Skip to content

CI-13 [HUMAN GATE]: Private-repository cutover — prove private-mode CI, budgets, runner trust; maintainer flips visibility for v0.3.0 #2337

Description

@Chris0Jeky

Wave: Smart CI Fabric (ADR-0066 acceptance conditions). Tracker: CI-00 #2324. Human gate: the maintainer performs visibility, billing, branch-protection, credential, package-visibility, publication, and runner-association actions. Agents prepare implementation and evidence; they never infer those actions complete.

Reconciled 2026-09-18 against the current release assessment in PR #3151. Historical comments remain part of the ruling/evidence record; newer explicit maintainer rulings and exact live settings remain authoritative.

Context and settled boundaries

Taskdeck's development repository goes private for v0.3.0 on a personal GitHub Pro account. The cutover must preserve a downloadable public release while keeping the development control plane private.

Settled boundaries:

  • GitHub Actions has a $0 hard ceiling with stop-on-limit enabled.
  • The public source/release mirror is Chris0Jeky/taskdeck-release.
  • Release GHCR packages are made explicitly public and anonymously verified before repository privacy, then verified again afterward.
  • sha_pinning_required: true is already enabled and verified; it is not a future cutover step.
  • Smart CI / Required Gate is registered as required only after the repository is private, because a public fork can otherwise emit the same check context.
  • Branch-current strictness, administrator enforcement, and break-glass are chosen from completed observation evidence, not pre-ruled here.
  • Runner isolation, cleanup, offline, override, reset, and revocation are proved before any GitHub association.
  • After privacy and before runner association, the complete private-mode rehearsal is fail-closed and Linux-only across every required, called, and reusable workflow. CI-17 CI-17: Add a fail-closed Linux-only private-cutover rehearsal across all workflows #3170 owns that mechanism.
  • Full Windows evidence and the final exact-tag Windows archive use the approved isolated runner classes only after association, unless the maintainer explicitly re-rules the budget.
  • The qualified private Release is published before the public mirror consumes and republishes it.

A. Preconditions before the visibility change

All evidence is bound to exact commits, workflow/config identities, and current live settings.

B. Maintainer cutover actions, in order

Each action is recorded here with date, actor, exact setting or command, and evidence. Stop on any mismatch.

  1. Pause merges and select a short frozen cutover window.
  2. Capture current branch protection/rulesets, Actions permissions, package visibility, Pages, Releases, collaborators, forks, external surfaces, and rollback values.
  3. Review and authorize only the fresh identity-bound storage deletion set from CI-09: Bounded CI caches and artifact retention with measured utility (storage under the Pro allowance) #2333; execute and remeasure.
  4. Create/verify Chris0Jeky/taskdeck-release, keep mirror Actions disabled, and install the narrowly scoped publishing credential without exposing it in issues, logs, or repository files.
  5. Set every release GHCR package explicitly public and prove anonymous pull/read access.
  6. Confirm the Pro plan and the settled $0 stop-on-limit posture.
  7. Change the development repository visibility to private. Agents never perform this action.
  8. Immediately register Smart CI / Required Gate, retain the security contexts, and apply the evidence-based strict, administrator-enforcement, and break-glass decisions.
  9. Re-check Actions permissions, fork approval policy, Dependabot, Pages, packages, Releases, mirror links, collaborators, forks, and anonymous GHCR access.
  10. Keep every self-hosted runner unassociated. Run R0/R2/R4 PRs, one normal merge, one nightly dispatch, and one no-publish release rehearsal through CI-17's trusted Linux-only mode. Abort the cutover if any private hosted Windows job is scheduled, the control is absent/bypassable, or expected Linux/control/security evidence is missing.
  11. Only after step 10 succeeds, associate the already-proven isolated runners if hybrid mode remains desired. Verify labels, read-only token posture, no secret exposure, selected self-hosted workload evidence, and full Windows evidence on approved runner classes.
  12. If hybrid mode is not retained, record hosted-only operation and explicitly re-rule the final Windows build budget/path before creating the release tag.
  13. Record the complete evidence ledger on CI-00 CI-00 [TRACKER][decision]: Smart CI Fabric and private-repository readiness (ADR-0066) — go private for v0.3.0 on a personal GitHub Pro account #2324 and resume merges only when every cutover assertion is reconciled.

C. Final release actions after cutover

  • Freeze one exact main commit and stop feature merges.
  • Complete final-head checks and a no-publish rehearsal.
  • Activate and prove a draft-only hold so the tag-triggered workflow cannot publish before post-tag evidence is accepted.
  • Create the real v0.3.0 tag on the frozen commit.
  • Qualify that exact tag on hosted Linux/control lanes and the secret-safe isolated Windows release runner.
  • Reconcile both runner-class evidence sets to the same tag, commit, policy, checksums, provenance, and release contract.
  • Consumer-smoke the Windows archive, immutable container, MCP proposal flow, upgrade path, and supported backup/restore claims.
  • Publish the private Release with the exact qualified assets, checksums, provenance, and body.
  • Let the mirror stage and verify its source snapshot and byte-identical assets before publishing its public commit, tag, and Release.
  • Verify mirror downloads, links, checksums, provenance, and GHCR access anonymously before announcement.

D. Rollback and abort rules

  • Keep previous workflow/config files reachable by immutable commit and capture all previous setting values before mutation.
  • The hosted control override remains available; runners can be detached and revoked in one step.
  • Do not flip public merely to regain free minutes. Diagnose against the captured state and use the documented override/rollback path.
  • Do not create the release tag while the publication hold, runner boundary, Linux-only rehearsal, public GHCR continuity, mirror handoff, or exact-head evidence is unproved.
  • A failed or ambiguous assertion stops the cutover. Record the failure and restore the captured safe setting where applicable.

Acceptance

  • Sections A and B are complete with exact evidence.
  • The development repository is private.
  • Smart CI / Required Gate and retained security checks are enforced under the recorded policy.
  • The pre-association private rehearsal used CI-17's fail-closed Linux-only mode and scheduled zero private hosted Windows jobs.
  • Any associated runners were already proven and passed their separate post-association workload evidence.
  • Public GHCR access, Pages, mirror source, Releases, assets, checksums, provenance, and links survive the cutover.
  • The real tag can be qualified and published through the approved runner and mirror boundaries without exceeding the settled budget.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Priority IRelease-blocking or trust-breaking now; release scope still requires milestone membership.ciCI/CD pipeline, workflow, and build infrastructure changes.human-actionNeeds maintainer credentials, settings, legal judgement, or confirmation; agents never infer done.securityAuthentication, authorization, data protection, abuse prevention, and compliance-related changes.

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions