The role-template registry moves out of rig's tree (heavy-duty/rig-templates, ruled 2026-07-24: pinned to the rig version by default, overridable per mint). This is the schema-and-resolution half rig keeps: RIG_TEMPLATES_DIR > RIG_TEMPLATES_REF > the in-tree RIG_TEMPLATES_PIN (the BOX_RELEASE discipline), template.env parsed against an allowlist and never sourced, every refusal naming the failing key, and the lint the registry repo's CI will run on every definition. The pin currently names the registry's pre-seed head; it bumps to the seeded tree in this PR's course (the seed PR is the other half of the build task). |
||
|---|---|---|
| .. | ||
| manifest.sh | ||
| runner-config.sh | ||
| sshd.sh | ||
| templates.sh | ||
| tenant-config.sh | ||
| users-config.sh | ||