Goal
Turn GroundControl's existing live topology + Loop foundation into a machine-readable repo-to-runtime control contract.
Why now
GroundControl already sees the real host state and has change ledger, journeys, evidence-backed investigation, approvals, and recovery concepts. The next step is to make repository intent and action policy explicit so agents can safely compare desired state with live reality and produce evidence-backed repair plans.
First slice
Add a declarative manifest, e.g. groundcontrol.yaml, with:
- app/project identity
- services
- image/build source
- ports
- domains/routes
- health checks
- dependency edges
- environment variable references (never values)
- storage
- deployment target
- rollout/rollback hints
- action policy / approval requirements
Add commands/API primitives equivalent to:
- plan: repo intent vs live state
- drift: explain mismatches with evidence
- apply: execute only approved changes
- verify: prove the intended customer/runtime outcome
Policy
Actions should have typed risk classes, not shell-command-string prompts. Examples:
- inspect/log/read: allowed
- restart/redeploy: policy-controlled
- DNS/proxy mutation: approval-required by default
- secrets read/delete volume/cross-project access: denied or explicit break-glass
Evidence
Every plan/drift item should cite the observed source:
repo file, container inspect, proxy config, DNS response, health probe, journey result, deployment record, etc.
Acceptance criteria
- Parse and validate one manifest schema.
- Build an intent graph from the manifest.
- Map at least Docker Compose services/ports/health checks into the existing live graph.
- Produce deterministic drift findings for port, missing service, route/domain, and health mismatch.
- Each drift item includes evidence and a proposed reversible action.
- Applying a high-risk action requires approval.
- Verification records proof after the action.
- No secret values are written into the manifest or evidence log.
Non-goal
Do not replace Loop. This should become the declarative input and policy/evidence spine Loop can reason over.
Goal
Turn GroundControl's existing live topology + Loop foundation into a machine-readable repo-to-runtime control contract.
Why now
GroundControl already sees the real host state and has change ledger, journeys, evidence-backed investigation, approvals, and recovery concepts. The next step is to make repository intent and action policy explicit so agents can safely compare desired state with live reality and produce evidence-backed repair plans.
First slice
Add a declarative manifest, e.g.
groundcontrol.yaml, with:Add commands/API primitives equivalent to:
Policy
Actions should have typed risk classes, not shell-command-string prompts. Examples:
Evidence
Every plan/drift item should cite the observed source:
repo file, container inspect, proxy config, DNS response, health probe, journey result, deployment record, etc.
Acceptance criteria
Non-goal
Do not replace Loop. This should become the declarative input and policy/evidence spine Loop can reason over.