Authenticated Admin and evidence-bound CI mesh
- Source
- Ledger event v36
Living Program Ledger
Immutable ingestion receipt
admin
status → amber
ci → green (exact-head Admin CI run 29756414021: typecheck, coverage, client and UI SDK builds, packed-consumer verification, production authentication boundary, Monaco route, accessibility, and reusable dispatch caller)
coverage → client 76%, web 100%, and TUI 23% floors pass; the repository coverage ratchet remains enforced
commit → d8332a2ca8ed7242b006f1927228a8beb598504e
observedAt → 2026-07-20
evidenceMode → automated
Closed: ADM-1, ADM-3, ADM-5
Production now composes the existing server-side OIDC/session/RBAC layer through a credential-free same-origin client. Navigation and direct routes are permission guarded; refresh failure invalidates the whole browser session; logout and reauthentication remain CSRF protected.
Backend selection remains exclusively server-owned through `ADMIN_BINDING`; the browser receives only sanitized runtime receipts for SpiceDB, Keto, or Cloud.
The schema route lazy-loads exact-pinned Monaco 0.55.1, connects authenticated Frauthy Script completion, hover, definition, and diagnostics to the same-origin LSP bridge, disposes resources, escapes untrusted hover content, and retains a visible accessible textarea fallback.
A real OIDC client/provider, backend credentials, and runtime deployment remain external activation prerequisites. This code closure does not claim a live production identity or backend.
devops
status → amber
ci → green (exact-head DevOps CI run 29756288185, E2E Smoke run 29756286932, and Delivery Foundation run 29756288087)
coverage → complete historical master evidence covers all 11 configured producers at 19,327/27,752 lines (69.64%); automated complete-set enforcement remains credential-gated
commit → 48ea1a81d0bc1984fd3ff6892641522f20b8146d
observedAt → 2026-07-20
evidenceMode → automated
The reusable dispatch sender validates an allowlisted Frauthy repository, `push`, `refs/heads/master`, exact lowercase commit SHA, schema-1 payload, and deterministic idempotency key. The receiver rejects mismatches, deduplicates concurrent receipts, and checks out the exact source SHA.
Sender authority is isolated in `FRAUTHY_DISPATCH_TOKEN`; receiver checkout authority is isolated in read-only `FRAUTHY_CI_READ_TOKEN`. No workflow uses one token for both boundaries or inherits all caller secrets.
DEVOPS-5 remains open because no dedicated sender credential exists and no live sibling-push dispatch has occurred. Green missing-credential skips are not dispatch evidence.
DEVOPS-7 remains open because Workspace coverage run 29755242260 performed only the explicit credential check; source resolution, collection, and enforcement correctly skipped without `FRAUTHY_CI_READ_TOKEN`. The checked-in 69.64% baseline proves the complete historical data contract, not the live automated path.
protocol
ci → green (exact-head Protocol CI run 29756434292: Rust, CLI, type contract, integrations, coverage gates, and reusable dispatch caller)
commit → c35be1e8cba83305198195106fda4f8012b387d0
observedAt → 2026-07-20
evidenceMode → automated
Protocol now calls the reviewed DevOps sender only after every mandatory terminal succeeds. The covered platform-init test retains all assertions and has a 30-second budget for its real cold Cargo-backed compile after the hosted 10-second default proved insufficient.
sdk
ci → green (exact-head SDK CI run 29755780234: four-language tests and coverage, type contract, conformance, and reusable dispatch caller)
commit → 13b5e1b1f85df8ce07234454b8ebfeadd06d95f2
observedAt → 2026-07-20
evidenceMode → automated
cloud
ci → green (exact-head Cloud CI run 29755777452: TypeScript, OTLP gRPC, container/Cloudflare contract, coverage, and reusable dispatch caller)
commit → 20b689929c94010ff106cb5b0dd330612d36c36c
observedAt → 2026-07-20
evidenceMode → automated
market
ci → green (exact-head Market CI run 29755782538: backend, UI/web, container health, coverage, and reusable dispatch caller)
commit → 5c02958d9e8f7dfde04e4145b7722792f7602cad
observedAt → 2026-07-20
evidenceMode → automated
site
ci → green (exact-head Site CI run 29755779630 and Dagger Delivery run 29755778865)
coverage → 87.00% on the expanded current master instrumented surface (348/400 lines), above the enforced 50% floor; v35's 97.06% remains immutable historical evidence from the earlier narrower scope
commit → bf5cf5d11ce577669126bc851c536b9ac25b2e96
observedAt → 2026-07-20
evidenceMode → automated
Site now calls the reviewed sender after its enforced coverage terminal; the exact Dagger delivery remains provider-disabled and no Cloudflare mutation occurred.
infrastructure
ci → green (exact-head Infrastructure CI run 29755777669: Terraform validation/plans, topology and lifecycle tests, Compose validation, coverage contract, and reusable dispatch caller)
commit → 02ceb2d2a57992e305ec37f58c82e363a827f7ae
observedAt → 2026-07-20
evidenceMode → automated
Terraform remains the sole owner of Cloudflare, Neon, DNS, routing, secret references, and environment topology. The caller rollout performed no apply or provider mutation.
Program-wide
Every sibling caller is pinned to reviewed DevOps dispatch workflow commit `d39572723b2815bd1175546210325959883c3200`, waits for its real terminal CI DAG, and removes the legacy inline `FRAUTHY_CI_TOKEN` / `peter-evans` sender.
No secret was created, copied, printed, or persisted. No Cloudflare or Neon account was assumed to exist; no Terraform apply, DNS change, deployment, image publication, or SDK/UI package publication occurred.
All implementation used isolated worktrees. Active UI and product checkouts, including untracked Project Management UI work, were preserved.