Architecture¶
Forge has four connected boundaries: repository source, authorization, runtime configuration, and deployment results.
Flow¶
- The GitHub origin identifies the default repository.
- Committed
HEADidentifies the default source. - Authorization derives deployment context and app identity.
- Forge App authorization begins when deployment requires repository access.
- Forge builds and starts the app described by
mithran.yaml. - Forge returns the deployment result.
Authority separation¶
The operator's GitHub authority performs ordinary source-control operations. Forge uses its App authorization only for repository access required by deployment. Forge injects no repository workflow.
Selectors¶
Automation can select only repository, ref, or commit. The customer cannot select environment, tenant, account, installation, or app identity.
Proof¶
The manifest, origin, commit, local HTTP result, and deployment result form a useful proof packet. The packet does not establish hosted behavior beyond accepted evidence.