Task · GCV-0052

Vend Frontend Observability apps

Description

frontendobservability apps is a three-CRD group in the pinned provider with nothing vended. It is the Faro surface: a vended stack cannot receive browser telemetry until somebody creates an app by hand and pastes its key into a frontend build.

Small and self-contained, which is why it is tracked separately rather than folded into a larger surface. The only real design question is credential handling: the app key is what a browser bundle carries, so the machine has to be explicit about what is published and what is not.

Acceptance Criteria

Definition of Done

Implementation Plan

Wave 6: implement the commissioned surface under the frozen goal and root-owned integration; prove admission and renderer boundaries with required negative controls, then just check and exact-SHA hosted Validate before finalization.

Final Summary

Vended Faro apps using the trusted organization Cloud client and explicit observed identity retention. The browser-visible app key boundary is documented and tested; no management token is published. Singleton stack ownership and immutable stack reference are admitted. Complete provider schema and inert catalog checks passed; no browser telemetry receipt is claimed. Completing source/pin SHA: 187b03ea40ee32fcea890e40c138f00a8c73bd5f. Hosted Validate run 34296536930: success. Local just check passed with 23 real API-server tests, zero skips.

View the source file on GitHub