Objective
Import, parity-check, cut over, and retire protected GitHub-secret managed authorization desired sets without changing decisions unexpectedly or losing recovery.
Current Status
State: Planned migration under #2061 after the DB-native administration surface and recovery contract pass their gates. No production set migration is authorized yet.
Scope
- Inventory every protected
LAUNCHPLANE_AUTHZ_*_MANAGED_SET_JSON input and exact workflow owner.
- Import desired sets into DB-native drafts with source digest/provenance and no immediate authority change.
- Compare old and new policy decisions across principals, actions, products, contexts, instances, workflows, and negative cases.
- Exercise rollback, final-admin recovery, GitHub outage, secret loss, and provider-loss scenarios.
- Cut routine administration to Launchplane API/UI only after parity and recovery gates pass.
- Remove or disable routine workflow selectors and delete obsolete desired-set secrets after verified cutover.
- Retain only the explicitly accepted bootstrap/break-glass transport and document its bounded capability.
Acceptance Criteria
- Every current managed set has an exact DB-native import and decision-parity report.
- No product repository owns or stores Launchplane permission desired state.
- GitHub secret loss after cutover does not affect active authority or routine administration.
- Rollback and bounded recovery are tested before any secret/workflow retirement.
- Obsolete workflows, inputs, docs, tests, and secret references are removed rather than left as a second authority path.
Finish Line
Routine Launchplane authorization administration and desired state are entirely DB-native; GitHub retains only identity and the explicitly reviewed bootstrap/break-glass transport.
Objective
Import, parity-check, cut over, and retire protected GitHub-secret managed authorization desired sets without changing decisions unexpectedly or losing recovery.
Current Status
State: Planned migration under #2061 after the DB-native administration surface and recovery contract pass their gates. No production set migration is authorized yet.
Scope
LAUNCHPLANE_AUTHZ_*_MANAGED_SET_JSONinput and exact workflow owner.Acceptance Criteria
Finish Line
Routine Launchplane authorization administration and desired state are entirely DB-native; GitHub retains only identity and the explicitly reviewed bootstrap/break-glass transport.