Outcome
Run a bounded credentialed live-confidence lane from main on a schedule and by manual dispatch, using the existing PUTIO_SDK_TYPESCRIPT_SOPS_FILE consumer contract and runner-owned age delivery.
Raised from #108. Repository-side SOPS rendering and fresh-token lifecycle support already exist. Implementation remains blocked until the runner can supply a scoped age identity and ciphertext path through an environment-owned delivery contract.
Acceptance criteria
Verification
vp run verify
vp run lint:package
vp run test:compat
- Linked successful manual and scheduled workflow runs.
Boundaries
Do not copy private ciphertext into this repository, store age private material in GitHub repository secrets, reintroduce Infisical, or make public PR CI depend on credentials.
Outcome
Run a bounded credentialed live-confidence lane from
mainon a schedule and by manual dispatch, using the existingPUTIO_SDK_TYPESCRIPT_SOPS_FILEconsumer contract and runner-owned age delivery.Raised from #108. Repository-side SOPS rendering and fresh-token lifecycle support already exist. Implementation remains blocked until the runner can supply a scoped age identity and ciphertext path through an environment-owned delivery contract.
Acceptance criteria
main, supportsworkflow_dispatch, and has an explicit bounded schedule.mainworkflow.Verification
vp run verifyvp run lint:packagevp run test:compatBoundaries
Do not copy private ciphertext into this repository, store age private material in GitHub repository secrets, reintroduce Infisical, or make public PR CI depend on credentials.