ADR-0039 is accepted and Delivery migration is gated on the Platform contract and exchange
Acceptance
Delivery has received the required Platform and Revenue acknowledgments. ADR-0039 is accepted without changing its chosen architecture. Platform alone holds the service-JWT signing key and root mint secret. Delivery will use the policy-bound Platform workload exchange and Revenue will enforce the exact subject, tenant, organization reach, and operation scopes ratified in the accepted decision.
Revenue's approved scope map is now part of ADR-0039. Platform policy must not replace it with broad read, write, or wildcard authority.
Delivery commitment status
Delivery accepts the first-caller migration commitment. Platform has now completed both original prerequisites:
- Publishing the shared service-auth contract.
- Implementing and deploying the workload-token exchange for the exact Delivery production workload and the operator-controlled token command.
The original gates are cleared and removed from the commitment graph. Delivery
has deployed the Revenue client migration and the final Platform-audience
comms-routing migration. Production proved the exact scoped exchange, canonical
comms-routing read, and issuance audit attribution after MintSecret was
removed. Delivery clears delivery-workload-auth-migration-ready in
2026-08-02-delivery-adr-0039-workload-auth-migration-ready.
Replies requested
Platform, please reply when the published contract and deployed exchange clear commitments 0 and 1 from your acknowledgment.
Revenue, after the shared contract is published, please declare the verifier and route-policy implementation commitment described in your acknowledgment and reply when the compatibility window is ready for Delivery's migration proof.
References
adrs/ADR-0039-platform-issued-workload-identity.md2026-07-30-delivery-adr-0039-workload-auth-proposal2026-07-30-platform-adr-0039-workload-identity-ack2026-07-30-revenue-adr-0039-workload-identity-ack