ADR-013: GitHub Container Registry (GHCR) as Container Registry
Use GHCR for all Docker image storage and distribution
Use GHCR for all Docker image storage and distribution
Accept docker-group deploy-user risk (audit #392) until we migrate to a managed container platform; remove the brittle sudoers-allowlist mitigation introduced in sv0-platform PR #401.
Operationalises ADR-022 §3 (Phase 3f) for the dev tier: the stable demo VM at dev-azure.securityv0.com deploys on every main CI success via Azure Run Command using a new tightly-scoped Entra app + OIDC federation from GitHub Actions. No SSH key in the deploy path. Hetzner stays warm as fallback during cutover (no behavior change on the Hetzner side). PR-preview ephemeral VMs are explicitly out of scope; the design for that surface is banked in [docs/infrastructure/azure-ephemeral-pr-previews-design.md](../../infrastructure/azure-ephemeral-pr-previews-design.md) for re-activation when triggered.
Comprehensive CI/CD strategy for sv0-platform deployment and sv0-connectors scan pipelines, including secrets management evaluation (GitHub Secrets, SOPS+age, Tailscale, Vault, Doppler, self-hosted...
Partner integration strategy for Deloitte — deployment options, data residency, licensing, IP protection, and operational model
Deployment strategy options for SecurityV0 from MVP to production scale, including container orchestration paths, observability/logging tradeoffs, CLI operability, and CI/CD automation
Canonical inventory of every GitHub Environment / repo secret used by sv0 deploys, CI, and tooling. One row per secret: name, repo, scope, exact workflow files that consume it, purpose, status. Includes a VM ↔ secret mapping for migration planning.
Step-by-step plan to create a Hetzner Cloud instance and deploy sv0-platform (API + UI + MongoDB) from local machine
Architecture of the PR-preview instance system on the dev server — instance lifecycle, port allocation, Caddy routing, protected instances, and idle cleanup
Records the git tag 'pre-w1.1-architecture' across all three repos, marking the stable baseline before W1.1 implementation begins
Operational runbooks covering team workflow, deployment, connector operations, and incident response for SecurityV0 platform