docs: accept central extension update architecture

This commit is contained in:
inman committed 2026-09-03 16:17:11 +08:00
1 parent 322475860a
commit efc342c626
10 files changed
+132 -16

No files matched your search

@@ -12,6 +12,7 @@
| NETWORK-001 | In the trusted internal deployment, AgentBus roster attachment URLs may resolve to internal/private addresses; HTTPS, credential rejection, DNS pinning, redirect validation, bounds, and digest checks remain. | Active | 2026-08-31 | AgentBus attachment ingress | [Reply contract](../../agent设计规范/agentbus-reply-contract.md) |
| AUTH-001 | The fixed deployment scope uses administrator-managed `admin`, `team_lead`, and `user` accounts, owner-isolated normal tasks, display-only leadership metrics with explicit filtering, explicit non-admin route grants, and assignee-bound AgentBus/browser/ERP execution. | Active except clauses superseded by AUTH-002 | 2026-09-01 | Authentication, authorization, audit, AgentBus workers, and operations oversight | [ADR](AUTH-001-fixed-scope-account-authorization.md) |
| AUTH-002 | ERP execution is serialized per immutable assigned account, administrator visibility is never execution routing, and explicit force delete physically removes authorized tasks regardless of lifecycle state. | Active | 2026-09-03 | ERP claim queues, executable events/results, and task removal | [ADR](AUTH-002-account-scoped-execution-and-force-delete.md) |
| EXT-001 | The separate central control plane publishes private OSS extension releases and uses bounded ECS Cloud Assistant commands to update shared unpacked-extension files only while every mapped account is idle; target-version browser heartbeats are required before ERP execution resumes. | Active | 2026-09-03 | Chrome extension release, Windows host update, and ERP claim safety | [ADR](EXT-001-central-service-host-extension-updates.md) |
## Superseded Decisions