Part of #1096.
Goal
Give the Operator a narrowly authorized service identity and deterministic GitHub event reconciliation without relying on a shared personal PAT.
Scope
- GitHub App installation-token support with least-privilege permission documentation.
- Polling-first reconciliation with optional webhook acceleration; webhook delivery is never the sole source of truth.
- Repository allowlist, event cursor/checkpointing, duplicate suppression, rate-limit backoff, and revocation behavior.
- Read-only shadow posture and separately authorized active mutation posture.
- Owner setup and rotation runbook.
Acceptance criteria
Code Mower delivery
One focused PR with mocked GitHub App flows, reconciliation fixtures, docs, and independent exact-head review. Live App provisioning remains an owner-controlled pilot step.
Part of #1096.
Goal
Give the Operator a narrowly authorized service identity and deterministic GitHub event reconciliation without relying on a shared personal PAT.
Scope
Acceptance criteria
Code Mower delivery
One focused PR with mocked GitHub App flows, reconciliation fixtures, docs, and independent exact-head review. Live App provisioning remains an owner-controlled pilot step.