[{"data":1,"prerenderedAt":608},["ShallowReactive",2],{"navigation":3,"\u002Fdevelopment\u002Fsource-control":250,"\u002Fdevelopment\u002Fsource-control-surround":603},[4,28,56,91,117,135,169,224],{"title":5,"path":6,"stem":7,"children":8,"icon":27},"Start here","\u002Fgetting-started","1.getting-started\u002F1.index",[9,11,15,19,23],{"title":10,"path":6,"stem":7},"Introduction",{"title":12,"path":13,"stem":14},"Decisions and open gates","\u002Fgetting-started\u002Fdecisions","1.getting-started\u002F2.decisions",{"title":16,"path":17,"stem":18},"Scope and non-goals","\u002Fgetting-started\u002Fscope","1.getting-started\u002F3.scope",{"title":20,"path":21,"stem":22},"Organization pilot","\u002Fgetting-started\u002Fpilot","1.getting-started\u002F4.pilot",{"title":24,"path":25,"stem":26},"Economics and quotas","\u002Fgetting-started\u002Feconomics","1.getting-started\u002F5.economics","i-lucide-compass",{"title":29,"path":30,"stem":31,"children":32,"icon":55},"Architecture","\u002Farchitecture","2.architecture\u002F1.index",[33,35,39,43,47,51],{"title":34,"path":30,"stem":31},"System architecture",{"title":36,"path":37,"stem":38},"Trust zones","\u002Farchitecture\u002Ftrust-zones","2.architecture\u002F2.trust-zones",{"title":40,"path":41,"stem":42},"Control plane","\u002Farchitecture\u002Fcontrol-plane","2.architecture\u002F3.control-plane",{"title":44,"path":45,"stem":46},"Organization tenancy","\u002Farchitecture\u002Ftenancy","2.architecture\u002F4.tenancy",{"title":48,"path":49,"stem":50},"Core data model","\u002Farchitecture\u002Fdata-model","2.architecture\u002F5.data-model",{"title":52,"path":53,"stem":54},"Codebase organization","\u002Farchitecture\u002Fcodebase","2.architecture\u002F6.codebase","i-lucide-layers",{"title":57,"icon":58,"path":59,"stem":60,"children":61,"page":90},"Identity and security","i-lucide-shield-check","\u002Fsecurity","3.security",[62,66,70,74,78,82,86],{"title":63,"path":64,"stem":65},"Identity and sessions","\u002Fsecurity\u002Fidentity","3.security\u002F1.identity",{"title":67,"path":68,"stem":69},"Domains and TLS","\u002Fsecurity\u002Fdomains","3.security\u002F2.domains",{"title":71,"path":72,"stem":73},"Ingress and egress","\u002Fsecurity\u002Fnetworking","3.security\u002F3.networking",{"title":75,"path":76,"stem":77},"Access policies and WAF-lite","\u002Fsecurity\u002Faccess-policies","3.security\u002F4.access-policies",{"title":79,"path":80,"stem":81},"Secrets and integrations","\u002Fsecurity\u002Fsecrets-integrations","3.security\u002F5.secrets-integrations",{"title":83,"path":84,"stem":85},"Governance and ownership","\u002Fsecurity\u002Fgovernance","3.security\u002F6.governance",{"title":87,"path":88,"stem":89},"Threat model","\u002Fsecurity\u002Fthreat-model","3.security\u002F7.threat-model",false,{"title":92,"icon":93,"path":94,"stem":95,"children":96,"page":90},"Building applications","i-lucide-code","\u002Fdevelopment","4.development",[97,101,105,109,113],{"title":98,"path":99,"stem":100},"AI and MCP","\u002Fdevelopment\u002Fai-mcp","4.development\u002F1.ai-mcp",{"title":102,"path":103,"stem":104},"Source control","\u002Fdevelopment\u002Fsource-control","4.development\u002F2.source-control",{"title":106,"path":107,"stem":108},"Sandboxed builds","\u002Fdevelopment\u002Fbuilds","4.development\u002F3.builds",{"title":110,"path":111,"stem":112},"Runtime contract and SDK","\u002Fdevelopment\u002Fruntime-contract","4.development\u002F4.runtime-contract",{"title":114,"path":115,"stem":116},"APIs and protocols","\u002Fdevelopment\u002Fapi","4.development\u002F5.api",{"title":118,"icon":119,"path":120,"stem":121,"children":122,"page":90},"Runtime and delivery","i-lucide-rocket","\u002Fdelivery","5.delivery",[123,127,131],{"title":124,"path":125,"stem":126},"Runtime clusters and previews","\u002Fdelivery\u002Fruntime-clusters","5.delivery\u002F1.runtime-clusters",{"title":128,"path":129,"stem":130},"Deployments and approvals","\u002Fdelivery\u002Fdeployments","5.delivery\u002F2.deployments",{"title":132,"path":133,"stem":134},"Databases and recovery","\u002Fdelivery\u002Fdata-recovery","5.delivery\u002F3.data-recovery",{"title":136,"icon":137,"path":138,"stem":139,"children":140,"page":90},"Operations","i-lucide-activity","\u002Foperations","6.operations",[141,145,149,153,157,161,165],{"title":142,"path":143,"stem":144},"Observability and audit","\u002Foperations\u002Fobservability","6.operations\u002F1.observability",{"title":146,"path":147,"stem":148},"Operating model","\u002Foperations\u002Foperating-model","6.operations\u002F2.operating-model",{"title":150,"path":151,"stem":152},"Deploy and roll back","\u002Foperations\u002Fdeploy-rollback","6.operations\u002F3.deploy-rollback",{"title":154,"path":155,"stem":156},"Back up and restore","\u002Foperations\u002Fbackup-restore","6.operations\u002F4.backup-restore",{"title":158,"path":159,"stem":160},"Upgrade and patch","\u002Foperations\u002Fupgrades","6.operations\u002F5.upgrades",{"title":162,"path":163,"stem":164},"Rotate keys and credentials","\u002Foperations\u002Fkey-rotation","6.operations\u002F6.key-rotation",{"title":166,"path":167,"stem":168},"Incidents and access revocation","\u002Foperations\u002Fincidents","6.operations\u002F7.incidents",{"title":170,"path":171,"stem":172,"children":173,"icon":223},"Implementation plan","\u002Froadmap","7.roadmap\u002F01.index",[174,175,179,183,187,191,195,199,203,207,211,215,219],{"title":170,"path":171,"stem":172},{"title":176,"path":177,"stem":178},"Phase 0: architecture spikes and ADRs","\u002Froadmap\u002Fphase-0","7.roadmap\u002F02.phase-0",{"title":180,"path":181,"stem":182},"Phase 1: control-plane foundation","\u002Froadmap\u002Fphase-1","7.roadmap\u002F03.phase-1",{"title":184,"path":185,"stem":186},"Phase 2: managed source and change sets","\u002Froadmap\u002Fphase-2","7.roadmap\u002F04.phase-2",{"title":188,"path":189,"stem":190},"Phase 3: sandboxed build system","\u002Froadmap\u002Fphase-3","7.roadmap\u002F05.phase-3",{"title":192,"path":193,"stem":194},"Phase 4: runtime and data plane","\u002Froadmap\u002Fphase-4","7.roadmap\u002F06.phase-4",{"title":196,"path":197,"stem":198},"Phase 5: deployment, preview, migration, and recovery","\u002Froadmap\u002Fphase-5","7.roadmap\u002F07.phase-5",{"title":200,"path":201,"stem":202},"Phase 6: Entra identity and security policy","\u002Froadmap\u002Fphase-6","7.roadmap\u002F08.phase-6",{"title":204,"path":205,"stem":206},"Phase 7: MCP and AI-native workflow","\u002Froadmap\u002Fphase-7","7.roadmap\u002F09.phase-7",{"title":208,"path":209,"stem":210},"Phase 8: Pilot hardening","\u002Froadmap\u002Fphase-8","7.roadmap\u002F10.phase-8",{"title":212,"path":213,"stem":214},"Phase 9: developer hybrid and v1 GA","\u002Froadmap\u002Fphase-9","7.roadmap\u002F11.phase-9",{"title":216,"path":217,"stem":218},"Test strategy","\u002Froadmap\u002Ftesting","7.roadmap\u002F12.testing",{"title":220,"path":221,"stem":222},"Definition of done","\u002Froadmap\u002Fdefinition-of-done","7.roadmap\u002F13.definition-of-done","i-lucide-list-checks",{"title":225,"icon":226,"path":227,"stem":228,"children":229,"page":90},"Reference","i-lucide-book-open","\u002Freference","8.reference",[230,234,238,242,246],{"title":231,"path":232,"stem":233},"Plan coverage","\u002Freference\u002Fplan-coverage","8.reference\u002F1.plan-coverage",{"title":235,"path":236,"stem":237},"Decision register","\u002Freference\u002Fdecisions","8.reference\u002F2.decisions",{"title":239,"path":240,"stem":241},"Glossary","\u002Freference\u002Fglossary","8.reference\u002F3.glossary",{"title":243,"path":244,"stem":245},"Sources","\u002Freference\u002Fsources","8.reference\u002F4.sources",{"title":247,"path":248,"stem":249},"Contributing and docs access","\u002Freference\u002Fcontributing","8.reference\u002F5.contributing",{"id":251,"title":102,"body":252,"description":596,"extension":597,"links":598,"meta":599,"navigation":600,"path":103,"seo":601,"stem":104,"__hash__":602},"docs\u002F4.development\u002F2.source-control.md",{"type":253,"value":254,"toc":585},"minimark",[255,271,276,287,290,294,297,300,306,309,315,318,324,333,337,343,349,352,355,361,364,370,373,377,380,403,406,425,428,432,435,438,458,466,469,475,478,484,487,495,499,502,516,519,523,526,563,566,570,581],[256,257,258],"note",{},[259,260,261,265,266,270],"p",{},[262,263,264],"strong",{},"v1 design baseline."," This page specifies intended behavior. Delivery and validation are tracked in the ",[267,268,269],"a",{"href":171},"implementation plan","; it is not a claim that the platform is already implemented.",[272,273,275],"h2",{"id":274},"two-source-modes","Two source modes",[277,278,284],"pre",{"className":279,"code":281,"language":282,"meta":283},[280],"language-text","Managed Source\n└── Forgejo is canonical\n\nExternal Git\n└── External provider is canonical\n","text","",[285,286,281],"code",{"__ignoreMap":283},[259,288,289],{},"An application has exactly one writable source of truth at a time.",[272,291,293],{"id":292},"managed-source","Managed source",[259,295,296],{},"Managed applications are stored in hidden Forgejo repositories.",[259,298,299],{},"Mapping:",[277,301,304],{"className":302,"code":303,"language":282,"meta":283},[280],"intrnl organization\n└── Forgejo organization using opaque ID\n    ├── app_01K...\n    ├── app_01K...\n    └── app_01K...\n",[285,305,303],{"__ignoreMap":283},[259,307,308],{},"Users see:",[277,310,313],{"className":311,"code":312,"language":282,"meta":283},[280],"Version 12 — Added manager approval\nVersion 11 — Added department selection\nVersion 10 — Initial app\n",[285,314,312],{"__ignoreMap":283},[259,316,317],{},"They do not have to see:",[277,319,322],{"className":320,"code":321,"language":282,"meta":283},[280],"commit\nbranch\norigin\nrebase\nmerge\n",[285,323,321],{"__ignoreMap":283},[259,325,326,327],{},"Forgejo supports normal repository APIs, SSH\u002FHTTPS Git, webhooks, mirroring, and push-to-create. Push-to-create remains disabled for ordinary users by default and can later support controlled developer workflows. ",[267,328,332],{"href":329,"rel":330},"https:\u002F\u002Fforgejo.org\u002Fdocs\u002Flatest\u002Fuser\u002Fgetting-started\u002Ffirst-repository\u002F",[331],"nofollow","Forgejo repositories",[272,334,336],{"id":335},"branchchange-set-model","Branch\u002Fchange-set model",[277,338,341],{"className":339,"code":340,"language":282,"meta":283},[280],"main\nchange\u002Fchg_01K...\nchange\u002Fchg_01K...\n",[285,342,340],{"__ignoreMap":283},[259,344,345,348],{},[285,346,347],{},"main"," is protected. Only the intrnl control-plane service can advance it.",[259,350,351],{},"An AI or browser edit operates on a change-set branch.",[259,353,354],{},"A change set has:",[277,356,359],{"className":357,"code":358,"language":282,"meta":283},[280],"base revision\ncurrent revision\nhuman actor\nagent\u002Fclient\nstatus\nbuild\npreview\nrequested capabilities\nmigration analysis\n",[285,360,358],{"__ignoreMap":283},[259,362,363],{},"Suggested lifecycle:",[277,365,368],{"className":366,"code":367,"language":282,"meta":283},[280],"Draft\nBuilding\nBuild Failed\nReady for Preview\nDeployment Requested\nApproved\nMerged\nDeployed\nDiscarded\n",[285,369,367],{"__ignoreMap":283},[259,371,372],{},"When accepted, preserve full commit history with a controlled merge commit. Do not throw away audit-relevant intermediate history unless retention policy explicitly says otherwise.",[272,374,376],{"id":375},"direct-git-access","Direct Git access",[259,378,379],{},"Managed apps may later enable:",[277,381,385],{"className":382,"code":383,"language":384,"meta":283,"style":283},"language-bash shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","git clone git@code.intrnl.cloud:org_01K\u002Fapp_01K.git\n","bash",[285,386,387],{"__ignoreMap":283},[388,389,392,396,400],"span",{"class":390,"line":391},"line",1,[388,393,395],{"class":394},"sBMFI","git",[388,397,399],{"class":398},"sfazB"," clone",[388,401,402],{"class":398}," git@code.intrnl.cloud:org_01K\u002Fapp_01K.git\n",[259,404,405],{},"This is:",[407,408,409,413,416,419,422],"ul",{},[410,411,412],"li",{},"Disabled by default",[410,414,415],{},"Available only to Developer-role users",[410,417,418],{},"Scoped to specific repositories",[410,420,421],{},"Audited",[410,423,424],{},"Revoked through the organization identity lifecycle",[259,426,427],{},"The Forgejo web interface remains hidden unless a future developer product intentionally exposes it.",[272,429,431],{"id":430},"external-git","External Git",[259,433,434],{},"V1 GA supports GitHub through a GitHub App.",[259,436,437],{},"Use:",[407,439,440,443,446,449,452,455],{},[410,441,442],{},"Installation on selected repositories",[410,444,445],{},"Minimum repository permissions",[410,447,448],{},"Signed webhooks",[410,450,451],{},"Short-lived installation tokens",[410,453,454],{},"Exact commit SHA fetching",[410,456,457],{},"No personal access tokens",[259,459,460,461],{},"GitHub Apps can authenticate as an installation and be installed on selected repositories, which fits repository-scoped access better than broad personal credentials. ",[267,462,465],{"href":463,"rel":464},"https:\u002F\u002Fdocs.github.com\u002Fen\u002Fapps\u002Foverview",[331],"GitHub Apps overview",[259,467,468],{},"For an external repository:",[277,470,473],{"className":471,"code":472,"language":282,"meta":283},[280],"GitHub = canonical source\n\nGitHub push\u002Fwebhook\n        ↓\nverify webhook\n        ↓\nfetch exact SHA\n        ↓\ncreate immutable source revision\n        ↓\nbuild\n",[285,474,472],{"__ignoreMap":283},[259,476,477],{},"If AI editing is enabled:",[277,479,482],{"className":480,"code":481,"language":282,"meta":283},[280],"AI change\n   ↓\nintrnl creates branch\n   ↓\ncommits change\n   ↓\nopens pull request\n   ↓\nGitHub workflow remains authoritative\n",[285,483,481],{"__ignoreMap":283},[259,485,486],{},"intrnl does not independently modify an internal mirror and later attempt unrestricted two-way synchronization.",[259,488,489,490],{},"Forgejo mirroring can be useful for caching or archiving, but push mirrors can force-push and overwrite changes, reinforcing why two writable masters are prohibited. ",[267,491,494],{"href":492,"rel":493},"https:\u002F\u002Fforgejo.org\u002Fdocs\u002Flatest\u002Fuser\u002Frepo-mirror\u002F",[331],"Forgejo repository mirrors",[272,496,498],{"id":497},"source-cache","Source cache",[259,500,501],{},"For external repositories, intrnl may maintain a read-only bare cache or mirror for:",[407,503,504,507,510,513],{},[410,505,506],{},"Faster builds",[410,508,509],{},"Resilience",[410,511,512],{},"Immutable revision retrieval",[410,514,515],{},"Audit preservation",[259,517,518],{},"The external repository remains canonical.",[272,520,522],{"id":521},"managed-to-external-transfer","Managed-to-external transfer",[259,524,525],{},"A production-worthy citizen-developed app can be transferred to engineering:",[527,528,529,532,535,538,541,544,547,550,557,560],"ol",{},[410,530,531],{},"Freeze managed-source writes.",[410,533,534],{},"Export the complete Git history.",[410,536,537],{},"Create or select the external repository.",[410,539,540],{},"Push history.",[410,542,543],{},"Install and validate the GitHub App.",[410,545,546],{},"Verify webhook delivery.",[410,548,549],{},"Record the external canonical repository.",[410,551,552,553,556],{},"Switch ",[285,554,555],{},"source_mode",".",[410,558,559],{},"Unfreeze operations.",[410,561,562],{},"Audit the cutover.",[259,564,565],{},"Thereafter, AI edits must become external branches\u002FPRs.",[272,567,569],{"id":568},"related-documentation","Related documentation",[407,571,572,576],{},[410,573,574],{},[267,575,106],{"href":107},[410,577,578],{},[267,579,580],{"href":213},"Developer GA phase",[582,583,584],"style",{},"html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":283,"searchDepth":391,"depth":586,"links":587},2,[588,589,590,591,592,593,594,595],{"id":274,"depth":586,"text":275},{"id":292,"depth":586,"text":293},{"id":335,"depth":586,"text":336},{"id":375,"depth":586,"text":376},{"id":430,"depth":586,"text":431},{"id":497,"depth":586,"text":498},{"id":521,"depth":586,"text":522},{"id":568,"depth":586,"text":569},"Managed Forgejo repositories, change sets, GitHub canonical mode, and full-history transfer.","md",null,{},true,{"title":102,"description":596},"626izB6bxqQi-qROobPv5AaHr0p9PY_AitbMdK7BCIM",[604,606],{"title":98,"path":99,"stem":100,"description":605,"children":-1},"Scoped human grants, approved AI clients, reviewable change sets, and server-enforced authorization.",{"title":106,"path":107,"stem":108,"description":607,"children":-1},"Immutable build inputs, dependency policy, disposable execution, and signed artifact provenance.",1790019415367]