You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
CTRL-REPO-THOTH-01 - Canonical shared doctrine and core repository controls
Programme: Shared Engineering Control Repository:thoth-pub/thoth Task ID:CTRL-REPO-THOTH-01 Risk: MEDIUM governance Reasoning: HIGH Workflow: STANDARD Original authorized base:develop @ ed32712766c8f5a1951bb53ec3192e18f067c7d2 Production/runtime effect: NONE
Objective
Reconcile the canonical Thoth engineering-delivery doctrine with the approved Control & Delivery model so GitHub is the durable live task ledger, mutation permissions are granular and non-transitive, cross-repository impact is assessed before substantive task scope is approved, and repository-local controls inherit a single shared contract without copying repository-specific assumptions.
Authoritative merged result
The core control work and its subsequent reconciliation/closeout stages are merged on develop:
merge commit / current authoritative develop: 0a33d553ef82140caf6c0378c1dfc5f48782361c
All three stages were documentation/control work. No runtime source, schema/migration, workflow implementation, provider configuration, release or deployment file was introduced by these changes.
Durable control result
The merged doctrine now establishes:
GitHub issues/PRs/reviews/CI/merge records as the live lifecycle ledger;
mandatory cross-repository impact analysis before substantive scope approval;
downstream compatibility and merge/deployment ordering controls;
one bounded task/branch/PR per repository;
exact-head independent review;
separate implementation, review, merge, migration, deployment and production-activation gates;
explicit automatic-side-effect accounting.
The task specification, implementation handoff/report and independent-review templates carry those controls. The repository/contract map distinguishes verified owners and consumers, including the standalone Python thoth-pub/thoth-client from the internal Rust workspace member.
Cross-repository result
The six repository-local child controls were implemented only after the shared doctrine merged. Their authoritative integration heads are:
App dev @ 7a4e7c6ceaec36fbdb201eaeb9ae36985a709889
Final cross-repository integration review under parent #818 is APPROVED against those six heads plus thoth/develop @ 0a33d553ef82140caf6c0378c1dfc5f48782361c, with no unresolved P0/P1 findings. Parent integration approval is recorded in #818 comment 5303923636.
GitHub holds live lifecycle state; committed docs retain durable doctrine/architecture.
Substantive/contract-affecting tasks require cross-repository impact analysis before repository scope approval.
Known consumers are assigned downstream work or explicitly evidenced as compatible.
Implementation handoffs contain exact base/target/branch, write budget, authorized/prohibited actions, automatic side effects, acceptance, validation and HOLD/STOP conditions.
Implementation reports record actual actions/effects against authorization.
Independent review verifies exact head, actual diff, acceptance evidence, compatibility and action/write-budget compliance.
Repository map includes verified standalone Client, Sphinx, Pyramid and Strapi records alongside the existing managed repositories.
Standalone Python client is distinguished from the internal Rust thoth-client crate.
Sphinx canonical state is reconciled without performing BR-SPHINX-01 or SPHINX-BOOT-01.
No runtime, schema, migration, auth implementation, CI workflow, branch-protection or deployment behaviour change was introduced.
Separate follow-up work
Branch normalization, Sphinx bootstrap, Dissemination README/environment protection, Pyramid dev CI coverage, Strapi Docker/Node CI repair and Metrics-programme documentation/control work remain separate tasks. They do not reopen this completed core-control implementation unless a future change invalidates the shared doctrine itself.
Parent: #818
CTRL-REPO-THOTH-01 - Canonical shared doctrine and core repository controls
Programme: Shared Engineering Control
Repository:
thoth-pub/thothTask ID:
CTRL-REPO-THOTH-01Risk: MEDIUM governance
Reasoning: HIGH
Workflow: STANDARD
Original authorized base:
develop @ ed32712766c8f5a1951bb53ec3192e18f067c7d2Production/runtime effect: NONE
Objective
Reconcile the canonical Thoth engineering-delivery doctrine with the approved Control & Delivery model so GitHub is the durable live task ledger, mutation permissions are granular and non-transitive, cross-repository impact is assessed before substantive task scope is approved, and repository-local controls inherit a single shared contract without copying repository-specific assumptions.
Authoritative merged result
The core control work and its subsequent reconciliation/closeout stages are merged on
develop:f789f3b50576c40efa0fd6050f75aac51f711970ec7868a4a44b3d52da5638975995bb66a488b3b408a700ecad7e4c9de8cfe561eaa08c23be0813cce70fd5e04f9ee8d6b0dfb85ff14ef3b0622fdab2e304cf93e5c90d921dd535b9d72d1a2c85403516develop:0a33d553ef82140caf6c0378c1dfc5f48782361cAll three stages were documentation/control work. No runtime source, schema/migration, workflow implementation, provider configuration, release or deployment file was introduced by these changes.
Durable control result
The merged doctrine now establishes:
The task specification, implementation handoff/report and independent-review templates carry those controls. The repository/contract map distinguishes verified owners and consumers, including the standalone Python
thoth-pub/thoth-clientfrom the internal Rust workspace member.Cross-repository result
The six repository-local child controls were implemented only after the shared doctrine merged. Their authoritative integration heads are:
dev @ 7a4e7c6ceaec36fbdb201eaeb9ae36985a709889develop @ 71ef7724326e9e75ccea2c004b5ca5be8197f27edevelop @ d6ffdc67c48cbf64f8a716f26d7d82eb541d1ecfdevelop @ ff7de985d03f0c94d5ad8d60727f9cf85b6435cddev @ 2ee7a71f068db828a547fb60627d5a89243d209ddevelop @ 306220326189697252a708a203d6b4cc02f018ccFinal cross-repository integration review under parent #818 is APPROVED against those six heads plus
thoth/develop @ 0a33d553ef82140caf6c0378c1dfc5f48782361c, with no unresolved P0/P1 findings. Parent integration approval is recorded in #818 comment5303923636.Acceptance criteria
thoth-clientcrate.BR-SPHINX-01orSPHINX-BOOT-01.Separate follow-up work
Branch normalization, Sphinx bootstrap, Dissemination README/environment protection, Pyramid
devCI coverage, Strapi Docker/Node CI repair and Metrics-programme documentation/control work remain separate tasks. They do not reopen this completed core-control implementation unless a future change invalidates the shared doctrine itself.Current gate
MERGED - RECONCILED - FINAL PROGRAMME INTEGRATION APPROVED - CLOSURE AUTHORIZATION REQUIRED.
No further source action is required for
CTRL-REPO-THOTH-01. Issue closure remains a separate mutation requiring explicit authorization.