docs(adr): ADR-0105 D12 amendment — group posture activation is entitled, not open (#3570) - #3603
Merged
Merged
Conversation
…led, not open (#3570) Founder ruling: OS_TENANCY_POSTURE=group is not an open-edition feature. The code was already corrected in #3570 (group probes org-scoping exactly like isolated; no runtime => single + degraded; an os serve boot configured for group fail-fasts). This brings the ADR text in line: - D12 rewritten to the code-vs-activation split: the wall's implementation ships open, posture activation is entitled for BOTH multi-org postures; iron-rule safety is satisfied by refusing to run an unwalled group boot, not by free activation. ADR-0081 D2's commercial line stands. - Amendment block records the original text, why it was wrong (inverted ADR-0081 D2 + the silent-degradation hole), and the #3559 -> #3570 trail. - Consequences clause updated to match; header Status moves to Accepted with the amendment note; Tracking points at #3541 / #3539 / #3540 / cloud #874. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015FebXPaaGrLhGKw1LHPbpL
|
The latest updates on your projects. Learn more about Vercel for GitHub. 1 Skipped Deployment
|
21 tasks
os-zhuang
marked this pull request as ready for review
July 27, 2026 09:21
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Founder ruling on the decision flagged in #3559:
OS_TENANCY_POSTURE=groupis not an open-edition feature — ADR-0105's D12 text had it wrong. The code was already corrected by #3570 (groupprobesorg-scopingexactly likeisolated; no enterprise runtime ⇒single+degraded; anos serveboot configured forgroupfail-fasts instead of silently running unwalled). This PR brings the ADR document in line with the corrected decision. Doc-only.Changes
accessible_org_ids, D6 lints — same asisolated's wall has always lived inplugin-security), while posture activation is entitled for both multi-org postures. The iron rule (强制免费、治理收费) is satisfied by refusing to run an unwalledgroupboot — open code is not free activation. ADR-0081 D2's commercial line stands.isolatedstayed entitled, and it opened the silent-degradation hole whereOS_TENANCY_POSTURE=groupskipped both the enterprise package load and the ADR-0093 D5 fail-fast), and the feat(authz)!: group tenancy posture + org scope as a first-class dimension — ADR-0105 Phase 0/1 #3559 → fix(authz)!: make thegroupposture an entitlement again — ADR-0105 D12 correction #3570 trail.Verification
check:nul-bytes,check:doc-authoring,check:role-word,check:org-identifier.Follow-up in this session: tracking issue #3541's own "D12 line re-draw" note is being updated to match (issue body edit, not part of this diff).
🤖 Generated with Claude Code
https://claude.ai/code/session_015FebXPaaGrLhGKw1LHPbpL
Generated by Claude Code