docs: D-1 remainder — stale Internal-ops framing and OQ list

Completes review 001 D-1 (vision.md's half landed with ADR-015):

- alk-stack.md gitea-lesson item 2: supersession note pointing at
  ADR-012 §3 / ADR-015 (repo ops are External, scope + manage grant —
  right mechanism, wrong axis).
- AGENTS.md lifecycle status: active OQ list updated (OQ-03
  partially resolved, OQ-05 deferred, OQ-16 deferred; OQ-04/06/08
  resolved via ADR-013/012/011).
- review 001: D-1 marked resolved.

All three stale statements were pre-decomposition landmines: research
docs are declared 'current source of truth' by AGENTS.md, so the
superseded admin-API design needed marking.
This commit is contained in:
glm-5.3-flash committed 2026-09-29 08:30:45 +00:00
1 parent 85bde4c241
commit 201c7a1fce
3 files changed
+12 -3

No files matched your search

+5
View File
@@ -46,6 +46,11 @@ unreachable from the wire. alkgit must extend the same philosophy:
call protocol as `Visibility::Internal` ops over the admin interface
(or via alkhttp with auth); there is no admin endpoint that exists on the
same unauthenticated surface as git traffic.
*(Superseded by ADR-012 §3 / ADR-015 for alkgit's repo ops: the ops are
`Visibility::External`, gated by scope + the per-repo `manage` grant —
the gitea lesson is served by the ACL (visible-surface =
authorized-surface), not by hiding the ops. "Right mechanism, wrong
axis.")*
3. **No plaintext secrets in the DB.** Credentials/tokens go through
alkvault; the metadata store holds references, not keys.
4. **Blast-radius thinking carries into the design**: single binary, no