Q3 E2E Environment Matrix
This document records non-secret endpoints and access boundaries. Credentials belong in Secret Manager or an approved CI environment, never in scenarios, logs, documentation, or command-line arguments.
| System | Approved acceptance surface | Allowed behavior | Accountable owner / approval route | Current readiness |
|---|---|---|---|---|
| LTI | https://lti-dev-wjcjlby2qq-ew.a.run.app |
Scenario control, evidence, reports, Agent API, scheduler | Cristian Silva, LTI delivery owner | Ready |
| CitizenGO Website | https://staging.citizengo.org/ |
Browser and public API journeys using acceptance backend | Cristian Silva for test integration; WebApp owner confirmation in Asana task 1216410130917800 |
Ready for the confirmed browser path |
| HazteOir Website | https://staging.hazteoir.org/ |
Browser and public API journeys using acceptance backend | Cristian Silva for test integration; WebApp owner confirmation in Asana task 1216410130917800 |
Ready for the confirmed browser path |
| Backend API | https://cgo-backend-acceptance-wjcjlby2qq-ew.a.run.app |
Acceptance member, signature, campaign, and Iterable flows | Cristian Silva for acceptance delivery; WebApp owner confirmation in Asana task 1216410130917800 |
Ready for currently deployed acceptance routes |
| DonUI | https://sandbox.donate.citizengo.org/ |
Sandbox OTD, MD, express, fallback, and recovery UI | Cristian Silva for test integration; payment owner approval remains per provider | Ready for non-provider checks |
| HazteOir DonUI | https://sandbox.donate.hazteoir.org/ |
HazteOir sandbox OTD, MD, express, fallback, and recovery UI | Cristian Silva for test integration; payment owner approval remains per provider | Ready for non-provider checks |
| FRAPI | https://frapi-acceptance-wjcjlby2qq-ew.a.run.app |
Acceptance donation API and provider test-mode calls | Cristian Silva for acceptance delivery; database/Salesforce impact confirmation in Asana task 1216410130843500 |
Ready; provider gates remain independent |
| MODB | Development Cloud SQL operational_db through approved backend access |
Read and append acceptance-owned events only | Cristian Silva for test queries; MODB owner confirmation in Asana task 1216410161185886 |
Ready with shared-development acknowledgement |
| Iterable | EU API, restricted internal test audience | Acceptance profiles, subscriptions, events, and unsubscribe webhook | Cristian Silva for test integration; journey owner confirmation in Asana task 1216860419874164, handed off from completed planning task 1216410130911271 |
API key ready; owner contract and webhook setup pending |
| Stripe | Test mode through FRAPI/LTI secret references | Synthetic charges, intents, customers, and subscriptions | Cristian Silva coordinates; payment integration owner approves fixture and cleanup contract | Pending credentialed scenario validation |
| GoCardless | Sandbox through FRAPI/LTI secret references | Synthetic mandates, customers, and subscriptions | Cristian Silva coordinates; payment integration owner approves fixture and cleanup contract | Pending credentialed scenario validation |
| Salesforce | Sandbox | Read/write only for approved synthetic records | Cristian Silva for test integration; Salesforce/FRAPI owner confirmation in Asana task 1216410130843500 |
Pending end-to-end verification |
| BigQuery | Dataset to be confirmed by Data Area | Read-only validation after documented ingestion latency | Cristian Silva for test integration; Data Area confirmation in Asana task 1216410161122874 |
Blocked on dataset contract |
Production Boundary
Automated acceptance runs do not write to production. Production Website, DonUI, FRAPI, backend, payment providers, Salesforce, databases, and messaging systems are excluded from mutable scenarios. Any production observation must be separately approved, read-only, and unnecessary for a passing acceptance run.
Delivery Boundary
lti-devis deployed from an explicitly selected branch through the stable workflow onmain.- The workflow builds an immutable image, deploys a no-traffic candidate,
performs an authenticated health smoke, promotes the candidate, and then
updates
lti-dev-cron. - Backend and FRAPI acceptance delivery use candidate validation and explicit traffic promotion.
- Website and DonUI acceptance surfaces are Firebase-hosted staging or sandbox deployments.
Open Contracts
The detailed assertions, approval questions, and closure evidence are maintained
in q3-e2e-dependency-contracts.md. Cristian Silva is accountable for keeping
each dependency task open until its named external owner confirms the contract.
The bounded list, locale, form, provider, and journey inventory is maintained
in q3-e2e-scenario-inventory.md.