You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Part of #1029 (linked deployment changes epic — read it first for the big picture). Needs #1034 and #1035.
Goal
Make the feature findable and correctly described everywhere prose about deployment governance
lives, and close the epic. Every earlier part documented its own contract next to its code; this
part adds the narrative chapter section, reconciles the cross-references, refreshes the public
site, and regenerates the help corpus. No code.
Design constraints agreed on the epic (restated so the docs cannot drift from them):
Approval never executes a linked query; the gate needs APPROVED or EXECUTED; execution is confirm-execution with execute_linked_queries=true, in sequence_order, first failure →
deployment FAILED, no rollback, remaining links untouched.
docs/18-deployment-governance.md — a new numbered section after §7 (:331), before
§8 "CI wrappers" (:362): "Linked database changes" — the trigger field and its validation
table, the replay 409, the gate rule, execute_linked_queries and its failure semantics with
the audit rows (DEPLOYMENT_SUBMITTED metadata, DEPLOYMENT_EXECUTED.linked_queries_executed, DEPLOYMENT_LINKED_QUERY_FAILED with trigger=linked_query), the core.api LinkedQueryExecutionService inversion and why (workflow → deploygov already exists), and
the two UI surfaces. Renumber the later sections and fix every intra-document anchor. Update
§2 (:118), §3 (:153), §5 (:246), §8 (:362), the "Audit & notifications" list (:522)
and the module layout tree (:31) for the new files.
docs/04-api-spec.md — reconcile the rows the earlier parts added (:7701, :7775): the
trigger field, the query_request_id list filter, linked_queries on request responses, linked_queries_ready / linked_queries on the gate, the confirm body, and the five problem
codes (DEPLOYMENT_LINKED_QUERY_NOT_FOUND, _INVALID, _FAILED, DEPLOYMENT_LINKED_QUERIES_REPLAY_MISMATCH) in the error table.
docs/16-iac.md — under "CI Actions & pipeline templates" (:191): the new deployment-gate inputs, run-query's execute: "false", and a link to ci-templates/examples/github-migrations-workflow.yml.
docs/12-roadmap.md — add the item under the milestone the epic is scheduled in (or
"Backlog / Unscheduled", :247, if none), as the D1/D3/D5 deploygov epics are listed.
README.md — one sentence in the deployment-governance feature paragraph (:131) and the
IaC table row (:173) mentioning linked database changes.
website/ — features/deployment-governance/index.html (a feature block with the panel
screenshot, captured per e2e/screenshots/capture.ts), docs/guides/deployment-approval/index.html
(the migrations recipe, mirroring the example workflow), docs/iac/index.html (the new
inputs), docs/integrations/index.html if it lists gate inputs. Bump the JSON-LD dateModified on each edited page (features/deployment-governance/index.html:64, docs/guides/deployment-approval/index.html:67) and the matching sitemap.xml<lastmod>
entries (:28, :238); keep the frontend/src/config/docs.ts ↔ website/app.js anchor
contract intact (.claude/patterns/website-drift.md). Plain language on the marketing page —
"the deployment waits until the migration is approved", not "the releasable function".
help-corpus/ — regenerate with node .github/scripts/build-help-corpus.mjs and commit;
the help-corpus CI job fails on drift. No new route, so no ROUTES entry; no new website
area, so no SECTION_RULES entry.
CLAUDE.md — extend the deploygov module line with the epic's one-paragraph summary,
in the style of the existing #741 / #742 / #967 sentences.
docs/18 section numbering and every #… anchor resolve; docs/README.md index row unchanged
(no new chapter).
The website builds without a build step: tag-balance check on each edited HTML file, three
modified dates current, sitemap.xml<lastmod> updated for every edited page.
help-corpus/ is byte-identical to a fresh regeneration on main after the merge.
The frontend CI job's website guards and the help-corpus job pass on the PR.
Part of #1029 (linked deployment changes epic — read it first for the big picture). Needs #1034 and #1035.
Goal
Make the feature findable and correctly described everywhere prose about deployment governance
lives, and close the epic. Every earlier part documented its own contract next to its code; this
part adds the narrative chapter section, reconciles the cross-references, refreshes the public
site, and regenerates the help corpus. No code.
Design constraints agreed on the epic (restated so the docs cannot drift from them):
column — say so in one sentence, and do not describe a promotion ladder here.
APPROVEDorEXECUTED; execution isconfirm-executionwithexecute_linked_queries=true, insequence_order, first failure →deployment
FAILED, no rollback, remaining links untouched.Steps
docs/18-deployment-governance.md— a new numbered section after §7 (:331), before§8 "CI wrappers" (
:362): "Linked database changes" — the trigger field and its validationtable, the replay
409, the gate rule,execute_linked_queriesand its failure semantics withthe audit rows (
DEPLOYMENT_SUBMITTEDmetadata,DEPLOYMENT_EXECUTED.linked_queries_executed,DEPLOYMENT_LINKED_QUERY_FAILEDwithtrigger=linked_query), thecore.apiLinkedQueryExecutionServiceinversion and why (workflow → deploygovalready exists), andthe two UI surfaces. Renumber the later sections and fix every intra-document anchor. Update
§2 (
:118), §3 (:153), §5 (:246), §8 (:362), the "Audit & notifications" list (:522)and the module layout tree (
:31) for the new files.docs/04-api-spec.md— reconcile the rows the earlier parts added (:7701,:7775): thetrigger field, the
query_request_idlist filter,linked_querieson request responses,linked_queries_ready/linked_querieson the gate, the confirm body, and the five problemcodes (
DEPLOYMENT_LINKED_QUERY_NOT_FOUND,_INVALID,_FAILED,DEPLOYMENT_LINKED_QUERIES_REPLAY_MISMATCH) in the error table.docs/03-data-model.md— verify thedeployment_request_queriessection deploygov: persistence — deployment_request_queries link table #1030 wrotesits under
## Deployment governance(:2583) and cross-linksquery_requests.docs/05-backend.md— the analyzer input paragraph (:4326-4334) already describes thenew field from ai: linked SQL and verdicts in the DeploymentAnalyzer input #1033; add the
DEPLOYMENT_LINKED_QUERY_FAILEDaction andtrigger=linked_queryto the deploygov audit list under "State machine (deploygov: deployment governance — trigger API, AI analysis, state machine & routing #691)", and note thenew
core.apiinterface in the module-boundary discussion of theworkflowmodule.docs/16-iac.md— under "CI Actions & pipeline templates" (:191): the newdeployment-gateinputs,run-query'sexecute: "false", and a link toci-templates/examples/github-migrations-workflow.yml.docs/12-roadmap.md— add the item under the milestone the epic is scheduled in (or"Backlog / Unscheduled",
:247, if none), as the D1/D3/D5 deploygov epics are listed.README.md— one sentence in the deployment-governance feature paragraph (:131) and theIaC table row (
:173) mentioning linked database changes.website/—features/deployment-governance/index.html(a feature block with the panelscreenshot, captured per
e2e/screenshots/capture.ts),docs/guides/deployment-approval/index.html(the migrations recipe, mirroring the example workflow),
docs/iac/index.html(the newinputs),
docs/integrations/index.htmlif it lists gate inputs. Bump the JSON-LDdateModifiedon each edited page (features/deployment-governance/index.html:64,docs/guides/deployment-approval/index.html:67) and the matchingsitemap.xml<lastmod>entries (
:28,:238); keep thefrontend/src/config/docs.ts↔website/app.jsanchorcontract intact (
.claude/patterns/website-drift.md). Plain language on the marketing page —"the deployment waits until the migration is approved", not "the releasable function".
help-corpus/— regenerate withnode .github/scripts/build-help-corpus.mjsand commit;the
help-corpusCI job fails on drift. No new route, so noROUTESentry; no new websitearea, so no
SECTION_RULESentry.CLAUDE.md— extend thedeploygovmodule line with the epic's one-paragraph summary,in the style of the existing
#741/#742/#967sentences.Acceptance criteria
merged by deploygov: persistence — deployment_request_queries link table #1030–frontend: linked changes panel on the deployment page and "ships in" on the query page #1035 — verify by grep, not memory.
docs/18section numbering and every#…anchor resolve;docs/README.mdindex row unchanged(no new chapter).
modified dates current,
sitemap.xml<lastmod>updated for every edited page.help-corpus/is byte-identical to a fresh regeneration onmainafter the merge.frontendCI job's website guards and thehelp-corpusjob pass on the PR.