Source: MIZOKI audit 2026-09-06 (pinned fc8b03f9) → work-order backlog 2026-09-08 (docs/audits/AUDIT_WORK_ORDERS_2026-09-08.md); WO-44..49 added 2026-09-08 from the source-verified review v1.1 (docs/reports/MIZOKI_ACQUISITION_ECONOMICS_REVIEW_v1.1_2026-09-06.md, verified on main 635318712). Findings are hypotheses until reproduced on current main (WO-00).

Finding (measured 2026-09-04, PR #948 body; docs/runbooks/ORG_MIGRATION_HOMEPAGE_LANE_REPAIR_2026-09-04.md): MIZOKICloudRun moved from the mediaintelligence account into org MIZOKI-3-5 on 2026-09-04. deploy-homepage.yml has failed since 2026-09-03T00:44Z and nobody noticed (dispatch-only). Five guards fail: (1) repo-identity literal — fixed by #948; (2) ACTOR_ID != OWNER_ID structurally unsatisfiable in an org; (3) WIF pool attributeCondition and (4) homepage-prod-deployer@ principalSet are GCP-side; (5) ref_protected is FALSE and CANNOT be set — rulesets/branch protection on a private repo in a Free org return 403. The same plan limit blocks WO-26 (protect the exact commit that ships / V4-17) and environment required_reviewers. Files: .github/workflows/deploy-homepage.yml, .github/workflows/fix-homepage-deploy.yml; tests/governance/test_homepage_deploy_guard.py; GCP WIF pool + SA binding (owner gcloud, runbook §5, new binding before old). Fix: Owner ruling A — recommended A1: explicit actor-id allowlist {163805125} (already pinned by #963/037233b05); A2 environment required_reviewers added once the plan allows. Owner ruling B — recommended B1: upgrade org to GitHub Team (restores rulesets, ref_protected, unblocks WO-26/V4-17, enables A2). B2 (make repo public) is irreversible — not recommended. B3 (drop guard 5) asserts a protection the platform no longer enforces — refuse. Then run the two GCP commands and dispatch one homepage deploy. Acceptance: rulings A and B recorded in OPEN_ITEMS.md; one owner-dispatched deploy-homepage.yml run proves the live Actions-runtime guards on main (2026-09-13 run #120 already proved guards 1/2/5, with github.ref_protected=true on the dispatch — do not treat the REST branch .protected field as the measurement of record for guard 5); after runbook §5 STEP 1–2 are applied, one fresh owner-dispatched deploy-homepage.yml run passes WIF auth, completes the deploy, and live-verifies on mizoki3.com. Until then homepage production deploys are honestly BLOCKED at breakages (3)/(4) — never patched green. Depends on: none. Blocks: WO-26. Owning prompt: owner (rulings, billing, gcloud); CX-4 for any workflow edit.

Measured 2026-09-13 (run 34774896326 / #120, approved_sha c0650abd2, dispatched under the owner's in-session deploy gate for the Executive Demo pages): guards (1), (2) and (5) all PASSED — github.ref_protected evaluated true on this dispatch, so (5) is no longer what blocks the lane as written above (the REST branch object still reports protected: false; that field is classic protection only, not the guard's measurement); every content gate inside homepage-production passed; the run failed at google-github-actions/auth with unauthorized_client: The given credential is rejected by the attribute condition — breakages (3)/(4), runbook §5 STEP 1–2, owner gcloud, new binding before old. Nothing deployed; mizoki3.com unchanged. Issue #1006 carries the same measurement.

Measured 2026-09-14 (run 34798946595 / #126, approved_sha 6844e75b, dispatched under the owner's typed merge + deploy gates for the /media Executive Demo): google-github-actions/auth PASSED — the WIF attribute condition and the MIZOKI-3-5/MIZOKICloudRun principalSet bindings (runbook §5 STEP 1–2) are applied; the deploy completed end to end (revision mizoki-website-00224-xid at 100 %, rollback 00221-cus, bindings preserved) and live-verified on mizoki3.com (docs/reports/MEDIA_EXEC_DEMO_LIVE_2026-09-14.md §8). Acceptance MET for the lane. Remaining, owner-held: runbook §5 STEP 4 (remove the old mediaintelligence principalSet bindings — only now permitted, since §6 verification has passed) and ruling B1 (Team plan). Attempts #124/#125 (01:38Z–01:39Z) failed at job creation during the Actions outage, not at any guard.

Measured 2026-09-14 (last-40 close-out, read-only): org plan is enterprise and main carries the active ruleset main-block-force-push (/rulesets answers; /branches/main/protection → 404 Branch not protected, no longer 403 Upgrade), so ruling B1's purpose is met by the plan change and B2/B3 are moot. The REST branch object now also reports protected, but the run logs stay the measurement of record for guard (5): runs 34798946595 and 34855150962 log REF_PROTECTED: true in both jobs. gcloud (read-only): the pool attributeCondition names both MIZOKI-3-5 and mediaintelligence (STEP 1), and homepage-prod-deployer@ holds both principalSets on roles/iam.workloadIdentityUser and roles/iam.serviceAccountTokenCreator (STEP 2). STEP 4 is not applied and stays owner-held (IAM).

Status: CLOSED 2026-09-15 — A1 landed, B1 moot (plan enterprise + ruleset), lane live (#126), STEP 4 measured done; see OPEN_ITEMS.md row.

← All docsView source on GitHub →