diff --git a/documentation-metadata.json b/documentation-metadata.json index 891dea8..8035142 100644 --- a/documentation-metadata.json +++ b/documentation-metadata.json @@ -53,6 +53,66 @@ "helm-charts": "78b680595d4beda3184124312d61d86ce0cc51e7", "lifecycle-opentofu": "b14865912608096379c28ef648f7ed99538b5600" } + }, + "2026-09-14-sites-pending-release": { + "verifiedOn": "2026-09-14", + "sources": { + "lifecycle": "3e313fae532c4997c595e676e551a4f590dcc691", + "lifecycle-ui": "ab98c292aa2155ca0a08e62d6a9823507feeecd6", + "lifecycle-cli": "14552f966cc0eff3e4bb067a1f072f2d0b9dd57a", + "helm-charts": "992cfe38aa1175ea2acef517932a38f9dd974fef" + }, + "notes": "These commits identify baseline checkouts only. Sites access-control behavior was reviewed in uncommitted working trees and is pending release. Replace this baseline with implementing commit revisions before publication." + }, + "2026-09-21-sites-downgrade-pending-release": { + "verifiedOn": "2026-09-21", + "sources": { + "lifecycle": "5a95f69995272b9dec92c8a3c067458be46a65d4", + "lifecycle-ui": "a8d65d351d68ca7466d4368d9eb4018bd46621aa", + "lifecycle-cli": "6814da76083fa989ffcc967e433b931d40f1dd7f", + "helm-charts": "0b5a50890635c7941984aaff622cc6e4fe79d1c1" + }, + "notes": "Sites V1 remains pending release. The core migration supports an intentional full downgrade that preserves Site rows and versions but publishes content through the older gateway and discards ACL metadata. An isolated PostgreSQL up/down/up test passed." + }, + "2026-09-21-sites-ui-filter-pending-release": { + "verifiedOn": "2026-09-21", + "sources": { + "lifecycle": "4343694b08c158832f6fd269b81d848bcdaf9077", + "lifecycle-ui": "a8d65d351d68ca7466d4368d9eb4018bd46621aa", + "lifecycle-cli": "6814da76083fa989ffcc967e433b931d40f1dd7f", + "helm-charts": "0b5a50890635c7941984aaff622cc6e4fe79d1c1" + }, + "notes": "Sites V1 behavior remains pending release. The UI offers My sites and Public list views; the API also supports view=all for other clients." + }, + "2026-09-15-sites-rollout-pending-release": { + "verifiedOn": "2026-09-15", + "sources": { + "lifecycle": "d2af3d1f651dcfb1e38b38619ebfd89ab2760012", + "lifecycle-ui": "b925d650870109859deca23e218f298e349b2879", + "lifecycle-cli": "6814da76083fa989ffcc967e433b931d40f1dd7f", + "helm-charts": "4acd7917c4f19f4f0d8420af3f62e5db43438e3f" + }, + "notes": "Sites access-control behavior was verified against these implementing commits and remains pending release. User JWTs authorize Site-only browser access, capped at five minutes and JWT expiry. Private reads check current Site state. Ordinary UI logout does not immediately revoke issued access. These checks do not establish a supported released version set or production rollout." + }, + "2026-09-22-sites-stable-url-pending-release": { + "verifiedOn": "2026-09-22", + "sources": { + "lifecycle": "0af126b06788110e5db4762b9b7fe4d7491de8e1", + "lifecycle-ui": "eb73479ddc0543bf133a9d8146334e94641ae88e", + "lifecycle-cli": "8dab9f14b45673703f3244ae220919042f0805bd", + "helm-charts": "0b5a50890635c7941984aaff622cc6e4fe79d1c1" + }, + "notes": "Sites V1 remains pending release. Verified stable Site ID and content URL on visibility changes, server owner checks, the temporary same-apex opt-in, and the intentional full downgrade. Live browser retest of private open remains pending." + }, + "2026-09-22-sites-access-control-released": { + "verifiedOn": "2026-09-22", + "sources": { + "lifecycle": "e50c29f7659fc14dc98f061e0c8fa57b40b788c0", + "lifecycle-ui": "917d8a8936b6054ae9fc102571a5b9c808a0bcb7", + "lifecycle-cli": "a08d9c2d0abb79ab7941c12d6ead1783a70ea45f", + "helm-charts": "6aff91c22411e641964774bcbb09e5265ac1250c" + }, + "notes": "All four Sites access-control implementing PRs merged to main and deployed to production. Live-verified end to end: owner-only private access, distinct denied-vs-missing responses on the management API, the CLI's visibility/create/list/get/update/extend/delete commands, the shared-apex opt-in, stable Site ID and content URL across visibility and content changes, and the intentional full downgrade path." } } } diff --git a/documentation-style-baseline.json b/documentation-style-baseline.json index efe69eb..95c3247 100644 --- a/documentation-style-baseline.json +++ b/documentation-style-baseline.json @@ -1,6 +1,6 @@ { "schemaVersion": 3, - "updatedOn": "2026-08-01", + "updatedOn": "2026-09-23", "references": { "canonical": "ASD-STE100 Issue 9", "canonicalRules": [ @@ -69,8 +69,8 @@ "/docs/api-authentication/api-keys": { "file": "src/pages/docs/api-authentication/api-keys.mdx", "profile": "asd-ste100", - "reviewedOn": "2026-07-25", - "sha256": "abccff28a910388f751789b3cd1ba7aba1ef81fc98e31ba66379427332eb6257" + "reviewedOn": "2026-09-23", + "sha256": "6ab98c32c5f8ebf35d609cdb62d6d67820fbaa6cc9ece818537948ab86eb4aa6" }, "/docs/api-authentication/overview": { "file": "src/pages/docs/api-authentication/overview.mdx", @@ -135,8 +135,8 @@ "/docs/features/cli": { "file": "src/pages/docs/features/cli.mdx", "profile": "asd-ste100", - "reviewedOn": "2026-08-01", - "sha256": "88a35c2ebf6bb6ac52874de2df6edd96b99dab582e6e3de3414226d12cbe5c7c" + "reviewedOn": "2026-09-22", + "sha256": "0f57d131ad05effbf05847828dd7f30d8b5641c5ecde54af181c3aec6821e15b" }, "/docs/features/cli-telemetry": { "file": "src/pages/docs/features/cli-telemetry.mdx", @@ -177,8 +177,8 @@ "/docs/features/mcp-server": { "file": "src/pages/docs/features/mcp-server.mdx", "profile": "asd-ste100", - "reviewedOn": "2026-08-01", - "sha256": "69ab72bfb6486d0189fc903d4a3d8e170c578be252d39335b7bea8e7c8b0da36" + "reviewedOn": "2026-09-22", + "sha256": "70ab60a321461fb609365c7184ad40fd7450e1ae68271748681b87be80d7e699" }, "/docs/features/native-helm-deployment": { "file": "src/pages/docs/features/native-helm-deployment.mdx", @@ -201,8 +201,8 @@ "/docs/features/sites": { "file": "src/pages/docs/features/sites.mdx", "profile": "asd-ste100", - "reviewedOn": "2026-07-25", - "sha256": "598f40560777f7d3f2074137ba9b2a102ceb4f61946fc05bc74f3a85d64d6bca" + "reviewedOn": "2026-09-23", + "sha256": "7a1bbdb4b545c7fcba428fc4f4eaa336ee6f556916ee4cb9f2371203cdfaf1e8" }, "/docs/features/template-variables": { "file": "src/pages/docs/features/template-variables.mdx", @@ -273,8 +273,8 @@ "/docs/operations/configuration": { "file": "src/pages/docs/operations/configuration.mdx", "profile": "asd-ste100", - "reviewedOn": "2026-08-01", - "sha256": "dcf78161c9d44e74638153de0f0b074361ba9ac6a8878a41338d35716860d755" + "reviewedOn": "2026-09-22", + "sha256": "fd1c2f4537187df8dfced9799dec480e5754c6ba519f548d244f65f66666717f" }, "/docs/operations/day-two": { "file": "src/pages/docs/operations/day-two.mdx", @@ -291,8 +291,8 @@ "/docs/operations/security": { "file": "src/pages/docs/operations/security.mdx", "profile": "asd-ste100", - "reviewedOn": "2026-07-25", - "sha256": "892aafebdd33b0c39b51f5c8ae6817e067679e3797d02eaaceee949b6ce13365" + "reviewedOn": "2026-09-23", + "sha256": "0d56688220d7f4a802d79f085237ae6f8b9d57ec5e7566bc3e650ac401583b4d" }, "/docs/reference/statuses": { "file": "src/pages/docs/reference/statuses.mdx", @@ -309,7 +309,7 @@ "/docs/releases/compatibility": { "file": "src/pages/docs/releases/compatibility.mdx", "profile": "asd-ste100", - "reviewedOn": "2026-07-25", + "reviewedOn": "2026-09-23", "sha256": "1901b9d61ca33af98a41c41382624e7c07607c6cbaffb112e71718c3e17bbb1f" }, "/docs/schema/aurora-restore": { @@ -387,7 +387,7 @@ "/docs/setup/install-lifecycle": { "file": "src/pages/docs/setup/install-lifecycle.mdx", "profile": "asd-ste100", - "reviewedOn": "2026-07-25", + "reviewedOn": "2026-09-23", "sha256": "675a15ac05fef8f53b5cd2e177eb24b1fac1f745e5189ae6d8fc3133d9580a0c" }, "/docs/setup/prerequisites": { diff --git a/public/llms.txt b/public/llms.txt index a54e48a..f8fb8f8 100644 --- a/public/llms.txt +++ b/public/llms.txt @@ -32,22 +32,22 @@ This index is generated from the human documentation. Follow the linked page for - [Cloud secrets](https://uselifecycle.com/docs/features/secrets.md): Reference External Secrets Operator values from Lifecycle Services and native Helm deployments. _(audience: application-developer, platform-operator; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ - [Environment expiration and cleanup](https://uselifecycle.com/docs/features/environment-ttl.md): Understand how Lifecycle cleans up pull-request environments and expires API-created environments. _(audience: application-developer, platform-operator, administrator; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ - [API-created Environments](https://uselifecycle.com/docs/features/api-environments.md): Create branch-based Lifecycle Environments without a pull request. Then, track, extend, redeploy, or tear them down. _(audience: api-user, application-developer; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ -- [Sites](https://uselifecycle.com/docs/features/sites.md): Upload and manage static HTML sites through Lifecycle's UI, CLI, or authenticated v2 API. _(audience: application-developer, platform-operator; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ +- [Sites](https://uselifecycle.com/docs/features/sites.md): Upload and manage static HTML sites through Lifecycle's UI, CLI, or authenticated v2 API. _(audience: application-developer, platform-operator; last verified: 2026-09-23; baseline: 2026-09-22-sites-access-control-released)_ - [Lifecycle Agent](https://uselifecycle.com/docs/features/ai-agent.md): Investigate a Lifecycle Environment, examine evidence, and do approved recovery tasks from the Environment details page. _(audience: agent-user; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ - [Configure Lifecycle Agent](https://uselifecycle.com/docs/features/ai-agent-configuration.md): Configure models, instructions, tools, approvals, and repository overrides for Lifecycle Agent from Settings. _(audience: administrator; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ - [Agent Sessions](https://uselifecycle.com/docs/features/agent-sessions.md): Start, examine, and continue repository work with Lifecycle Agent in an isolated workspace. _(audience: agent-user; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ - [Agent administration](https://uselifecycle.com/docs/features/agent-administration.md): Administer Lifecycle Agent availability, models, instructions, permissions, tools, workspaces, and session audit. _(audience: administrator; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ - [Agent workspace backends](https://uselifecycle.com/docs/features/workspace-backends.md): Compare and safely activate the runtime backend used for new Lifecycle Agent workspaces. _(audience: administrator; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ - [Connect external MCP servers](https://uselifecycle.com/docs/features/mcp-integration.md): Add administrator-approved Model Context Protocol servers and complete authentication for each Lifecycle Agent user. _(audience: agent-user, administrator; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ -- [Lifecycle MCP](https://uselifecycle.com/docs/features/mcp-server.md): Enable Lifecycle MCP, connect an OAuth client, and use Lifecycle tools with existing user permissions. _(audience: agent-user, administrator, platform-operator; last verified: 2026-08-01; baseline: 2026-08-01-lifecycle-mcp-preparation)_ -- [CLI (lfc)](https://uselifecycle.com/docs/features/cli.md): Install and use the Lifecycle CLI to examine Environments, manage Services, stream logs, and validate configuration. _(audience: application-developer, platform-operator; last verified: 2026-08-01; baseline: 2026-08-01-configuration-schema-fix)_ +- [Lifecycle MCP](https://uselifecycle.com/docs/features/mcp-server.md): Enable Lifecycle MCP, connect an OAuth client, and use Lifecycle tools with existing user permissions. _(audience: agent-user, administrator, platform-operator; last verified: 2026-09-22; baseline: 2026-09-22-sites-access-control-released)_ +- [CLI (lfc)](https://uselifecycle.com/docs/features/cli.md): Install and use the Lifecycle CLI to examine Environments, manage Services, stream logs, and validate configuration. _(audience: application-developer, platform-operator; last verified: 2026-09-22; baseline: 2026-09-22-sites-access-control-released)_ - [Lifecycle CLI telemetry](https://uselifecycle.com/docs/features/cli-telemetry.md): Understand the pseudonymous command-usage event sent by lfc, its destination, and how to opt out. _(audience: application-developer, platform-operator; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ - [Use the Lifecycle UI](https://uselifecycle.com/docs/features/lifecycle-ui.md): Use the web UI to find Environments, examine Services and logs, run actions, and examine webhooks. _(audience: application-developer, platform-operator; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ ## API authentication - [API authentication](https://uselifecycle.com/docs/api-authentication/overview.md): Select a supported authentication method for Lifecycle v2 API requests and understand typical authorization failures. _(audience: api-user, administrator; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ -- [API keys](https://uselifecycle.com/docs/api-authentication/api-keys.md): Create, scope, use, rotate, and revoke personal or service API keys for authenticated Lifecycle v2 requests. _(audience: api-user, administrator; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ +- [API keys](https://uselifecycle.com/docs/api-authentication/api-keys.md): Create, scope, use, rotate, and revoke personal or service API keys for authenticated Lifecycle v2 requests. _(audience: api-user, administrator; last verified: 2026-09-23; baseline: 2026-09-22-sites-access-control-released)_ ## HTTP API @@ -74,22 +74,22 @@ This index is generated from the human documentation. Follow the linked page for - [Starter infrastructure prerequisites](https://uselifecycle.com/docs/setup/prerequisites.md): Prepare cloud, DNS, domain, and command-line access for the starter OpenTofu evaluation path. _(audience: evaluator, platform-operator; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ - [Set up an evaluation cluster](https://uselifecycle.com/docs/setup/setup-infra.md): Provision starter GKE or EKS infrastructure, DNS, dependencies, and Lifecycle for evaluation. _(audience: evaluator, platform-operator; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ -- [Install Lifecycle](https://uselifecycle.com/docs/setup/install-lifecycle.md): Select the OpenTofu-managed or standalone Helm installation path. Make sure that the API, UI, identity, and cluster are healthy. _(audience: evaluator, platform-operator; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ +- [Install Lifecycle](https://uselifecycle.com/docs/setup/install-lifecycle.md): Select the OpenTofu-managed or standalone Helm installation path. Make sure that the API, UI, identity, and cluster are healthy. _(audience: evaluator, platform-operator; last verified: 2026-09-23; baseline: 2026-09-22-sites-access-control-released)_ - [Create the GitHub App](https://uselifecycle.com/docs/setup/create-github-app.md): Create and connect a private GitHub App for Lifecycle. _(audience: platform-operator; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ - [Optional configuration](https://uselifecycle.com/docs/setup/configure-lifecycle.md): Apply optional installation-wide settings safely after Lifecycle is running. _(audience: platform-operator; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ ## Operations - [Lifecycle architecture](https://uselifecycle.com/docs/operations/architecture.md): Understand how requests become Lifecycle Environments and plan dependencies, security controls, availability, and recovery. _(audience: evaluator, platform-operator; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ -- [Runtime configuration surfaces](https://uselifecycle.com/docs/operations/configuration.md): Select a supported UI, API, Helm, or repository configuration surface and verify each change. _(audience: platform-operator, administrator; last verified: 2026-08-01; baseline: 2026-08-01-lifecycle-mcp-preparation)_ -- [Security boundaries](https://uselifecycle.com/docs/operations/security.md): Understand Lifecycle authentication, network, Kubernetes, secret, and Agent boundaries before other networks can reach a deployment. _(audience: platform-operator; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ +- [Runtime configuration surfaces](https://uselifecycle.com/docs/operations/configuration.md): Select a supported UI, API, Helm, or repository configuration surface and verify each change. _(audience: platform-operator, administrator; last verified: 2026-09-22; baseline: 2026-09-22-sites-access-control-released)_ +- [Security boundaries](https://uselifecycle.com/docs/operations/security.md): Understand Lifecycle authentication, network, Kubernetes, secret, and Agent boundaries before other networks can reach a deployment. _(audience: platform-operator; last verified: 2026-09-23; baseline: 2026-09-22-sites-access-control-released)_ - [Monitor Lifecycle](https://uselifecycle.com/docs/operations/monitoring.md): Interpret health endpoints, verify end-to-end operation, and collect safe diagnostic data for stuck work. _(audience: platform-operator; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ - [Day-two operations](https://uselifecycle.com/docs/operations/day-two.md): Plan Lifecycle upgrades, backups, rollback decisions, recovery validation, and uninstall. _(audience: platform-operator; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ ## Releases and compatibility - [Releases](https://uselifecycle.com/docs/releases.md): Find your installed Lifecycle versions and the release information for an upgrade. _(audience: platform-operator, application-developer; last verified: 2026-08-01; baseline: 2026-08-01-adopt-lifecycle-mcp-browser-validation)_ -- [Compatibility and deprecation policy](https://uselifecycle.com/docs/releases/compatibility.md): Select compatible Lifecycle components and prepare a safe upgrade or rollback. _(audience: platform-operator, application-developer; last verified: 2026-07-24; baseline: 2026-07-24-comprehensive-audit)_ +- [Compatibility and deprecation policy](https://uselifecycle.com/docs/releases/compatibility.md): Select compatible Lifecycle components and prepare a safe upgrade or rollback. _(audience: platform-operator, application-developer; last verified: 2026-09-23; baseline: 2026-09-22-sites-access-control-released)_ ## Troubleshooting diff --git a/src/pages/docs/api-authentication/api-keys.mdx b/src/pages/docs/api-authentication/api-keys.mdx index 0f0a4aa..66c9d1c 100644 --- a/src/pages/docs/api-authentication/api-keys.mdx +++ b/src/pages/docs/api-authentication/api-keys.mdx @@ -4,8 +4,8 @@ description: Create, scope, use, rotate, and revoke personal or service API keys audience: - api-user - administrator -lastVerified: "2026-07-24" -verificationBaseline: "2026-07-24-comprehensive-audit" +lastVerified: "2026-09-23" +verificationBaseline: "2026-09-22-sites-access-control-released" contentProfile: asd-ste100 tags: - api @@ -54,15 +54,15 @@ creation. Lifecycle recognizes seven scopes: -| Scope | Access | -| ------------- | ------------------------------------------------------------------- | -| `env:read` | Read Environments and Builds | -| `env:write` | Create or change Environments and Builds. Also satisfies `env:read` | -| `sites:read` | Read sites. `sites:write` satisfies this scope. | -| `sites:write` | Upload, replace, extend, or delete sites | -| `repos:read` | Read repository information. `repos:write` satisfies this scope. | -| `repos:write` | Change supported repository configuration | -| `env:admin` | Legacy/reserved Environment administration | +| Scope | Access | +| ------------- | -------------------------------------------------------------------- | +| `env:read` | Read Environments and Builds | +| `env:write` | Create or change Environments and Builds. Also satisfies `env:read`. | +| `sites:read` | Read sites. `sites:write` satisfies this scope. | +| `sites:write` | Upload, replace, extend, or delete sites | +| `repos:read` | Read repository information. `repos:write` satisfies this scope. | +| `repos:write` | Change supported repository configuration | +| `env:admin` | Legacy/reserved Environment administration | New keys can request only the first six scopes. A legacy service key can keep `env:admin`. You cannot grant this scope to a new key. @@ -76,6 +76,28 @@ grant `sites:read`. repositories. +## Sites access with API keys + +`sites:read` permits public reads and reads of sites owned by the caller. +`sites:write` also permits creation and changes to owned sites, including visibility changes. +Scopes do not grant access to another user's private site. +Administrator status does not override ownership. + +A personal key uses its user's ownership and defaults to private uploads. +An older personal key without an identity binding cannot access Sites. +Create a replacement personal key through your signed-in account. + +Service keys create public sites only. +Each service key owns only the sites created with that exact key. +A replacement service key does not inherit site ownership. +Before you retire a service key that owns sites, contact your platform operator. +Revoked or expired keys cannot manage their sites. +For sites with retired keys, see [Sites troubleshooting](/docs/features/sites#troubleshooting). + +Keep API keys in authorization headers. +Do not put API keys in site content or URLs. +For request details, see [Sites](/docs/features/sites#api-access). + ## Select an expiration The personal-key policy defaults to a 168-hour (7-day) selection and caps finite diff --git a/src/pages/docs/features/cli.mdx b/src/pages/docs/features/cli.mdx index 40a6f38..1def2b0 100644 --- a/src/pages/docs/features/cli.mdx +++ b/src/pages/docs/features/cli.mdx @@ -4,8 +4,8 @@ description: Install and use the Lifecycle CLI to examine Environments, manage S audience: - application-developer - platform-operator -lastVerified: "2026-08-01" -verificationBaseline: "2026-08-01-configuration-schema-fix" +lastVerified: "2026-09-22" +verificationBaseline: "2026-09-22-sites-access-control-released" contentProfile: asd-ste100 tags: - cli @@ -222,15 +222,27 @@ each field. Exit code `3` means that the CLI did not find a configuration file. ### Static sites +User uploads default to private. +Public uploads require confirmation when you specify `--visibility public`. +Only the owner can change a site. +`--mine` selects ownership, and `--public` selects public sites. +These filters cannot be combined. + ```sh -lfc sites create [--name