docs(architecture): resolve OQ-06/07/08 — per-repo authz, registry backing, CRUD ops

ADR-011 (resolves OQ-08): per-repo authorization — grants live in repo
records keyed on the stable logical identity id (alkcall ADR-025,
referenced); policy is alkgit-core's authorize() function (public+read
anonymous-first-class, write always authenticated+granted); alkgit
stores no identity records; vault placement resolved as nothing to
place in v1.

ADR-012 (resolves OQ-06/OQ-07): registry backing + write surface —
GitRegistryStore write supertrait (alknet ADR-035 read/write split
shape); registry-file default (per-repo record files + in-memory
index, config-seeded, op-mutable, no gitoxide); git/repo/* CRUD ops
shipped External with scope+ownership ACL (create mints ownership and
seeds creator grants; ownership never implies git access); the
two-op-kind classification recorded (open op + call ops from one
crate, per alkcall ADR-047); recorded split trigger for a downstream
platform crate.

Doc sync: backend.md (five-trait family, feature model split,
two-op-kinds), doors.md + overview.md (authorize policy, dual-kind
crate map), open-questions.md (OQ-06/07/08 resolved), README (ADR
table, current state), oq-06 tracker task closed (resolved early).

Verification: cargo test (default + --no-default-features), clippy
-D warnings, fmt --check.
This commit is contained in:
glm-5.3-flash committed 2026-09-21 16:26:59 +00:00
1 parent 86bf5a0cf0
commit addc874667
8 files changed
+492 -104

No files matched your search

+16 -12
View File
@@ -1,37 +1,41 @@
---
id: architecture/oq-06-metadata-backing
name: OQ-06 unblock — metadata-scale requirements arrive
status: pending
status: done
depends_on: []
scope: narrow
risk: trivial
impact: component
level: research
tags: [external-trigger, deferred-oq]
tags: [external-trigger, deferred-oq, resolved-early]
---
## Description
Tracker for OQ-06 (`deferred(scope)`): registry/metadata backing store.
This task is not actionable work — it tracks whether the blocking
condition has arrived: concrete metadata-scale requirements (repo count,
metadata fields beyond id/root/visibility/ACL scope, alkcall-hub
integration scope). When they exist, mark completed; OQ-06 transitions to
`open`.
**Resolved early (2026-09-21, ADR-012)** before the blocking condition
arrived: the deferral's premise was wrong — the deferred "metadata-scale
requirements" only ever gated a *persistence adapter* (future, separate,
additive), never the default backing. The default (`registry-file`
feature: per-repo record files + in-memory index, config-seeded,
op-mutable) is file-scale by design under the alknet repo/adapter
pattern. Marking done closes the tracker.
## Work
None by default. On trigger: set OQ-06 to `open` and schedule the backing
decision session.
None. OQ-06 is resolved by
`docs/architecture/decisions/012-registry-backing-and-ops.md` (§1–2, §4).
## Verification
- OQ-06 status matches `docs/architecture/open-questions.md`.
- OQ-06 status matches `docs/architecture/open-questions.md` (resolved).
## Out of scope
- Choosing the backing store.
- Building a persistence adapter (gated on a real deployment need —
additive, no tracker needed until then).
## Summary
> Filled on completion.
Resolved early via ADR-012: the repo/adapter pattern made the default
independent of scale requirements; the deferral dissolved.