Settings

Read-only provider readiness and trust boundaries

Trust Boundaries

Repository trustGitHub App + OIDC
Runtime defaultCloud Run service and job
Exception runtimeInterface only

Provider Readiness

Static CP-08 visibility from the current provider readiness record

ProviderStatusRequired non-secret inputCredential boundaryWrites
GCPconfig-confirmed / credential-check-blockedProject thesoftworld-dev and region europe-west1 are selected.Local ADC, workload identity, or equivalent Pulumi provider configuration still needs verification.read-only
CloudflareblockedConfirm dev.thesoftworld.com is an active zone or delegated into one.CLOUDFLARE_API_TOKEN with zone read permission is required before live checks.read-only
NeonblockedConfirm thesoftworld-platform-dev account/project path and preview branch support.NEON_API_KEY or Pulumi secret config must be available before live checks.read-only
AWS S3blockedConfirm AWS account/IAM path for S3 bootstrap in eu-central-1.Standard AWS provider chain with scoped S3 bootstrap permissions is required.read-only
MongoDB Atlasdeferred-placeholderNo near-term workload requires Atlas yet.No credential boundary is active for CP-08.read-only