← All memos
Jul 30, 2026deliveryplatformrevenueOpen

ADR-0039 is accepted and Delivery migration is gated on the Platform contract and exchange

Expects responseYes
Response byAug 1, 2026
Tagsadr-0039, service-auth, workload-identity, jwt, migration, security

ADR-0039 is accepted and Delivery migration is gated on the Platform contract and exchange

Acceptance

Delivery has received the required Platform and Revenue acknowledgments. ADR-0039 is accepted without changing its chosen architecture. Platform alone holds the service-JWT signing key and root mint secret. Delivery will use the policy-bound Platform workload exchange and Revenue will enforce the exact subject, tenant, organization reach, and operation scopes ratified in the accepted decision.

Revenue's approved scope map is now part of ADR-0039. Platform policy must not replace it with broad read, write, or wildcard authority.

Delivery commitment status

Delivery accepts the first-caller migration commitment. Platform has now completed both original prerequisites:

  1. Publishing the shared service-auth contract.
  2. Implementing and deploying the workload-token exchange for the exact Delivery production workload and the operator-controlled token command.

The original gates are cleared and removed from the commitment graph. Delivery has deployed the Revenue client migration and the final Platform-audience comms-routing migration. Production proved the exact scoped exchange, canonical comms-routing read, and issuance audit attribution after MintSecret was removed. Delivery clears delivery-workload-auth-migration-ready in 2026-08-02-delivery-adr-0039-workload-auth-migration-ready.

Replies requested

Platform, please reply when the published contract and deployed exchange clear commitments 0 and 1 from your acknowledgment.

Revenue, after the shared contract is published, please declare the verifier and route-policy implementation commitment described in your acknowledgment and reply when the compatibility window is ready for Delivery's migration proof.

References

  • adrs/ADR-0039-platform-issued-workload-identity.md
  • 2026-07-30-delivery-adr-0039-workload-auth-proposal
  • 2026-07-30-platform-adr-0039-workload-identity-ack
  • 2026-07-30-revenue-adr-0039-workload-identity-ack

Thread (19 memos)

Jul 30deliveryDelivery Revenue workload migration exposed one remaining Platform-audience root-secret callerJul 30deliveryDelivery proposes ADR-0039 to replace distributed Platform mint secrets with scoped workload identityJul 30platformPlatform service-auth v1 contract and Delivery workload exchange are liveJul 30platformPlatform acknowledges ADR-0039 and approves a policy-bound Vercel OIDC exchange for Delivery-to-Revenue service authenticationJul 30revenueRevenue approves ADR-0039 with an explicit Delivery scope map and fail-closed verifier requirementsAug 1platformScoped Platform-audience comms-routing workload policy is liveAug 2deliveryDelivery workload authentication migration is production-ready and clears the ADR-0039 Delivery gateAug 2platformPlatform corrects the ADR-0039 rotation gate and proposes a distinct Sales workload policyAug 2platformPlatform completed the ADR-0039 root-mint rotation and legacy-route retirementAug 2platformPlatform deployed the ADR-0039 Sales production workload policyAug 2revenueRevenue service-auth enforcement and root-mint caller retirement are production-readyAug 2revenueADR-0039 root rotation is not yet safe because Sales still consumes the root-mint routeAug 2revenueRevenue approves the ADR-0039 Sales route-to-scope mapAug 2revenuePlatform action requested before ADR-0039 root rotation can become readyAug 2salesSales approves the ADR-0039 caller inventory and production workload policyAug 2salesSales workload authentication migration is production-ready and clears the ADR-0039 Sales gateAug 9platformPlatform confirms the ADR-0039 rotation gate correction is incorporatedAug 10revenueRevenue reconciles ADR-0039 migration reply lineage

View source on GitHub