Dashboard › institutional-transition-lab › Distillation
c25291e4-d69e-42ab-b52b-28aaff614b7e["lore_tm_v1_ftpykfZR3-_UNkyaVFZqZ55Oi0c6ArdtP2eZI_cvtpU","lore_tm_v1_yo-H02LZiG8ly24QvFlR7x4e-_SwoJdpgNN4nKuMAdw","lore_tm_v1_pRtKzpntk9eLKsGg1xiGv5PtXaRQO2kdKgreg9hQZGs","lore_tm_v1_lMBgmXWHXuNsMwf5PEy60rqIsCHJNjl8_fvxk5mE5q0","lore_tm_v1_JA8pCkmpzHmjzcL0-53VM2tdClCSeFTldOVLHnQapSw","lore_tm_v1_y5coodQxWCOFU8SI5XtFmMtKuS4d4NQFyBeR1wozSS8","lore_tm_v1_kjIgzEGQhUyLTPuNS8G1jknEXyUB0l0Xfcu3s7KiqEY","lore_tm_v1_Mfh3ccWXE_aEeepsb2S2I9a9GWw_eEXinyESsKisl80","lore_tm_v1_iPd6aHW3ipkvCZidFGIHM7d62wd4FDZJ9iRdtvirQCk","lore_tm_v1_0AVEMDGY-KJt-GADpy0NdCUKzIO15UXkvp7_vO0XEqE"]
-target applies in some circumstances to complete changes in a specific area.vpc_flow_logs.ignore_changes limits some detected updates, but Terraform targeting can still refresh dependencies and then change resources outside the intended target.terraform plan, verify that changes affect only resources from the original -target, and apply only if that check succeeds.terraform-github-issue-22468, titled “Terraform really needs a way of securely targetting,” concerns Terraform 0.11.14 and requests a strict -target mode that fails gracefully if the planned operation goes outside the target. Its example targets a vpc_flow_logs resource associated with a shared-ownership VPC that has governance requirements.terraform-github-issue-34139 reports Terraform 1.6.0 x64 failing to retrieve azuread_access_package_assignment_policy.this[0] with HTTP 403 and OData UnAuthorized: User is not authorized to perform the operation; the configuration uses depends_on for azuread_access_package.this, azuread_access_package_resource_catalog_association.this, and azuread_access_package_resource_package_association.this.terraform-github-issue-34139, the Azure DevOps pipeline service role has Identity Governance Administrator and Directory.ReadWrite.All; catalogue and AAD-group creation succeed, but access-package policy association fails as unauthorized. The expected order is resource-catalog association creation, resource-package association creation, then assignment-policy creation.opentofu-github-pr-2953 changed 43 files, base 3c170157023ac1290c89567ce432c35aa185099a, head 5f5705b8947cd62834733e6c20635d8d13a616dd, merge commit 75bf1c2f65ad4baabd51a5e88873f805f5b2a1c7; it was merged and closed at 2025-06-25T17:50:10Z. Its body says references were updated and governance material moved to the new opentofu/org repository.opentofu-github-pr-2959 changed 1 file, base 0afbaae42d70c49159f25bac5a95f94f7048a17c, head 6c1afd075a69497c77a5341eb47162aeacb8f67f, merge commit b82ed64756670f0ff54f034120d1e71aefa21358; it was merged and closed at 2025-06-25T15:47:24Z. The PR updates CODEOWNERS for the new governance chart because the new team is opentofu-maintainers.opentofu-github-pr-3473 changed 1 file, base a961f737b7938f51a52202fdc6de5a2917b3c250, head 3679fe6fa8e9cbcacbd5a0904f937a41151aa16a; it remains open and unmerged. The RFC proposes a Databricks backend with locking to reduce IaC friction for data practitioners and provide unified governance over the state file.opentofu-github-pr-3559 changed 1 file, base 1907ce104cbd6ec9a60e347b973b0f262eb4d43b, head d06503ad9f725637a690bf9348bcff1f6ade528f, merge commit b2c6b935e06bfca47662792e7f71a7df8a6a36ad; it was merged and closed at 2025-12-09T17:53:08Z. The PR updates the support policy in RELEASE.md following the 09-12-25 @opentofu/technical-steering-committee meeting.opentofu-github-pr-4018 changed 7 files, base 34e03c9fc38eb1b290e7db57537e42506aca1c28, head 38a52bc2038c180c9ca1859c8ff2e2fb24a6326f, merge commit 82676082728b0dc5fb14552f2a663850d7422817; it was merged and closed at 2026-08-11T20:53:09Z.opentofu-github-pr-4018 implements a compromise for forthcoming termination of official 32-bit support: 1. introduce “official builds,” activated by an extra environment variable set only in the GitHub Actions release workflow, because third-party distributors might reuse .goreleaser.yml but are less likely to reuse the GitHub Actions workflow; 2. for official builds only, have tofu init warn on 386 or arm, choosing init because it is run less often and is less annoying than warnings on every tofu plan or tofu apply. The PR intends not to prevent third parties such as Linux distributions from continuing their own 32-bit builds.opentofu-github-pr-727 changed 1 file, base 913578a9f45acebbb2c35279925e475ff839c14b, head 8e98cd47b7dccb37b6ac437680d18a50d81bc7f6, merge commit 131b15c45e373c743648b0059d022b58b2f53251; it was merged and closed at 2023-10-15T08:04:41Z. The non-user-facing enhancement added the missed license to compare-release-versions.sh.opentofu-github-pr-823 changed 1 file, base b2069bb0bbfc7dd121a5d72613bb71ca12375405, head f449ce3afb8fe0bc1866291652348499c20d35ae, merge commit 60a3f72d43c002f83246e657a15b9b2157fd74c6; it was merged and closed at 2023-11-06T11:21:40Z.opentofu-github-pr-990 changed 1 file, base 5fc6ba240dbbe6ecc3643040150686f88e223583, head 7db41d4cfbbd4c54cfd9db70c3d58282a0118bb3, merge commit 6b864ef262d6b924d94a61a0e1e29ff27b834a02; it was merged and closed at 2023-12-11T11:52:31Z./home/byk/Code/institutional-transition-lab/schema/governance-adjudication-v1.schema.json defines provenance fields workflow_run_id and artifact_id as integers with minimum 1; artifact_sha256, documents_sha256, documents_file_sha256, coding_package_file_sha256, protocol_sha256, coding_schema_sha256, and adjudication_schema_sha256 use a lowercase 64-character SHA-256 pattern ^[0-9a-f]{64}$.reviewer object requires exactly reviewer_id, reviewer_type, model, role, and assistance; reviewer_type is one of human, llm, or human_llm_assisted, and role is one of source_adjudicator, evidence_auditor, or synthesizer.claim_evidence_ref requires exactly field, source_id, and quote; field must be one of record_class, event_kind, title, announced_on, effective_on, affected_scope, or body_patch_relation.power_change requires exactly actor, right_kind, target, direction, change_status, scope, and evidence_refs. Allowed right_kind values are appoint, remove, elect, vote, delegate, override, approve, merge, write, release, veto, own, license, steward, fund, set_budget, set_strategy, set_policy, set_membership, set_terms, and inform; direction is added, removed, or modified; change_status is effective, announced, proposed, rejected, or unclear; evidence_refs requires at least 1 item.coding object requires record_class, event_kind, title, announced_on, effective_on, affected_scope, body_patch_relation, power_changes, confidence, and ambiguity. record_class allows effective_institutional_change, announced_institutional_change, proposal_only, control_event, no_event, or abstain; event_kind allows leadership, board_or_steering, control_rights, reorganization, foundation_transfer, license, fork, reunification, strategy, product, external, or null; body_patch_relation allows consistent, patch_supersedes_body, body_only, patch_only, conflict, not_applicable, or unclear; confidence ranges from 0 to 1.edge_revision requires basis, added, and removed; basis is luna_a, luna_b, terra_advisory, or null, while added and removed are arrays of power_change.evidence_bounds requires source_text_truncated, files_listing_complete, patch_selection_truncated, and patch_unavailable_count; the last is an integer with minimum 0. source_audit requires inspected_before_codings equal to true, at least one unique source_id, and evidence_bounds.record in /home/byk/Code/institutional-transition-lab/schema/governance-adjudication-v1.schema.json requires exactly the fields record_id, source_url, decision, accepted_from, reviewer_ids, source_audit, rationale, evidence_limitations, unresolved_reason, claim_evidence_refs, final_coding, and graph_edge_revision. decision is accept, revise, reject, or abstain; accepted_from is luna_a, luna_b, terra_advisory, or null; final_coding and graph_edge_revision may each be null.opentofu-github-pr-2953, published 2025-06-24; 2. opentofu-github-pr-2959, published 2025-06-25; 3. opentofu-github-pr-3473, published 2025-11-05; 4. opentofu-github-pr-3559, published 2025-12-09; 5. opentofu-github-pr-4018, published 2026-04-09; 6. opentofu-github-pr-727, published 2023-10-14; 7. opentofu-github-pr-823, published 2023-11-05; 8. opentofu-github-pr-990, published 2023-12-10; 9. terraform-github-issue-22468, published 2019-08-14; 10. terraform-github-issue-34139, published 2023-10-25. The first 8 are github_pull_request sources from opentofu/opentofu; the final 2 are github_issue sources from hashicorp/terraform.2023-11-02 names attendees Igor Savchenko (@DiscyDel, linked as DicsyDel), Marcin Wyszynski (@marcinwyszynski), Roger Simms (@allofthesepeople), and Roni Frantchi (@roni-frantchi); absent were Yevgeniy Brikman (@brikis98) and Omry Hary (@omry-hay).2023-11-02 TSC summary records unanimous selection of the “Homebrew-like artifact resolution registry component” RFC (opentofu/opentofu#741). Reasons were to keep the core team focused on the CLI rather than operating highly available mission-critical SaaS, maximize availability using GitHub/AWS, retain Git-repository transparency, and decouple artifact resolution from documentation serving and artifact signing so each component can evolve under its own non-functional requirements.2023-11-02 TSC summary says launch signing security would match the legacy registry while leaving room for later enhancements; the core team would not yet pursue a user-facing registry/documentation design. Action items for @RLRabinowitz and @cube2222 were: 1. announce the chosen RFC ASAP; 2. investigate implementation details, specifically 2.1 whether to scrape existing modules/providers and keys, 2.2 key-submission design, 2.3 version-bump design, 2.4 sharing the detailed design document, and 2.5 defining scope and task breakdown for the core team.2023-11-02 TSC summary proposes weekly recurring meetings on Thursdays at 7:30PM CET, with exact time pending as an action for @allofthesepeople; agenda suggestions must be posted at least 24h in advance or the meeting is cancelled.2023-11-02 TSC summary records a founders’ decision to hire core-team members through pledging companies’ payroll and donate their time rather than use direct foundation payroll; Spacelift had hired 2 dedicated maintainers and built a Tofu-specific profile and hiring pipeline to share with other interested companies.opentofu-github-pr-727: luna_a and luna_b both classify it as effective_institutional_change, event_kind: "license", title “Added MPL-2.0 license to compare-release-versions.sh,” announced 2023-10-14, effective 2023-10-15, body_patch_relation: "consistent", confidence 0.98, with an added license right for compare-release-versions.sh grounded in the body and patch quote # SPDX-License-Identifier: MPL-2.0. terra_advisory instead classifies it no_event, with affected scope .github/scripts/compare-release-versions.sh, confidence 0.99, and no power changes.opentofu-github-pr-2953 are all abstain: luna_a confidence 0.7, luna_b 0.58, and terra_advisory 0.42. All identify governance-document relocation to opentofu/org; the limiting issue is that a 43-file PR has truncated/omitted patch evidence and the visible relocation does not establish an organizational-rights change.opentofu-github-pr-2959 are all abstain over CODEOWNERS and opentofu-maintainers: luna_a confidence 0.72, luna_b 0.86, and terra_advisory 0.45. The shared limitation is that the implementing patch is absent, so the actual rights change and effective scope cannot be verified.opentofu-github-pr-3473: luna_a classifies it as control_event, event_kind: "product", title “RFC for Databricks backend with locking,” confidence 0.97; luna_b also uses control_event/product, title “Databricks backend with locking RFC,” confidence 0.98; both use announced date 2025-11-05, no effective date, and no power changes. terra_advisory is null.opentofu-github-pr-3559 differ: luna_a says no_event, confidence 0.7, because no patch or rights change is shown; luna_b says control_event/product, effective 2025-12-09, confidence 0.78; terra_advisory says control_event/product, announced 2025-12-09, body_patch_relation: "body_only", confidence 0.68. All have no power changes.opentofu-github-pr-4018: luna_a and luna_b classify it as a control_event/product concerning official-build detection, announced 2026-04-09, effective 2026-08-11, with confidences 0.9 and 0.84; their limitation is that official-build detection is shown but not the warning-generation code. terra_advisory instead classifies it as proposal_only/control_rights, confidence 0.84, with a proposed removal of the OpenTofu project’s release right for official 32-bit CPU packages, grounded by “ending official support for 32-bit CPU architectures” and “The maintainers have not discussed this yet, and so we might decide to do something quite different in the end.”opentofu-github-pr-823 all use control_event/strategy, no power changes, and concern TSC registry strategy: luna_a confidence 0.94, title “TSC selects RFC for a registry solution”; luna_b confidence 0.95, title “TSC selected an RFC for a registry solution”; terra_advisory confidence 0.9, title “TSC selected registry RFC and deferred user-facing registry design,” noting no demonstrated organizational authority change.opentofu-github-pr-990 all use control_event with no power changes: luna_a uses event_kind: "strategy" and confidence 0.94; luna_b and terra_advisory use event_kind: "product", confidences 0.88 and 0.91, and describe a TSC decision to change the default registry namespace to opentofu, while noting the supplied patch documents but does not implement the change.terraform-github-issue-22468: luna_a and luna_b both classify it no_event, body_patch_relation: "not_applicable", no power changes, with confidences 0.96 and 0.98; luna_b titles it “Request for securely targeting Terraform changes.” terra_advisory is null.terraform-github-issue-34139: luna_a classifies it as control_event/product, affected scope “Terraform Azure access package assignment policy deployment,” confidence 0.98; luna_b and terra_advisory classify it no_event, confidence 0.99, with titles “Azure access package association returns 403” and “Azure access package association.” All use body_patch_relation: "not_applicable" and no power changes./home/byk/Code/institutional-transition-lab/tests/test_governance_adjudication.py includes test_accept_edge_revision_uses_the_accepted_response(), which changes graph_edge_revision["basis"] to "luna_b" and expects an error containing accept revision basis must equal accepted_from plus canonicalization_gate == "closed".test_institutional_claims_require_grounded_claim_and_edge_evidence() inserts the quote "invented" into both claim_evidence_refs and a power-change evidence_refs, sets graph_edge_revision to {"basis": "luna_a", "added": [], "removed": []}, and expects a not grounded error with the canonicalization gate closed._institutional_adjudication(record_class) maps effective_institutional_change → effective, announced_institutional_change → announced, and proposal_only → proposed; it creates a revised coding titled “Council gains release approval,” with actor The council, right_kind: "approve", target releases, direction added, scope project releases, and grounded quote The council may approve releases. Its graph revision has basis: None, adds a deep copy of the final power changes, and removes none.test_institutional_class_and_edge_status_must_agree() tests mismatched pairs effective_institutional_change/proposed, announced_institutional_change/effective, and proposal_only/effective, expecting an error containing does not permit edge status and a closed canonicalization gate.test_gemini_cannot_adjudicate_or_assist() sets reviewer model to google/gemini-3.7-flash and expects Gemini is restricted to event triage plus canonicalization_gate == "closed".