diff --git a/documentation/runbooks/target-selection.md b/documentation/runbooks/target-selection.md index 8b8be962..c18103ad 100644 --- a/documentation/runbooks/target-selection.md +++ b/documentation/runbooks/target-selection.md @@ -25,6 +25,28 @@ Fences name **acts**, not machines. "Do not destroy demo-hp's `drill-r50` fixtur demo-hp to host a throwaway VM" are unrelated; only the first has ever been meant. Read a per-machine prohibition as covering the act it names and nothing more. +## A drill night that forbids baking a golden — what you will see, and why it is expected + +**This is written here because the instruction that caused it was mine and I left it out** (R-417). +An overnight drill runbook that says *"no golden bake, no vouch, no floor change tonight — those are +the operator's acts"* is correct, and it also guarantees the `golden-currency` gate is RED for the +whole night whenever a controller release is newer than the last bake. **That is the gate telling the +truth**, not a fault to work around. + +Since 2026-09-01 (R-404) it no longer refuses your pushes. A drill's own pushes — evidence, register +rows, `STATUS.md`, `REPORT.md` — are documents-only, so the gate's conviction prints as a loud +**ADVISORY** block and the push proceeds. **Expect to see it, every push, all night. Do not silence +it and do not bypass the hook for it.** + +Two things still hold: + +* A push that touches **code** is still refused — bake first or do not push code. +* **Every other gate still refuses every push.** If a push is refused during a drill it is NOT the + golden gate, and the message will name which gate it was. + +If the drill genuinely must ship a release with no golden, the honest instrument is a **waiver row** +in `documentation/backlog/OPEN-ITEMS.md`, never `--no-verify`. + ## Before you revert it — take the evidence off first > **A phase's evidence is copied off the machine at the end of THAT phase, before any revert, snapshot