Skip to content

Bind immutable model lifecycle sources at startup #257

Description

@dotnetpower

Problem

Model lifecycle reconciliation can produce proposal-only evidence and deterministic expired-unmerged review decisions, and the Operator service has a bounded asynchronous Key Vault source adapter. The active startup path still consumes file or inline JSON without one shared immutable source revision, so lifecycle holds cannot yet prove parity with the model mapping bound by Core and Operator.

Scope

Complete the authority-free model lifecycle source and review path. This issue does not authorize model mapping changes, PR merge, provider activation, or managed-resource execution.

Exit criteria

  • Proposal evidence binds the exact source-model digest and affected capabilities.
  • Expired unmerged proposals deterministically move affected capabilities to human review without changing model mappings.
  • The service-owned asynchronous Key Vault source validates origin, audience, secret identity and version, expiration, bounds, timeout, and redaction.
  • An asynchronous startup owner publishes one immutable source revision to capability binding and lifecycle-hold evaluation.
  • Core and Operator reject a source-revision mismatch before model capability binding.
  • Trusted PR lifecycle observation verifies proposal and decision digests and persists the resulting review decision.
  • Pre-binding capability holds are applied without mapping or execution authority.
  • A governed scheduled reconciliation receipt proves deprecation or family drift creates only a sanitized draft PR.

Validation

Focused unit, integration, Ruff, strict mypy, roadmap, localization, punctuation, and link checks must pass for the exact committed paths. Governed Azure or GitHub runtime evidence must target a pushed SHA.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:operator-consoleread-only console + narrator (Bragi)area:rule-catalogcatalog-as-code: collection, governance, discovery loopcompletedAll exit criteria are satisfied; no residual work remains.priority:p1Next: planned for the current or next iterationshadow-modeshadow -> enforce promotion / shadow validationtype:taskImplementation unit that supports a story or stands alone

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions