# Task #91 — IPZ E2E always-remote contract

## Outcome

Make `/ipz-e2e` fail closed as an always-remote contract. Every dependency install, snapshot/admin
build, WordPress/MariaDB stack, readiness gate, Playwright/Chromium/Firefox run, retry, focused or
full test, smoke, screenshot/visual capture, and diagnostic browser run must execute on one
registry-selected Debian buildbox through `~/.claude/bin/e2e-remote`; the workstation must never
become a fallback or host a local build/browser/server half.

## Status

DONE — Codex updated the canonical skill, command, plan registry, and durable plan. Deterministic documentation checks passed. Commit `391a1c8b182e8e3717a73035b68f8f49b33b40f0` landed on `origin/master` through controller receipt `d82588941e6e0d24fde9aecd3ecc49e2d6ba9e57`. No E2E build or test ran for this documentation-only change.

## Task IDs

- `IPZ-E2E-REMOTE-01` — always-remote, fail-closed execution invariant.
- `IPZ-E2E-REMOTE-02` — registry-only `debian1`/`debian2`/`debian3` receiver selection and wrapper seam.
- `IPZ-E2E-REMOTE-03` — durable receipt, deterministic documentation checks, commit, land, and push.

## Source request

Owner request, 2026-08-15:

> Update and land the International Press Zone `/ipz-e2e` contract so E2E builds and browser tests
> are ALWAYS offloaded to the registered Debian build hosts (`debian1`/`debian2`/`debian3`), never
> only sometimes and never on the workstation. Work directly; do not delegate or invoke other coding
> agents. Update both canonical documents together with terse AI-agent-first imperatives and explicit
> reject examples. Record this actionable request in the plan index and one durable plan file. Preserve
> the existing topology, safety, artifact, cleanup, Chromium+Firefox, fixture, and readiness rules.
> Every dependency install, admin build, WordPress stack, Playwright/browser run, retry, focused test,
> full test, screenshot/visual capture, smoke, and diagnostic browser run must be remote; reject
> workstation fallback, local build/browser/server halves, direct SSH, hardcoded host selection that
> bypasses `e2e-remote` registry/spill logic, and all testing of deployment-only `dev1`. Do not run an
> E2E build or test for this documentation-only change. Commit with one short imperative sentence and
> no co-author, land through `ship.sh` from outside the worktree, push `origin/master`, and report the
> landed commit and exact changed files.

## Files and acceptance

Change these active contract files together:

- `plugins/international-press-zone/.claude/skills/ipz-e2e.md`
- `plugins/international-press-zone/.claude/commands/ipz-e2e.md`

Also record this request in:

- `plugins/international-press-zone/docs/plans/INDEX.md`
- this plan file

Acceptance:

- State the full always-remote invariant and workstation-only caller boundary in both canonical
  documents.
- Name the only registered E2E hosts as `debian1`, `debian2`, and `debian3`; require registry-driven
  wrapper selection/spill and reject ad-hoc direct SSH, hardcoded normal-run host selection, local
  fallback, proxy/tunnel, and `dev1` testing.
- Preserve the existing remote stack, snapshot fingerprint, localhost target, dependency/build,
  readiness, fixture, ownership-label, cleanup, artifact, Chromium, Firefox, evidence, and failure
  ladder requirements.
- Run deterministic policy-text checks and `git diff --check` only. Do not run any E2E build, browser,
  smoke, screenshot, visual, stack, retry, or diagnostic run.
- Commit with one short imperative sentence and no co-author; land from outside the worktree through
  `/home/user/Projects/Press.zone/wordpress/wp-content/.claude/scripts/ship.sh`; push `origin/master`.
- Report the published commit and exact changed files; record the execution receipt and next action here.

## Preserved WIP / ref / path

- Requested worktree/ref: `/home/user/Projects/Press.zone/wordpress/wp-content/.worktrees/ipz-deploy-package`
  on `wt/ipz-e2e-always-remote`, freshly based on `origin/master`.
- Mounted execution path: `/sandbox/workspaces/ipz-deploy-package-4981aec30240`; the harness presented
  the checkout detached at `db5836e3`, so the requested local branch was created there before edits.
- Preserve all unrelated WIP, refs, worktrees, generated artifacts, and runtime state. The starting
  worktree was clean; no unrelated WIP was present or changed.

## Constraints

- Work directly in this thread; use no coding-agent delegation.
- Keep scope documentation-only: the two canonical E2E documents plus this plan and the index entry.
- Use only `e2e-remote` for any future E2E workload; never direct SSH, a local stack/browser/server,
  a workstation fallback, a proxy/tunnel, or `dev1` testing.
- Do not edit generated `admin/dist`, tests, stack scripts, fixtures, host registry, or wrapper logic.
- Do not run E2E builds/tests for this change. Do not weaken topology, safety, readiness, artifact,
  fixture, cleanup, browser, or failure requirements.
- Land only through the named `ship.sh` controller from outside the worktree; do not raw-merge or
  raw-push as a substitute. Keep the commit subject one short imperative sentence and add no
  co-author.

## Execution receipt

- Read root `CLAUDE.md`, plugin `CLAUDE.md`, plugin `.claude/agents/expert.md`, the current canonical
  skill/command, related plan/index entries, `tests/e2e/run-remote.sh`, `run-journey.sh`,
  `remote-stack.sh`, snapshot builder, and the registry/wrapper contract before editing.
- Created local branch `wt/ipz-e2e-always-remote` from the mounted checkout's clean detached HEAD;
  no unrelated paths were dirty.
- Updated both canonical documents with the always-remote invariant, registry-only receiver set,
  wrapper/spill rules, explicit rejects, and preserved existing E2E gates. No E2E command has run.
- Exact policy-text assertions passed for both canonical documents; staged `git diff --check` passed.
  No E2E build, browser, smoke, screenshot, visual, stack, retry, or diagnostic command ran.
- Codex completed the scoped documentation changes and deterministic checks in the remote execution sandbox. Its requested landing controller was unavailable there, so the synchronized working-tree changes returned to the main session for the authorized controller publication.
- Main-session commit `391a1c8b182e8e3717a73035b68f8f49b33b40f0` contains exactly the two canonical E2E documents, this plan, and its index entry. Repository controller receipt `d82588941e6e0d24fde9aecd3ecc49e2d6ba9e57` verifies publication on `origin/master`.
- No raw merge, raw push, E2E run, build, browser, smoke, screenshot, visual, stack, retry, or diagnostic command was used as a substitute.

## Next action

None — task #91 is complete.
