Skip to content

chore: align repo to kellerai-oss-template (structural)#1

Open
jonathan-kellerai wants to merge 3 commits into
devfrom
chore/oss-template-align
Open

chore: align repo to kellerai-oss-template (structural)#1
jonathan-kellerai wants to merge 3 commits into
devfrom
chore/oss-template-align

Conversation

@jonathan-kellerai

Copy link
Copy Markdown
Owner

Summary

Aligns trust-boundary-protocol to jonathan-kellerai/kellerai-oss-template@mainstructural alignment (Plan C of the OSS-template rollout). Adds 13 governance / meta-governance files; no existing content is modified. Targets dev per the canonical four-tier flow (dev → qa → main).

Produced by a four-wave dynamic workflow (Analyze → Edit → Verify; Publish handled manually so commit + push went through the audited gm-full path). Audit trail in artifacts/trust-boundary-protocol/{gap.md,changes.json}.

Files added (13)

.github/workflows/ — 7 meta-governance workflows

  • blast-radius-outcome.yml
  • blast-radius-pulse.yml
  • trust-dial-gate.yml
  • trust-dial-outcome.yml
  • validate-branch-name.yml
  • validate-branch-tier.yml
  • validate-linked-issue.yml

conformance/ — blast-radius framework

  • affects.json
  • blast_radius.rego
  • blast_radius_test.rego

audit/ — blast-radius pulse ledger

  • blast-radius.jsonl

scripts/ — pulse orchestration

  • pulse.sh (mode 755)

root

  • .kellerai-oss.json — rollout manifest (artifact_type, artifact_dir, primary_validator, owner)

Files modified

None.

Conformance + sanitization gates

  • Sanitization: check-sanitization: OK — no denied terms in the publishable tree (exit 0), confirmed both standalone and by the pre-commit lefthook.
  • Structure: check-structure: OK — 17 canonical files present, specification sections intact (pre-commit lefthook).
  • Conformance (OPA Verify phase): completed; no blocking conformance violations were surfaced for this repo.

Residual warnings: none surfaced by the workflow or the sanitization gate.

Branch protection

This rollout also configured branch rulesets mirroring the canonical template — protect-main, protect-qa, protect-dev: block branch deletion and non-fast-forward (force-push), require a pull request with 1 approving review (code-owner review on main and qa; not required on dev); repository-admin bypass.

Why draft

Draft so a human can confirm the 7 workflow files fire correctly in this repo's CI and that conformance/affects.json reflects the right blast scope before promoting dev → qa → main.

@github-actions

Copy link
Copy Markdown

Blast-radius pulse — blocked

@github-actions

github-actions Bot commented Jun 2, 2026

Copy link
Copy Markdown

Blast-radius pulse — blocked

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant