Summary
Add the new deploy-control repository and its future GitHub App/control-plane
integration to Atrinik's desired-state and manual governance records.
Implementation / behavior
- Record the stable deploy-control repository identity, public visibility,
default branch, MIT license, repository properties, lifecycle, and release
policy.
- Define its required CI contexts, merge/ruleset behavior, Actions allowlist,
Dependabot expectations, and community-health defaults.
- Record the GitHub App identity, installation identity, selected repository
set, exact read-only permissions/events, accountable owner, verification
cadence, and revocation runbook as value-free manual state.
- Record only secret and variable names for webhook secrets, App keys, agent
enrollment, and Cloudflare bindings; never record values or token responses.
- Preserve the existing metaserver and Classic package/repository access
boundaries and do not widen any App to all repositories.
- Coordinate any private package access or production environment with the
owning workflow after it is merged and reviewed.
Acceptance criteria
- Desired-state and manual inventories name stable IDs and exact selected
repositories without credential material.
- The new repository's required checks match its actual workflows.
- Policy validation and publisher plan mode identify the complete intended
delta and preserve unchanged repositories/settings.
- Any manual UI or Team-plan limitation is documented explicitly.
- No Cloudflare resource, GitHub App, environment, secret, package grant, or
official deployment is provisioned by this issue alone.
Dependencies
Summary
Add the new deploy-control repository and its future GitHub App/control-plane
integration to Atrinik's desired-state and manual governance records.
Implementation / behavior
default branch, MIT license, repository properties, lifecycle, and release
policy.
Dependabot expectations, and community-health defaults.
set, exact read-only permissions/events, accountable owner, verification
cadence, and revocation runbook as value-free manual state.
enrollment, and Cloudflare bindings; never record values or token responses.
boundaries and do not widen any App to all repositories.
owning workflow after it is merged and reviewed.
Acceptance criteria
repositories without credential material.
delta and preserve unchanged repositories/settings.
official deployment is provisioned by this issue alone.
Dependencies
atrinik/deploy-control#2
atrinik/atrinik#527
atrinik/github-settings#77