docs(agents): gate re-scope — code fast-moving, human gate moved to KNEL/access-roster [#345]
Founder ruling 2026-09-02: no gates for code/host work; two-human approval applies to the badge-ID control file (separate private repo). https://projects.knownelement.com/issues/345
This commit is contained in:
@@ -26,19 +26,19 @@ House rules layering: `~/.zcode/AGENTS.md` (global) < PFVCluster
|
||||
[tests/remote.sh](https://git.knownelement.com/KNEL/PFVCluster/src/branch/main/tests/remote.sh).
|
||||
- DNS names only — never IP literals.
|
||||
|
||||
## PR process (founder ruling 2026-09-02) — physical access is 100% human-gated
|
||||
## Gate scope (founder ruling 2026-09-02, revised same day)
|
||||
|
||||
- `main` is BRANCH-PROTECTED: no direct pushes, by anyone. All changes
|
||||
land via PR with the sign-off template (`.gitea/pull_request_template.md`).
|
||||
- **Two human approvals required to merge.** Gitea enforces the count.
|
||||
Agents may author and push PR branches and implement review feedback —
|
||||
agents NEVER approve, NEVER merge, NEVER bypass (`--no-verify` is not
|
||||
a bypass for the approval count).
|
||||
- Access-control changes (badge roster, unlock policy, door-adjacent
|
||||
code) additionally require the template's checklist and a
|
||||
founder-approved ticket.
|
||||
- Full audit chain per change: Redmine ticket → PR description → two
|
||||
named human approvals → merge → deployment note (#356).
|
||||
- **This repo (code) is fast-moving**: tests + shellcheck are the only
|
||||
gates; commit+push per standing policy. The two-approval requirement
|
||||
on `main` was removed by founder ruling — "no gates" for code/host
|
||||
work on pfvsvrpi and ultix-field.
|
||||
- **The human gate lives on the badge-ID control file**:
|
||||
[KNEL/access-roster](https://git.knownelement.com/KNEL/access-roster)
|
||||
(private, PR-only, two human approvals enforced). The listener NEVER
|
||||
carries badge data — a change to who can open the door means a PR
|
||||
there, never a change here.
|
||||
- Deployment discipline still applies: ultix-field (dev) first, verify,
|
||||
then pfvsvrpi (prod) — serial, health-gated.
|
||||
|
||||
## Scope boundary: Home Assistant
|
||||
|
||||
|
||||
Reference in New Issue
Block a user