Skip to content

[R1] Prove manual single-organization credentials for the foreground MVP #67

Description

@jjangg96

Goal

Demonstrate a manually configured single-organization credential path for the foreground MVP that binds the intended installation and never exposes management credentials to workers.

Dependencies

None for the isolated credential evidence work; coordinated under #66.

Scope

Extract the R1 credential subset of #2 without closing or rewriting its broader Manifest, multi-organization or launchd qualification. Use the already-created test App and private canary repository only under explicit authorization; no automatic App creation. Foreground-only execution must declare its identity and lifecycle; unattended login/logout/reboot service behavior is NOT supported in R1.

Acceptance

  • Explicit minimal permission, org/repository/installation identity and credential source validation before remote effects.
  • Actual authorized manual configuration works; missing/wrong/expired credentials, wrong installation and partial setup refuse safely without extra Apps or leaked values.
  • Management credentials never reach worker argv/environment/files; only per-worker JIT follows the reviewed G01 transport.
  • Record source/artifact provenance, private input/parent ownership and ACL safeguards appropriate to the chosen path, actual authorized platform result, support limits and rollback.
  • Credentials are not persisted or imported to Keychain implicitly; any storage change has separately scoped authorization.
  • Sanitized evidence and independently reviewed PR; broader [G02] Prove local App enrollment and launchd credential access #2 remains open until its own criteria pass.

Execution and safety

Release R1. Maintainer-approved delivery reorganization #66; preserve the full original parent issue and historical records. Main implementation Grok 4.6 xhigh; independent Luna max review. TDD meaningful failing behavior before minimal implementation; exact commands/results, gaps and rollback. Exact-head clean external Codex review (inline/comments/stale) and CI required before merge. Existing #1 native Goal stays unchanged; no additional native goal during this coordinated run. No live operation is authorized by this issue: reviewed immutable commits and explicit concrete maintainer authorization required. Preserve manually installed runners, existing App/Keychain/launchd/Docker context; no busy cancellation, broad cleanup, workflow replay or credential/raw-log disclosure.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    release:mvpApproved delivery sequencing; does not change acceptance or dependency gates

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions