Status: LIVE_CANDIDATE / FAIL_CLOSED / PROVIDER_UNBOUND / PRODUCTION_NO_GO
This service creates an independent deployment-control boundary separate from both the continuity relay and the dedicated R2 authorizer.
R2_DEPLOY_ROOT_TOKEN;R2_ALLOW_DEPLOY: absent / false;R2_GITHUB_APP_TOKEN: absent;NOT_BOUND;Every prepared deployment plan binds exactly to:
Exact duplicate plans are rejected.
POST /v1/execute fails closed in this order:
R2_ALLOW_DEPLOY=true must be explicitly present;At present step 2 fails with HTTP 423. No provider-side mutation can occur.
Val Town evaluation:
01a04b9c-9389-760a-be16-a819d85ebf7f
Result: PASS.
Matrix:
Test plan request SHA-256:
4fdc1f93766e2b457c58ae02189b6666c075dc8fadef9c6a9afd2e1ee3d4f5c4
The external deployer controller runtime exists and is live fail-closed.
Actual provider deployment remains unresolved because no dedicated GitHub App provider
credential or provider adapter is bound. This is intentional and must not be reported as
EXTERNAL_DEPLOYER_EXECUTION_LIVE.