ClaraWideProvider selection + deployment attestation QA
v0.12.38 · SCHEMA 37

Production Provider Selection + Adapter Deployment Attestation Foundation

This gate binds an intentionally selected provider identity to the exact already-reviewed adapter code digest and a deployment artifact digest. It rejects provider/origin drift, inline secret material, missing reviews/selections, adapter-version drift, digest mismatches, release/runtime drift, production-source impersonation and any attempt to enable network dispatch. QA uses deterministic simulator attestations only; it does not select a real production provider or deploy/contact one.

SCHEMA

Provider deployment schema

READYExpected schema v37.
AUTOMATED ATTACK PATHS

Selection + deployment self-test

READYRuns the server-owned provider-selection and adapter-deployment attack matrix.
VISIBLE QA FLOW

Exercise the provider-selection/deployment boundary

GREEN means the safe QA selection manifest and deployment attestation were accepted. EXPECTED BLOCK means Clara correctly stopped drift or a production-impersonation attempt. RED means the test itself failed.

READYStart with a QA Deployment Admin session.
QA deployment policyLoad deployment state to inspect provider selection, digest pinning, secret-reference and network-lockout rules.
PROVIDER SELECTION EVIDENCE

Selected QA manifests

No provider selections loaded yet.

DEPLOYMENT ATTESTATIONS

Reviewed artifact pins

No deployment attestations loaded yet.

IMMUTABLE EVIDENCE

Selection/deployment guard history

No deployment events loaded yet.

PRODUCTION GATE — DO NOT FAKE

Real provider selection + deployed artifact evidence

Leave these open until a real production provider has been intentionally chosen, its approved connection and secret-store reference exist, the exact deployed Cloudflare adapter artifact/digests are recorded, production monitoring/rollback are proven, and public QA endpoints are disabled. The QA simulator manifest is not a production provider selection or Cloudflare deployment attestation.

Recent deployment QA runs

No QA runs recorded yet.

Evidence tools

Clearing browser evidence never rewrites server-owned provider selection, deployment attestation or event records.