rdmsm4x-changelog-20260828-1831-tyrell-cloudkit-metadata-foundation
Added a private, metadata-only CloudKit projection foundation so Tyrell can later expose truthful fleet, agent, MCP, coordinator, health, and lifecycle presence to signed macOS and iOS clients without syncing content or secrets.
Tyrell CloudKit metadata foundation
- Host:
rdmsm4x - Scope: local isolated Tyrell worktree only; no live CloudKit, schema, account, deployment, canonical-root, or fleet-host mutation.
- Worktree:
/Users/richh/dev/_worktrees/tyrell-cloudkit-hour-20260828 - Branch:
codex/tyrell-cloudkit-hour-20260828 - Commit:
3e03408bebb723f02a7831340eb0e58b3c627fca
Files changed
Package.swiftSources/TyrellCloudKit/CKContainerCloudProjectionStore.swiftSources/TyrellCloudKit/CloudProjectionModels.swiftSources/TyrellCloudKit/CloudProjectionStore.swiftSupport/TyrellApp.entitlementsTests/TyrellCloudKitTests/CloudProjectionTests.swiftdocs/status/2026-08-28-tyrell-cloudkit-metadata-foundation.mdios/Sources/MobileCloudProjectionFactory.swiftios/Tests/TyrellMobileTests.swiftios/project.yml
What changed
- Added typed versioned projections for nodes, canonical
agent@hostnameidentities, MCP connections, coordinator authority, health/freshness, and content-free audit lifecycle events. - Added an exact field allowlist, bounded metadata identifiers, complete lowercase SHA-256 evidence pointers, account-lane isolation, and explicit available/partial/offline/unavailable/failed states.
- Added a private
CKContaineradapter foriCloud.com.eastcoastscience.Tyrell, an in-memory implementation, and an unavailable implementation for unprovisioned processes. - Added an entitlement-gated iOS factory so unsigned simulator tests do not initialize CloudKit without provisioning.
- Added matching source entitlements for iOS and macOS. The macOS entitlement is intentionally not wired into signing until provisioning is independently verified.
Commands and verification
swift test --filter TyrellCloudKitTests— passed 15 tests.swift test— passed the complete repository Swift test suite.xcodegen generate --spec project.ymlfromios/— generated the project successfully.- Focused
xcodebuild ... test CODE_SIGNING_ALLOWED=NOon iPhone 17 Pro Simulator — passed. - Generic iOS Simulator
xcodebuild ... build-for-testing CODE_SIGNING_ALLOWED=NO— passed. plutil -lint Support/TyrellApp.entitlements ios/TyrellMobile.entitlements— both valid.git diff --check— passed.- Path-only secret-pattern scan of changed task files — zero matching files; no secret values were printed.
- Worktree status after commit — clean.
Backup and undo
- Before commit:
42e9287a7d79548b7b41f61f3f9c3ce1099c731b. - After commit:
3e03408bebb723f02a7831340eb0e58b3c627fca. - The isolated branch and worktree are the rollback copy. To omit the
change, do not integrate commit
3e03408; if it has been integrated, revert that commit with a new commit after coordinating with the integration owner.
Outstanding owner actions
- Review and integrate the isolated commit; reconcile any concurrent
Package.swiftorios/project.ymledits. - Confirm Apple Developer team, App IDs, provisioning profiles, and container access for each signed bundle.
- Create and canary the allowlisted development schema only after separate authorization; do not promote production schema implicitly.
- Designate one signed writer per account lane, validate with an approved private test account and physical device, and record integration, signing, canary, schema promotion, device acceptance, and fleet rollout separately.