proposal: every org owns its ground + the one-MCP decision #117
No reviewers
Labels
No labels
bug
discussion
duplicate
enhancement
goal
help wanted
horizon:backlog
horizon:governance
horizon:mvp
invalid
operator-decision
question
roadmap
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
open-platform/mitosis!117
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "docs/org-ground"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Two design artifacts that anchor the completion push:
docs/proposals/every-org-owns-its-ground.md— every org gets<org>/gitops; deployment config becomes subject to the same Forgejo access panel as everything else. Staged writers (A: MCP-only + org read → B: org PRs + verify gate → C: per-org SA + Kyverno bounds), tier-in-tenant-file resource envelopes, and a migration that is Flux ownership transfer with a hard 2-before-3 ordering. Lazy org-repo creation means germinate threads nothing and daughters get it free.docs/design/one-mcp-front-door.md— decision record: no second MCP server.mcp.<domain>already authenticates via Forgejo and authorizes per call; the gap was access-management tools and documentation.Implementation is up for review alongside this:
🤖 Generated with Claude Code