Skip to content

Grant CloudCurator access to isolated public macOS CI runners #166

Description

@jmcte

Updated incident

OMT-Global/cloudcurator is now public. Public pull-request code must not run on the persistent private runner pool described in the original incident. CloudCurator PR #33 now follows the APW-CLI public-pool trust pattern while retaining the native macOS/Xcode requirements:

["self-hosted", "public", "macOS", "ARM64", "xcode"]

Current evidence:

This is now a public macOS runner-group access or pool-availability blocker. Do not grant public PR code access to the persistent private pool.

Required change

Grant OMT-Global/cloudcurator access to an isolated public macOS ARM64/Xcode runner group, or provision an eligible ephemeral/public runner matching those labels. Preserve the public trust-boundary label.

Acceptance criteria

Next actor

Runner-fleet or organization administrator: grant the repository access to the isolated public macOS/Xcode group (or provision that pool), then rerun PR #33.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:infraInfrastructure, CI, release, governance, scripts, or repo setup.bugSomething isn't workingneeds-humanHuman decision or credentialed action required.priority:P1Codex Connector P1; blocks execution until Athena and Ares validate.reliabilityrisk:highHigh-risk change; validation required.

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions