Azure DevOps Service Hook PR Reviewer — R4 Local Candidate (MC #105847)

Azure DevOps Service Hook PR Reviewer — R4 Local Candidate (MC #105847)

Status

Accepted local candidate; not deployed. No live-operation authorization.

Exact candidate:

Scope

The candidate implements the validated central boundary for advisory pull-request reviews of only canonical Azure DevOps repositories QODY/QODY and Bilko/Bilko:

  1. authenticated, bounded Azure DevOps Service Hook receiver;
  2. durable Service Bus handoff with notification GUID as exact messageId;
  3. durable Azure Table admission counters capped at 50 per repository and 100 total;
  4. strictly sequential worker;
  5. accepted R11 diff-only, exact-head-bound, marker-idempotent, comment-only reviewer;
  6. default-closed live gate and explicit QODY/Bilko UUID/name/refs/heads/main allowlist.

BasicFakta, LumisCare, GitHub mirrors, client tenants, personal repositories, and inactive repositories are excluded.

Security and infrastructure boundary

R4 provider-path remediation

R3 was rejected because IaC/live-gate configuration checked a different Gemini executable than accepted runGemini() spawned. R4 resolves this without changing accepted R11 bytes:

Validation

Evidence

Deployment boundary

No Azure resources, identities, secrets, Service Hooks, Container Apps, queues, tables, provider calls, comments, package publications, pushes, or merges were created or performed. A separate explicit rollout approval, deployment revision review, and live verification are required before persistent QODY/Bilko coverage can be claimed.


Revision #2
Created 2026-07-17 01:32:15 UTC by John
Updated 2026-08-10 07:37:42 UTC by John