Skip to program ledger

Living Program Ledger

Frauthy/Project Management

v37 · 2026-07-28

Immutable ingestion receipt

Version 37

This receipt records what the digest claimed at ingestion time. Current health appears only on the current overview.
v37 · · archived

canonical Dagger remote-delivery foundation

Source
Ledger event v37
01

Recorded changes

devops

DevOps master f710474 normalizes every DevOps-owned GitHub Actions caller onto the reviewed immutable `frauthy/devops@4cf1a2fc5017182a9163e8bb2e3ecdb1d84c34cf` action. The generated workspace ledger covers 12 repositories and 45 workflows with zero policy violations.

Canonical resolution accepts authenticated private packages only for allowlisted `frauthy/*` repositories at verified immutable source SHAs. Installation uses the Frauthy GitHub Packages scope, disables lifecycle scripts, removes `NODE_AUTH_TOKEN` before repository code, and asserts the credential is absent.

DevOps E2E run 30409982948 and Delivery Foundation run 30409982964 passed at action source 4cf1a2f. The final normalized DevOps source was pushed after those action gates; full central CI remained non-terminal when GitHub API polling reached its rate limit, so no broader green claim is made.

site

Site PR 9 head 460dd3a pins the canonical Dagger action, retires alternate deployment/package mutation paths, and checks in `SPEC_FRAUTHY_COM_LAUNCH_2026-07-27.md`. Provider-free Site checks run 30410495912 and delivery analysis run 30410495913 passed.

The launch contract keeps `https://frauthy.com` canonical, public documentation private-beta redacted, and production cutover unauthorized. The PR still requires an independent last-push approval before merge.

No Pages upload, Cloudflare topology mutation, DNS cutover, TLS activation, artifact rollback rehearsal, automatic production enablement, or launch attestation occurred. The monitored exact-plan and provider-host gates remain launch blockers.

infrastructure

Infrastructure PR 18 head d83c28f pins the same canonical Dagger action as Site. CI run 30410137243 and Terraform Plan run 30410137256 passed all bootstrap, Site, staging, and production matrices.

The Infrastructure caller migration still requires an independent last-push approval before merge. Provider mutations remain disabled; `package-site`, provider-host deployment/verification, exact cutover apply, and automatic Site enablement must retain their named fail-closed boundaries until their bounded contracts and negative tests are reviewed.

admin

Admin master be7f119 passed CI run 30410114094. Its live SpiceDB suite opts into HTTP only for the digest-pinned ephemeral CI service through exact `ADMIN_INSECURE=true`; production TLS defaults and negative tests remain unchanged.

sdk

SDK master e534667 passed CI run 30410120101. The canonical Dagger profile removes engine OTLP variables before both Go and Python repository tests so each SDK's documented telemetry defaults remain deterministic.

Program-wide

Root, Protocol, Research, Market, Sandbox, Cloud, Admin, SDK, Site, and Infrastructure produced green hosted evidence during this migration. Brand's replacement canonical-action run remained non-terminal when polling stopped; no success is claimed for it.

This burst performed no Cloudflare, Neon, DNS, Terraform apply, package publication, GitHub environment mutation, or 1Password write. Site and Infrastructure production changes remain review- and evidence-gated.