fix(site): name the configuration each security and execution claim needs #186
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "ryangr0/site-claims-name-their-profile"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The site said every Run has credentials only for its own work and that they
expire, that Ploeg executes managed Runs and that every Vloer Run goes
through Ploeg. By default writers share one push token that never expires,
GitLab has no per-Run token, key isolation is off, Ploeg's executor is off,
and Vloer still executes the Runs it starts. Each claim now names the
setting it holds for or is labelled planned, in English and Dutch, and the
guardrails section links the capability matrix.
Two commits: a new docs/reference/capability-matrix.md backing each claim with its setting, default and source, and the EN/NL site copy changes. No claim now says more than the default configuration does: credentials expire only for model keys, writers share a push token unless a Forgejo bot password is set, and Vloer still executes managed Runs itself (ADR-0002 not yet complete). Not proven by a test yet: LiteLLM's own max_budget enforcement, and 'Unfold never merges'.
Verified with
mise run verifyon the pinned toolchain (all gates passed).Ticket: https://vikunja.webgrip.dev/tasks/1749
🤖 Generated with Claude Code