Implementation status
docs/status/ledger.json is the sole mutable authority for current implementation
status. Specs and ADRs define obligations. Handoffs are immutable evidence.
| ID | Kind | Status | Current state | Evidence |
|---|---|---|---|---|
CAP-RUNTIME-STORAGE | capability | implemented | Single multicall binary, SQLite and PostgreSQL stores, migrations, and CI | #42 handoff |
CAP-SECURITY-FOUNDATIONS | capability | implemented | Envelope encryption, authorization chokepoint, append-only audit trails, and gap-free PostgreSQL audit export | #43 handoff, #44 handoff, #45 handoff, #84 handoff |
CAP-CORE-API-CLI | capability | implemented | Bootstrap administration, local login, hierarchy CRUD, key declarations, validation, encrypted values, copy, clone, and bulk apply | #47 handoff, #48 handoff, #49 handoff, #50 handoff |
CAP-HUMAN-ACCESS | capability | implemented | OIDC, WebAuthn, TOTP, recovery, sessions, grants, role templates, protected environments, and member invitation at org and instance scope from API, CLI and WebUI with browser credential establishment and recovery-code sign-in | #54 handoff, #55 handoff, #568 handoff |
CAP-MATRIX-DISCLOSURE | capability | implemented | Embedded app shell, environment matrix, row editor, problems filter, reveal/copy ceremonies, protected publish flows, key declaration from the matrix, catalogue declaration detail and editing, and key rename/reclassify/delete | #56 handoff, #57 handoff, #58 handoff, #491 handoff, #494 handoff, #492 PR, #493 PR |
CAP-MACHINE-ACCESS | capability | implemented | Service accounts with browser create/delete, display-once credentials, OIDC workload federation with browser issuer and binding administration, receiving-side connection credentials, and machine-access UI | #61 handoff, #62 handoff, #67 handoff, #464 PR, #497 PR, #498 PR |
CAP-MULTI-INSTANCE | capability | implemented | Directory-tier remotes and browser-direct workspace sessions | #71 handoff |
CAP-ENTERPRISE-IDENTITY | capability | implemented | SAML service-provider support and SCIM provisioning, fully open-source | SAML contract, #73 handoff |
CAP-BACKUP-RESTORE | capability | implemented | Encrypted export/restore plus the cross-engine recovery drill | #76 handoff |
CAP-REVISION-LIFECYCLE | capability | implemented | Drafts, snapshots, selective publish, rollback, durable pins, retention, GC, and history restore/pin lifecycle | #51 handoff, #52 handoff, #53 handoff, #59 handoff |
CAP-ADMINISTRATION-UI | capability | implemented | Members at organisation, project and instance scope, organisation/project/instance settings, account security, browser step-up, OIDC/SAML/SCIM provider administration, organisation, project and environment audit query and export, and remote cryptographic maintenance | #60 handoff, #567 handoff, #500 handoff, #499 PR, #501 PR, #502 PR, #503 PR |
CAP-IMPORTS-ONBOARDING | capability | implemented | Kubernetes, SOPS, and Infisical file imports; live Kubernetes and Vault/OpenBao connectors; import wizard; dotenv scaffolding; browser imports of .env, Kubernetes, Infisical, and Vault/OpenBao sources | #68 handoff, #69 handoff, #112 handoff, #496 handoff, #495 PR |
CAP-DELIVERY | capability | implemented | Compose delivery and hikyo run, Kubernetes operator/CRDs, Forgejo and GitHub Actions adapters with multi-target synchronization and a browser-operated adapter lifecycle, and machine-reveal opt-in | #63 handoff, #64 handoff, #65 handoff, #66 handoff, #157 handoff, #504 handoff |
CAP-KEY-ROTATION | capability | implemented | Root, master, DEK, token, and scanning-key rotation plus resumable re-encryption | #75 handoff |
CAP-SECRET-SCANNING | capability | implemented | Surface-1 warnings and Surface-2 blocks on every CLI/API value ingress | #74 handoff |
CAP-PRODUCTION-OPS | capability | partial | All registered operational bounds, doctor, upgrade path, no-egress posture, and pinned operator resource limits Remaining: Record an arm64 cgroup run proving operator reconciliation within the 128 MiB limit under load | operations contract, bound registry, #76 handoff |
CAP-SUPPLY-CHAIN-SITE | capability | implemented | Signed release pipeline, SBOMs, documentation/governance site, matching icons, and offline-capable PWA | #46 handoff, #78 handoff |
CAP-PUBLIC-RELEASE | capability | partial | Cosign trust, SBOM generation, GoReleaser/Helm packaging, and installer verification Remaining: Run full acceptance, freeze API/CLI, and publish 1.0 under #79 | #46 handoff, 1.0 blockers |
CAP-BROWSER-SCANNING | capability | implemented | Surface-1 warn dialog on matrix editing and the Surface-2 block dialog on the declaration editor | #74 handoff, #183 handoff |
CAP-WEBUI-PARITY | capability | implemented | Executable parity registry over every public operation with closed exception classes, browser-only lifecycle acceptance from an empty organisation to Kubernetes-ready delivery, recovery-code sign-in, project and environment audit, browser administration of identity providers, adapters, and remote crypto, and dynamic-secret provider and lease management | parity registry, #490 handoff, #504 handoff, #595 handoff |
OBL-SCAN-PERFORMANCE | obligation | implemented | Committed Pi-class artifact gates scan latency, compile time, and scanner boot memory. | benchmark artifact, #74 handoff |
OBL-OPERATOR-PI-FIT | obligation | open | Arm64 cgroup evidence for reconciliation within the 128 MiB operator limit is still required. | operator limits, #64 handoff |
OBL-IMPORT-FIXTURES | obligation | implemented | Adversarial connector fixtures, provider-error sanitization, exporter floor, and canonical JSON serialization are executable tests. | connector fixtures, #68 handoff |
OBL-ADAPTER-FIXTURES | obligation | implemented | Forgejo/GitHub contract tests cover conflict behavior, sealed-box delivery, and representation refusals. | GitHub contract, #65 handoff, #66 handoff |
OBL-CI-ACTION-PINS | obligation | implemented | CI and release workflows carry immutable action pins and executable verification. | CI workflow, #46 handoff |
OBL-CLI-GOLDENS | obligation | implemented | CLI output and scenario contracts are checked against committed golden fixtures. | CLI goldens, walking-skeleton handoff |
OBL-REPOSITORY-TRANSFER | obligation | implemented | Canonical repository and organization controls are hosted under Hikyo-Org. | transfer handoff |
OBL-UI-SCHEMA-POLISH | obligation | open | Dialog-level visual refinement remains available within the frozen UI contract. | UI contract, 1.0 blocker handoff |
OBL-OPS-SUPERSESSION | obligation | open | Editorial consolidation remains optional when ops-spec is next reissued. | operations contract |
OBL-DOCS-SITE | obligation | implemented | Canonical Starlight documentation and O4-O6 governance artifacts are built and verified. | #78 handoff |
OBL-OPS-ROW-NUMBERING | obligation | open | Editorial row renumbering remains for the next ops-spec amendment. | ops catalogue |
OBL-ACCEPTED-RESIDUALS | obligation | accepted | Named residual risks stay governed by their owning ADRs and reopen triggers. | operations contract |