feat: complete Epic 1 production foundation

This commit is contained in:
2026-08-25 01:24:11 +03:00
parent 767428436d
commit 182bde8ac0
298 changed files with 35719 additions and 5299 deletions
+24
View File
@@ -19,4 +19,28 @@ Published migrations are immutable and checksummed. Partial schema, unknown exte
Version 3 adds nullable canonical Trace ID storage and partial Request/Trace indexes. New application writes provide both identities; historical rows remain honestly nullable and are never assigned fabricated traces.
Version 4 freezes version-local Operation identity and provenance. Legacy versions are marked as migration-time observations rather than fabricated history. PostgreSQL rejects updates or cascade deletion of Published payloads; later edits append a new Draft revision.
Version 5 (`execution-outcome-v5`) adds nullable exact Operation version,
execution stage, stable error code, retryability, and outcome certainty to
Invocation History. Legacy v4 rows remain `NULL`; no classification is fabricated.
Version 7 (`master-key-identity-v7`) adds durable master-key identity and
operator-controlled rotation state.
Version 8 (`admin-auth-lifecycle-v8`) adds one-time local bootstrap contracts, <!-- community-scope: allow=one-time-token -->
CSRF-backed browser sessions, login backoff, and bounded admin auth audit.
Production first-admin setup uses `crank-migrate admin-auth bootstrap-create`
plus the `/login` bootstrap flow, not a static startup password.
Lost Admin password recovery uses `crank-migrate admin-auth recover` with
local secret files and active master-key identity verification; it revokes
browser sessions and never prints password, pepper, master key, Secret plaintext,
or ciphertext.
Version 11 (`onboarding-product-events-v11`) adds nullable exact MCP key
provenance to Invocation History, immutable workspace-scoped local ProductEvents,
and daily eligible-denominator rollups. Historical and externally verified rows
remain honestly unscoped; no raw key, invocation payload, or external analytics
export is introduced.
For the complete ledger inventory, recovery table, and authoring rules, see the canonical [Russian operator contract](../migrations.md).