fix(site): name the configuration each security and execution claim needs #186

Merged
ryangr0 merged 2 commits from ryangr0/site-claims-name-their-profile into development 2026-10-03 15:11:58 +00:00 AGit
Owner

The site said every Run has credentials only for its own work and that they
expire, that Ploeg executes managed Runs and that every Vloer Run goes
through Ploeg. By default writers share one push token that never expires,
GitLab has no per-Run token, key isolation is off, Ploeg's executor is off,
and Vloer still executes the Runs it starts. Each claim now names the
setting it holds for or is labelled planned, in English and Dutch, and the
guardrails section links the capability matrix.

Two commits: a new docs/reference/capability-matrix.md backing each claim with its setting, default and source, and the EN/NL site copy changes. No claim now says more than the default configuration does: credentials expire only for model keys, writers share a push token unless a Forgejo bot password is set, and Vloer still executes managed Runs itself (ADR-0002 not yet complete). Not proven by a test yet: LiteLLM's own max_budget enforcement, and 'Unfold never merges'.

Verified with mise run verify on the pinned toolchain (all gates passed).

Ticket: https://vikunja.webgrip.dev/tasks/1749

🤖 Generated with Claude Code

The site said every Run has credentials only for its own work and that they expire, that Ploeg executes managed Runs and that every Vloer Run goes through Ploeg. By default writers share one push token that never expires, GitLab has no per-Run token, key isolation is off, Ploeg's executor is off, and Vloer still executes the Runs it starts. Each claim now names the setting it holds for or is labelled planned, in English and Dutch, and the guardrails section links the capability matrix. Two commits: a new docs/reference/capability-matrix.md backing each claim with its setting, default and source, and the EN/NL site copy changes. No claim now says more than the default configuration does: credentials expire only for model keys, writers share a push token unless a Forgejo bot password is set, and Vloer still executes managed Runs itself (ADR-0002 not yet complete). Not proven by a test yet: LiteLLM's own max_budget enforcement, and 'Unfold never merges'. Verified with `mise run verify` on the pinned toolchain (all gates passed). Ticket: https://vikunja.webgrip.dev/tasks/1749 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Each claim the marketing site makes about credentials and execution gets a
row: the settings it needs, whether they are the chart default, and the test
or source that shows it. Per-Run Forgejo push tokens need botPasswordSecret,
GitLab writers always share one token, key and token isolation are off by
default, Forgejo tokens never expire, and Vloer still executes the Runs it
starts in shared mode.

VIK-1749

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
fix(site): name the configuration each security and execution claim needs
Some checks are pending
[Workflow] On Pull Request / checks (pull_request) Waiting to run
[Workflow] On Pull Request / warnings (pull_request) Blocked by required conditions
[Workflow] On Pull Request / release-policy (pull_request) Waiting to run
3ddf79e5a2
The site said every Run has credentials only for its own work and that they
expire, that Ploeg executes managed Runs and that every Vloer Run goes
through Ploeg. By default writers share one push token that never expires,
GitLab has no per-Run token, key isolation is off, Ploeg's executor is off,
and Vloer still executes the Runs it starts. Each claim now names the
setting it holds for or is labelled planned, in English and Dutch, and the
guardrails section links the capability matrix.

VIK-1749

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ryangr0 merged commit f25b83d9a4 into development 2026-10-03 15:11:58 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/unfold!186
No description provided.