Skip to content

Build the Owner workbench and trusted GitHub projections #2004

Description

@shiny-code-bot

Goal

Provide one Launchplane workbench for engineers and Owners and compile the minimum trusted governance projection into GitHub repositories.

Scope

  • Add Launchplane views for engineering attestations, affected products, Owner actions, release evidence, production authorization, staleness, and next required action.
  • Project stable merge checks for engineering review and Owner acceptance; an engineering-only decision may satisfy the Owner check as not required.
  • Generate or reconcile required-check/ruleset/CODEOWNERS metadata only where GitHub needs it for enforcement or routing.
  • Detect and report projection drift; runtime authority remains in Launchplane.
  • Keep checked-in .github/github.json limited to non-authoritative routing or generated metadata and delete superseded authority fields at repository cutover.
  • Use provider APIs rather than requiring operators to reproduce routine changes in GitHub or Dokploy web UIs.

Acceptance Criteria

  • Owners can review changes and production candidates, request changes, approve, revoke, and inspect history from Launchplane.
  • Engineers and agents can see exact blockers and execute only actions their identities permit.
  • GitHub requires trusted Launchplane statuses but cannot mint passing authority from PR code.
  • Branch protection remains strict and admin bypass is disabled for governed checks.
  • Projection reconciliation is idempotent, auditable, and has a tested rollback per repository.
  • Mobile/narrow and desktop browser paths are validated for human Owner actions.

Finish Line

Launchplane is the usable governance control surface and GitHub exposes only minimal reconciled non-authoritative enforcement projections.

Next Action

Design the read models and two stable status contexts, then add the smallest Owner and engineer workflows around server-owned contracts.

Current Status

State: Active on August 7, 2026. #2028, #2029, and re-scoped #2030 are production-verified. #2030 completed dedicated App registration/install, managed identity/secret configuration, exact operator grants, live neutral Owner-check projection/replay, and advisory self-exclusion safety without any product-repository implementation change.

Safety status: PR #2041 closed the final-review merge-train feedback-loop finding by excluding paginated Launchplane advisory/legacy status contexts before aggregation. Merge commit 01478a3934644c7b6c35425263b0726a927190b8, post-merge CI, deployment, and public health are green.

Next action: #2042 waits for a genuine product change backed by a truthful Every Code implementer request. #2031 remains downstream of that proof.

Blocked by: no blocker on completed #2030. #2031 is blocked by #2042; #2032 is blocked by #2042, #2031, and #2003.

Waiting for: genuine product work suitable for #2042. No authentication or infrastructure action remains.

Last verified: August 7, 2026.

Metadata

Metadata

Assignees

No one assigned

    Labels

    planDurable planning issueplan:activeCurrent active plan

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions