Goal
Demonstrate a manually configured single-organization credential path for the foreground MVP that binds the intended installation and never exposes management credentials to workers.
Dependencies
None for the isolated credential evidence work; coordinated under #66.
Scope
Extract the R1 credential subset of #2 without closing or rewriting its broader Manifest, multi-organization or launchd qualification. Use the already-created test App and private canary repository only under explicit authorization; no automatic App creation. Foreground-only execution must declare its identity and lifecycle; unattended login/logout/reboot service behavior is NOT supported in R1.
Acceptance
Execution and safety
Release R1. Maintainer-approved delivery reorganization #66; preserve the full original parent issue and historical records. Main implementation Grok 4.6 xhigh; independent Luna max review. TDD meaningful failing behavior before minimal implementation; exact commands/results, gaps and rollback. Exact-head clean external Codex review (inline/comments/stale) and CI required before merge. Existing #1 native Goal stays unchanged; no additional native goal during this coordinated run. No live operation is authorized by this issue: reviewed immutable commits and explicit concrete maintainer authorization required. Preserve manually installed runners, existing App/Keychain/launchd/Docker context; no busy cancellation, broad cleanup, workflow replay or credential/raw-log disclosure.
Goal
Demonstrate a manually configured single-organization credential path for the foreground MVP that binds the intended installation and never exposes management credentials to workers.
Dependencies
None for the isolated credential evidence work; coordinated under #66.
Scope
Extract the R1 credential subset of #2 without closing or rewriting its broader Manifest, multi-organization or launchd qualification. Use the already-created test App and private canary repository only under explicit authorization; no automatic App creation. Foreground-only execution must declare its identity and lifecycle; unattended login/logout/reboot service behavior is NOT supported in R1.
Acceptance
Execution and safety
Release R1. Maintainer-approved delivery reorganization #66; preserve the full original parent issue and historical records. Main implementation Grok 4.6 xhigh; independent Luna max review. TDD meaningful failing behavior before minimal implementation; exact commands/results, gaps and rollback. Exact-head clean external Codex review (inline/comments/stale) and CI required before merge. Existing #1 native Goal stays unchanged; no additional native goal during this coordinated run. No live operation is authorized by this issue: reviewed immutable commits and explicit concrete maintainer authorization required. Preserve manually installed runners, existing App/Keychain/launchd/Docker context; no busy cancellation, broad cleanup, workflow replay or credential/raw-log disclosure.