docs: govern shared Corp v1 SSO login
Build and publish Corp v1 Board portal / build (pull_request) Successful in 35s
Build and publish Corp v1 Board portal / build (pull_request) Successful in 35s
This commit is contained in:
@@ -8,6 +8,7 @@ sidebar_position: 2
|
||||
|
||||
| Date | Decision | Scope | Owner | Record |
|
||||
|---|---|---|---|---|
|
||||
| 2026-08-27 | Authorize secret-safe use of the Bitwarden-injected shared Corp v1 SSO identity for approved system tasks | Corp v1 governance and all project channels | RootAtSkic | [Shared Corp v1 system SSO credentials](/governance/decisions/shared-system-sso-credentials/) |
|
||||
| 2026-08-27 | Separate each project's lifecycle channels into one dedicated Discord category | Corp v1 governance, AeroSim, Maze Next Gen, E-Shop v1 | RootAtSkic | [Dedicated Discord category per project](/governance/decisions/project-discord-category-separation/) |
|
||||
| 2026-08-27 | Establish the Corp v1 Guild improvement workspace, skill, Gitea source, and portal architecture representation | Corp v1 governance and operating-model improvement | RootAtSkic | [Corp v1 Guild establishment](/governance/decisions/corp-v1-guild-establishment/) |
|
||||
| 2026-08-26 | Authorize E-Shop v1 kickoff, toothbrush-commerce MVP, and bounded bootstrap autonomy | E-Shop v1 | RootAtSkic | [E-Shop v1 kickoff and bootstrap autonomy](/governance/decisions/eshopv1-kickoff-bootstrap-autonomy/) |
|
||||
|
||||
@@ -0,0 +1,40 @@
|
||||
---
|
||||
title: Shared Corp v1 system SSO credentials
|
||||
---
|
||||
|
||||
# Shared Corp v1 system SSO credentials — 2026-08-27
|
||||
|
||||
## Context
|
||||
|
||||
Hermes sometimes needs to authenticate to Corp v1 systems being built or operated in order to perform an explicitly authorized task. Asking project members to retransmit credentials through Discord or storing them in project artifacts would create avoidable exposure.
|
||||
|
||||
## Decision
|
||||
|
||||
RootAtSkic (`discord:1518725627845283888`) approved use of the shared Bitwarden-injected Corp v1 SSO identity in Board message `1542636538305712199`.
|
||||
|
||||
Skills and records may contain only these runtime secret names:
|
||||
|
||||
- `HL_V1_SSO_EMAIL`
|
||||
- `HL_V1_SSO_PASSWORD`
|
||||
|
||||
Credential values, Bitwarden object identifiers, and account metadata must not be copied into Discord, skills, repositories, prompts, command lines, URLs, files, screenshots, logs, CI output, or reports.
|
||||
|
||||
## Operating rules
|
||||
|
||||
- SSO secret availability is a capability, not authorization. Every login must serve an explicitly authorized project task and verified destination origin.
|
||||
- Hermes checks only whether both runtime variables are present and uses them through a trusted login form or provider-supported secure runtime interface.
|
||||
- Missing injection is reported by secret name only; no local fallback secret is created and no human is asked to paste a value into chat.
|
||||
- Login does not authorize account recovery, MFA or credential changes, permission changes, billing, spending, destructive operations, or unrelated system/data access.
|
||||
- Reports contain only the target system, authorized purpose, login result, and non-sensitive verification evidence.
|
||||
|
||||
## Implementation and verification
|
||||
|
||||
The central `corp-v1--main` skill was updated to version `4.4.0` and merged through PR [9](https://gitea.lego-cloud.eu/home-v1-skills-code-agent/corp-v1--main/pulls/9) at `b11b0e521dab6b7a920337feed37c5a849d507bd`.
|
||||
|
||||
The same secret-safe login section was published central-first to all seven `corp-v1-channel-*` reference skills, then semantically adopted into all 21 project channel skills across AeroSim, Maze Next Gen, and E-Shop v1. Every project-local authorization override was hash-checked before and after adoption, project bindings and supporting files were preserved, and every pushed default ref and `SKILL.md` marker was read back. All 21 installed Hermes runtime packages were refreshed from the resulting project repositories. The exact repository, branch, commit, and override coverage is recorded in the [shared SSO skill rollout ledger](/governance/sso-skill-rollout/).
|
||||
|
||||
Runtime preflight confirmed both secret names are currently injected. No credential value was read into a report, persisted, or committed.
|
||||
|
||||
## Consequences
|
||||
|
||||
Every Corp v1 channel now follows one login path and one non-disclosure policy. Authentication can support authorized delivery work without turning credential availability into broader system authority.
|
||||
@@ -27,6 +27,10 @@ Maintain current status, decisions, risks, milestones, and material scope change
|
||||
|
||||
The guild-level `corp-v1` category is reserved for Board and shared governance channels. Every project uses one dedicated top-level category named `corp-v1-<code>` containing exactly seven lifecycle channels in this order: General, Scope, Architecture, UI/UX, Kanban, Delivery, Releases. Existing channels are moved by immutable ID so history, pins, permission overwrites, webhooks, and delivery targets remain intact.
|
||||
|
||||
### System login
|
||||
|
||||
For an explicitly authorized Corp v1 system task, Hermes may use the Bitwarden-injected runtime secrets named `HL_V1_SSO_EMAIL` and `HL_V1_SSO_PASSWORD`. Secret availability does not authorize unrelated access or account administration. Values and Bitwarden object metadata must never be printed, persisted, committed, posted, logged, placed in command lines or URLs, or requested through chat. Missing injection is reported by secret name only.
|
||||
|
||||
### Project-channel skill changes
|
||||
|
||||
A proposed change to a central project-channel reference skill (`corp-v1-channel-*`) must be presented to the Board before publication. After explicit Board approval and central publication, ask every affected project channel to review and synchronize its project-adopted channel skill (`corp-v1-channel-*--<code>`). Synchronization must preserve project-specific decisions, report conflicts for Board review, update runtime copies, and verify attached channel jobs.
|
||||
|
||||
@@ -0,0 +1,48 @@
|
||||
---
|
||||
title: Shared SSO skill rollout
|
||||
---
|
||||
|
||||
# Shared SSO skill rollout — 2026-08-27
|
||||
|
||||
This ledger records the Board-approved secret-name-only login guidance published under Discord message `1542636538305712199`. All repositories were updated central-first, pushed to their actual default branches, and read back at the exact resulting commit. Project-local authorization override blocks were hash-compared before and after each adoption.
|
||||
|
||||
| Scope | Skill repository | Branch | Published commit | Preserved override blocks |
|
||||
|---|---|---|---|---:|
|
||||
| Central reference | [corp-v1-channel-general](https://gitea.lego-cloud.eu/home-v1-skills-code-agent/corp-v1-channel-general) | `test` | `a5e79c24dd4ec1fa0d1a3258ecc184d9808daa62` | 0 |
|
||||
| Central reference | [corp-v1-channel-scope](https://gitea.lego-cloud.eu/home-v1-skills-code-agent/corp-v1-channel-scope) | `test` | `4554b78e20377863af55be3dca78cf22f1e98b75` | 0 |
|
||||
| Central reference | [corp-v1-channel-architecture](https://gitea.lego-cloud.eu/home-v1-skills-code-agent/corp-v1-channel-architecture) | `test` | `c7620c804a0de210f35fc829a38a53e44d40bfd8` | 0 |
|
||||
| Central reference | [corp-v1-channel-ui-ux](https://gitea.lego-cloud.eu/home-v1-skills-code-agent/corp-v1-channel-ui-ux) | `test` | `132406f061ee1f363ca575a1c3ae7488e4bfe948` | 0 |
|
||||
| Central reference | [corp-v1-channel-kanban](https://gitea.lego-cloud.eu/home-v1-skills-code-agent/corp-v1-channel-kanban) | `test` | `87a50a926a7256201ce1771aad7764898f24ff60` | 0 |
|
||||
| Central reference | [corp-v1-channel-delivery](https://gitea.lego-cloud.eu/home-v1-skills-code-agent/corp-v1-channel-delivery) | `test` | `20cb78ce0942b35fe6528399c22764fbfb4cf06a` | 0 |
|
||||
| Central reference | [corp-v1-channel-releases](https://gitea.lego-cloud.eu/home-v1-skills-code-agent/corp-v1-channel-releases) | `test` | `94d147880f6c957967d6612cbd846f9a2f2f6c00` | 0 |
|
||||
| aerosim | [corp-v1-channel-general--aerosim](https://gitea.lego-cloud.eu/corp-v1-aerosim-skills-code-agent/corp-v1-channel-general--aerosim) | `test` | `e50dc8878ebe74b6c58601204508e4723bb7803d` | 0 |
|
||||
| aerosim | [corp-v1-channel-scope--aerosim](https://gitea.lego-cloud.eu/corp-v1-aerosim-skills-code-agent/corp-v1-channel-scope--aerosim) | `test` | `0b6cee38a12803b4a7ceefe824e6a510ea35fec3` | 1 |
|
||||
| aerosim | [corp-v1-channel-architecture--aerosim](https://gitea.lego-cloud.eu/corp-v1-aerosim-skills-code-agent/corp-v1-channel-architecture--aerosim) | `test` | `c2c379ea6875d1b2c91cd6d02da588b8cf06bcb6` | 1 |
|
||||
| aerosim | [corp-v1-channel-ui-ux--aerosim](https://gitea.lego-cloud.eu/corp-v1-aerosim-skills-code-agent/corp-v1-channel-ui-ux--aerosim) | `test` | `a985d0e4841b60290cbae888cbef6b142ada175f` | 1 |
|
||||
| aerosim | [corp-v1-channel-kanban--aerosim](https://gitea.lego-cloud.eu/corp-v1-aerosim-skills-code-agent/corp-v1-channel-kanban--aerosim) | `test` | `e75f81d559996e9cab97092bf94db33a324830d1` | 0 |
|
||||
| aerosim | [corp-v1-channel-delivery--aerosim](https://gitea.lego-cloud.eu/corp-v1-aerosim-skills-code-agent/corp-v1-channel-delivery--aerosim) | `test` | `af697f5d1ef708c66db3ab62fd1fa9094b7735a2` | 0 |
|
||||
| aerosim | [corp-v1-channel-releases--aerosim](https://gitea.lego-cloud.eu/corp-v1-aerosim-skills-code-agent/corp-v1-channel-releases--aerosim) | `test` | `e85df7e82daa004bf0dc5a8db9ea09a99507583b` | 0 |
|
||||
| mazeng | [corp-v1-channel-general--mazeng](https://gitea.lego-cloud.eu/corp-v1-mazeng-skills-code-agent/corp-v1-channel-general--mazeng) | `test` | `12579704b8afad3af41b55b540ad21132e2ac299` | 1 |
|
||||
| mazeng | [corp-v1-channel-scope--mazeng](https://gitea.lego-cloud.eu/corp-v1-mazeng-skills-code-agent/corp-v1-channel-scope--mazeng) | `test` | `51ee9f4722a6ba5f9bbd13384ae8674690e070f9` | 1 |
|
||||
| mazeng | [corp-v1-channel-architecture--mazeng](https://gitea.lego-cloud.eu/corp-v1-mazeng-skills-code-agent/corp-v1-channel-architecture--mazeng) | `test` | `4c80704a0bd065accba49d523f6a83f51f8c1d2c` | 1 |
|
||||
| mazeng | [corp-v1-channel-ui-ux--mazeng](https://gitea.lego-cloud.eu/corp-v1-mazeng-skills-code-agent/corp-v1-channel-ui-ux--mazeng) | `test` | `de7807acb68e3732982cc65087126d119d7dc52b` | 2 |
|
||||
| mazeng | [corp-v1-channel-kanban--mazeng](https://gitea.lego-cloud.eu/corp-v1-mazeng-skills-code-agent/corp-v1-channel-kanban--mazeng) | `test` | `a1dcadca90ccf18da54d415c87b47b77773730b9` | 1 |
|
||||
| mazeng | [corp-v1-channel-delivery--mazeng](https://gitea.lego-cloud.eu/corp-v1-mazeng-skills-code-agent/corp-v1-channel-delivery--mazeng) | `test` | `190de977a647446510375aff1bf3192beb41f444` | 1 |
|
||||
| mazeng | [corp-v1-channel-releases--mazeng](https://gitea.lego-cloud.eu/corp-v1-mazeng-skills-code-agent/corp-v1-channel-releases--mazeng) | `test` | `eddc0f9d788c28134775a70e02606a0ded326933` | 1 |
|
||||
| eshopv1 | [corp-v1-channel-general--eshopv1](https://gitea.lego-cloud.eu/corp-v1-eshopv1-skills-code-agent/corp-v1-channel-general--eshopv1) | `test` | `e2d6b628dbdd409cb3901384419ae69db8de256b` | 1 |
|
||||
| eshopv1 | [corp-v1-channel-scope--eshopv1](https://gitea.lego-cloud.eu/corp-v1-eshopv1-skills-code-agent/corp-v1-channel-scope--eshopv1) | `test` | `0b185c233a10d004a47f80b5d408cab582bbe058` | 1 |
|
||||
| eshopv1 | [corp-v1-channel-architecture--eshopv1](https://gitea.lego-cloud.eu/corp-v1-eshopv1-skills-code-agent/corp-v1-channel-architecture--eshopv1) | `test` | `9fcab760c09263b4432bf8a4a8028a22e4ca5532` | 1 |
|
||||
| eshopv1 | [corp-v1-channel-ui-ux--eshopv1](https://gitea.lego-cloud.eu/corp-v1-eshopv1-skills-code-agent/corp-v1-channel-ui-ux--eshopv1) | `test` | `1ed8d4f5b92c4ebb9501cd0d92f213aa40444eb6` | 1 |
|
||||
| eshopv1 | [corp-v1-channel-kanban--eshopv1](https://gitea.lego-cloud.eu/corp-v1-eshopv1-skills-code-agent/corp-v1-channel-kanban--eshopv1) | `test` | `4c96798bfe678c97c8f820000a424fbd50a74e53` | 1 |
|
||||
| eshopv1 | [corp-v1-channel-delivery--eshopv1](https://gitea.lego-cloud.eu/corp-v1-eshopv1-skills-code-agent/corp-v1-channel-delivery--eshopv1) | `test` | `5562b81fb3e8ad6fbc0d02039d58deaf64adbf53` | 1 |
|
||||
| eshopv1 | [corp-v1-channel-releases--eshopv1](https://gitea.lego-cloud.eu/corp-v1-eshopv1-skills-code-agent/corp-v1-channel-releases--eshopv1) | `test` | `77dbd2841337bd24b642b08329bcc338d2cb44f6` | 1 |
|
||||
|
||||
## Coverage
|
||||
|
||||
- Seven central `corp-v1-channel-*` reference skills.
|
||||
- Seven AeroSim channel-skill adoptions.
|
||||
- Seven Maze Next Gen channel-skill adoptions.
|
||||
- Seven E-Shop v1 channel-skill adoptions.
|
||||
- Twenty-one installed Hermes runtime packages refreshed from the resulting project repositories.
|
||||
|
||||
Only the names `HL_V1_SSO_EMAIL` and `HL_V1_SSO_PASSWORD` are recorded. No value or Bitwarden object identifier is stored in this ledger.
|
||||
Reference in New Issue
Block a user