v37 · 2026-07-28
canonical Dagger remote-delivery foundation
Site PR 9 head 460dd3a pins the canonical Dagger action, retires alternate deployment/package mutation paths, and checks in `SPEC_FRAUTHY_COM_LAUNCH_2026-07-27.md`. Provider-free Site checks run 30410495912 and delivery analysis run 30410495913 passed.
The launch contract keeps `https://frauthy.com` canonical, public documentation private-beta redacted, and production cutover unauthorized. The PR still requires an independent last-push approval before merge.
No Pages upload, Cloudflare topology mutation, DNS cutover, TLS activation, artifact rollback rehearsal, automatic production enablement, or launch attestation occurred. The monitored exact-plan and provider-host gates remain launch blockers.
Root, Protocol, Research, Market, Sandbox, Cloud, Admin, SDK, Site, and Infrastructure produced green hosted evidence during this migration. Brand's replacement canonical-action run remained non-terminal when polling stopped; no success is claimed for it.
This burst performed no Cloudflare, Neon, DNS, Terraform apply, package publication, GitHub environment mutation, or 1Password write. Site and Infrastructure production changes remain review- and evidence-gated.
v36 · 2026-07-20
Authenticated Admin and evidence-bound CI mesh
Site now calls the reviewed sender after its enforced coverage terminal; the exact Dagger delivery remains provider-disabled and no Cloudflare mutation occurred.
Every sibling caller is pinned to reviewed DevOps dispatch workflow commit `d39572723b2815bd1175546210325959883c3200`, waits for its real terminal CI DAG, and removes the legacy inline `FRAUTHY_CI_TOKEN` / `peter-evans` sender.
No secret was created, copied, printed, or persisted. No Cloudflare or Neon account was assumed to exist; no Terraform apply, DNS change, deployment, image publication, or SDK/UI package publication occurred.
All implementation used isolated worktrees. Active UI and product checkouts, including untracked Project Management UI work, were preserved.
v35 · 2026-07-20
Terraform-owned topology and Dagger master delivery
Browser, accessibility, Lighthouse, per-file binary hashes, package evidence, and final directory identity gate the same build artifact. Dagger admitted 33 files and 2,714,639 bytes at Site digest `sha256:b6ce6c31cb3bbd6b64db2d5eb358acb6c03c68ae4f2b688b0f69ce710de6f273`; the legacy direct-deploy workflows remain visible refusal stubs.
No Cloudflare or Neon account was assumed to exist. No Terraform apply, DNS mutation, Pages deployment, database creation, secret write, container publication, or SDK/UI package publication occurred.
Active product and UI worktrees were preserved. This program used isolated worktrees and exact-master ancestry checks so concurrent work was not overwritten.
v34 · 2026-07-19
Infrastructure-owned Site Pages contract
SITE-9 remains closed. Activating hosting still requires the protected Site deployment environments and credentials, an approved Infrastructure production import-or-create plan, and a separately reviewed domain/DNS contract if `frauthy.dev` is attached.
No live Cloudflare API mutation, Terraform apply, Pages deployment, GitHub secret write, DNS change, or cache pruning occurred in this version.
v33 · 2026-07-19
Authenticated workspace installs and gated Site delivery
Site master 620c6a7 adds a `workflow_dispatch`-only, GitHub-environment-scoped delivery path that fails closed on missing Cloudflare credentials, retains an immutable `site-dist-<commit-sha>` artifact, publishes only `dist/`, and verifies the returned URL plus the canonical `https://frauthy.dev` sitemap.
The workflow cannot create Cloudflare projects, accounts, DNS, domains, or secrets. Resource provisioning remains owned by Infrastructure; the Site workflow only uploads an application artifact to a pre-provisioned Pages project.
Rollback promotes a prior known-good Pages deployment matched to its retained commit artifact. No Site Actions secrets or Cloudflare deployment environments were present during this burst, so the manual workflow was not dispatched.
Active Root, Site, and Project Management UI checkouts were preserved. The untracked `research/packages/ui/ui` tree and all product UI SDK surfaces were untouched.
v32 · 2026-07-16
Site typed content architecture
Site master 1c66b1d moves all fourteen Discovery sections into an ordered, schema-validated MDX collection and reduces `src/pages/index.astro` to a collection renderer. Multiline code and structured examples live in typed neighboring data modules.
Ten local Astro presentation components now own repeated badges, code blocks, diagrams, headers, links, and tuples. Architecture tests enforce the exact component inventory and prohibit client directives or inline scripts in those server-rendered components.
A static baseline comparison preserved every section's bounding box and all 26,230 visible text characters at 1440px. Only 979 of 27,305,280 screenshot pixels differed, limited to antialiasing noise (0.003585%).
SITE-9 remains open and human-gated pending the production hosting-provider decision; no deployment was performed.
No public UI SDK package changed or was published. The active Site, Brand, and Research UI checkouts were not modified; implementation and ledger ingestion used isolated latest-master worktrees.
v31 · 2026-07-16
Site production quality gates and interactive GP.Family lab
Site master e547aa9 adds deterministic unit coverage, fourteen browser checks across six routes, axe scans with zero accepted violations, Lighthouse evidence uploads, and exact-pinned ESLint/Prettier tooling. The hosted run passed the reusable coverage workflow with a real LCOV artifact and its ratchet floor enforced.
The GP.Family page now contains a client-side SolidJS permission lab with editable identity input, trusted-domain mapping, four timed lifecycle stages, allow/deny verdicts, and an explicit `email_verified` fail-closed path. Browser tests verify allow, deny, and guard behavior.
The shared layout now emits a 1200x630 Frauthy social card through `og:image` and `twitter:image` metadata. Context-aware light, dark, and federated component palettes also resolved legacy WCAG contrast failures discovered by the new gate.
SITE-7, SITE-8, and the human-gated SITE-9 remain open; this burst did not claim component extraction, content-collection migration, or a production hosting decision.
No package was published, no production deployment occurred, and no active Brand or Research UI checkout was modified. Work was performed in isolated latest-master worktrees to preserve concurrent frontend changes.
v30 · 2026-07-16
Portal quality program assessment
Getting Started links directly to detailed UI and SDK documentation, and the reference accurately covers TypeScript, Rust, Go, and Python.
SITE-1, SITE-2, SITE-5, SITE-6, SITE-7, SITE-8, and SITE-9 remain open.
v29 · 2026-07-15
CI mesh completion and Market container contract
This burst stayed outside the concurrent frontend program's ownership: no Brand, Site UI, Admin web, Cloud web, Market web, DevOps Portal, Research UI, or product `packages/ui` implementation was changed.
v23 · 2026-07-15
Cloud runtime contract moved to Cloudflare
Runtime hosting decisions are now standardized on Cloudflare. Provider-specific deployment and persistence requirements should use Cloudflare primitives; prior Kubernetes/AWS/provider-selection placeholders are no longer authoritative.
v19 · 2026-07-14
Wave 14 Protocol platform and app initialization
Wave 14 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol CLI code, tests, documentation, its gap checklist, and this Research ledger event changed; no UI-owned surface, product packages/ui, Portal, registry publication, release tag, or concurrent UI branch was touched.
v18 · 2026-07-14
Wave 13 Protocol mapping completion
Wave 13 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol mapping/lifecycle code, tests, dependency metadata, its gap checklist, and this Research ledger event changed; no UI-owned, product packages/ui, Portal, registry publication, or tag path was touched.
v17 · 2026-07-14
Frontend SDK federation prerelease gate
Product UI PR 1 merged as 94a0fb5. The published @frauthy/site-ui@1.0.0-next.0 tag tree is byte-identical to merged master under packages/ui.
Frontend SDK Federation automated prerelease gate complete: seven Internal @frauthy/*-ui packages at 1.0.0-next.0, exact immutable tags and registry versions, seven verified Brand Portal libraries, 240 public components, and 634 catalog previews. Stable 1.0.0 promotion remains blocked only on the planned manual VoiceOver, NVDA, and TalkBack/touch-AT evidence.
v16 · 2026-07-14
Wave 12 Protocol LSP completion
Wave 12 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol LSP code/tests/documentation and the Research ledger changed; no UI-owned, product packages/ui, Portal, registry publication, or tag path was touched.
v15 · 2026-07-14
Wave 11 Protocol async contracts
Wave 11 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol core/backend contracts, Protocol tests/documentation, and the Research ledger changed; no UI-owned, product packages/ui, Portal, registry publication, or tag path was touched.
v14 · 2026-07-14
Wave 10 Protocol dev runner
Wave 10 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol CLI, Protocol documentation, and the Research ledger changed; no UI-owned, package publication, registry, or tag path was touched.
v13 · 2026-07-14
Wave 9 Protocol-SDK type contract
Wave 9 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Protocol and core SDK are wholly Gap Closure-owned; no Brand, packages/ui, frontend composition, Portal, product UI, registry publication, or tag path changed.
v12 · 2026-07-14
Wave 8 Protocol release readiness
Wave 8 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Protocol is wholly Gap Closure-owned; no Brand, packages/ui, frontend composition, Portal, or product UI path changed.
v11 · 2026-07-14
Wave 7 branch protection
Wave 7 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. No Brand, packages/ui, frontend composition, DevOps Portal, Research UI, or Sandbox UI path changed.
v10 · 2026-07-14
Wave 6 Protocol and SDK coverage gates
Wave 6 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. No Brand, packages/ui, frontend composition, DevOps Portal, Research UI, or Sandbox UI path changed.
GitHub Actions billing is restored; all Protocol, SDK, and DevOps master workflows in this wave received runners and completed successfully.
v9 · 2026-07-14
Wave 5 coverage producers verified
GitHub Packages authentication was verified through the local gh credential. Brand packages are available at 1.0.0-next.1 and all seven product UI packages at 1.0.0-next.0 with internal visibility.
Verification remained inside the ownership boundary in root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md; no Brand, packages/ui, web composition, Portal, Research UI, or Sandbox UI path changed.
v8 · 2026-07-14
Wave 5 Cloud and Market coverage producers
Local gates passed: Cloud 208 tests with 30 live-service tests gated, Market 176 tests with 29 live-service tests gated, and DevOps 132 tests; all three typechecks passed.
GitHub marked the DevOps, Cloud, and Market jobs failed without starting a runner because recent account payments failed or the spending limit must be increased. This is recorded as a human-gated infrastructure blocker, not as code verification.
Wave 5 remained inside the ownership boundary in root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md; no Brand, packages/ui, web composition, Portal, Research UI, or Sandbox UI path changed.
v7 · 2026-07-13
Wave 4 Rust telemetry and real CI enforcement
Wave 4 followed root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. No Brand, product packages/ui, web composition, DevOps Portal, Research UI, or Sandbox UI path was changed.
GitHub Packages publication and UI release coordination remain owned by the concurrent Frontend SDK Federation.
v6 · 2026-07-13
Wave 3 cross-backend verification and observability
Wave 3 followed root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Brand, Site, product packages/ui, Cloud/Market web migration, Admin editor composition, DevOps Portal, Research UI, and Sandbox UI were intentionally untouched.
GitHub Packages publication remains blocked on a registry-compatible PAT in the concurrent federation session; no package publication is claimed here.
v5 · 2026-07-12
Wave 2 deconflicted backend and CI mesh
Wave 2 followed root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Brand, Site, product packages/ui, Cloud/Market web migration, Admin editor composition, DevOps Portal, Research UI, and Sandbox UI were intentionally untouched.
GitHub Packages publication remains blocked on a registry-compatible PAT in the concurrent federation session; no package publication is claimed here.
v4 · 2026-07-12
Wave 1 remote CI gate
Remote gate complete: SDK CI, infrastructure CI/image build, sandbox tokenless integration, and the manually-dispatched SDK staleness workflow are green.
v3 · 2026-07-12
Wave 1 deconflicted backend lanes
Wave 1 was deconflicted from the concurrent Frontend SDK Federation. Brand, site, root, research UI, and all owned web/portal surfaces were intentionally untouched.
v1 · 2026-07-12
Baseline — workspace-wide gap audit
Seeded from the 2026-07-12 twelve-agent audit of all eleven repos plus the Cuitty capability catalog. Eleven gap-closure specs written; orchestration plan at root/specs/06-GAP-CLOSURE-ORCHESTRATION.md.