Skip to program ledger

Living Program Ledger

Frauthy/Project Management

v37 · 2026-07-28

Immutable ingestion receipt

Version 3

This receipt records what the digest claimed at ingestion time. Current health appears only on the current overview.
v3 · · archived

Wave 1 deconflicted backend lanes

Source
Ledger event v3
01

Recorded changes

protocol

Closed: PROTO-2, PROTO-6, PROTO-7, PROTO-8, PROTO-10, PROTO-14, PROTO-15

Domain registration now round-trips, eject is reversible, compiler diagnostics are expanded, BetterAuth and Hydra adapters are real, OIDC-connected proof verification works, lifecycle trace context is carried, and CI installs are Socket Firewall compliant.

PROTO-1 remains open; the async trait redesign was deliberately deferred instead of landing a partial contract migration.

sdk

Closed: SDK-7, SDK-8

Go New() and Python from_config() now construct real SpiceDB/Keto clients; TypeScript canAll() now returns the cross-language BatchResult shape in v0.5.0.

Rust, Go, and Python OTLP exporters plus real Rust OIDC verification landed, but SDK-1 and SDK-4 remain open until their remaining endpoint-level acceptance tests are added.

cloud

Closed: CLOUD-2, CLOUD-5, CLOUD-9, CLOUD-12

Runtime repository selection, checks/lookup/relationship proxying, idempotent Postgres migrations, and the 41014/41015 port split are implemented and covered offline.

Docker/deploy, RLS, and persistent-token work landed substantially; their gap IDs remain open where acceptance items are still outstanding.

market

Closed: MKT-4, MKT-8

Domain verification now supports well-known, DNS TXT, and connected OIDC proofs; the missing adoption, API-key, and organization-member routes are implemented across memory and Postgres repositories.

Frauthy-backed OIDC authentication, Postgres/ReBAC runtime selection, and OTLP tracing landed but retain open live-integration acceptance items.

admin

Closed: ADM-6, ADM-8

SecretStore-backed key management and the full Keto AdminClient binding are implemented with offline coverage.

NDJSON watch and the expanded TUI landed, while their deferred Cloud SSE and editor-suspension acceptance items keep ADM-2 and ADM-4 open.

infrastructure

Closed: INFRA-4, INFRA-6, INFRA-7, INFRA-8

Offline-safe plan/apply workflows, the runnable BetterAuth development image, Terraform lint gates, and Keto seeding are implemented. Docker target plans produce concrete containers across the six modules.

Full target apply/destroy, AWS state/SSM activation, and a live Keto metrics probe remain open and human/environment gated.

devops

Closed: DEVOPS-4, DEVOPS-8, DEVOPS-9, DEVOPS-10

Shared conformance fixtures, callable conformance CI, corrected coverage paths, and a dry-run-safe publish workflow are implemented; all 125 tests pass.

The 41xxx e2e migration landed, but DEVOPS-11 remains open for its live stack and portal/Cuitty acceptance items.

sandbox

Closed: SBX-1, SBX-2, SBX-3, SBX-5, SBX-7

Offline CI now uses vendored SDK artifacts, dynamic board creation writes and rolls back authorization tuples, observability is asserted per hop, and sandbox APM uses 41023.

The vendored snapshot was refreshed after SDK master landed (sdk c237968, TypeScript v0.5.0); tokenless typecheck and unit gates pass for shared, aggregator, Quill, and Lens.

Program-wide

Wave 1 was deconflicted from the concurrent Frontend SDK Federation. Brand, site, root, research UI, and all owned web/portal surfaces were intentionally untouched.