Require signed production E2E before readiness - #12
Draft
echoomegaprime wants to merge 7 commits into
Draft
echoomegaprime wants to merge 7 commits into
echoomegaprime wants to merge 7 commits into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds CertForge 1.2.0 production-E2E evidence as an engine invariant. A verdict cannot be PRODUCTION_READY without a fresh pinned-key Ed25519 attestation bound to the exact source SHA, deployment SHA, target identity, environment identity, required checks, and signed envelope. Adds the strict Echo GitHub Autonomy profile for the canonical 30-tool, four-account, public/private, upstream-reconciled, four-client service.
Why
Commander directive: Certification Forge must never issue a green certificate before the entire production journey is complete end to end. Source-only checks, successful exits, and reachable URLs are insufficient.
Validation
Live production E2E not run: this issuer change must deploy before it can verify the Autonomy deployment.
Security
Collector keys are independently pinned server-side; target-controlled public keys are rejected. Raw dictionaries cannot satisfy the executor type boundary. GitHub App credentials remain preferred, Vault user-token fallback is permitted only server-side, and model/client-config credentials or secret exposure fail the Autonomy profile. No database migration. Rollback is deployment of parent commit 153ee6b.
Evidence
Commit: 8a6e10d
Branch: agent/e2e-verdict-gate
Certification Forge: not run - live E2E prerequisite intentionally not yet satisfied
Release Sentinel: not run - review branch only
CodeQL: pending hosted checks on this exact SHA