merge feat/le-prod-approval-guard (42008b2373) #247

Open
pipeline-bot wants to merge 1 commit from feat/le-prod-approval-guard into trunk
Collaborator
No description provided.
The LE-staging hard rule was prose-only and had drifted: the Stack
XRD's acmeServer DEFAULT was silently LE-prod, and bob's instance
carried a 'staging is the default' banner directly above an LE-prod
value (stale since the approved 09ce76d flip). Now: (1) XRD default +
composition placeholder = LE-STAGING (no live effect — every Stack sets
acmeServer; unpatched renders fail safe); (2) every LE-prod value line
requires a 'le-prod-approved: <who> <when>' marker within 5 preceding
lines, enforced by tests/check-acme-approval.sh through the
validate-flux repo-guard hook. alice/bob carry markers for the recorded
2026-06-13/19 approvals. Teeth-tested red (marker stripped) and green.
This pull request has changes conflicting with the target branch.
  • CHANGELOG.md
  • apis/stack/composition.yaml
  • tests/check.sh
View command line instructions

Manual merge helper

Use this merge commit message when completing the merge manually.

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin feat/le-prod-approval-guard:feat/le-prod-approval-guard
git switch feat/le-prod-approval-guard
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
sean/platform-seanfarm!247
No description provided.