Skip to content

CI-13 [HUMAN GATE]: Private-repository cutover — prove private-mode CI, budgets, runner trust; maintainer flips visibility for v0.3.0 #2337

Description

@Chris0Jeky

Wave: Smart CI Fabric (ADR-0066 §Acceptance conditions). Tracker: CI-00 #2324. Human gate — the maintainer performs the visibility change, the spend ceiling, the branch-protection edits and any runner registration; agents prepare and verify, never flip.

Context

Maintainer directive (2026-08-30): the repository goes private for the v0.3.0 release and must work on a personal GitHub Pro account first. The full checklist is docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md (reconciled from the pack for personal-account mode). This issue is the executable version.

A. Prerequisites (agent-verifiable, waivable only with a recorded reason)

  • CI-01 baseline recorded; CI-09 storage under the 1 GB allowance or a spend decision recorded here.
  • CI-02 planner in shadow mode with the recall report over >=20 PRs.
  • CI-03 Smart CI / Required Gate in observation mode with zero false reds over >=20 PRs; landed verifier proven.
  • CI-11 every external action SHA-pinned; hosted-only R4 fixture green.
  • Rehearsal while still public, hosted-only, no runner attached: R0 docs PR, R2 ordinary PR, R3 migration/auth/MCP PR, R4 workflow PR, cancelled/superseded PR, normal merge -> bounded main verifier, direct-push simulation -> full escalation, nightly no-change skip, release dry-run.
  • Public-asset review: GitHub Pages frontend (pages-frontend.yml), release assets, packages, docs links, the awesome-selfhosted/launch-kit references (#2242) — each has a decision (stays public elsewhere / moves / retires).
  • Automated review integrations (Codex GitHub App, Copilot review) — private-mode billing verified, not assumed; review cadence adjusted so reviews run after CI stabilises, not after every micro-push.

B. Maintainer actions (in order; each recorded here with date + evidence)

  1. Confirm GitHub plan (Pro) and set a monthly Actions spend ceiling + alert (Billing settings).
  2. Pause merges briefly; capture current required-check and Actions settings (gh api repos/Chris0Jeky/Taskdeck/branches/main/protection, actions/permissions).
  3. Register Smart CI / Required Gate as required; set strict: true; keep the three security contexts; decide enforce_admins / break-glass (CI-03 supplies the exact commands).
  4. Flip sha_pinning_required on (CI-11).
  5. Change repository visibility to private (Settings -> Danger zone). Agents never do this.
  6. Re-check: Actions permissions, fork-PR approval policy, Dependabot, Pages/package/release visibility, runner association, collaborator list.
  7. Run in private mode: R0, R2, R4 PRs, one merge (main verifier), one nightly dispatch, one no-publish release rehearsal; verify hosted-minute accounting against the ceiling.
  8. Only now: register the isolated runners (CI-04) and switch CI_EXECUTION_MODE to hybrid; verify self-hosted jobs consume no hosted minutes and expose no secrets.
  9. Resume merges; record post-cutover evidence on CI-00.

C. Rollback

  • Previous workflow files stay reachable by tag/commit; the manual hosted full-qualification workflow stays available; runners can be detached in one step; previous branch-protection contexts are recorded in step 2. Do not flip visibility back merely to regain free minutes before understanding a failure — use the hosted override first.

Acceptance

  • Sections A and B complete with evidence; the repository is private; v0.3.0 can be cut from a private repository with the required gate enforced.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Priority IRelease-blocking or trust-breaking now; release scope still requires milestone membership.ciCI/CD pipeline, workflow, and build infrastructure changes.human-actionNeeds maintainer credentials, settings, legal judgement, or confirmation; agents never infer done.securityAuthentication, authorization, data protection, abuse prevention, and compliance-related changes.

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions