Repository navigation
Configurator MVP: provision isolated application instances from platform contracts #93
Description
Activity
- addedpriority:p1High impact correctness, security or required product capability; schedule firstHigh impact correctness, security or required product capability; schedule firsteffort:lArchitecture, lifecycle or multiple systems; split before implementationArchitecture, lifecycle or multiple systems; split before implementationarea:configuratorLanding Zone Configurator application, runtime and its infrastructureLanding Zone Configurator application, runtime and its infrastructuremvp:requiredRequired acceptance gate for the agreed Configurator MVP; not a merge approvalRequired acceptance gate for the agreed Configurator MVP; not a merge approval
on Oct 1, 2026 MVP audit 2026-10-04: Updated the description and acceptance checklist against the current implementation. Implemented criteria are checked; remaining requirements are retained. Local tests are not a release or live customer acceptance. This issue stays open until its remaining criteria are met. The first remaining safety fix (#89, backend-free initial plans on existing/partial/legacy state) is now implemented locally: 23/23 isolated PostgreSQL tests and the full check gate (310 unit tests) pass. No customer Apply, API restart, native artifact rebind, commit or merge was performed.
Local Application Runner Checkpoint (2026-10-05)
The current feature work was checkpointed locally as 4ad9367 and additionally saved in a verified full Git bundle outside the synced workspace. The application source pin is 4d15d78; worker/package/documentation changes are local commit 21801fd. These commits have NOT been pushed or released.
Implemented and locally qualified:
- Separate application backend/provider/version files and an application-specific provider lock (STACKIT 0.114.0, time 0.14.1; official Darwin ARM64/Linux AMD64 checksums).
- Explicit local-only package opt-in archives the fixed application root plus its sibling landing-zone module. Production opt-in is rejected; existing platform pin and bound packages are unchanged.
- Worker application-plan/application-apply accepts only the application pin/lock and strict tenant/instance binding, exact applications///terraform.tfstate S3 key with lockfile. Bootstrap/platform state and arbitrary roots are rejected.
- Saved-plan-only Apply, no replan/bootstrap migration; minimal private recovery-state retention.
Evidence: canonical check 346 passed/33 gated skipped; focused worker 80 passed/1 gated skipped using a controlled engine; real OpenTofu native mock tests 14 application + 3 network passed. A fresh Darwin ARM64 package actually passed backend-free init/validate with readonly lock and signed provider mirror. Package SHA-256: 848c402a75ba8906abd958158044ba07cda2dfbb6f7fe14353048a157c9cb0d1. Gitleaks found no secrets in staged commit content; editor diagnostics clean.
This does NOT satisfy the complete runner/dispatch criterion: executionEnabled remains false. Persisted instance jobs, PE-authorized bounded application credential grants, real backend locks, quotas/cloud retry idempotency, explicit upgrades, Linux runtime and separately authorized live Plan/Apply acceptance remain outstanding. New template versions must explicitly use the new application pin; existing versions/plans are not rebound. API/customer DB/active runner unchanged, no customer credentials or cloud operations used. Browser/PG were not rerun in this UI/SQL-free slice (previous evidence 152 browser and 31/29 PG). Issue stays OPEN and mvp:required.
Prepared Application Jobs / Grants Checkpoint (2026-10-05)
Local issue-specific commit: ad4842f. A verified full Git bundle additionally preserves this revision outside the synchronized workspace. No code push or release in this step.
Migration 026 and HTTP/service boundaries now implement explicit idempotent prepared application Plan jobs, SQL-derived immutable grant snapshots and monotonic revocation by requester or current approving PE. New publications must explicitly select the reviewed application source revision; this creates a new immutable template version, while old versions/default remain unchanged. Arbitrary source revisions and caller credential overrides are rejected.
Actual SQL guards validate the live issuer session, verified tenant organization, approving PE membership, requester identity/owner, version/policy and bounded expiry. App role cannot read the sessions table or directly insert/rebind grants. Job responses contain only metadata and executionEnabled:false/cloudPlanExecuted:false; there is no credential or ticket output and no runner dispatch.
Evidence: canonical lint/types/build + 346 unit passed/33 gated skipped; 29 real PostgreSQL identity/application cases extended with source-version, job/grant/idempotency/RLS/revocation and actual Fastify auth/origin/CSRF/tenant/strict body tests; all 31 real platform-broker PostgreSQL cases under the new migration pass. Editor diagnostics clean; staged Gitleaks scan clean. No UI change/browser rerun; prior browser evidence 152. Customer migrations 021-026 not activated, no API/native restart, no customer Plan/Apply.
Issue remains OPEN and mvp:required. Next is one-time credential release under current PE/profile authority plus explicitly approved instance S3 backend/lock binding and dispatch. A prepared grant record is not a real cloud credential release/state/Plan. Quotas/cloud retry safety, explicit upgrades and separately approved live acceptance remain required.
Weiterer lokal qualifizierter #93-Schritt: Commit e7cbe63 bindet vorbereitete Application-Jobs nach expliziter PE-Freigabe an ein registriertes Tenant-S3-Backend mit festem applications///terraform.tfstate-Key und Lockfile. SQL prueft aktuelle Rollen, echte Sessions und Human-Identitaeten; Freigabe ist immutable, sessiongebunden, begrenzt und wird durch Retry nicht verlaengert. AO erhaelt nur einen nicht geheimen Beleg, keine Backend-Credentials. HTTP prueft Session/Origin/CSRF/Tenant/strikte Bestaetigung. Parallele Freigaben idempotent; Backend-Wechsel 409, widerrufener oder abgelaufener Grant gesperrt. Gates: canonical 346 pass/33 gated skip, 29 erweiterte echte isolierte Identity/Application-PG-Faelle, 31 echte Plattform-Broker-PG-Faelle unter Migration 027; staged Gitleaks sauber. Vollstaendiger Feature-Branch zusaetzlich als externes verifiziertes Git-Bundle gesichert. Kein Push, Live-Migrations-/API-/Paketwechsel, Cloud-Plan/Apply oder S3-Zugriff. #93 bleibt OPEN/mvp:required: einmalige Credential-Ausgabe, Runner-Dispatch, echter State/Lock, Cloud-Abnahme, Quoten und Upgrade-Pfad sind weiterhin offen.
Naechster gesicherter lokaler #93-Commit: 50e0e76 implementiert Migration 028 und einen internen einmaligen Claim fuer den vorbereiteten Application-Grant. Nur die tatsaechliche aktuelle PE-Backend-Freigabesession darf claimen; keine AO-PE-Impersonation. Revalidierung aller 027-Grenzen, atomare Grant-Zeilensperre und immutable Verbrauchsbeleg. Zwei konkurrierende Claims: genau ein Erfolg. Claim/Widerruf-Rennen: genau eine Aktion erfolgreich, niemals beides. Andere echte PE-Session, abgelaufene/widerrufene Freigabe, direkter INSERT/DELETE und Consume-Replay abgewiesen. Widerruf nach Verbrauch explizit 409; Job-Vorbereitungs-Replay meldet nicht erneut prepared. Kein Browser-/Runner-Claim-Endpunkt (HTTP404 getestet), keine Secret-Ausgabe oder Runner-Start. Gates: canonical 346 pass/33 gated skip, 29 bestehende erweiterte echte Identity/Application-PG-Faelle, 31 echte Broker-PG-Faelle unter 028, Editor-Diagnostik0, staged Gitleaks sauber. Vollstaendiges externes Feature-Git-Bundle verifiziert. Kein Push, API-/Runner-/Kundendatenbankwechsel, Cloud-/S3-Zugriff oder Apply. #93 bleibt OPEN/mvp:required: Credential-Pruefung/Ausgabe/finale Autoritaetskontrolle und ticketgebundener Dispatch, reale State-/Lock-/Cloud-Abnahme, Quoten und explizite Upgrades fehlen weiterhin.
Neue verbindliche Architekturgrenze lokal umgesetzt und gesichert: Commit c4b43c3 (lokaler Feature-Branch) erhaelt den Accelerator als unabhaengiges CLI-Produkt; Configurator ist optional, keine notwendige API/DB/Session/Template Engine. Der Plattform-Root kann fuer NEUE Plattformen ohne Application-Instanzen betrieben werden und exportiert einen nicht geheimen platform_contract (Org/Folder/Region/SNA/Next-Hop/Nameserver, deterministische UUID-Revision, CLI-Namespace standardmaessig Org). Manuell aufgeloestes Application-JSON und S3-Backend-Beispiel inklusive separatem State/Lock/normalen Credentials und explizitem Saved-Plan-Apply sind dokumentiert. Herkunft: landing_zone_accelerator=true immer auf label-faehigen Ressourcen; landing_zone_configurator=true zusaetzlich fuer Configurator-Inputs. CLI-Application default ohne Configurator-Marker; Kundenlabels erhalten. Labels sind keine IAM-Grenze/Audit-Signatur. Bestehende Quell-Pins, Pakete, Publikationen und States nicht umgebunden. Eigenstaendige Accelerator-CI testet Application-Root. Lokal: canonical348 pass/33 gated skip, 8 native Plattform/Public/Corporate/eu01+eu02-Mocks, 16 native Application-Mocks mit manuellem JSON und beiden Herkuenften, 3 Netzwerk-Mocks, 29 Identity/Application-PG und31Broker-PG; Terraform fmt rekursiv PASS. Vollstaendiger Commit-Secret-Scan vom Repo-Root: 1 Commit/25KB/keine Leaks; komplettes externes Git-Bundle verifiziert. Kein Push, API-/Kundenbackend-/Paketwechsel oder realer Cloud-Apply. OPEN/required bleibt: reale Zwei-Phasen-CLI-/S3-/IAM-Abnahme und bestehende State-Migration, explizite neue Application-Source/Paket-Qualifizierung, eigentliche Credential-Ausgabe/Dispatch, Quoten und Upgrades. Die bestehenden Gesamtkriterien werden nicht gestrichen.
Lokaler Fortschritt im Feature-Branch:
39fd7d0(kein Push, keine Aktivierung).- Die CLI-kompatible Application-Quelle
c4b43c36af198985980b17626c48d357795e3fbdist explizit qualifiziert: neue immutable Publikationsversion und eigener Grant-Snapshot. Alte Versionen/Jobs bleiben unverändert; der neue Worker lehnt Altjobs auf dem neuen Paket ab. - Neues inaktives natives Paket
runner-local-20261005-application-cli.tar.gz, SHA-256bd87f44d1bafa0a3c9d974c735aa1edfd70add08d8ad9f1e503500bbe8af8aa7. Native Init/Validate, readonly Application-Lock und signierter Provider-Mirror bestanden (darwin_arm64/OpenTofu 1.12.6; kein Linux-/Cloud-Nachweis). - Migrationen 029/030 und interne
releaseJobCredential: nur die originale echte PE-Freigabesitzung, einmaliger Claim vor technischer Credential-Prüfung/Vault-Zugriff, feste Source-/Profil-/Secret-Version/Key-ID/Service-Account-Bindung und erneute SQL-Live-Autorisierung unmittelbar vor Rückgabe. Kein synthetischer PE und keine AO-Credential-Freigabe. - Echte isolierte PostgreSQL-Tests mit Vault-/Cloud-Mocks prüfen erfolgreiche Freigabe, Claim-vor-Secret, AO-Ablehnung, Replay, Rotation, Source-Abweichung, Parallelfreigabe mit genau einem Erfolg und Rechteentzug während Secret-Zugriff. Fehler verbrauchen den Claim; kein automatischer Retry/Reset.
Nachweise: kanonischer Lint/Types/Build-Gate und 349 Unit-Tests bestanden; 33 umgebungsabhängige Fälle bewusst übersprungen; 29 erweiterte Identity/Application- und 31 Platform-Broker-Fälle in isoliertem echten PostgreSQL bestanden; Worker 81 Fake-Engine-Fälle/1 native-gated skipped. Keine UI-Änderung, Browser-Suite nicht erneut ausgeführt. Secret-Scan ohne Befund.
#93 bleibt offen. Diese interne Freigabe ist noch kein Runner-Ticket, Dispatch oder Cloud-Plan. Weiter fehlen reale Instanz-State-/Lock-/Recovery-Abnahme, Quoten, ausdrückliche Upgrade-Plans und separat freizugebende Cloud-Plan/Apply-Abnahme.
executionEnabled:falsebleibt bestehen. Keine Kunden-Credentials/-Daten/-Backends gelesen; Kunden-API, aktives Paket, gebundene Kundenplans und alte Publikationen unverändert. Migrationen nicht live aktiviert, kein Cloud-Plan/Apply, State-Migration, Release oder Merge. Der Accelerator bleibt ohne Configurator nutzbar.- Die CLI-kompatible Application-Quelle
Weiterer lokaler Teilstand im Feature-Branch:
538d79c(kein Push/keine Aktivierung).- Migration 031: gehashte Einmal-Runner-Tickets, pro Job genau eines, gebunden an originale echte PE-Freigabesession, Paket-UUID, festen c4b43c3-Source-Pin und Application-Provider-Lock. Falsches Paket/Session, Ablauf, Replay und Parallelverbrauch geben keine zusätzlichen Credentials frei; keine direkten App-Tabellenrechte.
- Vollständiger interner
runnerInput: Ticket/Grant-Verbrauch vor technischem Zugriff; immutable Job-Variablen plus freigegebener S3-Instanz-Key/Lockfile; vorhandener HCL-Serializer und S3-Broker; erneute Live-Autorisierung nach S3-Credential-Freigabe. Ausschließlich application-plan, kein Apply/Bootstrap/Plattform-State. Backend-Abweichung oder Rechteentzug liefert keinen Input zurück. - Migration 032 und interner Dispatch-Kern mit vorhandener PlanRunner-Schnittstelle: atomare Reservierung pro Instanz, genau ein Start bei Doppelklick, Paket-/Ticketbindung im Callback vor Startfreigabe, kein automatischer Restart. Fehler nach Bindung sind konservativ reconciliation_required statt fehlgeschlagen/frei: Instanz und Ticket bleiben gesperrt, da ein tatsächlicher Start nicht sicher ausgeschlossen werden kann.
Nachweise: 349 Unit-Tests/33 bewusst gated skipped plus Lint/Types/Build bestanden; 29 erweiterte echte isolierte Identity/Application-PostgreSQL-Fälle und 31 Platform-Broker-PostgreSQL-Fälle unter 031/032 bestanden. Dispatch-Tests verwenden einen Fake-Runner und Vault/Cloud/S3-Credential-Mocks, keinen echten Application-Prozess oder Cloud-Plan. Root-staged Secret-Scan ohne Befund. Vollständige private externe Branch-Bundle-Sicherung verifiziert.
Noch keine aktive Application-Ausführung. Produktionsverdrahtung enthält keinen Application-Runner; kein HTTP-Start-/Ticket-/Credential-Endpunkt. Report-/Artefakt-/Result-Anbindung und Operator-Reconciliation sind noch zu implementieren, bevor native/Cloud-Aktivierung überhaupt geprüft werden kann. Quoten, Upgrade-Plans und reale State-/Lock-/Recovery-Abnahme bleiben offen. Deshalb bleiben ursprüngliche Dispatch-/Cloud-Kriterien und #93 insgesamt offen; executionEnabled:false unverändert.
Migrationen 021–032 nicht live aktiviert; aktive Kunden-API, Runner-Paket, Kundenplans und CLI-Unabhängigkeit unverändert. Keine Kunden-Credentials/-Daten/-Backends gelesen, kein Cloud-Plan/Apply, State-Migration, Push, Release oder Merge.
Lokaler Zwischenstand 2026-10-05, Commit 975cc94 (nur lokaler Feature-Branch, kein Push/Release/Merge):
- Migration033: immutable, owner-bound encrypted Application saved-plan/output records; ordered initializing/validating/planning stages; success requires exact saved artifact SHA, summary and package. Replay/conflicting upload is rejected.
- Dedicated /api/application-runner/* endpoints bind the server-selected package, source and lock. No browser-selected package, standalone credential endpoint or synthetic PE session. Endpoints remain closed without explicit setup.
- Worker and LocalPlanRunner select a fixed platform/application broker profile; cross-domain inputs fail before engine access. Application package identity now includes its root and sibling modules; existing platform identities remain unchanged.
- Explicit confirmed job dispatch checks actual session/tenant/origin/CSRF. Local Application execution requires an explicit separate package path and activation flag; no default package activation. Instance reservations cover all live phases; unknown start after work began remains reconciliation_required, not automatically retried.
- Terraform folder deletion fails with projects scheduled for deletion inside #22 / provider#1075 are an external API lifecycle constraint: project deletion schedules purge, hidden children can block folder deletion for up to7days. This is not immediate cleanup. New local saved-plan summary rejects folder delete/replace; it is NOT in the active package yet.
- Joint Cloud acceptance: use the existing Landing Zone organization and existing folders. User first reviews the configuration, then we prepare the Cloud Plan jointly. Apply only after explicit approval of that exact saved Plan. No automatic folder deletion/replacement, state rm, cleanup or repeated destroy.
Evidence: npm run check PASS (lint/types/build,370unit pass/33environment-gated skip); expanded isolated identity/catalogue/policy PostgreSQL29PASS; existing platform broker/state/grant PostgreSQL31PASS; focused worker84PASS/1nativeSkip, HTTP21PASS, local process8PASS/1nativeSkip; repo-root staged Gitleaks0. No browser or current Application native-runtime rerun; existing older source/root/package native proofs do not prove this new broker transport. Full verified private Git bundle retained.
Active API, package, customer DB/state and Cloud resources were NOT changed. Original criteria remain open: fresh native package qualification/approved activation and real Application Plan/Apply/state locking, owner plan visibility, quotas, explicit upgrades, operator reconciliation/recovery and live acceptance. #93 remains OPEN; this is not a feature-parity or Cloud sign-off.
Label-Korrektur vor Cloud-Apply, 2026-10-05: local feature commit fb334a0, no push/release/merge.
User-supplied saved bootstrap plan shows management project labels only managed_by=opentofu. Both canonical compilers already add landing_zone_accelerator=true and landing_zone_configurator=true. Known active API process started Oct4, before that change. The pinned older Terraform root passes var.labels to the unchanged management project resource; source pin alone is not the cause.
Fix: NEW preparation must bind exactly serializeTfvars(recordValues(saved document)); legacy or modified exports without either mandatory label cannot produce a new preparation. Tests cover legacy/common/platform documents and absent/false provenance. Native existing standalone test now checks actual planned management project labels plus preserved customer label (not only root locals), with mocked STACKIT/Vault/Time.
Evidence: 27focused compiler/preparation tests PASS; npmruncheck lint/types/build +370unit PASS/33gatedskip;31isolated platform broker PostgreSQL PASS; native credential-free init/validate +9mock tests PASS;editor0;root-staged Gitleaks0; full private verified provenance-preparations.bundle retained.
Active API, database, package and saved plan unchanged; no Cloud action. No rewriting/rebinding old plan. Fresh preparation and Plan of SAME configuration needed after activation; do NOT apply checksum c496daff4861c86eccabba14a8a2bdb34488d06911ead28ced4c35d9ea7ca75a. Runtime activation via local startup would also apply pending migrations021-033, so separate explicit approval + private customer DB backup required before doing that broader step. #93 remains OPEN.
Label-Korrektur: freigegebene lokale API-Aktivierung (2026-10-05)
- Nach ausdruecklicher Freigabe: private PostgreSQL-Sicherung ausserhalb des Repositorys, vollstaendiger isolierter Restore und echte transaktionale Migration 021–033 mit Bestandsdaten bestanden.
- Anzahl und Digest der bisherigen Spalten in acht geschuetzten Tabellen sind sowohl im Restore als auch nach der lokalen Aktivierung unveraendert. Bestehende Konfiguration, Credential-Profil, Vorbereitung, sieben Plans und Plattform-State bleiben erhalten; die geprueften Backend-/Application-Tabellen sind weiterhin leer.
- Die laufende API verwendet jetzt den korrigierten Compiler und Schema 033. Das bestehende unveraenderliche Plattformpaket sowie alte Quell-/Plan-/Paketbindungen wurden nicht gewechselt. API und vorhandene UI: HTTP 200. Application-Ausfuehrung bleibt ausdruecklich deaktiviert; ihr Runner-Endpunkt: HTTP 404.
- Fuer Configurator-Inputs sind
landing_zone_accelerator=trueundlanding_zone_configurator=trueverbindlich; Kundenlabels bleiben erhalten. Die zuvor dokumentierten nativen Management-Projekt- und kanonischen Vorbereitungstests gelten weiterhin. - Der alte Plan wird weder umgeschrieben noch angewendet. Naechster notwendiger Schritt ist eine neue Vorbereitung und ein neuer Plan derselben gespeicherten Konfiguration, anschliessend Pruefung und ausdrueckliche Freigabe genau dieses Plans. Kein Cloud-Plan, Apply, automatischer Retry, Folder-Delete/-Replace oder Cloud-Cleanup wurde gestartet.
Lokale Commits:
fb334a0(Label-Bindung) und8e4e39c(Aktivierungsnachweis). Kein Push/Release/Merge. #93 bleibt OPEN: echte native Application-Broker-/State-/Lock-/Cloud-Abnahme, Owner-Planansicht, Quoten, explizite Upgrades und Recovery/Reconciliation sind dadurch nicht erledigt.3 remaining items
Publication and current Platform-source acceptance recorded in the updated body; commit798661a adds readable frozen configuration name/Apply completion date. Version1 is live and retained; schema039 preserves all operational data. Application execution remains disabled and real Application Plan/Apply, quotas, state/locks/recovery and upgrades remain OPEN. No push,merge,release or new cloud Apply.
Application-Einstieg lokal nachgebessert (785bc69/8c630b9, kein Push): Ein neuer Login kann den bisherigen Owner-Nachweis ueberholen; die erfolgreiche Plattform-Apply-Auswahl bleibt dann aus Sicherheitsgruenden leer. Die Plattformanbindung bietet jetzt direkt die geschuetzte Erneuerung und laedt die Quellen nach erfolgreichem Nachweis neu. Im realen laufenden System danach bestaetigt: vorhandener erfolgreicher Apply mit Konfigurationsname/Datum waehlbar und kompatibles public-eu01-Ziel zum bestehenden Public-Template sichtbar. Current-State-, Tenant-, Rollen- und Owner-Gates unveraendert. 403 Unit-Tests/36 fokussierte Browserfaelle PASS; kein neuer Vertrag, keine neue Template-Version und keine Plan/Apply-Ausfuehrung. Application-Ausfuehrung bleibt deaktiviert; #93 bleibt fuer echte Application-Ausfuehrung, Quoten, State-Lock/Recovery und Upgrades offen.
- added 12 commits that reference this issue
on Oct 6, 2026 Local qualification update — 2026-10-10 (#93)
Extended the existing real PostgreSQL order-idempotency test: eight parallel repeats through a new Applications service and separate runtime pool return the same frozen instance, settings and state key, leaving exactly one order. Existing publication does not change earlier instance bindings.
Evidence: all 31 real isolated identity/PostgreSQL cases pass with --testTimeout=30000; targeted Biome and full typecheck pass. Single-case selection lacks shared earlier identity fixtures; full suite is required. Default 5-second timeout remains a final-CI qualification risk as documented in mvp-acceptance.md.
This proves durable ORDER idempotency, not real CLOUD PROJECT idempotency. Quotas remain unimplemented and must use an authoritative tenant-wide view rather than an Application Owner RLS-filtered count. Explicit instance upgrade Plans, approved current runner dispatch, real distinct state/locks, least-privilege and separately authorized Cloud Plan/Apply/recovery remain open. No runner or cloud project was started, no user database migration/rollout occurred. Issue remains open.
Current Status (2026-10-06)
The versioned non-secret platform-contract producer/import and durable application orders now exist. The earlier claim that there is no producer or persistent caller is obsolete. Application cloud execution remains disabled (
executionEnabled: false): a validated Plan input/state key is not a real Plan, deployment or state file.Evidence and Next Step
Sources:
src/application/,landing-zone-configurator/app/apps/api/src/applications/, contracts/domain application compiler, associated unit/PostgreSQL/browser tests. Contract and Plan-input documentation:landing-zone-configurator/docs/plan-execution.md.The active Platform runner is pinned to Accelerator commit
c4b43c36af198985980b17626c48d357795e3fbd. This is not activation or cloud qualification of the separate Application runner; old plans/packages were not rebound. Current local work is not automatically released. Next: reviewed application-root packaging and bounded dispatch/state integration, before cloud qualification and quotas/upgrades.Current Publication and Source Acceptance (2026-10-06)
The current successful Platform Apply exports the real non-secret contract and is approved through the protected server-derived workflow. Existing Public template version 1 is published with that contract, public-eu01, default Application Owners access and approval-required policy. The Apply selector now shows the frozen configuration name plus completion date instead of a state-key hash. Only current successful/unlocked tenant-scoped Applies with valid human proof remain selectable; owner proof can be renewed after binding.
Application execution remains explicitly disabled. Publication is not a real Application Plan or Apply. Quotas, explicit instance upgrade Plans, real distinct state/locks and failure/recovery, least-privilege bounded dispatch and separately approved cloud acceptance remain open.
Local-only commits: a8447b6 (#91), 53b806b (#92), 798661a (#93). Final validation: 403 unit tests, 30 real isolated identity/PostgreSQL cases, 49 platform broker cases and all 32 desktop/mobile management/publication/proof flows passed. Schema 039 activated after fresh private backup, full restore, repeated migration and unchanged operational-table verification. No push, merge, release or new Application cloud execution.
Dependencies
Durable Apply/state (#90), verified tenants/job grants (#91) and published template policies (#92). No automatic migration of existing monolithic state, autonomous Apply or shared platform-state exposure.