You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Repository-side S6 scaffolding is already substantial on main: the canonical S6 manifest has five partitions (contract, postgres, operator-desktop, operator-mobile, host-boundary) driven by four S6 suite commands plus a separate signed host preflight. Historical integrated review explicitly removed a duplicate issuance S6 partition because packet issuance belongs to #179/S4 and is already proven there.
The S6 controller surface defaults fail closed with externalControllerRequired: true, host evidence untrusted locally, ingress/issuance disabled and live activation disabled. Repository code cannot itself provide the required independent external trust.
The remaining release-critical work is operational: bind the independently installed controller GitHub App/check identity, protected repository rules, supported isolated host/root harness, signer/attestation material and final signed evidence chain to an exact reviewed commit.
Desired Outcome
An independently controlled supported-host release lane executes S6 against an exact reviewed SHA, produces externally signed preflight/suite/output/teardown/destruction evidence, publishes the exact-App-pinned forge/host-boundary-controller Check Run, and allows final Epic-172 readiness only when all required predecessor/authorization/lease/evidence predicates are satisfied.
Repository Actions/checkout code cannot counterfeit the required controller identity/evidence.
Install/verify attestation public key + controller challenge path required by npm run preflight:mcp:host-boundary.
Run exact current S6 set: preflight + test:mcp:contract + test:mcp:postgres + e2e:mcp-operator + test:mcp:host-boundary; do not resurrect a separate S6 issuance suite.
Verify manifest identity/count and zero skip/retry/missing scenario behavior.
Produce signed evidence bound to exact SHA/build/image/App/check/epoch for preflight, suite results, output allowlist/scan, teardown/quiescence and VM destruction/trusted reimage.
Run canonical inspect/disable/retry/key-rotation operator commands and prove fail-closed behavior under wrong identity/fingerprint/state.
Execute final enabled-build proof only inside allowed provisional window/lease and verify final readiness consumes required enablement + enabled-build receipts atomically.
Record release-closeout receipt/report containing only approved sanitized/path-free evidence metadata; no raw quarantined artifact upload.
Preflight proof — run signed preflight from exact checkout; wrong host/image/key/challenge/SHA/dependency digest fails before suites.
Suite proof — execute current four commands/five manifest partitions with fixed ordering/limits, no skip/retry, isolated fixtures and exact scenario identity/count assertions.
Quarantine/output proof — scan/allow only schema-validated sanitized path-free evidence; prove raw Playwright reports/logs/traces/screenshots/videos/dumps/diffs/archives/prompts/credentials cannot leave disposable host.
Teardown/destruction proof — signed quiescence/process/resource teardown plus controller-owned VM destruction/trusted reimage receipt outside checkout authority.
Failure/replay/controller-loss matrix — wrong/replayed signatures, stale authorization, lease expiry, controller/runner loss, timeout/failing suite/quarantine/destruction loss; every path fails closed with no readiness promotion.
Provisional activation/final readiness — exercise controlled activation window with live controller lease/heartbeat and atomically consume exact enablement + enabled-build green receipts before deadline.
Key rotation/disable/retry/recovery — canonical operator commands and signer/controller lifecycle evidence; no stale key/receipt promotion.
Every required suite runs first-attempt with no skip/retry and exact manifest identities/counts.
Signed evidence covers preflight, exact suite result, output scan/manifest, teardown/quiescence and VM destruction/reimage bound to exact build/image/App/check identity.
Wrong/stale/replayed/cross-build/cross-App evidence or controller/lease loss fails closed before activation/final readiness.
Output quarantine permits only schema-validated sanitized path-free status/evidence; raw reports/logs/traces/screenshots/videos/dumps/diffs/archives/prompts/credentials do not leave disposable environment.
Final readiness occurs only while same provisional owner/lease/deadline is valid and consumes required receipts atomically.
Unsupported hosts remain activation-ineligible without corrupting epoch/evidence/state.
Operator inspect/disable/retry/key-rotation/rollback behavior is proven against the live configured lane.
Closeout contains no raw controller private key/token/credential and is independently reviewable.
Reintroducing a standalone S6 packet-issuance suite.
Letting repository code own the privileged controller/harness.
Weakening output quarantine for debugging.
Implementation Scope
Very Large / release-critical infrastructure - repository-side changes may be small, but host/App/ruleset provisioning and evidence exercises require multiple independently reviewable operational checkpoints.
Technical Notes
This work necessarily includes external GitHub/host mutations and secret material. Implementation agents may prepare/configure through available authorized interfaces, but every consequential change must retain operator-visible evidence and never expose raw keys/tokens in ordinary GitHub issues/Actions artifacts.
Execution mode: implementation
Parent release Epic: #181 / #172
Depends on: #348, #352
Issue Type
Project Setup / Release Governance
Context
Repository-side S6 scaffolding is already substantial on
main: the canonical S6 manifest has five partitions (contract,postgres,operator-desktop,operator-mobile,host-boundary) driven by four S6 suite commands plus a separate signed host preflight. Historical integrated review explicitly removed a duplicateissuanceS6 partition because packet issuance belongs to #179/S4 and is already proven there.The S6 controller surface defaults fail closed with
externalControllerRequired: true, host evidence untrusted locally, ingress/issuance disabled and live activation disabled. Repository code cannot itself provide the required independent external trust.The remaining release-critical work is operational: bind the independently installed controller GitHub App/check identity, protected repository rules, supported isolated host/root harness, signer/attestation material and final signed evidence chain to an exact reviewed commit.
Desired Outcome
An independently controlled supported-host release lane executes S6 against an exact reviewed SHA, produces externally signed preflight/suite/output/teardown/destruction evidence, publishes the exact-App-pinned
forge/host-boundary-controllerCheck Run, and allows final Epic-172 readiness only when all required predecessor/authorization/lease/evidence predicates are satisfied.Repository Actions/checkout code cannot counterfeit the required controller identity/evidence.
Tasks
forge/host-boundary-controllerrequired Check Run binding only for the applicable S6 release path/ruleset, without weakening base [BUG][P0][SECURITY] Enforce Forge release gates with GitHub main-branch protection/ruleset #348 checks or deadlocking unrelated changes.npm run preflight:mcp:host-boundary.test:mcp:contract+test:mcp:postgres+e2e:mcp-operator+test:mcp:host-boundary; do not resurrect a separate S6 issuance suite.Implementation Sequence
main; produce one immutable external-dependency manifest before provisioning.Primary Code / Control Seams To Inspect First
docs/operators/host-boundary-controller-v2.mddocs/architecture/issue-181-e2e-admission-regression.mddocs/architecture/issue-181-review-amendments.md.github/workflows/mcp-host-boundary-trusted.ymlweb/test-contracts/mcp-admission-v2.jsonweb/lib/mcps/epic-172-s6-release-adapter.tsweb/package.jsonOrthogonal Checkpoints
Acceptance Criteria
mainprotections remain intact and S6 adds an exact external App/check requirement only where applicable; ordinary PRs are not deadlocked.Out of Scope
Implementation Scope
Very Large / release-critical infrastructure - repository-side changes may be small, but host/App/ruleset provisioning and evidence exercises require multiple independently reviewable operational checkpoints.
Technical Notes
This work necessarily includes external GitHub/host mutations and secret material. Implementation agents may prepare/configure through available authorized interfaces, but every consequential change must retain operator-visible evidence and never expose raw keys/tokens in ordinary GitHub issues/Actions artifacts.