Drop the two runbooks that walk through the foundation/apps roots, trim the
Cloud SQL consumer contract's source notes to what the relay needs, scan the
lease action's history in Cloud Verify, and exclude that action from the
monorepo formatter so syncs from the private repo stay byte-identical.
defaults.run.working-directory: cloud does not exist before actions/checkout,
so the eight guard/gate steps that run first (and the two checkout-free jobs,
clock-skew and requeue) failed to start. Pin those steps to '.'. The pretest
lease-action paths are ../.github from cloud/, and the two bare pnpm setups
read cloud/package.json instead of the root's pnpm 12. Cloud Verify now also
triggers on the lease action.
Format-checks, initialises without a backend, and validates cloud/infra/terraform
on the same pinned Terraform the private repository's CI uses. Fork pull requests
reach this workflow, so the job configures no backend and holds no credential.
Import the relay server and its wire contract under cloud/ as an independent
pnpm workspace, with a Cloud Verify workflow that builds, tests, and
secret-scans it.