconflicted backend gap burst
Stripe webhooks are signature-verified and persist tenant plan/status actions; Postgres queries enforce transactional tenant context and forced RLS; service tokens persist hashed with bounded caches; OTLP rotation invalidates cached old keys immediately; project PATCH is tenant-scoped. Tenant/export and schema work remain partial and open.
v23 · 2026-07-15
Cloud runtime contract moved to Cloudflare
Cloud master 04f35ef replaces the GHCR placeholder with a typed Worker, Durable Object container binding, pinned Bun image, and real cloudflare/wrangler-action deployment workflow.
CI builds the runtime image on every push and pull request, starts it, and verifies GET /health before validating both Wrangler environments.
GitHub Packages remains the registry for @frauthy/* SDK artifacts. Cloudflare's integrated container registry owns runtime images.
The hosting decision is Cloudflare-only. Container-local DuckDB is explicitly ephemeral; the next deployment lane migrates control-plane and APM persistence to Cloudflare-hosted durable services before production traffic.
Runtime hosting decisions are now standardized on Cloudflare. Provider-specific deployment and persistence requirements should use Cloudflare primitives; prior Kubernetes/AWS/provider-selection placeholders are no longer authoritative.
v19 · 2026-07-14
Wave 14 Protocol platform and app initialization
Wave 14 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol CLI code, tests, documentation, its gap checklist, and this Research ledger event changed; no UI-owned surface, product packages/ui, Portal, registry publication, release tag, or concurrent UI branch was touched.
v18 · 2026-07-14
Wave 13 Protocol mapping completion
Wave 13 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol mapping/lifecycle code, tests, dependency metadata, its gap checklist, and this Research ledger event changed; no UI-owned, product packages/ui, Portal, registry publication, or tag path was touched.
v17 · 2026-07-14
Frontend SDK federation prerelease gate
Product UI PR 1 merged as fced089. The published @frauthy/cloud-ui@1.0.0-next.0 tag tree is byte-identical to merged master under packages/ui.
Frontend SDK Federation automated prerelease gate complete: seven Internal @frauthy/*-ui packages at 1.0.0-next.0, exact immutable tags and registry versions, seven verified Brand Portal libraries, 240 public components, and 634 catalog previews. Stable 1.0.0 promotion remains blocked only on the planned manual VoiceOver, NVDA, and TalkBack/touch-AT evidence.
v16 · 2026-07-14
Wave 12 Protocol LSP completion
Wave 12 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol LSP code/tests/documentation and the Research ledger changed; no UI-owned, product packages/ui, Portal, registry publication, or tag path was touched.
v15 · 2026-07-14
Wave 11 Protocol async contracts
Wave 11 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol core/backend contracts, Protocol tests/documentation, and the Research ledger changed; no UI-owned, product packages/ui, Portal, registry publication, or tag path was touched.
v14 · 2026-07-14
Wave 10 Protocol dev runner
Wave 10 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol CLI, Protocol documentation, and the Research ledger changed; no UI-owned, package publication, registry, or tag path was touched.
v13 · 2026-07-14
Wave 9 Protocol-SDK type contract
Wave 9 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Protocol and core SDK are wholly Gap Closure-owned; no Brand, packages/ui, frontend composition, Portal, product UI, registry publication, or tag path changed.
v12 · 2026-07-14
Wave 8 Protocol release readiness
Wave 8 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Protocol is wholly Gap Closure-owned; no Brand, packages/ui, frontend composition, Portal, or product UI path changed.
v11 · 2026-07-14
Wave 7 branch protection
Wave 7 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. No Brand, packages/ui, frontend composition, DevOps Portal, Research UI, or Sandbox UI path changed.
v10 · 2026-07-14
Wave 6 Protocol and SDK coverage gates
Wave 6 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. No Brand, packages/ui, frontend composition, DevOps Portal, Research UI, or Sandbox UI path changed.
GitHub Actions billing is restored; all Protocol, SDK, and DevOps master workflows in this wave received runners and completed successfully.
v9 · 2026-07-14
Wave 5 coverage producers verified
Actions run 29337448693 passed with 2,220 of 3,508 instrumented lines covered. The retained gate artifact records the floor, target, measurement, and passing decision.
GitHub Packages authentication was verified through the local gh credential. Brand packages are available at 1.0.0-next.1 and all seven product UI packages at 1.0.0-next.0 with internal visibility.
Verification remained inside the ownership boundary in root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md; no Brand, packages/ui, web composition, Portal, Research UI, or Sandbox UI path changed.
v8 · 2026-07-14
Wave 5 Cloud and Market coverage producers
Master now emits coverage/lcov.info, uploads coverage-cloud, and requires the shared DevOps ratchet. CLOUD-13 remains open until the mandatory remote job can execute successfully.
Local gates passed: Cloud 208 tests with 30 live-service tests gated, Market 176 tests with 29 live-service tests gated, and DevOps 132 tests; all three typechecks passed.
GitHub marked the DevOps, Cloud, and Market jobs failed without starting a runner because recent account payments failed or the spending limit must be increased. This is recorded as a human-gated infrastructure blocker, not as code verification.
Wave 5 remained inside the ownership boundary in root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md; no Brand, packages/ui, web composition, Portal, Research UI, or Sandbox UI path changed.
v7 · 2026-07-13
Wave 4 Rust telemetry and real CI enforcement
Wave 4 followed root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. No Brand, product packages/ui, web composition, DevOps Portal, Research UI, or Sandbox UI path was changed.
GitHub Packages publication and UI release coordination remain owned by the concurrent Frontend SDK Federation.
v6 · 2026-07-13
Wave 3 cross-backend verification and observability
Cloud preserves OTLP service.name through parsing, DuckDB, ClickHouse, and the trace summary API, including migrations for existing stores.
Wave 3 followed root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Brand, Site, product packages/ui, Cloud/Market web migration, Admin editor composition, DevOps Portal, Research UI, and Sandbox UI were intentionally untouched.
GitHub Packages publication remains blocked on a registry-compatible PAT in the concurrent federation session; no package publication is claimed here.
v5 · 2026-07-12
Wave 2 deconflicted backend and CI mesh
Cloud adopted the shared CI-mesh contract on its backend master. Web migration remains owned by the concurrent Frontend SDK Federation.
Wave 2 followed root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Brand, Site, product packages/ui, Cloud/Market web migration, Admin editor composition, DevOps Portal, Research UI, and Sandbox UI were intentionally untouched.
GitHub Packages publication remains blocked on a registry-compatible PAT in the concurrent federation session; no package publication is claimed here.
v4 · 2026-07-12
Wave 1 remote CI gate
Remote gate complete: SDK CI, infrastructure CI/image build, sandbox tokenless integration, and the manually-dispatched SDK staleness workflow are green.
v3 · 2026-07-12
Wave 1 deconflicted backend lanes
Runtime repository selection, checks/lookup/relationship proxying, idempotent Postgres migrations, and the 41014/41015 port split are implemented and covered offline.
Docker/deploy, RLS, and persistent-token work landed substantially; their gap IDs remain open where acceptance items are still outstanding.
Wave 1 was deconflicted from the concurrent Frontend SDK Federation. Brand, site, root, research UI, and all owned web/portal surfaces were intentionally untouched.
v1 · 2026-07-12
Baseline — workspace-wide gap audit
Seeded from the 2026-07-12 twelve-agent audit of all eleven repos plus the Cuitty capability catalog. Eleven gap-closure specs written; orchestration plan at root/specs/06-GAP-CLOSURE-ORCHESTRATION.md.