Configure Enterprise Provider
Build a least-privilege integration that prepares an exact PR/MR for human review. The code host and human own checks, approval, and merge; issue-spec does not model or execute that authority.
Safety boundary
- Keep internal domains, repository names, identities, paths, credentials, deployment details, logs, and screenshots out of public repositories.
- Use
example.testplaceholders in committed documentation and tests. - Keep executable paths and credentials only in operator-owned private
configuration, never repository
issue-spec/config.yaml. - Advertise only operations that have real handlers and non-production contract tests. Missing operations limit that action; they do not make the repository planning-only and do not block unrelated Runner work.
Workflow
Read integration-surfaces.md and record one owner for issues, code changes, Git transport, and work-item projection.
Select only the integrations actually needed:
- OIDC for login;
- Source Binding for canonical repository coordinates;
issue-spec.code-provider/v1for PR/MR creation, ordinary discussion, or optional evidence snapshots;git-credential-v1or trusted host SSH for Runner clone/push;- a separate adapter for a Jira-like work tracker.
Keep issue-spec Server authoritative for issues, typed planning artifacts, Change status, and Runner commands. A work-tracker adapter is never placed in the code-provider registry. Read work-tracker-adapter.md before adding it.
Scaffold only required provider operations:
python3 .agents/skills/configure-enterprise-provider/scripts/scaffold_provider.py \ --provider-key code.example \ --display-name "Example Code" \ --remote-authority git.example.test \ --capability change.create \ --capability change.comment \ --output "$HOME/.config/issue-spec/providers/code.example"Treat the scaffold as inert. Read wrapper-mapping.md, implement and contract-test each selected handler, then copy only implemented capabilities into both
provider_bridge.pyandproviders.json.Store
providers.jsonas a private operator file. Point Server and relevant CLI processes to it withISSUE_SPEC_CODE_PROVIDERS_FILE, or use the self-hosted profile'soperator_registry_file. Keep the same description on both sides.Configure Source Binding with credential-free canonical HTTPS clone and web URLs. Run
issue-spec init --planbefore any remote or repository write.Validate registry safety and the exact runtime capability handshake:
python3 .agents/skills/configure-enterprise-provider/scripts/validate_provider.py \ --registry "$HOME/.config/issue-spec/providers/code.example/providers.json" \ --provider-key code.exampleValidation deliberately performs no snapshot, comment, create, review, or merge action. Exercise every advertised operation separately against a non-production repository at an exact revision.
Verify timeouts, output bounds, secret redaction, idempotency, stale-head and reference mismatch rejection, canonical URLs, and upstream failure behavior.
Report architecture, files, operator configuration, validation, remaining limitations, rollback, and the exact PR/MR handoff boundary. Sanitize public output.
Required checks
- Registry is strict JSON, absolute, private, and contains no secret values.
- Bridge emits one strict response and echoes protocol/request identity.
- Runtime and operator-described capabilities match exactly.
change.createreturns the created change reference and canonical URL for the pushed head; retries cannot create unrelated duplicate changes.change.commenttargets the exact existing change and head and remains an ordinary non-blocking human review aid.- Optional
evidence.snapshotis exact-head audit/navigation data only; it is not delivery acceptance or merge authority. - Source Binding contains coordinates only, never credentials.
- Runner Git credentials are isolated from provider API credentials.
- The workflow stops after reporting exact head, change link, tests, rationale, risks, and limitations. Approval and merge stay in the provider UI.
Product references
- User guide:
docs/self-hosting/enterprise-provider-integration.md - Code bridge wire contract:
docs/self-hosting/bridges/code-provider-v1.md - Runner credential contract:
docs/self-hosting/bridges/git-credential-v1.md - Authentication:
docs/self-hosting/authentication/README.md - Work-tracker adapter: work-tracker-adapter.md