pub struct Mission {Show 16 fields
pub id: String,
pub goal: String,
pub validation_contract: Vec<Assertion>,
pub milestones: Vec<Milestone>,
pub status: MissionStatus,
pub created_at: DateTime<Utc>,
pub base_branch: String,
pub base_sha: Option<String>,
pub mission_branch: String,
pub command_grants: Vec<String>,
pub touch_set: Vec<String>,
pub deny_exceptions: Vec<String>,
pub egress_grants: Vec<String>,
pub executor_route: Option<ExecutorRoute>,
pub standards_manifest: Option<StandardsPin>,
pub reviewer_independence: Option<ReviewerIndependence>,
}Fields§
§id: String§goal: String§validation_contract: Vec<Assertion>Defined BEFORE features (plan §2.3).
milestones: Vec<Milestone>§status: MissionStatus§created_at: DateTime<Utc>§base_branch: Stringe.g. “main”
base_sha: Option<String>Base-branch commit SHA pinned at plan approval; None until approved
or for missions created before this field existed.
mission_branch: Stringe.g. kranz/mission-<id>
command_grants: Vec<String>Read-only shell commands granted mission-wide to worker AND validator
sessions; single source of truth carried from the approved Plan.
touch_set: Vec<String>Gitignore/glob-style repo-relative path patterns the mission is
allowed to touch; single source of truth carried from the approved
Plan.
deny_exceptions: Vec<String>Worker deny rules (e.g. Bash(git push*)) an operator has LIFTED for
this mission via a WorkerDeny grant — subtracted from the worker deny
set by permissions::for_role. Extend-only, runtime-only (never plan-
declared): a deliberate, logged erosion of a safety guardrail.
egress_grants: Vec<String>Egress destinations (host:port) an operator has GRANTED for this
mission — folded into the egress proxy’s allowlist for fs+net
sessions (crate::egress_proxy). Extend-only, runtime-only (never
plan-declared): the fold target a GrantKind::Egress approval extends;
read into the proxy allowlist at spec build so that approval needs no
plumbing change.
executor_route: Option<ExecutorRoute>The executor route this mission was seeded with (ticket
routing-rules-config): derived at fold time from mission.created’s
original folded goal + routed config (crate::routing::seed_executor_route)
— plan.approved overwrites goal with the plan’s own, so the task
class exists only on that first event and the decision is folded here
once, then replayed onto every worker.spawned. None when the seed
carried no task class; additive (absent in pre-existing state
snapshots). A mid-mission config.changed backend flip moves the
LIVE tier (MissionState::executor_tier), not this seed-time record.
standards_manifest: Option<StandardsPin>The Flight Rules standards pin folded from the approved plan
(plan.approved / plan.revised; KRZ-342 D-E) — the single source of
truth every later mission stage resolves against. None for missions
without a standards-configured pack and in every pre-KRZ-342 state
snapshot; additive.
reviewer_independence: Option<ReviewerIndependence>Operator policy pinned by plan approval, never replaced by live config.