Keep maintainer tools out of student workspaces - #59
Merged
Merged
Conversation
This was referenced Sep 26, 2026
Students need runtime setup and application guidance without inheriting our test harness, image sources or investigation reports. Call the reviewed public maintainer actions against the exact template candidate and keep image verification after the build job's publication step. Preserve ordinary generated application tests and use the generated Compose recipe for browser tests in the existing workspace.
raghubetina
force-pushed
the
codex/maintainer-relocation
branch
from
September 26, 2026 23:07
3356aa9 to
555ea32
Compare
raghubetina
marked this pull request as ready for review
September 26, 2026 23:09
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Student template checkouts currently inherit First Draft's test harness, image build inputs, and investigation reports. Remove that maintainer material and call the public, SHA-pinned actions supplied by dockerfiles #7. The template shrinks from 47 to 23 tracked files. Every retained runtime/bootstrap file preserves its bytes and mode.
Keep the
contractcheck, exact candidate checkout, read-only CI permissions, and existing image publication triggers and separate build/verify jobs. External checks exist temporarily in the disposable CI checkout. Student terminal-publication instructions move into README; nested apps use ordinary setup/tests and the generated Compose Selenium recipe.Validation: external source/setup/preservation/credential/attachment/initialization checks and workflow lint pass. Local qualification passed two installation smokes, real released-CLI root materialization, and complete generated app CI (77 ordinary and 9 browser examples) after moving the planning archive outside the application. The relocated ARM64 image recipe also built and passed its runtime smoke. The receipt distinguishes observed proof and the initial Service-fixture database cleanup barrier. A subsequent authorized, bounded cleanup succeeded; the database is confirmed absent. The current-candidate hosted contract passed, and independent code/documentation review is complete. Latest native agent installation, runtime pins, attachment logic, and Selenium timeouts are unchanged. No provider trial, publication, or release was performed.
Relates to #54. Dockerfiles #7 has merged at
84cf8ecbb310f0abf2ace754ab3cb720fa8afd09; all three caller pins now select that revision. The final candidate contract is green. The coordinator owns integration. Board #48 and Service #762 remain separate; their guide destination is nowdockerfiles/drawing-board/README.md.