teleo-infrastructure/ops
fwazb 5c506b6ed1
Some checks are pending
CI / lint-and-test (push) Waiting to run
Revoke default PUBLIC execute on staging function
PostgreSQL grants EXECUTE to PUBLIC on every new function by default.
The verification block correctly rejects this, so revoke it before
granting the runtime role.
2026-07-24 12:15:50 -07:00
..
apply_gcp_iam_split.py Add idempotent GCP IAM apply runner 2026-07-07 13:05:08 +02:00
apply_gcp_iap_operator_access.py Make GCP replay bootstrap recoverable 2026-07-13 05:24:25 +02:00
apply_gcp_runtime_baseline.py Add GCP runtime baseline apply runner 2026-07-07 13:38:42 +02:00
attest_gcp_reasoning_compute.py Harden GCP parity proof against forged lifecycle claims 2026-07-15 10:20:27 +02:00
audit_kb_rebuild_coverage.py Audit source-derived KB rebuild coverage 2026-07-13 10:58:53 +02:00
backfill-contributor-roles.py fix: wire commit_type into contributor role assignment 2026-04-21 10:27:36 +01:00
backup_vps_sqlite_kb.sh Add VPS SQLite KB backup canary (#42) 2026-07-07 12:05:46 +02:00
build_gcp_cloudsql_restore_proof.py Prevent GCP proof harness heredoc deadlocks 2026-07-13 07:13:18 +02:00
build_v3_genesis_ledger_bundle.py Integrate hardened source-first V3 rebuild foundation 2026-07-21 21:41:30 +02:00
capture_vps_canonical_postgres_snapshot.py Preserve role ACLs in canonical parity preflight 2026-07-15 22:45:39 +02:00
check_gcp_infra_readiness.py Prove exact canonical Postgres restore parity 2026-07-11 20:05:56 +02:00
check_gcp_leoclean_nosend_preflight.py Close staging preflight review gaps 2026-07-20 23:43:10 -07:00
check_gcp_service_communications.py Add GCP service communication contract (#52) 2026-07-07 13:51:24 +02:00
check_observatory_read_adapter_gcp_preflight.py Fail closed on cross-provider WIF mappings 2026-07-15 22:45:24 +02:00
derive_leoclean_runtime_query_contract.py Normalize Cloud SQL identity addresses 2026-07-23 18:56:39 -07:00
detect_vps_gcp_source_drift.py fix: partition drift probe failures 2026-07-16 12:56:30 +02:00
gcp-teleo-pgvector-standby-server-ca.pem fix: prove least-privilege GCP Leo runtime context 2026-07-15 07:16:40 +02:00
gcp_leoclean_nosend_iap_remote.py Converge leoclean no-send installation state 2026-07-23 16:25:17 -07:00
gcp_leoclean_nosend_package.py Bind no-send database proof to container identity 2026-07-22 15:24:54 -07:00
gcp_leoclean_runtime_role.sql Revoke default PUBLIC execute on staging function 2026-07-24 12:15:50 -07:00
install_gcp_leoclean_nosend_release.py Converge leoclean no-send installation state 2026-07-23 16:25:17 -07:00
leoclean_nosend_service_control.py Harden leoclean first-start readiness 2026-07-23 10:41:40 -07:00
observatory_read_role.sql Merge remote-tracking branch 'origin/main' into codex/leo-negative-permissions-t3-w2-20260715 2026-07-16 12:08:06 +02:00
plan_gcp_iam_split.py Add GCP IAM split plan 2026-07-07 12:54:53 +02:00
plan_gcp_iap_operator_access.py Harden GCP replay and durable IAP bootstrap 2026-07-13 04:58:16 +02:00
plan_observatory_read_adapter_gcp.py Fail closed on cross-provider WIF mappings 2026-07-15 22:45:24 +02:00
postgres_parity_manifest.sql Replay PostgreSQL role and ACL parity 2026-07-16 12:32:02 +02:00
private_receipt_io.py Harden GCP parity proof against forged lifecycle claims 2026-07-15 10:20:27 +02:00
provision_gcp_leoclean_runtime_role.sh Harden leoclean runtime authority checks 2026-07-22 20:15:53 -07:00
redact_observatory_read_adapter_receipt.jq Harden Observatory private staging deploy gate (#163) 2026-07-15 09:55:49 +02:00
redact_sqlite_postgres_restore_canary.py Add portable restore canary capsule (#55) 2026-07-07 14:22:03 +02:00
restore_gcp_generated_postgres_snapshot.py Harden GCP parity proof against forged lifecycle claims 2026-07-15 10:20:27 +02:00
rollback_teleo_v3_epistemic_contract.sql Integrate hardened source-first V3 rebuild foundation 2026-07-21 21:41:30 +02:00
run_gcp_cloudsql_restore_drill.sh Prevent GCP proof harness heredoc deadlocks 2026-07-13 07:13:18 +02:00
run_gcp_infra_execute_canary.py Add GCP infra execute canary runner (#56) 2026-07-07 14:34:11 +02:00
run_gcp_leoclean_nosend_iap.py Converge leoclean no-send installation state 2026-07-23 16:25:17 -07:00
run_local_canonical_postgres_rebuild.py Replay PostgreSQL role and ACL parity 2026-07-16 12:32:02 +02:00
run_local_corpus_knowledge_rebuild.py Integrate hardened source-first V3 rebuild foundation 2026-07-21 21:41:30 +02:00
run_local_genesis_ledger_rebuild.py Harden V3 transition replay across timezones 2026-07-22 01:10:14 +02:00
run_sqlite_postgres_restore_canary.sh Add SQLite to Postgres restore canary (#43) 2026-07-07 12:21:54 +02:00
shard_corpus_extraction_work.py Integrate hardened source-first V3 rebuild foundation 2026-07-21 21:41:30 +02:00
sqlite_to_postgres_dump.py Add SQLite to Postgres restore canary (#43) 2026-07-07 12:21:54 +02:00
teleo_v3_epistemic_contract.sql Integrate hardened source-first V3 rebuild foundation 2026-07-21 21:41:30 +02:00
verify_gcp_canonical_lifecycle.py Pin lifecycle receipts to the reviewed parity manifest 2026-07-15 10:59:43 +02:00
verify_gcp_cloudsql_restore_readback.py Add Cloud SQL restore readback verifier (#49) 2026-07-07 13:16:24 +02:00
verify_gcp_leoclean_runtime_permissions.py Normalize Cloud SQL identity addresses 2026-07-23 18:56:39 -07:00
verify_gcp_leoclean_service_environment.py fix: prove least-privilege GCP Leo runtime context 2026-07-15 07:16:40 +02:00
verify_postgres_parity_manifest.py Replay PostgreSQL role and ACL parity 2026-07-16 12:32:02 +02:00
verify_teleo_v3_epistemic_contract.py Integrate hardened source-first V3 rebuild foundation 2026-07-21 21:41:30 +02:00
verify_vps_canonical_snapshot_delta.py Harden GCP parity proof against forged lifecycle claims 2026-07-15 10:20:27 +02:00