Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
93 commits
Select commit Hold shift + click to select a range
1c10205
fix: pin NOEMA_LLM_MODEL routing alias to orchestrator/free
claude Sep 2, 2026
4c76db2
test(noema): prohibit downstream routing heuristics
seonghobae Sep 2, 2026
514c43a
test(workflows): forbid local inference time budgets
seonghobae Sep 2, 2026
4c31594
chore(repair): add no-heuristic gateway source fix
seonghobae Sep 2, 2026
53183a7
chore(repair): add PR535 TDD source-fix workflow
seonghobae Sep 2, 2026
7ab6e1b
chore(repair): trigger PR535 no-heuristic source fix
seonghobae Sep 2, 2026
97b32fa
fix(noema): remove temporary self-writing repair machinery
seonghobae Sep 2, 2026
75d166a
fix(noema): enforce free-pool reviewer boundary
seonghobae Sep 2, 2026
b4264c0
test(noema): align reviewer tests with free-pool boundary
seonghobae Sep 2, 2026
f1494bf
ci(temp): finish PR535 no-heuristic gateway repair
seonghobae Sep 2, 2026
4f7a2f9
fix(noema): remove local inference routing and deadline controls
seonghobae Sep 2, 2026
a3469cf
refactor(test): remove local inference budget helper
seonghobae Sep 2, 2026
cc43223
test(noema): delegate inference timing and pin free-pool workflow
seonghobae Sep 2, 2026
cd2f79b
ci(temp): add transactional PR535 repair helper
seonghobae Sep 2, 2026
1989256
test(noema): prove model variables cannot broaden free-pool authority
seonghobae Sep 2, 2026
ff630e1
fix(repair): make PR535 source repair executable
seonghobae Sep 2, 2026
eacbf3e
test(orchestrator): expose legacy alias rollout deadlock
seonghobae Sep 2, 2026
7598cd8
test(orchestrator): bind legacy alias compatibility to CLI boundary
seonghobae Sep 2, 2026
c47f5e2
fix(orchestrator): normalize legacy service alias to free pool
seonghobae Sep 2, 2026
23de369
chore(ci): remove temporary self-modifying PR535 writer
seonghobae Sep 2, 2026
c1a6be5
chore(ci): remove temporary PR535 repair helper
seonghobae Sep 2, 2026
79a69b6
test(reviewer): expose legacy alias rollout deadlock
seonghobae Sep 2, 2026
405e9fb
fix(reviewer): canonicalize legacy gateway alias at transport boundary
seonghobae Sep 2, 2026
a740ed3
test(orchestrator): align workflow gate with transport canonicalization
seonghobae Sep 2, 2026
f9bcc12
test(reviewer): keep legacy compatibility fail-closed
seonghobae Sep 2, 2026
5a148e4
docs(orchestrator): record fail-closed legacy alias canonicalization
seonghobae Sep 2, 2026
b7a6324
docs(ops): remove obsolete model-variable rollout prerequisite
seonghobae Sep 2, 2026
da40254
docs(ops): align hourly model lifecycle with orchestrator ownership
seonghobae Sep 2, 2026
10a4e48
docs(changelog): align free-pool rollout with executable boundary
seonghobae Sep 2, 2026
8e17b24
test(review): reject local attempt controls and bind ZDR policy
seonghobae Sep 2, 2026
e2f45b2
fix(review): fail closed on local attempt controls
seonghobae Sep 2, 2026
9fc15a5
test(review): require request-level ZDR settings
seonghobae Sep 2, 2026
e2a1dfa
fix(review): forward trusted ZDR policy without local retries
seonghobae Sep 2, 2026
519500c
test(review): block approvals on every unresolved finding
seonghobae Sep 2, 2026
44e58c9
fix(review): remove local severity admission thresholds
seonghobae Sep 2, 2026
1de059b
test(review): bind central routing and ZDR workflow policy
seonghobae Sep 2, 2026
6de3cc7
test(ci): prevent temporary self-modifying writers
seonghobae Sep 2, 2026
b118607
test(ci): expose remaining orchestrator authority drift
seonghobae Sep 2, 2026
e5a92fe
fix(gateway): remove invented default health deadline
seonghobae Sep 2, 2026
637d8b4
test(gateway): verify caller-owned health deadline
seonghobae Sep 2, 2026
f9dbeb6
test(ci): scope review-authority regression to publication
seonghobae Sep 2, 2026
7e31a45
ci(noema): run exact-head review-quality GREEN repair
seonghobae Sep 2, 2026
0edc452
fix(review): preserve distinct deterministic findings
seonghobae Sep 2, 2026
d395100
fix(review): reject uncontracted model authority fields
seonghobae Sep 2, 2026
527a0b4
fix(review): treat repository evidence as untrusted prompt data
seonghobae Sep 2, 2026
2b12987
test(review): lock strict verdict and finding schemas
seonghobae Sep 2, 2026
8b428ba
test(review): reject repository prompt-injection authority
seonghobae Sep 2, 2026
7eeaee7
test(review): prevent same-path false-negative collapse
seonghobae Sep 2, 2026
5711ddf
ci(noema): remove superseded PR535 source writer
seonghobae Sep 2, 2026
15a9188
ci(noema): run remaining workflow-authority GREEN repair
seonghobae Sep 2, 2026
573ca87
fix(review): bind central inference to governed policy
seonghobae Sep 2, 2026
2602e18
ci(noema): preserve direct central repair in authority writer
seonghobae Sep 2, 2026
fcd671b
ci(noema): retrigger exact-head workflow authority repair
seonghobae Sep 2, 2026
857b76a
fix(review): fail closed for private OpenCode routing
seonghobae Sep 2, 2026
2736286
test(review): lock OpenCode visibility authority
seonghobae Sep 2, 2026
93a13c8
docs(review): bind OpenCode privacy authority
seonghobae Sep 2, 2026
af55fad
chore(review): remove completed PR535 repair writer
seonghobae Sep 2, 2026
031efc5
fix(review): attack demonstrated false-negative classes
seonghobae Sep 2, 2026
4fe8f30
test(review): lock adversarial false-negative corpus
seonghobae Sep 2, 2026
fd9d98e
docs(review): record adversarial corpus contract
seonghobae Sep 2, 2026
b45506d
fix(reviewer): attack externally demonstrated review misses
seonghobae Sep 2, 2026
6be5f28
test(reviewer): preserve external false-negative regressions
seonghobae Sep 2, 2026
19e7cac
docs(review): trace externally demonstrated reviewer regressions
seonghobae Sep 2, 2026
281aca9
fix(review): preserve findings in blocked verdicts
seonghobae Sep 2, 2026
290504c
test(review): lock blocked-finding retention regression
seonghobae Sep 2, 2026
ac6178b
fix(review): retain partial-model findings when evidence blocks
seonghobae Sep 2, 2026
2e1107c
test(review): preserve proven findings under blocked evidence
seonghobae Sep 2, 2026
c70b532
Merge protected main into orchestrator-free routing repair
seonghobae Sep 2, 2026
b9f2131
test(docs): require orchestrator-only model authority
seonghobae Sep 2, 2026
c143717
docs(trd): bind model execution to orchestrator authority
seonghobae Sep 2, 2026
bba0f56
docs(ops): remove direct provider credential authority
seonghobae Sep 2, 2026
57d3cd3
test: fail closed on unknown OpenCode capabilities
seonghobae Sep 2, 2026
724e690
fix: fail closed on unknown OpenCode capabilities
seonghobae Sep 2, 2026
79a8dbc
docs: trace OpenCode capability deny-by-default
seonghobae Sep 2, 2026
82dc4b1
Merge remote-tracking branch 'origin/main' into fix/noema-orchestrato…
claude Sep 3, 2026
410c52c
test(reviewer): reject string model routing
seonghobae Sep 3, 2026
8de1378
fix(reviewer): reject local string model routing
seonghobae Sep 3, 2026
a8a0815
test(orchestrator): bound health preflight transport wait
seonghobae Sep 3, 2026
abae56f
fix(orchestrator): bound health preflight transport wait
seonghobae Sep 3, 2026
9d06400
fix(review): sync stale gate tests with the severity-admission removal
claude Sep 3, 2026
ac5efa4
Merge protected main into orchestrator-free routing lane
seonghobae Sep 4, 2026
876a6fa
fix(actions): centralize hourly development admission
seonghobae Sep 4, 2026
425feb0
Revert "fix(actions): centralize hourly development admission"
seonghobae Sep 4, 2026
389bfc3
test(hourly): align final-candidate fixture with no-timeout authority
seonghobae Sep 4, 2026
bc70a96
test(opencode): cover malformed visibility fail-closed paths
seonghobae Sep 5, 2026
e9bb445
merge(reviewer): restack orchestrator boundary on protected reviewer …
seonghobae Sep 6, 2026
9dfc433
merge(context-fabric): restack orchestrator boundary on protected con…
seonghobae Sep 6, 2026
f20927d
test(reviewer): retain CodeGraph ambient-env isolation
seonghobae Sep 6, 2026
0a125fd
docs(release): restore orchestrator/free Unreleased note
seonghobae Sep 6, 2026
9378c9e
merge: converge orchestrator/free consumer lane onto protected #552 t…
seonghobae Sep 6, 2026
20c59b5
docs(agent): preserve free-pool contract across cross-session guidance
seonghobae Sep 6, 2026
99e44d0
docs(agent): preserve free-pool contract in current Claude guidance
seonghobae Sep 6, 2026
5de3fcb
merge: restack orchestrator-free consumer after #527 trust integration
seonghobae Sep 6, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 23 additions & 9 deletions .github/workflows/central-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -426,26 +426,40 @@ jobs:
- name: Install hash-pinned reviewer dependencies
run: pip install --require-hashes --no-deps -r reviewer/requirements-ci-hashes.txt

- name: Bind request privacy to live target visibility
env:
GH_TOKEN: ${{ steps.noema_write_app.outputs.token }}
run: |
set -euo pipefail
visibility="$(gh api "repos/${TARGET_REPOSITORY}" --jq .visibility)"
case "$visibility" in
public)
echo "NOEMA_LLM_ZDR_ONLY=false" >>"$GITHUB_ENV"
;;
private|internal)
echo "NOEMA_LLM_ZDR_ONLY=true" >>"$GITHUB_ENV"
;;
*)
printf '::error::Noema cannot derive request privacy from repository visibility=%s.\n' "${visibility:-missing}"
exit 1
;;
esac

- name: Run independent PydanticAI review and publish current-head verdict
env:
GH_TOKEN: ${{ steps.noema_write_app.outputs.token }}
PYTHONPATH: ${{ github.workspace }}/reviewer
NOEMA_REVIEW_TOKEN_SOURCE: noema-github-app
NOEMA_LLM_API_URL: ${{ vars.NOEMA_LLM_API_URL }}
NOEMA_LLM_MODEL: ${{ vars.NOEMA_LLM_MODEL }}
NOEMA_LLM_MODEL: orchestrator/free
# Dedicated inference token for contextual-orchestrator. Upstream
# provider credentials stay inside the orchestrator credential KV.
NOEMA_LLM_API_KEY: ${{ secrets.NOEMA_LLM_API_KEY }}
NOEMA_LLM_REQUEST_TIMEOUT_SECONDS: ${{ vars.NOEMA_LLM_REQUEST_TIMEOUT_SECONDS || '5400' }}
# One retry preserves transient recovery while keeping the request
# path inside the bounded publication job.
NOEMA_LLM_MAX_RETRIES: ${{ vars.NOEMA_LLM_MAX_RETRIES || '1' }}
run: |
set -euo pipefail
node scripts/verify-orchestrator-gateway.mjs
printf 'Noema provider contract: gateway=contextual-orchestrator primary=%s timeout=%ss retries=%s.\n' \
"${NOEMA_LLM_MODEL:-missing}" "${NOEMA_LLM_REQUEST_TIMEOUT_SECONDS:-missing}" \
"${NOEMA_LLM_MAX_RETRIES:-missing}"
printf 'Noema provider contract: gateway=contextual-orchestrator model=%s zdr_only=%s.\n' \
"${NOEMA_LLM_MODEL:-missing}" "${NOEMA_LLM_ZDR_ONLY:-missing}"
set +e
python -m noema_reviewer \
--manifest-file "$RUNNER_TEMP/noema-evidence/noema-manifest.json" \
Expand All @@ -456,7 +470,7 @@ jobs:
reviewer_status=$?
set -e
if [ -s "$RUNNER_TEMP/noema-verdict.json" ]; then
jq '{verdict,summary,findings,blocked_reasons,confidence}' \
jq '{verdict,summary,findings,blocked_reasons}' \
"$RUNNER_TEMP/noema-verdict.json"
fi
case "$reviewer_status" in
Expand Down
14 changes: 6 additions & 8 deletions .github/workflows/hourly-product-development.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,9 +22,8 @@ env:
DEFAULT_BRANCH: main
OPENCODE_VERSION: "1.17.13"
OPENCODE_SHA256: 157afa289d1a8d9372de0ce19ac726119b937a1f6b201808d46f06e4e59bb348
# One gateway-backed session plus setup/diagnostic reserve fits in 55 minutes.
OPENCODE_RUN_TIMEOUT_SECONDS: "2700"
OPENCODE_KILL_GRACE_SECONDS: "30"
# Model inference has no repository-authored wall-clock deadline.
# Runner/job termination remains an external platform-capacity event.
MAX_CHANGED_FILES: "40"
MAX_DIFF_BYTES: "500000"
MAX_PR_TITLE_BYTES: "120"
Expand All @@ -34,7 +33,6 @@ jobs:
propose_product_increment:
if: github.repository == 'ContextualWisdomLab/noema'
runs-on: ubuntu-latest
timeout-minutes: 55
permissions:
contents: read
pull-requests: read
Expand Down Expand Up @@ -145,7 +143,8 @@ jobs:
ContextualWisdomLab/.github, naruon, contextual-orchestrator, and other CWL
services. Keep interfaces explicit and replaceable. Route every Noema LLM
job through contextual-orchestrator. Do not sequentially try the next model
or agent inside Noema; the orchestrator selects min-cost / max-performance.
or agent inside Noema; routing is pinned to orchestrator/free, the
fail-closed zero-cost pool, ZDR-first.
Do not call NVIDIA NIM, Bytez, OpenRouter, OpenAI, or GitHub Models directly.
Do not alter the existing reviewer App identity, OIDC token-broker, or
sandbox boundaries.
Expand Down Expand Up @@ -241,7 +240,7 @@ jobs:
shell: bash
env:
NOEMA_LLM_API_URL: ${{ vars.NOEMA_LLM_API_URL }}
NOEMA_LLM_MODEL: ${{ vars.NOEMA_LLM_MODEL }}
NOEMA_LLM_MODEL: orchestrator/free
run: |
set -euo pipefail
node scripts/verify-orchestrator-gateway.mjs \
Expand Down Expand Up @@ -280,8 +279,7 @@ jobs:
run: |
set -euo pipefail
prompt="$(cat "$RUNNER_TEMP/noema-agent-prompt.md")"
if timeout --kill-after="${OPENCODE_KILL_GRACE_SECONDS}s" "${OPENCODE_RUN_TIMEOUT_SECONDS}s" \
env -u GH_TOKEN -u GITHUB_TOKEN \
if env -u GH_TOKEN -u GITHUB_TOKEN \
-u REPOSITORY_TOKEN \
-u ACTIONS_ID_TOKEN_REQUEST_TOKEN \
-u ACTIONS_ID_TOKEN_REQUEST_URL \
Expand Down
8 changes: 5 additions & 3 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -84,8 +84,9 @@ Worker (npm + `wrangler.toml`); tests run under Vitest.
judgments/decisions, and any later job — calls
`ContextualWisdomLab/contextual-orchestrator` through the same contract:
`NOEMA_LLM_API_URL` is an HTTPS OpenAI-compatible base ending in `/v1`,
`NOEMA_LLM_MODEL` is normally the routing alias `contextual-orchestrator`, and
`NOEMA_LLM_API_KEY` is a dedicated gateway inference token.
`NOEMA_LLM_MODEL` is the canonical routing alias `orchestrator/free`
(fail-closed zero-cost pool, ZDR-first), and `NOEMA_LLM_API_KEY` is a
dedicated gateway inference token.
- The reusable, secret-free copy is `contracts/orchestrator-gateway.json`
(`node scripts/verify-orchestrator-gateway.mjs --print-contract`). Narrative:
`docs/orchestrator-gateway-consumer-contract.md`. Validation helpers live in
Expand All @@ -96,7 +97,8 @@ Worker (npm + `wrangler.toml`); tests run under Vitest.
orchestrator credential KV, not in Noema or naruon runtime, workflows, or
this repository. Never `COPILOT_GITHUB_TOKEN`.
- Do **not** sequentially try the next model or agent inside Noema or naruon.
The orchestrator itself picks min-cost / max-performance. Do not configure a
Routing is pinned to `orchestrator/free`, the fail-closed zero-cost pool,
ZDR-first — not the paid-inclusive full pool. Do not configure a
direct-provider fallback. Shared preflight lives in
`scripts/verify-orchestrator-gateway.mjs`.
- Keep the OIDC token-broker, GitHub App identities, and sandbox/runner
Expand Down
1 change: 1 addition & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
# Changelog

## Unreleased
- Noema/naruon LLM 라우팅을 `contextual-orchestrator`의 paid-inclusive 전체 pool을 선택할 수 있던 bare 별칭 `contextual-orchestrator`에서 정규 라우팅 별칭 `orchestrator/free`(실패-폐쇄 zero-cost pool, ZDR-first)로 고정한다. `scripts/lib/orchestrator-gateway.mjs`의 공유 resolver는 `orchestrator/free`만 canonical alias로 허용하고, process/config anti-corruption boundary는 역사적 bare `contextual-orchestrator` 값만 즉시 `orchestrator/free`로 정규화한다. `orchestrator/auto`, 직접 provider 모델, 후보 목록은 계속 실패-폐쇄하며 `hourly-product-development`는 source에서 `orchestrator/free`를 고정한다. 따라서 관리자 측 model-variable migration은 안전한 rollout의 필수 선행조건이 아니며 provider routing/failover authority는 `contextual-orchestrator`에 남는다.
- Noema reviewer의 strict changed-file evidence를 historical 12-file prefix에서 canonical 80-file CodeGraph scope와 일치시켰다. 13–80 file PR은 선택된 모든 current-head file context를 유지하고 81개 이상은 기존처럼 실패-폐쇄하며, local CodeGraph fallback의 `HOME`·`TEMP`·`TMP`·`TMPDIR`은 ambient host path를 상속하지 않고 실행마다 새 private temporary directory로 격리한다.
- Workflow / Task Execution은 untrusted DAG를 execution/plan identity에 결합한 detached immutable snapshot으로 승인하고, validated array bounds 안에서만 task/dependency/state evidence를 읽는다. runnable 선택은 cross-execution·foreign·duplicate·non-canonical evidence, admitted concurrency를 초과한 running state, 성공하지 않은 prerequisite 뒤에 존재하는 causally impossible executed state를 실패-폐쇄하며, 선택 결과는 reservation이나 side-effect authority가 아닌 후보임을 명시한다. Agent Runtime lifecycle·State & Checkpoint·Workflow admission은 null·throwing accessor·revoked proxy 같은 malformed runtime input의 임의 JavaScript 예외를 각 bounded-context domain error로 정규화한다.
- State & Checkpoint admission은 accepted/replay 결과와 내부 checkpoint를 모두 caller-owned alias에서 분리한 frozen snapshot으로 반환한다. TypeScript `readonly`만으로는 막을 수 없는 JavaScript 런타임 alias mutation이 승인된 checkpoint authority나 `accepted`/`replay` 분류를 사후 변경하지 못하도록 실패-폐쇄한다.
Expand Down
2 changes: 1 addition & 1 deletion CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ This file provides guidance to Claude Code (claude.ai/code) when working with co

## What noema is

Noema is ContextualWisdomLab's multi-purpose GitHub App bot. The Cloudflare Worker (Free tier) remains the OIDC token broker: GitHub Actions presents a GitHub OIDC token (audience `cwl-noema-review`), noema verifies issuer/audience/org owner/trusted central workflow identity, then exchanges it for a GitHub App installation token scoped to the target repository with minimal permissions (`pull_requests: write`, `contents: read`, `checks: read`). Review is one job, not the only job. Noema also runs as a separate agent program inside `ContextualWisdomLab/naruon` for judgments and decisions; naruon is a first-class consumer of the same gateway contract (wiring is a separate naruon PR). Every LLM path — production review, hourly product development, and naruon judgments — calls `contextual-orchestrator` (`NOEMA_LLM_API_URL` ending in `/v1`, model normally `contextual-orchestrator`, dedicated `NOEMA_LLM_API_KEY`). The reusable contract is `contracts/orchestrator-gateway.json`. Noema does not sequentially try the next model or hold upstream provider keys.
Noema is ContextualWisdomLab's multi-purpose GitHub App bot. The Cloudflare Worker (Free tier) remains the OIDC token broker: GitHub Actions presents a GitHub OIDC token (audience `cwl-noema-review`), noema verifies issuer/audience/org owner/trusted central workflow identity, then exchanges it for a GitHub App installation token scoped to the target repository with minimal permissions (`pull_requests: write`, `contents: read`, `checks: read`). Review is one job, not the only job. Noema also runs as a separate agent program inside `ContextualWisdomLab/naruon` for judgments and decisions; naruon is a first-class consumer of the same gateway contract (wiring is a separate naruon PR). Every LLM path — production review, hourly product development, and naruon judgments — calls `contextual-orchestrator` (`NOEMA_LLM_API_URL` ending in `/v1`, model pinned to the canonical routing alias `orchestrator/free` — the fail-closed zero-cost ZDR-first pool, not the paid-inclusive full pool — dedicated `NOEMA_LLM_API_KEY`). The reusable contract is `contracts/orchestrator-gateway.json`. Noema does not sequentially try the next model or hold upstream provider keys.

## Commands

Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -62,7 +62,7 @@ Host-facing gateway configuration:
| Name | Meaning |
| --- | --- |
| `NOEMA_LLM_API_URL` | HTTPS OpenAI-compatible base ending in `/v1` |
| `NOEMA_LLM_MODEL` | Routing alias, normally `contextual-orchestrator` |
| `NOEMA_LLM_MODEL` | Routing alias, canonically `orchestrator/free` (fail-closed zero-cost pool, ZDR-first) |
| `NOEMA_LLM_API_KEY` | Dedicated gateway inference token |

Direct-provider fallbacks are intentionally rejected.
Expand Down
2 changes: 1 addition & 1 deletion contracts/orchestrator-gateway.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"id": "contextual-orchestrator-gateway",
"version": 1,
"service": "contextual-orchestrator",
"routing_alias": "contextual-orchestrator",
"routing_alias": "orchestrator/free",
"api_url": {
"scheme": "https",
"pathname_suffix": "/v1",
Expand Down
28 changes: 16 additions & 12 deletions docs/OPERABILITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -51,8 +51,12 @@ GitHub automation category:
- Maintainer App client identity and private key;
- exact reviewer App bot login;
- maintenance activation flag;
- model/development secret `NVIDIA_NIM_API_KEY`;
- reviewer model gateway credential contract, kept separate from development agent key.
- contextual-orchestrator gateway endpoint `NOEMA_LLM_API_URL`;
- dedicated gateway inference token `NOEMA_LLM_API_KEY`;
- routing alias `orchestrator/free`;
- reviewer model gateway credential contract, kept separate from repository publication authority.

Upstream provider credentials such as `NVIDIA_NIM_API_KEY`, `NVIDIA_NIM_API_KEY_SUB`, `BYTEZ_API_KEY`, `OPENROUTER_API_KEY`, and `OPENAI_API_KEY` are not Noema model-job configuration. Provider discovery, model selection, retries, failover, and paid/free routing remain contextual-orchestrator authority.

Secret values must not be copied into runbooks, PR bodies, model prompts, retained artifacts or acquisition evidence.

Expand Down Expand Up @@ -114,10 +118,12 @@ The proposal flow must preserve three trust domains.
### Proposal runner

- no repository write credential;
- OpenCode + NVIDIA NIM only;
- OpenCode uses only contextual-orchestrator's released gateway contract with routing alias `orchestrator/free`;
- receives `NOEMA_LLM_API_URL` and the dedicated `NOEMA_LLM_API_KEY`, never an upstream provider credential;
- does not define provider/model/group/paid fallback, retry, or model wall-clock timeout policy locally;
- bounded file/diff output;
- no symlink/gitlink authority;
- candidate failure cleanup before next model.
- proposal failure cleanup before the next independent work item.

### Verification runner

Expand All @@ -134,7 +140,7 @@ The proposal flow must preserve three trust domains.
- uses late-bound repository-scoped Maintainer App;
- conditionally creates and cleans up only run-owned branch/PR resources.

PR #80 further hardens this publisher. Until #80 lands and protected-main execution is observed, the new atomic publisher behavior is not operationally accepted.
Atomic proposal-publication and publisher-lease behavior must be judged from the current protected source and exact-head evidence, not from historical PR numbers. Candidate changes are not operationally accepted until they integrate and protected-main execution is observed.

## 9. Observability

Expand Down Expand Up @@ -199,7 +205,7 @@ If central workflow source changes unexpectedly or `ALLOWED_WORKFLOW_SHA` no lon

### Provider/model incident

Model provider outage or rate limit blocks only model-dependent work. Deterministic governance/security work continues. Do not change reviewer identity or merge gates merely to work around provider latency.
A contextual-orchestrator outage, capability rejection, or upstream condition surfaced by that gateway blocks only model-dependent work. Deterministic governance/security work continues. Noema does not select a direct provider, broaden a model group, add a paid fallback, create its own retry policy, or change reviewer identity/merge gates to work around model latency. Distinguish user cancellation, provider termination, and administrator policy timeout in retained evidence.

### GitHub Actions queue incident

Expand Down Expand Up @@ -227,7 +233,8 @@ Malformed/unavailable state decision fails credential issuance. Before deleting

### Product development

- disable schedule/workflow or revoke `NVIDIA_NIM_API_KEY` to stop model proposals;
- disable the proposal schedule/workflow or revoke/rotate the dedicated `NOEMA_LLM_API_KEY` gateway capability to stop new model proposals;
- do not substitute an upstream provider credential as a rollback path;
- revoke Maintainer App to stop publication;
- existing PRs remain governed by normal review/merge policy.

Expand Down Expand Up @@ -288,7 +295,7 @@ Evidence retention follows data class and existing security/disclosure policy. B
- scoped legal/contractual hold where applicable;
- secure deletion evidence that does not retain deleted secrets merely to prove deletion.

Coordinated vulnerability disclosure/retention specifics are owned by PR #72 and issue #73 until integrated.
Coordinated vulnerability disclosure/retention specifics must be verified from current protected source and the live owner issue/PR before operational acceptance; moving PR numbers are not durable authority.

## 15. Operator runbooks and commands

Expand All @@ -310,10 +317,7 @@ Runtime health/exchange, readiness/security state, maintenance/development workf

### Active proposed integration

- PR #71 architecture/workflow-source trust and this documentation graph.
- PR #76 dependency remediation.
- PR #78 deterministic package-manager/lockfile controls.
- PR #80 atomic publisher and work-conserving RCA contract.
Active PR state is intentionally not frozen in this canonical operability document. Read the live PR queue, exact heads/bases, dependency ancestry, reviews and current-head gates before treating any proposed integration as current.

### External / not yet proven by source

Expand Down
14 changes: 8 additions & 6 deletions docs/TRD.md
Original file line number Diff line number Diff line change
Expand Up @@ -235,9 +235,9 @@ protected merge → protected-main operational acceptance → queue top

### Trust-domain separation

1. **proposal runner**: OpenCode + NVIDIA NIM, no repository write credential.
2. **verification runner**: immutable artifact를 fresh source에 적용하고 release verification, no NIM/maintainer credential.
3. **publication runner**: verified immutable patch를 실행하지 않고 재구성한 후 late-bound Maintainer App credential만 사용.
1. **proposal runner**: OpenCode가 `contextual-orchestrator`의 released gateway contract와 `orchestrator/free` routing alias만 사용하며 repository write credential은 받지 않습니다.
2. **verification runner**: immutable artifact를 fresh source에 적용하고 release verification을 수행하며 model/maintainer credential을 받지 않습니다.
3. **publication runner**: verified immutable patch를 실행하지 않고 재구성한 후 late-bound Maintainer App credential만 사용합니다.

### Proposal contract

Expand All @@ -252,11 +252,13 @@ Atomic proposal-publication과 publisher-lease control은 protected main에 구

## 12. LLM and credential contract

- GitHub Actions development/maintenance agent: OpenCode Agent.
- model credential: `NVIDIA_NIM_API_KEY`.
- GitHub Actions development/maintenance model work는 OpenCode Agent가 `contextual-orchestrator`의 released API/client/schema contract를 통해 수행합니다.
- routing identity는 `orchestrator/free`이며 Noema가 provider/model/group/paid fallback을 선택하지 않습니다.
- gateway endpoint와 inference capability는 `NOEMA_LLM_API_URL`, 전용 gateway token은 `NOEMA_LLM_API_KEY`로 전달합니다.
- upstream provider credentials(`NVIDIA_NIM_API_KEY`, `NVIDIA_NIM_API_KEY_SUB`, `BYTEZ_API_KEY`, `OPENROUTER_API_KEY`, `OPENAI_API_KEY`)은 Noema model jobs의 credential contract가 아니며 repository가 읽거나 fallback authority로 사용하지 않습니다.
- Noema는 model wall-clock timeout, retry, provider failover를 별도로 소유하지 않습니다. 사용자 취소, provider 종료, 관리자 정책 timeout은 서로 다른 종료 원인으로 보존합니다.
- `COPILOT_GITHUB_TOKEN`은 사용하지 않습니다.
- reviewer App key contract를 autonomous development 때문에 변경하지 않습니다.
- `contextual-orchestrator`를 사용할 때 Noema는 upstream provider secret을 직접 받지 않고 gateway-level contract를 사용합니다.
- model output은 untrusted judgement evidence이며 deterministic security/governance gate와 분리합니다.

## 13. Package and toolchain reproducibility
Expand Down
Loading
Loading