CI mesh completion and Market container contract
- Source
- Ledger event v29
Living Program Ledger
Immutable ingestion receipt
devops
status → amber
ci → green (DevOps CI run 29465465358 and Site CI run 29465467309)
coverage → All original sibling repositories now adopt the shared reusable coverage workflow; Site is non-enforcing until SITE-1 supplies its first LCOV artifact
Closed: DEVOPS-1
Site master 617616d is the final original sibling caller of `frauthy/devops/.github/workflows/coverage.yml@master`; its first hosted invocation passed and explicitly deferred enforcement because Site has no coverage producer yet.
DEVOPS-5 remains open. `FRAUTHY_CI_TOKEN` is not configured, so Site's token-safe notification job skipped green and no live cross-repository dispatch was claimed.
DEVOPS-7 remains open until SITE-1 supplies Site coverage and the workspace orchestrator emits verified aggregate evidence.
The locally authenticated GitHub CLI token has broad OAuth scopes and was intentionally not copied into Actions; the live dispatcher still requires a dedicated least-privilege token.
market
status → amber
ci → green (Market CI run 29467159091: backend tests, typecheck, UI/web builds, credential-free executable, production image build, live container health smoke, and coverage gate)
deploy → Production Docker contract and manual immutable GHCR image publication are ready; runtime rollout remains owned exclusively by Infrastructure Terraform on Cloudflare
Closed: MKT-5
Market master 3e65b31 adds a pinned non-root Bun image around a compiled Linux-musl executable with embedded Postgres and SpiceDB schemas, a credential-free Docker context, `/health` probe, SBOM/provenance publication, and reusable GitHub Actions cache.
The deploy workflow publishes `ghcr.io/frauthy/market:<immutable-tag>` only when manually dispatched. It contains no Cloudflare, Wrangler, or Terraform apply and this burst created no runtime resources.
Local Docker verification was blocked by the host's critically low free space and a BuildKit metadata I/O error; no shared Docker data was pruned or restarted. The compiled executable passed a local loopback health probe, while hosted Actions supplied the authoritative clean image-build and container-health evidence.
Program-wide
This burst stayed outside the concurrent frontend program's ownership: no Brand, Site UI, Admin web, Cloud web, Market web, DevOps Portal, Research UI, or product `packages/ui` implementation was changed.