feat: complete Epic 1 production foundation
This commit is contained in:
@@ -19,4 +19,28 @@ Published migrations are immutable and checksummed. Partial schema, unknown exte
|
||||
|
||||
Version 3 adds nullable canonical Trace ID storage and partial Request/Trace indexes. New application writes provide both identities; historical rows remain honestly nullable and are never assigned fabricated traces.
|
||||
|
||||
Version 4 freezes version-local Operation identity and provenance. Legacy versions are marked as migration-time observations rather than fabricated history. PostgreSQL rejects updates or cascade deletion of Published payloads; later edits append a new Draft revision.
|
||||
|
||||
Version 5 (`execution-outcome-v5`) adds nullable exact Operation version,
|
||||
execution stage, stable error code, retryability, and outcome certainty to
|
||||
Invocation History. Legacy v4 rows remain `NULL`; no classification is fabricated.
|
||||
|
||||
Version 7 (`master-key-identity-v7`) adds durable master-key identity and
|
||||
operator-controlled rotation state.
|
||||
|
||||
Version 8 (`admin-auth-lifecycle-v8`) adds one-time local bootstrap contracts, <!-- community-scope: allow=one-time-token -->
|
||||
CSRF-backed browser sessions, login backoff, and bounded admin auth audit.
|
||||
Production first-admin setup uses `crank-migrate admin-auth bootstrap-create`
|
||||
plus the `/login` bootstrap flow, not a static startup password.
|
||||
Lost Admin password recovery uses `crank-migrate admin-auth recover` with
|
||||
local secret files and active master-key identity verification; it revokes
|
||||
browser sessions and never prints password, pepper, master key, Secret plaintext,
|
||||
or ciphertext.
|
||||
|
||||
Version 11 (`onboarding-product-events-v11`) adds nullable exact MCP key
|
||||
provenance to Invocation History, immutable workspace-scoped local ProductEvents,
|
||||
and daily eligible-denominator rollups. Historical and externally verified rows
|
||||
remain honestly unscoped; no raw key, invocation payload, or external analytics
|
||||
export is introduced.
|
||||
|
||||
For the complete ledger inventory, recovery table, and authoring rules, see the canonical [Russian operator contract](../migrations.md).
|
||||
|
||||
Reference in New Issue
Block a user