You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Give GitHub Actions a protected, short-lived, least-privilege identity for Firebase deployment. Prefer GitHub OpenID Connect plus Google Workload Identity Federation. Do not put a downloaded service-account key in the repository, website build, issue, email, screenshot, or AI conversation.
This is an owner/configuration ticket. It is not ready to claim until the owner confirms the target Firebase/GCP project, the staging project, two approved release reviewers, and the private place where IAM evidence will be kept.
Officer impact: Two named officers can approve a backend release without handling or copying a long-lived cloud key.
Officer documentation: Update docs/officers/ACCESS_CONTINUITY.md, docs/officers/PUBLISH_AND_CHECK.md, and OPERATIONS_RUNBOOK.md with only the verified no-secret approval/revocation steps.
Deployment evidence: None at creation. No Firebase, website, provider, or production change is authorized by publishing this ticket.
Why this is atomic
This ticket establishes deployment identity and approval only. It does not deploy application code, Functions, Firestore Rules, indexes, or a website. CI-001D will use the approved identity for a controlled backend-first release.
Stop if a step requests a JSON key, token, password, recovery code, project policy dump, private link, or broad Owner/Editor role in a public place. Stop if the exact target project or named approvers are unknown. Escalate to the platform/security owner and cloud IAM specialist.
Claim protocol
Creation is not a claim. After owner prerequisites are recorded privately, assign one agent, post CLAIMED by <canonical agent> at <UTC>; branch <branch>, and change the label only when the ticket is actually dependency-clear. Provider-console work requires the named human owner present; an agent must not invent or copy secrets.
Outcome
Give GitHub Actions a protected, short-lived, least-privilege identity for Firebase deployment. Prefer GitHub OpenID Connect plus Google Workload Identity Federation. Do not put a downloaded service-account key in the repository, website build, issue, email, screenshot, or AI conversation.
This is an owner/configuration ticket. It is not ready to claim until the owner confirms the target Firebase/GCP project, the staging project, two approved release reviewers, and the private place where IAM evidence will be kept.
Officer impact: Two named officers can approve a backend release without handling or copying a long-lived cloud key.
Officer documentation: Update
docs/officers/ACCESS_CONTINUITY.md,docs/officers/PUBLISH_AND_CHECK.md, andOPERATIONS_RUNBOOK.mdwith only the verified no-secret approval/revocation steps.Deployment evidence: None at creation. No Firebase, website, provider, or production change is authorized by publishing this ticket.
Why this is atomic
This ticket establishes deployment identity and approval only. It does not deploy application code, Functions, Firestore Rules, indexes, or a website. CI-001D will use the approved identity for a controlled backend-first release.
Prerequisites / owner decisions
Required design
Acceptance criteria
Stop conditions
Stop if a step requests a JSON key, token, password, recovery code, project policy dump, private link, or broad Owner/Editor role in a public place. Stop if the exact target project or named approvers are unknown. Escalate to the platform/security owner and cloud IAM specialist.
Claim protocol
Creation is not a claim. After owner prerequisites are recorded privately, assign one agent, post
CLAIMED by <canonical agent> at <UTC>; branch <branch>, and change the label only when the ticket is actually dependency-clear. Provider-console work requires the named human owner present; an agent must not invent or copy secrets.