elagents-p-foundry-ci now carries a hand-created federated credential github--github-private-main (subject repo:EasyLife365/.github-private:ref:refs/heads/main, created 2026-10-01 by @plamber for the scheduled Drift Check, see EasyLife365/.github-private#235 / PR #237).
createFoundryPrincipals.ps1 only creates and reconciles repo:<org>/<repo>:pull_request subjects and leaves every other shape untouched, so nothing declares this credential and a rebuild of the app would not recreate it.
Acceptance criteria
elagents-p-foundry-cinow carries a hand-created federated credentialgithub--github-private-main(subjectrepo:EasyLife365/.github-private:ref:refs/heads/main, created 2026-10-01 by @plamber for the scheduled Drift Check, see EasyLife365/.github-private#235 / PR #237).createFoundryPrincipals.ps1only creates and reconcilesrepo:<org>/<repo>:pull_requestsubjects and leaves every other shape untouched, so nothing declares this credential and a rebuild of the app would not recreate it.Acceptance criteria
pull_requestsubjects (e.g. a-MainRefReposlist) and creates the missing ones-RemoveOrphanedstill never touches a declared main-ref credentialgithub--github-private-mainas already present