Drop the two runbooks that walk through the foundation/apps roots, trim the
Cloud SQL consumer contract's source notes to what the relay needs, scan the
lease action's history in Cloud Verify, and exclude that action from the
monorepo formatter so syncs from the private repo stay byte-identical.
Copies the private repository's relay side: the IAM-only fence broker, the
operations console and incident monitor, the relay Terraform root with its
backend configuration and tfvars, and the deploy/capacity/admission/rehome/
monitoring scripts the workflows call, with their contract tests, contracts,
and fixtures.
The foundation and apps Terraform roots and the API and auth services stay
private. Four surfaces that spanned both trees are narrowed to the relay side
rather than left with a dangling read: the infra runner and the root-partition
and workload-identity-condition renderers now declare only the relay root, and
the Cloud SQL rollout census drops the six app workflows that are not here.