Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions CHANGELOG.md

Large diffs are not rendered by default.

Large diffs are not rendered by default.

23 changes: 17 additions & 6 deletions docs/engineering/ai-delivery/tasks/BE-03-CLOSEOUT-01.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# BE-03-CLOSEOUT-01 - Post-merge control correction for BE-03

Status: DRAFT
Status: APPROVED
Programme: Publisher Services and Distribution Configuration
Repository: `thoth-pub/thoth`
Workflow: STANDARD
Expand Down Expand Up @@ -383,8 +383,12 @@ touches no environment or production configuration.
dependency;
- [ ] `docs/publisher-services/decisions.md` section 3a retains its
authority-condition construction unchanged;
- [ ] no review, approval or merge identifier, merge SHA or merge timestamp is
newly transcribed into a repository file;
- [ ] no active control correction copies a review, approval or
merge-authorization identifier, merge SHA, merge timestamp, draft/ready
state or equivalent GitHub lifecycle metadata merely to restate terminal
review, authorization or merge state; exact SHAs recorded as the
authorized implementation base or as required preflight/ancestry evidence
are permitted execution evidence under repository controls;
- [ ] no migration-path reference in any implementation report is rewritten, and
any new prose naming the current BE-03 migration uses
`thoth-api/migrations/20260812_v1.7.0/`;
Expand Down Expand Up @@ -588,9 +592,16 @@ correction of materially stale active BE-03 programme state.

## 18. Approval

Approved for implementation by:
Date:
Notes:
Approved for implementation by: Javi, CTO
Date: 2026-08-14
Notes: implementation was explicitly authorized against exact `develop` base
`b51bcc0905ac17fc0c142b2002b11fec711331a3`, the merge commit of this
specification's own pull request
[#812](https://github.com/thoth-pub/thoth/pull/812). Authorization is limited to
the documentation and control correction specified here — correcting materially
stale active BE-03 programme state. It authorizes no runtime, schema, migration,
GraphQL, generated contract, workflow, deployment, environment or production
action, and it starts, specifies or authorizes no other task.

Record only the durable implementation authorization here. Independent review
decisions, CTO merge authorization and the merge itself are terminal GitHub
Expand Down
38 changes: 23 additions & 15 deletions docs/engineering/ai-delivery/tasks/BE-03.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
# BE-03 - Protected service configuration

Status: DRAFT
Status: APPROVED AND REPOSITORY-AUTHORITATIVE - BE-03 IMPLEMENTATION DELIVERED
AS AN INACTIVE FOUNDATION
Programme: Publisher Services and Distribution Configuration
Repository: `thoth-pub/thoth`
Workflow: STANDARD
Expand All @@ -27,11 +28,11 @@ content is reachable from the repository's authoritative integration branch
(`develop`). Live review, authorization and merge evidence is the GitHub
pull-request record and is not copied here.

Implementation authorization: **separate and absent.** This document specifies
BE-03; it does not authorize it. The branch `feature/publisher-services/be-03`
must not exist until the CTO separately and explicitly authorizes
implementation against a freshly verified exact `develop` head. Section 23
defines the lifecycle boundary and section 24 the approval boundary.
Implementation authorization: **separate.** This document specifies BE-03; it
does not authorize it. Implementation required, and received, explicit CTO
authorization against a freshly verified exact `develop` head, separately from
this specification's own approval. Section 23 defines the lifecycle boundary and
section 24 the approval boundary.

Specification authoring base: `bcb6ce3081abb14467798b372fcc3e6af9da1c6a`
(the merge commit of BE-02 implementation PR
Expand Down Expand Up @@ -2707,15 +2708,22 @@ Review reasoning level: Extra High / xhigh
## 23. Lifecycle boundary

This document is a specification. Its presence on `develop` makes BE-03's
requirements repository-authoritative; it does not create the implementation
branch, authorize an implementation edit, or activate anything.

BE-03 implementation status is `NOT AUTHORIZED`. The branch
`feature/publisher-services/be-03` must not exist until separate explicit CTO
authorization from a freshly verified base.

Live review, authorization and merge evidence for the pull request carrying this
content is the GitHub pull-request record and is not copied here (ADR-0005).
requirements repository-authoritative; it did not by itself create the
implementation branch, authorize an implementation edit, or activate anything.
Implementation was separately and explicitly authorized by the CTO from a
freshly verified base, as this boundary requires.

The BE-03 repository implementation has been delivered as an **inactive
foundation**. Its merge authorized repository integration only. It did not
authorize deployment, environment migration execution, production migration
execution, package commercial backfill, distribution assignment creation or
backfill, durable job creation, dissemination, distribution activation, any
`OBSERVE`/`ENFORCE` transition, workflow change or dispatch, or production
access; each remains separately gated and unauthorized.

Live review, authorization and merge evidence for the pull requests carrying
this specification and its implementation is the GitHub pull-request record and
is not copied here (ADR-0005).

## 24. Approval boundary

Expand Down
32 changes: 22 additions & 10 deletions docs/publisher-services/README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Publisher Services and Distribution Configuration

Status: CONTROL FOUNDATION CLOSED; BE-01 CLOSED; ADR-01-SPEC-AMEND-01 MERGED (PR #781, MERGE COMMIT a511e01c); CORRECTED ADR-01 SPECIFICATION REPOSITORY-AUTHORITATIVE; ADR-01 MERGED - COMPLETE (PR #783, MERGE COMMIT 299b0eff); ADR-0004 AND FINAL PLATFORM INVENTORY APPROVED AND REPOSITORY-AUTHORITATIVE; CG-07 RESOLVED; BE-02 CLOSED - INACTIVE FOUNDATION MERGED THROUGH PR #805; DEPLOYMENT, MIGRATION EXECUTION, BACKFILL AND DISTRIBUTION ACTIVATION NOT AUTHORIZED; ALL OTHER IMPLEMENTATION GATED
Status: CONTROL FOUNDATION CLOSED; BE-01 CLOSED; ADR-01-SPEC-AMEND-01 MERGED (PR #781, MERGE COMMIT a511e01c); CORRECTED ADR-01 SPECIFICATION REPOSITORY-AUTHORITATIVE; ADR-01 MERGED - COMPLETE (PR #783, MERGE COMMIT 299b0eff); ADR-0004 AND FINAL PLATFORM INVENTORY APPROVED AND REPOSITORY-AUTHORITATIVE; CG-07 RESOLVED; BE-02 CLOSED - INACTIVE FOUNDATION MERGED THROUGH PR #805; BE-03 CLOSED - INACTIVE FOUNDATION MERGED THROUGH PR #809; DEPLOYMENT, MIGRATION EXECUTION, BACKFILL, DURABLE JOB CREATION, DISSEMINATION AND DISTRIBUTION ACTIVATION NOT AUTHORIZED; ALL OTHER IMPLEMENTATION GATED
Programme owner: CTO
Primary coordinating repository: `thoth-pub/thoth`
Related repositories:
Expand Down Expand Up @@ -91,10 +91,17 @@ ADR-0004 APPROVED AND REPOSITORY-AUTHORITATIVE
FINAL DISTRIBUTION-PLATFORM INVENTORY APPROVED AND REPOSITORY-AUTHORITATIVE
CG-07 RESOLVED
BE-02 CLOSED (INACTIVE FOUNDATION MERGED THROUGH PR #805)
BE-03 DEPENDENCIES ON BE-01 AND BE-02 SATISFIED; BE-03 IMPLEMENTATION NOT
AUTHORIZED
DEPLOYMENT, ENVIRONMENT AND PRODUCTION MIGRATION EXECUTION, ASSIGNMENT
CREATION/BACKFILL AND DISTRIBUTION ACTIVATION NOT AUTHORIZED
BE-03 CLOSED (INACTIVE FOUNDATION MERGED THROUGH PR #809)
BE-04 BE-03 DEPENDENCY SATISFIED; BE-04 STILL BLOCKED AND NOT STARTED
MIG-01 BE-03 DEPENDENCY SATISFIED; MIG-01 STILL CRITICAL AND BLOCKED
APP-01 BE-03 BACKEND CONTRACT SATISFIED FOR ITS CONFIGURATION-ONLY SCOPE;
APP-01 STILL BLOCKED BY ITS OTHER CONTROLS; ITS JOB-AWARE ELEMENTS STILL
REQUIRE BE-04
APP-02 BE-03 DEPENDENCY SATISFIED ONLY; APP-02 STILL BLOCKED ON BE-04 AND
APP-01
DEPLOYMENT, ENVIRONMENT AND PRODUCTION MIGRATION EXECUTION, PACKAGE
COMMERCIAL BACKFILL, ASSIGNMENT CREATION/BACKFILL, DURABLE JOB CREATION,
DISSEMINATION AND DISTRIBUTION ACTIVATION NOT AUTHORIZED
CG-11 UNCHANGED; CG-13 OPEN / UNCHANGED
ALL OTHER IMPLEMENTATION REMAINS GATED
```
Expand Down Expand Up @@ -231,9 +238,15 @@ Reasons all other implementation remains gated:
not authorize deployment, environment or production migration execution,
assignment creation or backfill, distribution activation,
`OBSERVE`/`ENFORCE` or production access, each of which remains separately
gated. `BE-03`'s `BE-01` and `BE-02` dependencies are therefore satisfied,
and `BE-03` implementation remains `NOT AUTHORIZED` pending its own
approved bounded specification and separate explicit authorization.
gated. `BE-03` is `CLOSED` on the same terms: its bounded implementation
merged through [PR #809](https://github.com/thoth-pub/thoth/pull/809) as an
inactive additive foundation under its own approved bounded specification
and separate explicit implementation authorization. That merge satisfies the
`BE-03` dependency of `BE-04`, `MIG-01`, `APP-01` and `APP-02` without
making any of them ready, and authorizes no deployment, environment or
production migration execution, package commercial backfill, assignment
creation or backfill, durable job creation, dissemination or distribution
activation.
2. Every task still requires its own approved bounded specification, its
applicable dependencies, and separate explicit authorization before any
implementation branch or edit.
Expand All @@ -248,8 +261,7 @@ Reasons all other implementation remains gated:
Discovery, review, documentation, and read-only orientation may continue. An
approved specification makes a task's requirements repository-authoritative; it
does not create the implementation branch, authorize an implementation edit, or
unlock `BE-03`, `BE-04`, `APP-01`, OAI-PMH, release, deployment or production
work.
unlock `BE-04`, `APP-01`, OAI-PMH, release, deployment or production work.

## 6. Files

Expand Down
11 changes: 7 additions & 4 deletions docs/publisher-services/decisions.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# Publisher Services Decision Summary

Status: ACTIVE SUMMARY
Last updated: 2026-08-12 (BE-02 closed as an inactive merged foundation; BE-03/BE-04/APP-01 phase boundary raised as a specification candidate under a durable authority condition, including the APP-01 reconciliation)
Last updated: 2026-08-14 (BE-02 and BE-03 closed as inactive merged foundations; the BE-03/BE-04/APP-01 phase boundary's authority condition is satisfied and the decision is approved under its own self-resolving construction, including the APP-01 reconciliation)
Owner: CTO

This file summarizes decisions. The approved technical design and approved ADRs remain authoritative.
Expand Down Expand Up @@ -336,9 +336,12 @@ measured and evidenced under
This decision candidate **refines and, in that narrow respect, supersedes** the
earlier APP-01 wording that assigned superuser back-catalogue-status inspection
to a BE-03-only dependency. Nothing else in the approved APP-01 record is
changed: APP-01 remains a `thoth-app` task, remains MEDIUM risk, and remains
blocked on BE-03 exposing the approved protected API, app readiness controls, the
exact-SHA schema pinning control and its own approved bounded specification.
changed: APP-01 remains a `thoth-app` task and remains MEDIUM risk. Its
dependency on BE-03 exposing the approved protected API is **satisfied** for the
configuration-only surface enumerated below, BE-03 having merged that surface;
APP-01 itself remains **blocked** on app readiness controls, the exact-SHA
schema pinning control and its own approved bounded specification, and its
job-aware elements remain dependent on BE-04 as set out below.

Scope available from **BE-03 alone** — the BE-03-dependent part of APP-01:

Expand Down
32 changes: 28 additions & 4 deletions docs/publisher-services/rollout-plan.md
Original file line number Diff line number Diff line change
Expand Up @@ -119,7 +119,28 @@ BE-02 implementation state (2026-08-12):
integration only; deployment, environment and production migration execution,
assignment creation or backfill, distribution activation and
`OBSERVE`/`ENFORCE` remain separately gated and unauthorized. `BE-03`'s
`BE-02` dependency is satisfied; `BE-03` implementation is `NOT AUTHORIZED`.
`BE-02` dependency is satisfied.

BE-03 implementation state:

- `BE-03` is `CLOSED`. The bounded implementation was delivered under its own
approved specification (PR [#808](https://github.com/thoth-pub/thoth/pull/808))
and separate explicit implementation authorization, and merged into `develop`
through implementation PR
[#809](https://github.com/thoth-pub/thoth/pull/809) as an inactive additive
foundation: the canonical optimistic-concurrency configuration token, the
closed two-value configuration-source type, the append-only configuration
audit table, the single canonical service-configuration write coordinator,
the protected owner-and-superuser read, the superuser-only staff report and
replace mutation, and effective package capability exposure derived from
BE-01's code-owned capability mapping. The migration creates zero audit rows
and changes no package and no assignment. Merge authorized repository
integration only; deployment, environment and production migration execution,
package commercial backfill, assignment creation or backfill, durable job
creation, dissemination, distribution activation and `OBSERVE`/`ENFORCE`
remain separately gated and unauthorized. The `BE-03` dependency of `BE-04`,
`MIG-01`, `APP-01` and `APP-02` is satisfied; none of those tasks becomes
ready, and each retains its remaining blockers.

Outstanding evidence:

Expand Down Expand Up @@ -191,10 +212,13 @@ Controls:

### 2.2 Reserved BE-03/APP-01 GraphQL contract control

Reserved and documented, not implemented. It binds the later `BE-03` and
`APP-01` tasks.
Reserved and documented, not implemented. `BE-03` has merged, so this control
now binds the later `APP-01` task.

1. `BE-03` produces an exact generated GraphQL SDL at its reviewed head.
1. `BE-03` produced an exact generated GraphQL SDL at its reviewed
implementation head, merged through PR
[#809](https://github.com/thoth-pub/thoth/pull/809). This control binds
against that head, not against any later documentation change.
2. `APP-01` records the exact `BE-03` commit SHA.
3. `APP-01` code generation consumes a schema artifact pinned to that SHA, or a
preview API proven to expose that exact schema.
Expand Down
Loading
Loading