ATOMIK
FORGE / CONTROL PLANE
RELEASE ENGINE / CERTIFIEDPLAN + EXECUTE
SIGNED RELEASE CONTROL

Forge authorizes a frozen plan; pinned GitHub workflows perform cloud mutations.

NO DIRECT CLOUD IAM
IDENTITY GATE

Authenticate as a Forge operator

A verified Supabase session and an assigned Forge role are required. Authentication never grants cloud deployment permissions.

01 / ACTIVE PRODUCTION

Release planning workspace

UNAVAILABLE
PROD

Production snapshot

Revision NOT OBSERVED
Source SHA
Image digest
Deployed at
Service
Release planning is blocked until Production provenance is verified.
PHASE 2 / GATE C

Certified provider observation

Forge automatically reads source and active Production as one consistent planning basis. Use refresh to repeat the complete observation.

02

Available changesets

Real changes normalized from the source provider relative to active Production.

No verified changesets loaded

Sign in with an assigned role to read source metadata.

03

Release plan

BLOCKED
ACTIVE PROD VERIFIED BASE
+
SELECTED 0 CHANGESETS
CANDIDATE PLAN NOT BUILT NO ARTIFACT ID
AUTOMATIC CHECKS

Select an update to prepare its plan.

The immutable plan can be executed by the same authenticated operator.

04

Release lifecycle

WAITING FOR FROZEN PLAN
  1. 01
    SELECT + PLANSINGLE OPERATOR
  2. 02
    BUILD CANDIDATEAVAILABLE
  3. 03
    DEPLOY TO STAGINGAVAILABLE
  4. 04
    PROMOTE TO PRODUCTIONAVAILABLE
  5. 05
    ROLLBACKAVAILABLE
RI-001Chronology is not authority

Merge order and PR numbers cannot determine release order.

RI-002Production is the basis

The plan starts from the verified active Production state.

RM-001Selective release preserved

Unselected mainline changes remain explicitly excluded.

AUTHApplication role ≠ cloud IAM

Even Forge Admin has no deployment permission.