Infrastructure-owned Site Pages contract
- Source
- Ledger event v34
Living Program Ledger
Immutable ingestion receipt
infrastructure
status → amber
ci → green (exact-head Infrastructure CI run 29699859699: format, validation, mocked staging/production plans, environment plan smokes, lifecycle guards, lint, Compose validation, and deferred coverage gate)
deploy → Production Terraform owns the single direct-upload `frauthy-site` Pages project contract; no Terraform apply, Cloudflare mutation, DNS change, or deployment was performed
commit → 270c4361c52ac6d3c641da99c4c8353b5fd8340e
observedAt → 2026-07-19
evidenceMode → automated
Production state owns exactly one account-global Pages project with `master` as its production branch and `prevent_destroy`; staging owns none, while preview deployments share the production-owned project.
The resource intentionally omits Git source integration, build configuration, custom domains, DNS records, and credentials. The Site workflow remains limited to uploading an immutable built artifact.
Production preflight now verifies Pages read access and documents the required Pages Read/Write token scope. A pre-existing `frauthy-site` project must be imported once into production and produce a no-replacement plan before any apply.
site
status → green
deploy → Manual Cloudflare Pages production/preview workflow and its Infrastructure-owned project contract are ready; neither provisioning nor deployment was performed
observedAt → 2026-07-19
evidenceMode → automated
SITE-9 remains closed. Activating hosting still requires the protected Site deployment environments and credentials, an approved Infrastructure production import-or-create plan, and a separately reviewed domain/DNS contract if `frauthy.dev` is attached.
Program-wide
No live Cloudflare API mutation, Terraform apply, Pages deployment, GitHub secret write, DNS change, or cache pruning occurred in this version.