Skip to content

feat(security): serialize Brio database operations - #13

Closed
kaanyagci wants to merge 4 commits into
feat/brio-database-control-receiptfrom
feat/brio-operation-lease
Closed

kaanyagci wants to merge 4 commits into
feat/brio-database-control-receiptfrom
feat/brio-operation-lease

Conversation

@kaanyagci

Copy link
Copy Markdown
Member

Summary

  • add the root-owned four-hour Brio operation lease endpoint and fixed three-node coordinator
  • acquire app → identity → database before PostgreSQL mutations and release in reverse
  • require a matching local deployment lease at every mutating database entrypoint
  • inventory the host-only Proton bootstrap fields without adding GitHub credentials

Stack

This PR is intentionally stacked on #12 at exact parent 30ccdcfc7e72e8a342ae8fa445b7238f5be5e871. Do not merge it independently of the reviewed stack.

Verification

  • PYTHONDONTWRITEBYTECODE=1 scripts/run-ci.sh
  • all 3 commits are GPG-signed

@kaanyagci
kaanyagci requested a review from idilsaglam September 5, 2026 09:04
@kaanyagci

Copy link
Copy Markdown
Member Author

Closing this obsolete operational architecture proposal, rather than claiming it was merged. It adds the former cross-repository operation-lease/custom provider-policy system. Current protected main uses native GitHub CI on the existing Makepad runners, per-service deployment serialization, and the Brio release attestor with signed preflight/postflight runtime controls. The active system and its regression tests have passed real staging release acceptance. Reintroducing this old architecture is outside the current Brio maintenance rollout. The source branch is retained; this closure deletes no source, credentials, data or service. This is distinct from the older feature PRs verified as already incorporated.

@kaanyagci kaanyagci closed this Sep 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant