Appearance
Playbooks
Operational playbooks for running this action as a platform team: rolling a baseline out in rings, previewing fleet changes, splitting trust between tokens, producing audit evidence, and handling incidents. Each playbook composes inputs and sections that the README documents individually; the multi-repo guide covers the underlying mechanics. All of these work with the action as it is today.
- A fleet security baseline, rolled out in rings
- Preview the blast radius of a fleet change
- A cloud OIDC trust contract
- Private-fork PR containment
- Trust tiers: read-only preview, gated apply
- Drift attestation for auditors
- Access through teams, not direct collaborators
- Incident freeze and unfreeze
- Sunset and decommission