Skip to content

feat(publish): use shared Scroll lifecycle - #90

Open
MarcStdt wants to merge 2 commits into
masterfrom
codex/team-scroll-lifecycle
Open

MarcStdt wants to merge 2 commits into
masterfrom
codex/team-scroll-lifecycle

Conversation

@MarcStdt

@MarcStdt MarcStdt commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Scope

One cohesive publisher/workflow change; deliberately not split into an artificial stack.

  • Dedicated-account authentication and private robot staging through the existing explicit catalog script.
  • Freeze a staging digest, import through the shared Core lifecycle, and publish only with explicit content-review configuration. PR previews use private repositories, not tags inside public repositories.
  • Materialize inherited presentation and use deterministic build timestamps.
  • Release and PR callers now use the shared workflow with fail-closed readiness guards. This includes the previously local workflow cutover; the old statement that workflows were unchanged is superseded.

Review order

Review publisher and staging code/tests first, then the shared workflow and release/PR callers, then docs/shared-lifecycle-publication.md. Prerequisites are the monorepo stack and runtime stack; these are cross-repository dependencies, not one GitHub stack.

Exact implementation preserved

Existing final commit ce15065a75e9ac0fcda8f857b7403a4a9b8cf5a7, tree 610e65cdbae6fa20498d0a58964d0d16beb7d6c4. Normal fast-forward publication only, with no source edits or history rewrite.

Verification and rollout boundary

Local publisher/staging/workflow suites and authenticated real gateway/Core/Harbor import, identical-digest retry, publication and cleanup passed. Full evidence and limitations are in the final local audit. Fresh GitHub checks are separate from that local evidence.

Ready for review, not approval to publish production. The required protected scroll-release/scroll-preview environments, identity/secrets and SCROLL_LIFECYCLE_READY configuration must be provisioned before cutover. The October 3 audit found the environments absent; without setup, publication intentionally fails closed. This reconstruction does not provision them or weaken the guard. No merge or production release was performed.

Use dedicated account auth and private project robots for staging.

Import immutable releases and publish through the customer lifecycle;

keep private PR previews in separate repositories. Leave workflows

unchanged pending release-environment and credential approval.

Verify real local gateway/Core/Harbor retries with deterministic CLI

builds and clean up only identity-verified disposable fixtures.
Route releases and private previews through verified lifecycle publication with immutable revisions and fail-closed provisioning guards. Dedicated credentials and protected environments remain rollout prerequisites.

Recover the September 29 local draft and its offline regression coverage into the durable workspace. No remote publication performed.
@MarcStdt
MarcStdt marked this pull request as ready for review October 4, 2026 16:21
@druid-infra

Copy link
Copy Markdown
Collaborator
Error: This repo is not allowlisted for Atlantis.

This branch had an error being deployed

1 failed deployment
scroll-preview — ce15065a Deployed Oct 4, 2026 by MarcStdt via build-deploy / publish #251
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants