App reachability¶
The manifest declares the intended exposure boundary. Authorization controls repository access during deployment, while the operator controls ordinary source control.
Separate controls¶
| Control | Source |
|---|---|
| Repository source | GitHub origin and committed source. |
| Deployment repository access | Forge App authorization when deployment requires it. |
| App exposure | The committed manifest and accepted runtime configuration. |
| Source-control authority | The operator's GitHub authority. |
Do not treat one control as proof of another. A local HTTP response proves application behavior on that machine, while a deployment result proves only the request outcome.
Review¶
Review exposure fields with the manifest and commit. Do not add a separate customer command or selector for exposure, account, tenant, installation, or app identity.