Current Luci does not implement the approved generic prerequisites for Smith ADW:
durable auth and cache mounts;
temporary read-only file-secret binds;
temporary env files instead of secret-bearing process arguments;
immutable bounded artifacts and sandboxed HTML serving;
scheduled triggers with frozen revisions and coalescing;
per-job resource overrides;
generic frozen-plan CI_* metadata.
Current file secrets are copied into retained workspaces.
Current environment secrets are passed as --env NAME=value arguments.
The image and embedded docs also contain bugabinga-specific deployment values, contradicting Luci's generic boundary.
Close only after each generic capability is implemented and verified without Smith concepts entering Luci production code.
---
id: BB-ISSUE-AC5EBBDD
type: issue
title: Luci ADW prerequisite drift
specs:
- BB-SPEC-251EC85B
---
# Luci ADW prerequisite drift
Current Luci does not implement the approved generic prerequisites for Smith ADW:
- durable `auth` and `cache` mounts;
- temporary read-only file-secret binds;
- temporary env files instead of secret-bearing process arguments;
- immutable bounded artifacts and sandboxed HTML serving;
- scheduled triggers with frozen revisions and coalescing;
- per-job resource overrides;
- generic frozen-plan `CI_*` metadata.
Current file secrets are copied into retained workspaces.
Current environment secrets are passed as `--env NAME=value` arguments.
The image and embedded docs also contain bugabinga-specific deployment values, contradicting Luci's generic boundary.
Close only after each generic capability is implemented and verified without Smith concepts entering Luci production code.