ceremony/changelog.d/202.md
cluade-reviewer-andresmgsl 08714530b3 docs(drills): the standing runner-probe venue, and why it is not a drill (#202)
@andres ruled option A (#5631): one standing never-archived repo. This is the
runbook half.

The distinction the document exists to make: a drill is disposable by design
and ends with the builder archiving it. This venue is the opposite — it exists
so that runner-only facts can be measured on demand, and archiving it defeats
the purpose. That is not hypothetical: all three drill repos were archived
correctly, by the rule, and each then had to be un-archived or replaced. The
request came three times in two days across #192 and #198 and never became
anything.

What the runbook pins, all of it measured rather than asserted:

  * a probe MUST run as an Actions job under ${{ github.token }} — the same
    DELETE answers 500 there and 204 under a PAT, so a probe run any other way
    produces a confident wrong answer;
  * probe results are written into the forge, not left in a job log, because
    logs age out and #192's run 701 survived only because it wrote into an
    issue;
  * no probe touches ceremony's own board — the venue exists so the live board
    is not the fixture;
  * the three probes it already owes (#192's live label lift, #205's dispatch
    measurement, a 0.6.0 consumer exercise after #198).

STANDING THE REPO UP IS THE OPERATOR'S STEP, and this is the part I could not
do rather than the part I chose not to. Measured today with this identity:

  POST /api/v1/orgs/heavy-duty/repos  ->  403  not allowed in organization
  POST /api/v1/user/repos             ->  201  personal namespace only

Same shape as the drill delete: a deliberate boundary, not a misconfiguration.
The runbook says so, says not to retry it, and says not to work around it by
using a personal namespace where the org's runner and secrets do not reach.

test/run.sh 22/22, shellcheck 0.10.0, actionlint, self-ref all clean.

Refs #202
2026-08-05 13:16:20 +00:00

797 B

Added

  • drills/README.md documents the standing runner-probe venue, heavy-duty/ceremony-runner-probe — the place runner-only facts are measured on demand, ruled as option A by the operator (#202).

  • The runbook states that the drill disposal rule does not apply to it. Archiving it defeats its purpose, and that is exactly how the three existing drill repos each became unavailable (#202).

  • It records that a probe must run as an Actions job under the workflow token: the same call answers 500 there and 204 under a PAT, so a probe run any other way produces a confident wrong answer (#202).

  • Creating the repo is recorded as the operator's step, measured rather than assumed: a fleet identity gets 403 on org repo creation and 201 in its own namespace (#202).