fix(governance): automate ruleset owner-plane reconciliation - #1644
fix(governance): automate ruleset owner-plane reconciliation#1644seonghobae wants to merge 229 commits into
Conversation
…ked-pr-central-required-workflows
# Conflicts: # scripts/ci/test_strix_quick_gate.sh
Merge protected main non-destructively while retaining only the create-transition audit and its executable regressions. Focused ruleset audit: 20 passed. Full suite: 1,402 passed, 1 skipped, 16 subtests.
Preserve only the two governance owner files over protected main 0c6b9a6. Focused ruleset audit: 20 passed. Full suite: 1,402 passed, 1 skipped, 16 subtests.
|
Fresh owner-path dependency evidence for the Context Fabric control-plane repair: protected Before merge or any privileged reconciliation, re-fetch current protected main and compare #1644’s 19 governance-owned paths against |
|
Context Fabric dependency refresh — exact live central stack moved after the PR body was last validated. Fresh compare now reports Please have the central Context Fabric product branches remain intentionally unchanged until the central protected-main/default/review settings path reaches live truth. |
Buyer/control-plane outcome
This is the owner-plane writer for the live ruleset drift blocking Orgmetra's ordinary protected merge canary. Source integration alone does not mutate live settings: privileged apply remains disabled unless trusted protected
mainhasCWL_RULESET_RECONCILE_ENABLED=trueand the protectedruleset-governance-maintenanceenvironment supplies a separately provisioned least-privilegeCWL_RULESET_ADMIN_TOKENwith Administration write authority.Current exact stack — 2026-09-02
Current exact head:
7698f40fb0dafa4b8bbedbe46e8ab02ec662fbf9.Current protected
main:6f70174e338013fec9a000311bc72312f5d4dbf9(#1704). The existing writer preserves concurrent protected-main intent without force-push. Fresh comparison reportsbehind_by=0; the diff remains exactly the same 19 governance-owned paths.Exact-head evidence:
Ruleset Governance Reconcilerun33611906329is terminal SUCCESS on7698f40fb0dafa4b8bbedbe46e8ab02ec662fbf9; all current inline review threads are resolved. OSV, CodeQL, Python Security, Secret Scan, SBOM, Scorecard, Security Scan and SAST on this same exact head are queued at the current read, so focused governance success is not promoted to whole-PR merge/release evidence. Ordinary squash auto-merge is enabled; administrator bypass and self-approval are not used.A one-shot source-fix workflow attempted during earlier repair was blocked before any job executed and was immediately deleted; no temporary repair workflow remains in the current tree.
Reviewed implementation boundary
config/ruleset-governance.jsonbinds exactly repository ruleset17921150and organization ruleset18156473.PUTprecondition for these ruleset updates. A second live read detects visible drift but is not represented as compare-and-swap.PUT, and rechecks version state after settlement before trusting the restore.PUTmay already have been accepted, history settlement and lossless compensation finish without a stale-main veto so an overwritten administrator predecessor is not stranded.Live drift and acceptance boundary
Fresh live reads still show inherited organization ruleset
18156473withrequired_approving_review_count=1, stale-review dismissal and thread resolution enabled, merge/squash only, and routineOrganizationAdmin/alwaysbypass. The.githubrepository ruleset17921150has approval 0/last-push false/CODEOWNER false but still permits rebase and retains routineOrganizationAdmin/alwaysbypass. This PR therefore has not completed settings reconciliation merely by changing source.Require terminal successor-head security/review evidence before ordinary merge. After source reaches protected
main, provision the distinct least-privilege owner-plane identity, enable reconciliation only for a controlled maintenance interval, require exact live payload plus immutable-history convergence, re-run the canonical audit, and prove unchanged deterministic-GREENContextualWisdomLab/Orgmetra#88@0dc4f09cc3c87829ea1e3a0e3dc0188df07ad8cdcan take the ordinary protected merge path without synthetic approval or routine administrator bypass. Genuine failed/absent required workflows and unresolved required threads remain blocking.Refs #772, #1176, #1340, #1351, ContextualWisdomLab/Orgmetra#89.