Skip to program ledger

Living Program Ledger

Frauthy/Project Management

v37 · 2026-07-28

Immutable ingestion receipt

Version 36

This receipt records what the digest claimed at ingestion time. Current health appears only on the current overview.
v36 · · archived

Authenticated Admin and evidence-bound CI mesh

Source
Ledger event v36
01

Recorded changes

admin

status → amber

ci → green (exact-head Admin CI run 29756414021: typecheck, coverage, client and UI SDK builds, packed-consumer verification, production authentication boundary, Monaco route, accessibility, and reusable dispatch caller)

coverage → client 76%, web 100%, and TUI 23% floors pass; the repository coverage ratchet remains enforced

commit → d8332a2ca8ed7242b006f1927228a8beb598504e

observedAt → 2026-07-20

evidenceMode → automated

Closed: ADM-1, ADM-3, ADM-5

Production now composes the existing server-side OIDC/session/RBAC layer through a credential-free same-origin client. Navigation and direct routes are permission guarded; refresh failure invalidates the whole browser session; logout and reauthentication remain CSRF protected.

Backend selection remains exclusively server-owned through `ADMIN_BINDING`; the browser receives only sanitized runtime receipts for SpiceDB, Keto, or Cloud.

The schema route lazy-loads exact-pinned Monaco 0.55.1, connects authenticated Frauthy Script completion, hover, definition, and diagnostics to the same-origin LSP bridge, disposes resources, escapes untrusted hover content, and retains a visible accessible textarea fallback.

A real OIDC client/provider, backend credentials, and runtime deployment remain external activation prerequisites. This code closure does not claim a live production identity or backend.

devops

status → amber

ci → green (exact-head DevOps CI run 29756288185, E2E Smoke run 29756286932, and Delivery Foundation run 29756288087)

coverage → complete historical master evidence covers all 11 configured producers at 19,327/27,752 lines (69.64%); automated complete-set enforcement remains credential-gated

commit → 48ea1a81d0bc1984fd3ff6892641522f20b8146d

observedAt → 2026-07-20

evidenceMode → automated

The reusable dispatch sender validates an allowlisted Frauthy repository, `push`, `refs/heads/master`, exact lowercase commit SHA, schema-1 payload, and deterministic idempotency key. The receiver rejects mismatches, deduplicates concurrent receipts, and checks out the exact source SHA.

Sender authority is isolated in `FRAUTHY_DISPATCH_TOKEN`; receiver checkout authority is isolated in read-only `FRAUTHY_CI_READ_TOKEN`. No workflow uses one token for both boundaries or inherits all caller secrets.

DEVOPS-5 remains open because no dedicated sender credential exists and no live sibling-push dispatch has occurred. Green missing-credential skips are not dispatch evidence.

DEVOPS-7 remains open because Workspace coverage run 29755242260 performed only the explicit credential check; source resolution, collection, and enforcement correctly skipped without `FRAUTHY_CI_READ_TOKEN`. The checked-in 69.64% baseline proves the complete historical data contract, not the live automated path.

protocol

ci → green (exact-head Protocol CI run 29756434292: Rust, CLI, type contract, integrations, coverage gates, and reusable dispatch caller)

commit → c35be1e8cba83305198195106fda4f8012b387d0

observedAt → 2026-07-20

evidenceMode → automated

Protocol now calls the reviewed DevOps sender only after every mandatory terminal succeeds. The covered platform-init test retains all assertions and has a 30-second budget for its real cold Cargo-backed compile after the hosted 10-second default proved insufficient.

sdk

ci → green (exact-head SDK CI run 29755780234: four-language tests and coverage, type contract, conformance, and reusable dispatch caller)

commit → 13b5e1b1f85df8ce07234454b8ebfeadd06d95f2

observedAt → 2026-07-20

evidenceMode → automated

cloud

ci → green (exact-head Cloud CI run 29755777452: TypeScript, OTLP gRPC, container/Cloudflare contract, coverage, and reusable dispatch caller)

commit → 20b689929c94010ff106cb5b0dd330612d36c36c

observedAt → 2026-07-20

evidenceMode → automated

market

ci → green (exact-head Market CI run 29755782538: backend, UI/web, container health, coverage, and reusable dispatch caller)

commit → 5c02958d9e8f7dfde04e4145b7722792f7602cad

observedAt → 2026-07-20

evidenceMode → automated

site

ci → green (exact-head Site CI run 29755779630 and Dagger Delivery run 29755778865)

coverage → 87.00% on the expanded current master instrumented surface (348/400 lines), above the enforced 50% floor; v35's 97.06% remains immutable historical evidence from the earlier narrower scope

commit → bf5cf5d11ce577669126bc851c536b9ac25b2e96

observedAt → 2026-07-20

evidenceMode → automated

Site now calls the reviewed sender after its enforced coverage terminal; the exact Dagger delivery remains provider-disabled and no Cloudflare mutation occurred.

infrastructure

ci → green (exact-head Infrastructure CI run 29755777669: Terraform validation/plans, topology and lifecycle tests, Compose validation, coverage contract, and reusable dispatch caller)

commit → 02ceb2d2a57992e305ec37f58c82e363a827f7ae

observedAt → 2026-07-20

evidenceMode → automated

Terraform remains the sole owner of Cloudflare, Neon, DNS, routing, secret references, and environment topology. The caller rollout performed no apply or provider mutation.

Program-wide

Every sibling caller is pinned to reviewed DevOps dispatch workflow commit `d39572723b2815bd1175546210325959883c3200`, waits for its real terminal CI DAG, and removes the legacy inline `FRAUTHY_CI_TOKEN` / `peter-evans` sender.

No secret was created, copied, printed, or persisted. No Cloudflare or Neon account was assumed to exist; no Terraform apply, DNS change, deployment, image publication, or SDK/UI package publication occurred.

All implementation used isolated worktrees. Active UI and product checkouts, including untracked Project Management UI work, were preserved.