Rendered from docs/ops/needs.md, which is the source of truth and the markdown twin of this page. Rendered at site v0.1.2.
What only a human can do
secrets.sgit.ai · operations · maintained by the build session · last updated at v0.1.1 (2026-10-05) · CC BY 4.0
Everything on this list blocks a step of the brief and cannot be done from inside the repository. Each item says who, what, exactly, and which step waits on it. Items are removed when done and the removal is dated in docs/design/brief-corrections.md if anything turned out differently from the brief.
Done
- 2026-10-05, v0.1.0. DNS
secrets CNAME sgit-ai.github.io, GitHub Pages enabled with the custom domain and HTTPS, and the v0.1.0 workflow run re-run by Dinis.verify-livepassed;https://secrets.sgit.aiserves the released version. Nothing about the process turned out differently from the brief.
Blocking the protections (section 9.5), to be in place before step 3 lands real configuration
- Branch protection (organisation owner). Apply the rules in
docs/ops/branch-protection.mdtodevandmain, withvalidateas the required status check. - Organisation 2FA with hardware keys (organisation owner). Settings, Authentication security.
- Verified domain (organisation owner). Add and verify
sgit.aiunder Settings, Verified and approved domains. - Actions policy (organisation owner). Allow only GitHub-authored and organisation-authored actions; default
GITHUB_TOKENread-only; Actions may not create or approve pull requests.
Blocking step 3 (the dev GCP project)
- Billing account (GCP billing admin). A billing account the three projects can attach to. The build session will write
infra/bootstrap/bootstrap.shin step 3 and needs its id passed as a variable, never committed. - Project ids (GCP org admin). Confirm
sgit-secrets-tfstate,sgit-secrets-dev,sgit-secrets-main,sgit-secrets-prodare available, or choose others; the brief marks them PROPOSED. - Run the bootstrap (a human with org-level IAM). Once
infra/bootstrap/bootstrap.shexists: run it with--dry-run, then for real. It prints the values for the GitHub environment variables (WORKLOAD_IDENTITY_PROVIDER,SERVICE_ACCOUNT) per environment. - Google OAuth client secret for sign-in (GCP project owner). Create the Web application OAuth client in the
devproject (originhttps://secrets.sgit.ai, redirecthttps://<authDomain>/__/auth/handler) and store its secret as the GitHub environment secretGOOGLE_OAUTH_CLIENT_SECRETin thedevenvironment. It never enters the repository.
Not yet needed
mainandprodprojects, their OAuth clients and their environment secrets: step 7 and step 8.- A reviewer for the
prodenvironment: step 8. - The DNS guards (registrar lock, DNSSEC, CAA): listed on
/security/when it exists, with dates; not blocking.