Repository navigation
docs(governance): 支持 Registry 容器与 Neon 预览 - #32
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Registry 的目录、详情、Publisher 和原生分发由同一 CPython 服务交付。将 ext-reg 的预览约定更新为从精确 PR head 构建单一 OCI 镜像,每个同仓库 PR 使用独立 app、Neon 数据库分支及 R2 桶。
预览工作流自行构建镜像,再交给独立 runner 的可信控制器。云平台控制凭据仅属于控制器;候选迁移容器只获得所属分支的 owner 连接,运行服务使用普通数据库角色和所属桶的对象凭据。关闭 PR 后清理对应资源,生产权限保持既有边界。具体平台规格和迁移操作仍由 Registry 仓库拥有。
配套实现:InKCre/ext-reg#33。真实 Heroku Eco / Neon / R2 预览、普通数据库角色、浏览器发布与详情、重部署保留数据,以及临时资源清理均已验证,见实现 PR 的 task packet。首次验收由本机运行同一可信控制器完成;自动触发等待控制器进入默认分支。
已人工核对授权、构建、凭据隔离和生命周期,
git diff --check通过。本 PR 只更新交付约定,不执行生产部署;两个 PR 均未合并。