You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Wave: Smart CI Fabric (ADR-0066 acceptance conditions). Tracker: CI-00 #2324. Human gate: the maintainer performs visibility, billing, branch-protection, credential, package-visibility, publication, and runner-association actions. Agents prepare implementation and evidence; they never infer those actions complete.
Reconciled 2026-09-18 against the current release assessment in PR #3151. Historical comments remain part of the ruling/evidence record; newer explicit maintainer rulings and exact live settings remain authoritative.
Context and settled boundaries
Taskdeck's development repository goes private for v0.3.0 on a personal GitHub Pro account. The cutover must preserve a downloadable public release while keeping the development control plane private.
Settled boundaries:
GitHub Actions has a $0 hard ceiling with stop-on-limit enabled.
The public source/release mirror is Chris0Jeky/taskdeck-release.
Release GHCR packages are made explicitly public and anonymously verified before repository privacy, then verified again afterward.
sha_pinning_required: true is already enabled and verified; it is not a future cutover step.
Smart CI / Required Gate is registered as required only after the repository is private, because a public fork can otherwise emit the same check context.
Branch-current strictness, administrator enforcement, and break-glass are chosen from completed observation evidence, not pre-ruled here.
Runner isolation, cleanup, offline, override, reset, and revocation are proved before any GitHub association.
Full Windows evidence and the final exact-tag Windows archive use the approved isolated runner classes only after association, unless the maintainer explicitly re-rules the budget.
The qualified private Release is published before the public mirror consumes and republishes it.
A. Preconditions before the visibility change
All evidence is bound to exact commits, workflow/config identities, and current live settings.
CI-02/CI-03 planner and gate evidence meets the accepted observation window: at least 20 usable merged PRs after the last relevant fix, zero false reds, complete recall for enabled lane families, bounded normal merges, and fail-closed full escalation for direct pushes, missing receipts, moved bases, and ambiguous evidence.
Landed verification has authoritative evidence collection and workflow integration, not only a decision core.
Public-mode dry runs cover release, mirror, GHCR, private-rehearsal selection, and all expected Linux/control/security evidence.
Public assets, Pages, packages, Releases, install links, licensing, support, telemetry, launch-kit, and awesome-selfhosted references have an explicit post-cutover destination.
Codex/Copilot/private-mode review and Actions billing behaviour is verified rather than assumed; review cadence runs after CI stabilises instead of after every micro-push.
B. Maintainer cutover actions, in order
Each action is recorded here with date, actor, exact setting or command, and evidence. Stop on any mismatch.
Pause merges and select a short frozen cutover window.
Capture current branch protection/rulesets, Actions permissions, package visibility, Pages, Releases, collaborators, forks, external surfaces, and rollback values.
Create/verify Chris0Jeky/taskdeck-release, keep mirror Actions disabled, and install the narrowly scoped publishing credential without exposing it in issues, logs, or repository files.
Set every release GHCR package explicitly public and prove anonymous pull/read access.
Confirm the Pro plan and the settled $0 stop-on-limit posture.
Change the development repository visibility to private. Agents never perform this action.
Immediately register Smart CI / Required Gate, retain the security contexts, and apply the evidence-based strict, administrator-enforcement, and break-glass decisions.
Keep every self-hosted runner unassociated. Run R0/R2/R4 PRs, one normal merge, one nightly dispatch, and one no-publish release rehearsal through CI-17's trusted Linux-only mode. Abort the cutover if any private hosted Windows job is scheduled, the control is absent/bypassable, or expected Linux/control/security evidence is missing.
Only after step 10 succeeds, associate the already-proven isolated runners if hybrid mode remains desired. Verify labels, read-only token posture, no secret exposure, selected self-hosted workload evidence, and full Windows evidence on approved runner classes.
If hybrid mode is not retained, record hosted-only operation and explicitly re-rule the final Windows build budget/path before creating the release tag.
Freeze one exact main commit and stop feature merges.
Complete final-head checks and a no-publish rehearsal.
Activate and prove a draft-only hold so the tag-triggered workflow cannot publish before post-tag evidence is accepted.
Create the real v0.3.0 tag on the frozen commit.
Qualify that exact tag on hosted Linux/control lanes and the secret-safe isolated Windows release runner.
Reconcile both runner-class evidence sets to the same tag, commit, policy, checksums, provenance, and release contract.
Consumer-smoke the Windows archive, immutable container, MCP proposal flow, upgrade path, and supported backup/restore claims.
Publish the private Release with the exact qualified assets, checksums, provenance, and body.
Let the mirror stage and verify its source snapshot and byte-identical assets before publishing its public commit, tag, and Release.
Verify mirror downloads, links, checksums, provenance, and GHCR access anonymously before announcement.
D. Rollback and abort rules
Keep previous workflow/config files reachable by immutable commit and capture all previous setting values before mutation.
The hosted control override remains available; runners can be detached and revoked in one step.
Do not flip public merely to regain free minutes. Diagnose against the captured state and use the documented override/rollback path.
Do not create the release tag while the publication hold, runner boundary, Linux-only rehearsal, public GHCR continuity, mirror handoff, or exact-head evidence is unproved.
A failed or ambiguous assertion stops the cutover. Record the failure and restore the captured safe setting where applicable.
Acceptance
Sections A and B are complete with exact evidence.
The development repository is private.
Smart CI / Required Gate and retained security checks are enforced under the recorded policy.
The pre-association private rehearsal used CI-17's fail-closed Linux-only mode and scheduled zero private hosted Windows jobs.
Any associated runners were already proven and passed their separate post-association workload evidence.
Public GHCR access, Pages, mirror source, Releases, assets, checksums, provenance, and links survive the cutover.
The real tag can be qualified and published through the approved runner and mirror boundaries without exceeding the settled budget.
Wave: Smart CI Fabric (ADR-0066 acceptance conditions). Tracker: CI-00 #2324. Human gate: the maintainer performs visibility, billing, branch-protection, credential, package-visibility, publication, and runner-association actions. Agents prepare implementation and evidence; they never infer those actions complete.
Context and settled boundaries
Taskdeck's development repository goes private for
v0.3.0on a personal GitHub Pro account. The cutover must preserve a downloadable public release while keeping the development control plane private.Settled boundaries:
$0hard ceiling with stop-on-limit enabled.Chris0Jeky/taskdeck-release.sha_pinning_required: trueis already enabled and verified; it is not a future cutover step.Smart CI / Required Gateis registered as required only after the repository is private, because a public fork can otherwise emit the same check context.A. Preconditions before the visibility change
All evidence is bound to exact commits, workflow/config identities, and current live settings.
SHIP,CLOSE ON EVIDENCE,EXPLICIT RESIDUAL,DEFER, orHUMAN GATEdisposition; [Backend][Frontend][Review] Make proposal provenance metadata lifecycle- and authorization-safe #2315 retains its existing non-blocking residual ruling.$0.awesome-selfhostedreferences have an explicit post-cutover destination.B. Maintainer cutover actions, in order
Each action is recorded here with date, actor, exact setting or command, and evidence. Stop on any mismatch.
Chris0Jeky/taskdeck-release, keep mirror Actions disabled, and install the narrowly scoped publishing credential without exposing it in issues, logs, or repository files.$0stop-on-limit posture.Smart CI / Required Gate, retain the security contexts, and apply the evidence-basedstrict, administrator-enforcement, and break-glass decisions.C. Final release actions after cutover
maincommit and stop feature merges.v0.3.0tag on the frozen commit.D. Rollback and abort rules
Acceptance
Smart CI / Required Gateand retained security checks are enforced under the recorded policy.