feat(workloads): onboard trusted external validation - #139
Conversation
Nobodyworld
left a comment
There was a problem hiding this comment.
Connector planning review complete for issue #138 at exact head dc33806e57edd8d0255b3f17c8379a482cf8ab31 and exact base/merge base 33a5836496fa933dd6aae65ec71238d1b5ac9772.
The planning branch changes only the living ExecPlan and durable status report. Commitlint 31337683438 and CI 31337683431 succeeded, including lint, typecheck, full tests, security, full-history Secrets audit, Link check, Coverage, and strict Browser UI tests.
The accepted scope is one large coherent outcome rather than a catalog-only primitive: strict source-controlled repository/workload definitions, repository-to-manifest compatibility, an external accounting validation manifest, bounded worker logical-repository availability with restart-safe migration, repository-aware routing and reuse, command-center onboarding/readiness, production-path synthetic fresh/reuse coverage, and controlled real local dogfood against the exact current head of public Nobodyworld/app-accounting-modular PR #126.
The target PR must not be modified or published to automatically. MCP, provider execution, browser/desktop/RPA workers, Docker-worker expansion, repository writes, automatic approval/publication/merge, releases, deployments, and production/public-internet claims remain outside this slice.
No planning blocker remains. Keep PR #139 draft, open, and unmerged throughout implementation. Final readiness requires local implementation and dogfood evidence, the complete protected matrix, ultimate-head hosted workflows, and a new connector review.
Implementation continuation checkpointExact Switchboard state remains suitable for the large local implementation handoff: The planning head remains fully green: Commitlint The external target was rechecked immediately before handoff: The reviewed target Python quality contract at that exact head is Implementation must continue only on the existing branch and draft PR. Re-resolve the target PR head again immediately before live dogfood. The dogfood may validate the target exact SHA locally but must not comment on, modify, merge, close, retarget, or mark the target PR ready. Full logs and artifacts remain local; only bounded evidence belongs in Switchboard/GitHub records. The next step is the local multi-file implementation, migration, real-worker tests, strict browser acceptance, and controlled external dogfood described by issue #138 and the living ExecPlan. |
Summary
Begins issue #138 as the next large coherent Switchboard product slice after the merged Validation Broker command center.
Intended product outcome
Turn Switchboard from a self-validating proof into a trusted multi-repository local execution broker:
The first external dogfood target is public
Nobodyworld/app-accounting-modularPR #126. Its exact current head must be re-resolved immediately before acceptance. Switchboard may validate it locally, but this slice must not modify, merge, close, retarget, mark ready, or automatically publish a comment to that target PR.Locked scope
validate-accounting-modular@1fixed-argv manifest;first_available,cheapest_capable, hard pins, assessment, and exact reuse;Connector work already completed
.agent/execplans/014_trusted_workload_catalog_dogfood.md.docs/reports/status.mdrecords the merged PR feat(operator): ship end-to-end validation command center #137 baseline, current main, current single-repository limitation, active slice, and durable release/deployment boundary.613cf89396c41a0ee3c3aa5886a55c264a38daf0at the latest connector check; it has fully green hosted Python/container evidence and one separate manual literal-200%-zoom blocker.Planning validation
Exact planning head
dc33806e57edd8d0255b3f17c8379a482cf8ab31:31337683438— success;31337683431— success;4892665741found no planning blocker.The initial planning-head lint failure was only the end-of-file hook adding a final newline to the new ExecPlan. Connector commit
202dc7ec854c8ff59882a3c6c971ef64a8bd7669normalized it before this final green planning head.Explicit exclusions
No arbitrary shell, caller-authored manifest, database-authored executable profile, source modification, Git write, automatic external-PR publication, MCP, Secure MCP Tunnel, paid-provider integration, billing/rate-limit polling, browser/desktop/RPA worker, Docker-worker, webhook, Checks API, workflow dispatch, automatic approval/merge, release, deployment, or production/public-internet claim.
Required delivery process
Implementation must remain on this branch and in this existing draft PR. Maintain the living ExecPlan continuously. Use focused Conventional Commits. Run focused tests before the complete protected matrix, strict Playwright with zero skips, public-hygiene cleanup, and ultimate-head hosted checks. Keep the PR draft and unmerged until final connector review is complete. Merge remains a separate exact-head owner decision.
Closes #138 only after an explicitly authorized squash merge.