DIREKT Current Integration Status Register¶
Authoritative as-of date: 2026-07-19 (Asia/Tokyo)
Scope: repository kudzimusar/direkt, managed development/staging evidence, live Supabase verification and owner-configured external services
Purpose: prevent external provisioning, source integration and runtime activation from being conflated.
Status vocabulary¶
- ACTIVE — source/configuration and managed execution evidence prove approved runtime use.
- IMPLEMENTED_GATED — application/domain code exists, but real/provider-backed activation remains fail-closed.
- EXTERNALLY_PROVISIONED — account/domain/credential setup exists, but application runtime use is not proven.
- PLANNED — approved direction exists; implementation/runtime binding incomplete.
- DISABLED — intentionally off in the approved environment.
- SUPERSEDED — historical/fallback direction, not the current preferred runtime.
No integration becomes ACTIVE merely because an account, DNS record, API key or secret exists.
Domain and public edge¶
| Integration | State | Current role |
|---|---|---|
direkt.forum |
ACTIVE | Canonical owner-controlled public domain. |
| Vercel Domains | ACTIVE — registrar only | Domain registration; not current protected staging runtime. |
| Cloudflare DNS | ACTIVE | Authoritative DNS edge. |
| GitHub Pages | ACTIVE public static origin | Documentation and synthetic/non-sensitive PWA content. |
| Cloudflare Email Routing | EXTERNALLY_PROVISIONED | Role aliases/support routing; not outbound application delivery. |
| Cloudflare Turnstile | PLANNED / NOT ACTIVE | Future abuse-control challenge. |
Core data/backend infrastructure¶
| Integration | State | Current role |
|---|---|---|
| Supabase PostgreSQL | ACTIVE | System of record behind the API; project aeeuscifrxcjmnswqwnq. |
| PostGIS | ACTIVE | Spatial/service-area foundation. |
| Supabase Storage | ACTIVE infrastructure | Private evidence/media/export storage through server-side grants. |
| Supabase Data API/PostgREST | QUARANTINED | Not a privileged client application path. |
| NestJS DIREKT API | ACTIVE private staging | Canonical REST/OpenAPI trust boundary. |
| Artifact Registry | ACTIVE | Immutable container images. |
| Cloud Run | ACTIVE private staging | IAM-private API and operations portal. |
| Secret Manager | ACTIVE | Runtime secret authority. |
| GitHub Workload Identity Federation | ACTIVE | Keyless GitHub Actions → Google Cloud identity. |
| Cloud Logging/Monitoring | ACTIVE | Current infrastructure/runtime observability. |
| GitHub Actions | ACTIVE | CI, security, release and infrastructure gates. |
Managed Google resources:
Project: direkt-dev-502701 (264358173369)
Region: asia-northeast1
API runtime: direkt-api-runtime@direkt-dev-502701.iam.gserviceaccount.com
Portal runtime: direkt-portal-runtime@direkt-dev-502701.iam.gserviceaccount.com
GitHub deployer: direkt-github-deployer@direkt-dev-502701.iam.gserviceaccount.com
WIF: projects/264358173369/locations/global/workloadIdentityPools/direkt-github/providers/direkt-main
Live Supabase boundary checkpoint¶
Applied migration:
202607191200_integration_runtime_privilege_hardening.sql
sha256=e02d1be228a992b7541db92328e9528b8fe0e184660fb78206ca405e9c7b2372
Verified after apply:
- migration count
39; - browser application-schema usage
0; - browser executable application functions
0; - PUBLIC executable application functions
0; - application
SECURITY DEFINERfunctions0; - all four required Storage buckets remain private.
Supabase advisor warnings for mutable function search_path, extension placement and index opportunities remain explicit hardening/performance debt. They are not evidence of an exposed browser application path.
Android, identity and delivery¶
| Integration | State | Current role |
|---|---|---|
| Native Android | ACTIVE implementation / controlled distribution | Primary customer/provider native client. |
| Firebase project | ACTIVE foundation | Attached to direkt-dev-502701. |
| Firebase App Distribution | ACTIVE | Controlled Android delivery to direkt-internal-testers. |
| Firebase Authentication / phone OTP | IMPLEMENTED_GATED | Phone-possession proof/session exchange behind invite/consent/Phase 11 gates. |
| Firebase Crashlytics | PLANNED / NOT SOURCE-ACTIVE | Future Android crash/ANR option. |
| FCM | PLANNED | Future push delivery. |
| Firebase Test Lab | PLANNED | Future device-matrix automation. |
| Google Play | IMPLEMENTED_GATED | Release engineering prepared; no production release authorized. |
Current merged release manifest permissions:
android.permission.ACCESS_NETWORK_STATE
android.permission.INTERNET
com.google.android.providers.gsf.permission.READ_GSERVICES
com.kudzimusar.direkt.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION
No dangerous runtime permission prompt is currently introduced by these declarations. Location, camera, contacts, SMS/call-log, broad storage/media, microphone and notification runtime permissions remain absent.
Location and maps¶
| Integration | State | Current role |
|---|---|---|
| PostGIS location model | ACTIVE | Canonical location/service-area semantics. |
| Manual area/list fallback | ACTIVE | Provider-independent privacy/accessibility fallback. |
| Google Maps Platform | EXTERNALLY_PROVISIONED / RUNTIME NOT PROVEN | External setup reported; audited source does not prove SDK/runtime activation. |
| Private-coordinate map publication | DISABLED | Exact private provider bases must not become public markers/ranking inputs. |
Maps becomes ACTIVE only after restricted credentials, source integration, privacy terms, quotas, fallback/non-leakage tests and kill-switch evidence agree.
Communications and notifications¶
| Integration | State | Current role |
|---|---|---|
| Transactional outbox | ACTIVE domain foundation | Durable asynchronous-event foundation. |
| Resend | EXTERNALLY_PROVISIONED | Preferred email direction; runtime app-event delivery not yet proven. |
| Brevo | SUPERSEDED | Historical preferred email provider. |
| Firebase phone OTP | IMPLEMENTED_GATED | Current pilot phone-possession direction. |
| Twilio Verify | SUPERSEDED | Earlier OTP candidate. |
| WhatsApp Cloud API | PLANNED / DISABLED | Consent-aware domain handoff exists; production delivery adapter disabled. |
| FCM push | PLANNED | Future event delivery. |
| Cloud Tasks / Pub/Sub / Scheduler | PLANNED | Add only when real retry/fan-out/scheduling needs justify them. |
Resend remains EXTERNALLY_PROVISIONED until an application adapter, runtime secret attachment, outbox/idempotency/retry behavior, privacy/template controls and managed delivery canary exist.
Observability¶
| Integration | State | Current role |
|---|---|---|
| Cloud Logging / Monitoring | ACTIVE | Authoritative infrastructure/runtime observability. |
| Sentry API/portal | EXTERNALLY_PROVISIONED / RUNTIME NOT PROVEN | External setup reported; audited runtime SDK activation not proven. |
| Sentry Android | NOT DEFAULT | Android plan prefers Crashlytics unless a later reviewed decision changes this. |
No telemetry provider may receive raw evidence, tokens, contact data, exact private coordinates or unnecessary free text.
Browser/application surfaces¶
| Surface | State | Current role |
|---|---|---|
| Next.js operations portal | ACTIVE private staging | Privileged operator UI on IAM-private Cloud Run through the API. |
| Vercel portal hosting | SUPERSEDED for current staging | Not the current protected application runtime. |
| Customer/provider PWA | AUTHORIZED REMOTE-TEST CLIENT | Synthetic responsive/installable UI review surface; live API mode separately gated. |
The operations portal has no direct privileged database/Supabase client path. The PWA remains static/synthetic and must not silently acquire privileged API/Supabase access.
Payments and verification authorities¶
| Integration | State | Current role |
|---|---|---|
| Subscription/payment domain | ACTIVE implementation | Products, subscriptions, invoices, intents, ledger and reconciliation contracts. |
| Synthetic payment adapter | ACTIVE tests only | Lifecycle/idempotency testing without real money. |
| MTN MoMo | PLANNED / DISABLED | Candidate future provider. |
| Airtel Money | PLANNED / DISABLED | Candidate future provider. |
| Real money movement | DISABLED | Requires legal/commercial/provider/pilot/release gates. |
| PACRA | MANUAL EVIDENCE SOURCE | Business evidence source. |
| NCC | MANUAL EVIDENCE SOURCE | Contractor/technical evidence where applicable. |
| TEVETA | MANUAL EVIDENCE SOURCE | Training/qualification evidence source. |
| Automated registry APIs | NOT AUTHORIZED | No scraping/fabricated API access. |
API/client contract tooling¶
| Integration | State | Current role |
|---|---|---|
| OpenAPI | ACTIVE | Canonical backend contract generated and drift-checked in CI. |
| Android API boundary | ACTIVE implementation | Backend API only; no privileged direct Supabase path. |
| TypeScript/PWA live API boundary | AUTHORIZED ARCHITECTURE / NOT LIVE | Future live client must use the same REST/OpenAPI trust boundary. |
| Fully generated Kotlin/TypeScript client packages | NOT CURRENT RUNTIME INTEGRATION | Do not falsely claim generated-client adoption until a reviewed client migration exists. |
Phase 0–12 audit checkpoint¶
PR #149 promoted the full integration/runtime audit at 25deaae72ca2974c5560a8059a50fce37c810f63 after exact-head regression checks on e3cddf7645e514d9a6254fff86283d4055d745c4.
Permanent controls now verify:
- server-only Supabase privilege boundaries;
- private Cloud Run/WIF/Secret Manager invariants;
- Firebase gated/active states;
- inactive provider SDKs do not silently enter runtime dependencies;
- portal has no direct privileged data dependency;
- OpenAPI/outbox/payment boundaries remain intact;
- PWA remains synthetic/static;
- Android merged permissions and resolved release runtime dependencies match reviewed inventories.
Detailed evidence: docs/integrations/PHASE_INTEGRATION_RUNTIME_AUDIT_2026-07-19.md and docs/integrations/PHASE_INTEGRATION_AUDIT_CLOSEOUT_2026-07-19.md.
Change-control rule¶
Update this register whenever provider provisioning, source adapter/SDK, secret/runtime binding, managed canary, privacy/legal approval, fallback/kill switch or production authorization changes. External provisioning alone is never enough to mark an integration ACTIVE.