Production Provider Selection + Adapter Deployment Attestation Foundation
This gate binds an intentionally selected provider identity to the exact already-reviewed adapter code digest and a deployment artifact digest. It rejects provider/origin drift, inline secret material, missing reviews/selections, adapter-version drift, digest mismatches, release/runtime drift, production-source impersonation and any attempt to enable network dispatch. QA uses deterministic simulator attestations only; it does not select a real production provider or deploy/contact one.
Selection + deployment self-test
Exercise the provider-selection/deployment boundary
GREEN means the safe QA selection manifest and deployment attestation were accepted. EXPECTED BLOCK means Clara correctly stopped drift or a production-impersonation attempt. RED means the test itself failed.
Selected QA manifests
No provider selections loaded yet.
Reviewed artifact pins
No deployment attestations loaded yet.
Selection/deployment guard history
No deployment events loaded yet.
Real provider selection + deployed artifact evidence
Leave these open until a real production provider has been intentionally chosen, its approved connection and secret-store reference exist, the exact deployed Cloudflare adapter artifact/digests are recorded, production monitoring/rollback are proven, and public QA endpoints are disabled. The QA simulator manifest is not a production provider selection or Cloudflare deployment attestation.
Recent deployment QA runs
Evidence tools
Clearing browser evidence never rewrites server-owned provider selection, deployment attestation or event records.
