Task · GCV-0032

Vend into multiple Grafana Cloud organisations

Description

Every stack request today lands in exactly one Grafana Cloud organisation. organizationProviderConfigName is a single scalar in the stack Composition pipeline input, read once into platformSettings and used for every organisation-plane child: the Stack itself, its service account, the rotating token, the stack-realm access policies and plugin installations. The XRD also carries enforcedCompositionRef, so a second Composition is not available as a workaround. One organisation credential, one remote secret path, no selector anywhere.

A platform team running more than one Grafana Cloud organisation therefore cannot use this reference at all, and organisation choice is not a property a stack can acquire later: a Cloud stack belongs to the organisation that created it and cannot be moved.

Note the constraint recorded on the promotion-ladder task is about a stack belonging to one organisation, which stays true. It does not say a vending machine cannot serve several, and the README must not read as though it does.

The organisation is a platform-owned routing decision, not free-form request input, so the request names an organisation and the platform resolves it against a registry it owns. An unknown name must fail closed rather than fall through to a default.

Acceptance Criteria

Definition of Done

Implementation Plan

Wave 2 root plan: re-pin and verify the provider release identity; implement the required immutable organization seam, platform registry, fail-closed routing, organization-segmented secret path, catalogs, AWS examples, shared product/profile/input seams, split API registries, and pre-register compiling renderer stubs; run the full gate; commit and push with explicit pathspecs before dispatching lanes A-J.

Implementation Notes

Wave 1 disposition, 2026-09-08: Parked before implementation. The requested operational root route was gpt-5.6-sol at high effort, but the generic spawn exposed only its task name and no role, model, or effort metadata. Section 4.1 requires a hard stop when route metadata is missing. The actual clean starting head was 9af868e2b574bb13da11fbf81d81407593cb8366, aligned with origin/main, and hosted validation run 34213680492 passed at that exact SHA. Resume only in a client session that exposes and confirms the root model and effort; then re-read the wave goal, reconcile the recorded starting-state drift, and begin at section 5.0 step 2. No acceptance criterion or Definition of Done item was checked, and no implementation file or external service was changed.

Wave 2 verification: fail-closed registry and namespace-resolution tests passed; provider v2.14.0 and the published function digest were Cosign-verified. Final local just check passed, and hosted Validate run 34233686654 succeeded at 83f81afee7526fd6e7c4ec0a47675774d00036b8.

Final Summary

Delivered immutable multi-organization vending, registry-routed organization children, organization-segmented secret paths, the signed v2.14.0 provider, and the signed function pin. Completing SHA 83f81afee7526fd6e7c4ec0a47675774d00036b8; hosted Validate run 34233686654 succeeded.

View the source file on GitHub