Skip to content

platform-admin re-anchor L8 (cloud seam): control-plane env injection + invite-only interaction — cloud seat leg, designed blind #11977

Description

@os-support-ai

Leg L8 of the accepted #11663 platform-admin re-anchor design — a seam card: the fix lands in the cloud repo, which is not reachable from the filing session, so per the cross-repo rule it lives here with repo:cloud. Named reader: the cloud execution seat, at its queue-scan step — this card is its instruction to open the cloud-side issue and link it back here. Provenance: design document = #11663 comment 5394453215 (§6 row L8, §9 NOT MEASURED disclosure); maintainer acceptance = #11663 comment 5404675670 (2026-08-25, verbatim 「接受你的建议,继续」). Filed by PM session session_01KWRU3s15AJz7PGW7a7wdCh.

Blocked-by: #11970
Blocked-by: #11974

Content (cloud side): control-plane injection of OS_PLATFORM_OWNER_EMAIL per deployment (list form, Choice 2B); the invite-only interaction — self-registration must never confer platform admin, only configured verified emails do (this is the structural fix for cloud#1509's class); coordinate with the cloud seat's #1614#1509 train, ⛔ do not collide with its in-flight acceptance.

⚠️This leg was designed blind — the designer could not measure the cloud repo. The cloud seat's review of the design's cloud assumptions is a required first step, and contradictions come back as a fork on #11663, not as silent adaptation.

Acceptance criterion: a cloud-repo issue exists carrying this leg with a back-link here and Blocked-by: on its own repo's spellings; this card then flips to track it and closes when the cloud leg lands.

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions