Skip to content

docs: require HTTP-only Forge/Workspace peers and retain EP ingress parity - #197

Merged
pcvantol merged 1 commit into
mainfrom
codex/http-only-peers-thin-cli-docs-v1
Sep 12, 2026
Merged

docs: require HTTP-only Forge/Workspace peers and retain EP ingress parity#197
pcvantol merged 1 commit into
mainfrom
codex/http-only-peers-thin-cli-docs-v1

Conversation

@pcvantol

Copy link
Copy Markdown
Owner

Owner-requested documentary refinement HTTP_ONLY_PEERS_AND_THIN_CLI_V1, coordinated with Forge #104 and Workspace #29.

  • Forge and Workspace product calls to EP use authenticated versioned HTTP only, including on the same machine and on outage. No peer CLI/import/SQL/File Inbox fallback.
  • Preserve EP's supported HTTP, own CLI and Server-owned File Inbox over the same owning application/admission services. The peer restriction does not remove human/local automation ingress.
  • Own CLI remains management/AI automation; explicit supported local-only init/start/recovery is not an authorization bypass or a reason to expose privileged routes remotely.
  • Three planned EH conformance nodes reuse P-TRANSPORT, existing ingress tests and qualified evidence rather than rebuild working transport. OpenAPI/routes/Postman, installed parity and seven shared HT scenarios cover negative boundaries.
  • Bootstrap edit adds navigation only; no existing onboarding instruction, authority, parked item or generic projection is replaced.

Three documentation/JSON files; NO_BUMP. No source, tests, workflows, package/version, CENTRAL, services, credentials, grants, Mission, budgets, canary or PR175 changes.

Validation before PR: Python 3.13.5 offline checks PASS for JSON, unique/acyclic per-repo and combined graph, Markdown/JSON edges, shared transport invariants, source pins and graph/document links; staged git diff --check PASS. Existing modified Bootstrap bytes verified against original Git blob before additive links. Partial isolated editing workspace only: full local EP validation/installed/browser tests NOT run; await actual hosted exact-head checks. No independent review claimed.

Source observation bd4c09ff85bc82783da6efb9f1f781dfb8100e17; current base advanced via #196 to da0e558b8049ae1b384cefc139355e4a4b8f5c09. Readback comparison confirms no overlap with these three paths, so #196 is fully preserved. Candidate 211e206f64ae397f4333e1294b876fd724ad9c00. Normal protected merge only; retain work branch and PR if blocked.

Add owning P-TRANSPORT conformance design/DAG and bootstrap navigation. Forge/Workspace consume EP only over HTTP; own CLI and Server-owned File Inbox remain supported thin ingresses. No runtime, workflow, version, credential, installation or Mission change. Preserve independently merged #196.

Copy link
Copy Markdown
Owner Author

Finale deliverycontrole op exact 211e206f64ae397f4333e1294b876fd724ad9c00:

  • Drie bedoelde Markdown/JSON-bestanden; alle Git-blob-SHA's matchen de lokaal gecontroleerde bytes. Offline document-/DAGchecks opnieuw PASS op Python 3.13.5: resolvable/acyclisch, gelijke transportinvarianten in de drie repositories, table/JSON-pariteit, documentlinks, docs-only allow-list en staged whitespace. Dit is geen volledige lokale EP- of installed qualification.
  • Engineering Platform validation 34702383025: SUCCESS. Installed P-TRANSPORT 3×2 ingressmatrix, deterministische Genesis/Managed E2E, HTTP/OpenAPI/Postman en coverage liepen via de eigen hosted workflow. De conditionele browser-dashboard- en UI-GOLDEN-LOCALIZATION-jobs waren SKIPPED voor deze scope; niet als PASS meegeteld.
  • Golden Qualification 34702383023, Trusted Delivery 34702383147, Security baseline 34702383020, CodeQL 34702383026 en TDE observe 34702383040: SUCCESS. TDE blijft observe-only. Bestaande workflow meldt Owner Authorization SUCCESS; geen status of approval handmatig geconstrueerd.
  • Geen PR-reviews of open reviewthreads aangetroffen; deze comment is eigen diff-/evidencecontrole, geen onafhankelijke review.
  • fix: centralize advisory analysis and execution context #196 is behouden via base da0e558b8049ae1b384cefc139355e4a4b8f5c09; eerder gecontroleerde diff had geen overlap met deze drie paden. Forge docs: governed delivery boundaries without external CD takeover #104 is gemerged op 2ff27234ca95b1f94c7235cc7ce12244b9cd8f69; Workspace P-CENTRAL-CORE: single operational authority completion #29 op 664a3eb87b7b6523d0473dc8b696e94064908940.

Documentaire uitkomst: HTTP-only Forge/Workspace peerintegratie, gedeelde eigen applicatieservices voor HTTP/CLI/File Inbox, expliciete local-only managementgrens en 3 EH conformance-nodes onder bestaande P-TRANSPORT. Bestaande werkende ingress niet als ontbrekend geherclassificeerd. Geen nieuwe runtime, API-route, CLI-gedrag, workflow, packageversie, credential, CENTRAL-, service-, Mission-, budget- of E2E-mutatie. NO_BUMP; nieuwe conformance delivery blijft PLANNED. Normale squash-PR-route met expected-head, geen bypass.

@pcvantol
pcvantol merged commit 363a550 into main Sep 12, 2026
15 checks passed
@pcvantol
pcvantol deleted the codex/http-only-peers-thin-cli-docs-v1 branch September 12, 2026 15:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant