ADR-012: GE-Enforce manifest ownership in shopdb (ACCEPTED)
Formalizes the design built this session: manifest as shopdb data (wide entries table + entrytype discriminator, per-plugin Alembic chain), immutable published snapshots + rollback, behavioral-parity gate, engine-as-source-of-truth filter mirror, payload integrity separate from detection, observed-state reporting, service-token auth (contract 0.11.0), client kit + provisioning-agnostic Install-GEEnforce bootstrap (engine referenced not vendored), Milestone-1 export-to-share + staged cutover, and NO application auto-seeding (curated linking instead). Indexed in ADR README + CLAUDE.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -24,6 +24,7 @@ Each ADR captures a single architectural decision: the context, the decision its
|
||||
| [009](ADR-009-frontend-plugin-gating.md) | Frontend plugin route gating | ACCEPTED |
|
||||
| [010](ADR-010-frontend-plugin-hooks.md) | Frontend plugin hook contract | ACCEPTED |
|
||||
| [011](ADR-011-machines-rename.md) | Machines rename + modeltypes retyping | ACCEPTED |
|
||||
| [012](ADR-012-geenforce-manifest-ownership.md) | GE-Enforce manifest ownership in shopdb | ACCEPTED |
|
||||
|
||||
## Authoring
|
||||
|
||||
|
||||
Reference in New Issue
Block a user