CodLab/ docs
OPERATOR MANUALEnterprise reference · Planning

DOCS.CODECR.ORG / ENTERPRISE REFERENCE · PLANNING

Enterprise deployment reference.

These runbooks describe planning and reference contracts. They do not establish that CLI, VPC, microVM, KMS, integrations or example endpoints are available in a self-service workspace. Start with the hosted-product documentation for current setup.

Original CodLab document concept / source relationships · illustrative motion
RELEASE CONTRACT PREVIEW Examples define the intended operator interface—not proof that an endpoint or artifact is currently issued.

Obtain signed package URLs, checksums, chart versions, webhook endpoints, and environment-specific values from the controlled Trust Center release record before execution.

Open Trust Center controls
01INSTALLSigned CLI + scoped identity
02GOVERNDeterministic policy inheritance
03ISOLATEVPC, microVM, local KMS
04VERIFYEdge and release evidence
01 / GETTING STARTED

Establish identity before repository access.

For hosted GitHub review, start with the quickstart below. The CLI, infrastructure, and operator sections describe deployment planning and reference contracts; they are not additional capabilities included with a self-service workspace.

START HERE / GITHUB

Your first review and approved fix.

Use the hosted workflow on a repository connected to your CodLab workspace. Review findings are advisory; your team keeps merge approval.

Preview before publishing

A generated patch has not been proven correct by generation alone. Inspect the diff and run your repository tests before merging.

  1. Connect your repository

    Sign in to CodLab and install CodLab AI for the repositories you select.

  2. Read the review

    Open a pull request and follow its CodLab report. Check the reviewed commit, findings, evidence, security details, and pre-merge check results.

  3. Preview the patch

    Choose Fix in CodLab. Generate a proposal, inspect the file changes, and explicitly approve that patch as a workspace owner or administrator.

  4. Choose where to publish

    Create a new pull request or commit to the current branch. A changed source commit requires a fresh proposal. Generated tests and fixes still require your normal CI and human review.

HOSTED PRODUCT / SECURITY AND CONTROLS

Read the scope and the approval receipt.

Security reports distinguish observed evidence, inferred consequences, and proposed hardening. The blast-radius inventory shows supplied changed paths, line counts, and missing or partial patches at the reviewed commit. Unchanged callers, runtime permissions, deployment reach, and a full dependency graph remain unknown.

Evidence is not merge approval

The evidence score is not a probability or a safety guarantee. Skipped and unavailable checks are not passes. Generated patches and test files have not been executed by the fix engine.

Workspace controls

Owner, administrator, and member roles; current repository grants; organization controls for AI, automatic review, severity, and file budgets; patch approval tied to the patch hash and reviewed SHA.

Recent fix audit receipts

Authorized owners and administrators with current repository access can inspect the latest 100 available events, including fix approvals, cancellations, and publication. Expand a receipt for the actor, reviewed SHA, patch hash, and chosen publication mode. This is not a complete compliance archive.

Publication uncertainty

If CodLab cannot record the publication receipt, GitHub may already contain the approved commit. Check GitHub before starting another fix.

Current security and data boundaries · Synthetic sample review

01.1

CLI installation

Download only the platform-specific package referenced by your Trust Center release record. Verify its checksum and release signature before placing the binary on a managed workstation or runner.

Artifact gate

The public preview does not publish a CLI archive or checksum. Replace every bracketed value with the immutable artifact data from your approved release record.

shell / controlled workstation
# Download from the signed URI in the Trust Center
curl --proto '=https' --tlsv1.2 --fail --location \
  '<approved-package-uri>' \
  --output codecr-cli.tar.gz

# Verify before extraction
sha256sum -c SHA256SUMS
cosign verify-blob codecr-cli.tar.gz \
  --signature codecr-cli.sig \
  --certificate codecr-cli.pem

tar -xzf codecr-cli.tar.gz
install -m 0755 codecr "$HOME/.local/bin/codecr"
codecr version
01.2

Cloudflare-proxied API key scoping

Cloudflare protects the network edge; CodLab authorizes the application action. Issue separate, short-lived keys for human CLI use, CI review, and telemetry ingestion—never one key with combined read, write, and administrative authority.

WorkloadMinimum scopesMaximum TTL
PR reviewrepo:read policy:read checks:write24 hours
Policy validationpolicy:read policy:validate8 hours
Telemetry ingesttelemetry:write1 hour
shell / proposed CLI contract
codecr keys create \
  --name github-review-pilot \
  --scope repo:read \
  --scope policy:read \
  --scope checks:write \
  --ttl 24h
Edge request contract

Send the key only in Authorization: Bearer … over HTTPS. Never place it in a URL, query string, cookie, WAF expression, analytics field, or support ticket.

01.3

GitHub Enterprise and GitLab webhook setup

Create one webhook per enterprise organization or self-managed GitLab group. Restrict events to the pilot scope, retain delivery IDs for replay defense, and reject a payload before parsing when its signature or token is invalid.

ProviderEventsVerification
GitHub EnterprisePull request, push, check suiteX-Hub-Signature-256
GitLab Self-ManagedMerge request, push, pipelineX-Gitlab-Token + source allowlist
expected endpoint contract
GitHub Enterprise
POST https://api.codecr.org/v1/webhooks/github
Content-Type: application/json
X-Hub-Signature-256: sha256=<signature>

GitLab Self-Managed
POST https://api.codecr.org/v1/webhooks/gitlab
Content-Type: application/json
X-Gitlab-Token: <rotated-secret>

# Activate only the endpoint issued for your pilot.
# Never use placeholder values in production.
02 / CONFIGURATION REFERENCE

Policy is source-controlled architecture.

.codecr.yaml resolves organizational controls into a deterministic repository gate. Parent policies are pinned by digest, repository authors may tighten controls, and only a centrally signed exception may relax them.

02.1

Author a high-assurance policy file

This example blocks high-blast-radius changes in payment services until the Security owner signs off, requires P0 remediation, and prevents a repository-local file from weakening the inherited control.

  • Pin every parent policy by immutable digest.
  • Use stable rule IDs that appear in audit evidence.
  • Bind approval to an identity group, not a display name.
  • Validate the resolved policy before enabling merge enforcement.
.codecr.yaml / payments organization
version: 1

extends:
  - ref: "org://fintech/security-baseline"
    digest: "sha256:<pinned-policy-digest>"

scope:
  include:
    - "services/payments/**"
    - "contracts/ledger/**"

inheritance:
  strategy: strict
  allow_repository_relaxation: false

policies:
  - id: "PAYMENTS-BLAST-RADIUS-001"
    description: "Security approval for high-impact payment changes"
    when:
      service_tags: ["payments", "ledger"]
      blast_radius:
        severity: ["high", "critical"]
    require:
      approvals:
        - group: "security-owners"
          minimum: 1
      checks:
        - "codecr/p0-analysis"
        - "codecr/dependency-map"
    on_violation:
      decision: block
      remediation: required
      evidence_retention: "customer-policy"

exceptions:
  require_signed_record: true
  approver_group: "enterprise-risk-owners"
  maximum_ttl: "24h"
02.2

Resolve multi-repo inheritance

Resolution flows from organization to portfolio, repository, and path. CodLab records each source and digest in the decision evidence so reviewers can reproduce the effective rule set without relying on mutable defaults.

01Organization baselineMandatory identity, retention, and P0 controls
02Portfolio overlayPayments, healthcare, defense, or regional controls
03Repository policyService ownership and local test requirements
04Path ruleSchema, migration, secret, or privileged-code guardrail
DETERMINISTIC RESOLUTION
Conflict
The most restrictive enforceable rule wins.
Relaxation
Rejected unless a signed, unexpired exception authorizes the exact rule and scope.
Missing parent
Fail closed; do not evaluate against an unpinned substitute.
Evidence
Record source URI, digest, resolution order, decision, and approver identity.
03 / SELF-HOSTED + VPC

Bring the execution plane to the code.

The self-hosted data plane runs inside the customer network. Kubernetes schedules the services, a hardware-isolated runtime executes untrusted review workloads, and customer KMS policy controls envelope encryption and key rotation.

03.1

Kubernetes and Helm parameters

Use a dedicated namespace, restricted service account, private image mirror, NetworkPolicy default-deny, and an admission policy that rejects privileged pods. Pin the chart version and image digests from the signed release manifest.

Reserved registry contract

The registry path below describes the intended release channel. It becomes executable only when your Trust Center record grants access and supplies an approved version.

values.vpc.yaml / minimum boundary
global:
  deploymentMode: vpc
  imageRegistry: "<customer-private-registry>"
  imagePullPolicy: IfNotPresent

controlPlane:
  replicaCount: 3
  networkPolicy:
    defaultDeny: true
    allowedEgress:
      - "<approved-model-endpoint>"
      - "<approved-source-control-endpoint>"

analysisWorker:
  runtimeClassName: kata-qemu
  hardwareIsolationRequired: true
  ephemeralRootFilesystem: true
  automountServiceAccountToken: false
  timeoutSeconds: 900

kms:
  provider: "<aws-kms|azure-key-vault|gcp-kms|local-hsm>"
  keyReference: "<customer-managed-key-reference>"
  rotationPolicy: customer-managed

telemetry:
  sourcePayloads: disabled
  exportMode: customer-controlled
helm upgrade --install codecr oci://registry.codecr.org/charts/codecr --version <approved-version> --namespace codecr-system --create-namespace --values values.vpc.yaml
03.2

Hardware-isolated microVM setup

Route every untrusted checkout and model-assisted remediation task into a runtime class backed by a hardware-isolated virtual machine. Destroy the root disk, memory, network namespace, and derived workspace on completion, cancellation, timeout, or failure.

RUNTIMEKata Containers or approved microVM classNo fallback to the default container runtime.
FILESYSTEMRead-only image + ephemeral workspaceNo host path, persistent volume, swap, or shared cache.
NETWORKDefault deny + explicit destinationsBlock metadata endpoints and arbitrary Internet egress.
TEARDOWNTerminate on every exit pathEmit hashes and decision state—never source payloads.
03.3

Local KMS key management

Customer Security owns key creation, policy, rotation, disablement, and audit review. CodLab receives only the runtime permission required to generate or decrypt a data key for the authorized environment.

  • Separate keys by environment and data classification.
  • Bind use to workload identity and encryption context.
  • Deny direct key export and broad wildcard principals.
  • Alert on policy change, disabled rotation, or decrypt outside the expected runtime identity.
KEY AUTHORITYCUSTOMER
Material
Never exported
Rotation
Customer schedule
Revocation
Immediate customer action
Audit
Customer security log

Acceptance evidence: key ARN or resource ID, policy digest, workload identity, rotation state, last rotation timestamp, and a denied unauthorized decrypt test.

04 / ENTERPRISE INTEGRATIONS

Verify once.
Route inside your boundary.

CodLab delivers a source-free, signed event to a customer-owned HTTPS gateway. That gateway authenticates, deduplicates, classifies, and transforms the event before it reaches incident or communication systems.

04.1

Consume CodLab webhooks securely.

Expose a dedicated HTTPS endpoint, preserve the raw request bytes, and reject the delivery before parsing when its signature, timestamp, or key identifier is invalid. The signing secret belongs in the customer vault; never place it in CodLab policy, application logs, chat tools, or destination URLs.

Contract boundary

Payload examples contain opaque references and decision evidence—not source code, diffs, prompts, credentials, or secrets. Treat evidence_url as an authenticated link, not embedded evidence.

HeaderRequired value
Codecr-Webhook-IdStable delivery identifier; deduplicate for at least 7 days.
Codecr-Webhook-TimestampUTC RFC 3339 timestamp; reject drift greater than 5 minutes.
Codecr-Webhook-Key-IdActive key identifier used during controlled rotation.
Codecr-Webhook-Signaturev1=<base64url HMAC-SHA256>
Codecr-Event-TypeExact event type copied from the envelope.
Codecr-Delivery-AttemptPositive integer beginning at 1.
01CodLabSigns source-free event
02Customer gatewayVerify · replay gate · dedupe
03Internal routerClassify · enrich · redact
04DestinationsIncident + collaboration
signature verification / pseudocode
raw_body = request.body_bytes
timestamp = header("Codecr-Webhook-Timestamp")
delivery_id = header("Codecr-Webhook-Id")
key_id = header("Codecr-Webhook-Key-Id")
provided = header("Codecr-Webhook-Signature")

reject_unless abs(now_utc - parse(timestamp)) <= 300 seconds
reject_if dedupe_store.contains(delivery_id)

secret = vault.read("codecr/webhooks/" + key_id)
signed = timestamp + "." + raw_body
expected = "v1=" + base64url(hmac_sha256(secret, signed))
reject_unless constant_time_equal(provided, expected)

event = parse_json(raw_body)
reject_unless event.type == header("Codecr-Event-Type")
dedupe_store.put(delivery_id, ttl=7 days)
enqueue(event)
return 204
Signature input is the timestamp, one period, then the exact raw body bytes.
ACKNOWLEDGEAny 2xx; prefer 204Acknowledge only after durable internal enqueue or idempotent processing.
RETRY408, 425, 429, 5xxExponential backoff with jitter; use the delivery ID for idempotency.
DO NOT RETRYOther 4xxFix authentication, request size, or schema before redelivery.
04.2

Versioned envelopes. Minimal evidence.

Every event uses a CloudEvents-shaped JSON envelope with an immutable ID, type, source, subject, UTC time, and typed data object. Consumers must ignore unknown fields, reject unsupported major schemas, and never authorize a merge or remediation solely because a webhook arrived.

  • Use the event ID as the incident and delivery deduplication key.
  • Resolve the authenticated evidence URL with a separately scoped identity.
  • Keep merge authority and remediation approval in the system of record.
  • Alert if contains_source_code is anything other than false.
com.codecr.policy.violation.p0
{
  "specversion": "1.0",
  "id": "evt_01J7C6QY0K2M8G5P9R3T4V6W1X",
  "type": "com.codecr.policy.violation.p0",
  "source": "https://api.codecr.org/organizations/org_opaque",
  "subject": "pull_request/github/acme/payments/4821",
  "time": "2026-09-05T18:05:00Z",
  "datacontenttype": "application/json",
  "data": {
    "decision": "blocked",
    "severity": "P0",
    "rule_id": "payments.blast_radius.security_owner",
    "policy_digest": "sha256:7e91...0ac4",
    "repository_ref": "repo_opaque",
    "pull_request": {"provider": "github", "number": 4821, "head_sha": "f4b7c9d..."},
    "blast_radius": {"services": 14, "repositories": 6, "critical_paths": ["payments"]},
    "required_owner": "security-payments",
    "evidence_url": "https://codlab.app/evidence/ev_opaque",
    "contains_source_code": false
  }
}
com.codecr.remediation.triggered
{
  "specversion": "1.0",
  "id": "evt_01J7C72A4N8Q1S6U3Y5Z9B2D0F",
  "type": "com.codecr.remediation.triggered",
  "source": "https://api.codecr.org/organizations/org_opaque",
  "subject": "pull_request/github/acme/payments/4821",
  "time": "2026-09-05T18:06:12Z",
  "datacontenttype": "application/json",
  "data": {
    "correlation_id": "rem_opaque",
    "finding_id": "finding_opaque",
    "requested_by_ref": "principal_opaque",
    "agent": "customer_managed",
    "branch": "codecr/remediate-p0-4821",
    "write_boundary": {"repositories": 1, "paths": ["services/payments/**", "tests/payments/**"], "max_files": 3},
    "required_checks": ["policy_revalidation", "regression_tests"],
    "approvals_required": ["payments-platform", "security-payments"],
    "merge_state": "blocked",
    "contains_source_code": false
  }
}
04.3

Route decisions—not credentials.

After signature verification, map the normalized event inside the customer gateway. Destination credentials remain in the customer vault; CodLab does not receive PagerDuty routing keys, Datadog API keys, Slack webhook URLs, or Teams workflow URLs.

Severity policy

Page on P0 policy violations affecting a critical path. Send remediation triggers to an audit or engineering channel unless the customer’s incident policy explicitly escalates them.

PDPagerDuty Events API v2P0 → TRIGGER

Map the CodLab event ID to dedup_key; set event_action=trigger, payload.severity=critical, and keep the routing_key in the gateway vault.

{
  "routing_key": "<vault reference>",
  "event_action": "trigger",
  "dedup_key": "evt_01J7C6QY...",
  "payload": {"summary": "P0 · payments policy blocked PR #4821", "source": "codecr", "severity": "critical", "custom_details": {"rule_id": "payments.blast_radius.security_owner", "repository_ref": "repo_opaque"}}
}
PagerDuty Events API v2 ↗
DDDatadog Logs or Events APISOURCE-FREE

Submit a normalized log or event after verification. Put the Datadog API key in DD-API-KEY, select the correct regional API site, tag by severity and rule, and exclude source, diffs, email addresses, and destination secrets.

POST https://http-intake.logs.<DATADOG_SITE>/api/v2/logs
DD-API-KEY: <vault-injected key>
Content-Type: application/json

[{"ddsource":"codecr","service":"ai-code-governance",
  "status":"critical","message":"P0 policy blocked",
  "event_id":"evt_01J7C6QY...",
  "rule_id":"payments.blast_radius.security_owner"}]
Datadog Logs API ↗
SLSlack Incoming WebhookCHANNEL-SCOPED

Store the incoming webhook URL as a secret and post a short Block Kit message with the decision, rule, blast-radius summary, and authenticated evidence link. Revoke the URL immediately if it appears in logs.

{
  "text": "P0 policy violation blocked",
  "blocks": [{"type":"section","text":{"type":"mrkdwn",
  "text":"*PR BLOCKED · P0*\nRule: `payments.blast_radius.security_owner`\nImpact: 14 services · 6 repos"}}]
}
Slack Incoming Webhooks ↗
MSMicrosoft Teams WorkflowsHTTP TRIGGER

Create a Workflows flow using “When a Teams webhook request is received,” restrict who can invoke it, then post a message or Adaptive Card. Store the workflow URL as a secret; do not use a public general-purpose relay.

{
  "type": "message",
  "attachments": [{"contentType": "application/vnd.microsoft.card.adaptive",
    "content": {"type":"AdaptiveCard","version":"1.4",
      "body":[{"type":"TextBlock","weight":"Bolder",
      "color":"Attention","text":"PR BLOCKED · P0"}]}}
  ]
}
Teams webhook with Workflows ↗
PRODUCTION ACCEPTANCE
AuthenticationInvalid signature, stale timestamp, unknown key ID, and replay all return non-2xx and create no destination event.
ReliabilityA valid duplicate returns 204 without a second page or chat message; retryable failures preserve the delivery ID.
Data boundaryPayload inspection proves source-free output and destination logs redact all credentials and webhook URLs.
RotationCurrent and next signing keys overlap only for the approved window; removal of the old key is tested and recorded.
05 / PRODUCTION OPERATIONS

Publish once. Verify from every boundary.

The production record is incomplete until DNS, edge TLS, cache state, WAF behavior, security headers, accessibility checks, and regional performance measurements are attached to the deployed version.

05.1

Push saved Version 2 to docs.codecr.org.

Execute the immutable saved-version promotion against the public production hostname. Do not rebuild from a mutable workspace during cutover; the saved Version 2 digest and the last known-good rollback version must already exist in the release record.

Production state

The Version 2 baseline was promoted on 2026-09-05. This Version 3 operator revision records the exact command and the current live-asset verification gate.

SITES PRODUCTION PUSHVERSION 2 · DEPLOYED
release-control instruction
DEPLOY_SAVED_VERSION \
  PROJECT=codecr-docs \
  VERSION=2 \
  TARGET=production \
  HOSTNAME=docs.codecr.org \
  AUDIENCE=public
Accept only: deployment=succeeded · TLS=valid · release digest=recorded

This is a Sites release-control directive, not a shell command. If any post-push gate fails, redeploy the recorded last known-good version; never “fix forward” by weakening TLS or cache-integrity checks.

05.2

Activate docs.codecr.org without ambiguous DNS.

Publish the two verification TXT records first, prove them through independent resolvers, then replace only the conflicting docs address record with the exact Sites CNAME. TTL remains Auto; unrelated apex, mail, and verification records are outside this change.

Strict change boundary

Start the CNAME as DNS-only during hostname validation. Enable Cloudflare proxying only if the approved architecture and the upstream custom-hostname service explicitly support the proxied path; never assume an orange-to-orange route is valid.

HOSTNAME MANIFESTVALIDATION REQUIRED
docs.codecr.org DNS records
TYPECLOUDFLARE NAMECONTENT
TXT_openai-site-verification.docsopenai-site-verification=EYZwpNDHRABS3NS5paO82xoe0aAC2FmU8idcuVC_0zI
TXT_cf-custom-hostname.docsab7477e1-8aa8-4ab3-a326-140847c587b4
CNAMEdocscustom-domains.chatgpt.site.

Exact owners: _openai-site-verification.docs.codecr.org, _cf-custom-hostname.docs.codecr.org, and docs.codecr.org.

  1. 01

    Open the change record. Capture the current zone export, any existing docs A/AAAA/CNAME values, their proxy state, and the rollback owner.

  2. 02

    Publish verification first. Create both TXT records with TTL Auto. Wait until Cloudflare authoritative DNS plus 1.1.1.1 and 8.8.8.8 return the exact values.

  3. 03

    Clear only the collision. A CNAME cannot coexist with another A, AAAA, or CNAME at docs. Remove the recorded conflicting docs value; preserve every unrelated record.

  4. 04

    Create the route. Add docs → custom-domains.chatgpt.site., CNAME, TTL Auto, initially DNS-only.

  5. 05

    Wait for both planes. Require the Sites hostname state and certificate state to be active before application acceptance testing.

  6. 06

    Prove TLS and content. Confirm the SAN contains docs.codecr.org, the chain verifies, HTTPS returns the approved documentation release, and no fallback hostname appears.

resolver + TLS acceptance
dig +short CNAME docs.codecr.org @1.1.1.1
dig +short CNAME docs.codecr.org @8.8.8.8

dig +short TXT _openai-site-verification.docs.codecr.org @1.1.1.1
dig +short TXT _cf-custom-hostname.docs.codecr.org @1.1.1.1

openssl s_client \
  -connect docs.codecr.org:443 \
  -servername docs.codecr.org \
  -verify_hostname docs.codecr.org \
  -verify_return_error </dev/null

curl --fail --silent --show-error \
  --location --output /dev/null \
  --write-out 'status=%{http_code} tls=%{ssl_verify_result} url=%{url_effective}\n' \
  https://docs.codlab.app/
05.3

Purge the changed URLs. Verify the bytes.

Invalidate only the documentation URLs changed by the release unless the release invalidates the entire asset map. A cache status is transport evidence; the SHA-256 digest is the artifact-integrity check. Run the same block from at least three geographically distinct runners because one client cannot select or prove multiple Cloudflare colos.

CURRENT DOCS ASSET DIGESTS
/styles.css
742f80b1d23664723603dba0878427ef9b2e0052907391b131e772b1d30dd456
/app.js
a48319387beaba22fbcec5452ecec2de46b5a35ccac95b1f36e29504b4aacc41
purge exact documentation URLs
CF_ZONE_ID="<codecr.org-zone-id>"
CF_API_TOKEN="<scoped-cache-purge-token>"

curl --fail --silent --show-error \
  --request POST \
  "https://api.cloudflare.com/client/v4/zones/$CF_ZONE_ID/purge_cache" \
  --header "Authorization: Bearer $CF_API_TOKEN" \
  --header "Content-Type: application/json" \
  --data '{
    "files": [
      "https://docs.codlab.app/",
      "https://docs.codlab.app/styles.css",
      "https://docs.codlab.app/app.js"
    ]
  }'
Token scope: Zone · Cache Purge · codecr.org only
sha-256 integrity + observed edge cache status
#!/usr/bin/env bash
set -euo pipefail

DOCS_BASE_URL="${1:-https://docs.codlab.app}"
DOCS_PROBE_REGION="${CODECR_PROBE_REGION:-unlabeled}"
DOCS_VERIFY_DIR="$(mktemp -d)"
trap 'rm -rf -- "$DOCS_VERIFY_DIR"' EXIT

declare -A EXPECTED_SHA256=(
  [styles.css]="742f80b1d23664723603dba0878427ef9b2e0052907391b131e772b1d30dd456"
  [app.js]="a48319387beaba22fbcec5452ecec2de46b5a35ccac95b1f36e29504b4aacc41"
)

for ASSET in styles.css app.js; do
  ASSET_URL="${DOCS_BASE_URL%/}/$ASSET?v=20261006-globe"

  curl --fail --silent --show-error --location \
    --header 'Accept-Encoding: identity' \
    --dump-header "$DOCS_VERIFY_DIR/$ASSET.prime.headers" \
    --output /dev/null "$ASSET_URL"

  curl --fail --silent --show-error --location \
    --header 'Accept-Encoding: identity' \
    --dump-header "$DOCS_VERIFY_DIR/$ASSET.edge.headers" \
    --output "$DOCS_VERIFY_DIR/$ASSET" "$ASSET_URL"

  ACTUAL_SHA256="$(sha256sum "$DOCS_VERIFY_DIR/$ASSET" | awk '{print $1}')"
  if [[ "$ACTUAL_SHA256" != "${EXPECTED_SHA256[$ASSET]}" ]]; then
    echo "FAIL region=$DOCS_PROBE_REGION asset=$ASSET sha256=$ACTUAL_SHA256" >&2
    exit 1
  fi

  CACHE_STATUS="$(awk -F': *' 'tolower($1)=="cf-cache-status" {gsub(/\r/,"",$2); print toupper($2)}' \
    "$DOCS_VERIFY_DIR/$ASSET.edge.headers" | tail -n 1)"
  CF_RAY="$(awk -F': *' 'tolower($1)=="cf-ray" {gsub(/\r/,"",$2); print $2}' \
    "$DOCS_VERIFY_DIR/$ASSET.edge.headers" | tail -n 1)"

  # Integrity is mandatory; edge warmth depends on the hosting layer.

  echo "PASS region=$DOCS_PROBE_REGION asset=$ASSET cache=${CACHE_STATUS:-UNKNOWN} cf_ray=$CF_RAY sha256=$ACTUAL_SHA256"
done
Download executable verification script
FIRST REQUESTMISS, EXPIRED, or REVALIDATED may be valid after purge.
SECOND REQUESTRecord the observed cache status. Warmth is not an integrity check; REVALIDATED or BYPASS can still deliver the exact approved bytes.
INVESTIGATEBYPASS, DYNAMIC, or NONE/UNKNOWN requires policy/header review when caching is expected.
ACCEPTANCEHTTP 200 and exact SHA-256 are mandatory. Record cache status and CF-Ray separately for each probe region.
05.4

Cloudflare edge protocol

Proxy only validated hostnames, enforce Full (strict) where the approved origin architecture supports it, purge changed URLs after publication, and protect the telemetry API with narrow custom controls plus mandatory origin authorization. Never cache authenticated API responses.

CONTROLLED TTL AUTO WINDOWNO BROAD DELETIONS
01
Inventory before mutationExport the zone and query apex plus docs A, AAAA, CNAME, TXT, CAA, and MX records through authoritative DNS.
02
Resolve the exact owner collisionAt docs, retain verification TXT records and replace only a conflicting address/CNAME record. Never delete apex A records required by codecr.org.
03
Observe—not churnWith TTL Auto, wait for authoritative and recursive answers to converge. Do not alternate record values during propagation.
04
Roll back from the recordIf validation or TLS fails after the change window, restore the captured docs value and proxy state; attach the failure evidence.
05.5

Post-publication acceptance record

Execute the checks after the custom domain is active. A single local request cannot prove a global SLA; capture repeated cold and warm measurements from every contracted region and attach the raw results.

01HostnameExact CNAME and both verification TXT records resolve; certificate and Sites state are active.DNS + CONTROL PLANE
02CDN cachePurge changed URLs; confirm expected digest and observed CF-Cache-Status.ZONE ACCESS
03SSL/TLSValid hostname certificate, verified chain, HTTPS redirect, no 526, no loop.EDGE TEST
04PerformanceFive cold + five warm samples per region; approve p95 TTFB only below 1.2s.MEASURE
05AccessibilityKeyboard, focus, reflow, contrast, screen-reader, and 200% text checks completed.MANUAL QA
06RollbackPrevious approved version, DNS value, proxy state, owner, trigger, and recovery objective recorded.CHANGE RECORD