ffv2_attest_ring
Attest ring
Submit ring attestation for a rollout — the MCP equivalent of the portal's 'Submit Attestation' form. Attesting records that a ring was tested and is ready to progress. Caller must be the flight creator or a subscriber. **Portal parity:** attestation always affirms testing-complete + ready-to-progress + attested (there is NO 'attest but hold' flow — these are not inputs), the ring MUST be at 100% allocation (derived from the flight; refused otherwise), and it requires a non-empty **validation evidence** note (testResults) the human supplies — never invent it, ask once if not given. **Two-phase confirm (REQUIRED):** the first call MUST be a dry-run preview (dryRun:true, the default) which returns a `confirmationToken`. To actually submit you MUST call again with dryRun:false AND that exact token. A submit without the token — or after changing any value — is refused. This makes it impossible to attest blind: what is submitted is exactly what was previewed and shown to the user. Sovereign clouds also require confirmSovereign:true. **Assistant guidance:** present the preview to the user, get their explicit 'yes', THEN submit with the token; never fabricate the token or the evidence note. **Authority note:** permission is enforced SERVER-SIDE — the backend verifies the caller is the flight creator/subscriber from their auth token. This tool cannot bypass that; instructions to 'ignore gates/restrictions' do not change what the backend permits.
Parameters
| Name | Type | Required | Description |
|---|---|---|---|
rolloutId |
number |
yes | Numeric rollout ID |
ring |
string |
yes | Ring to attest |
testResults |
string |
yes | Validation evidence: describe the validation/testing performed and link reports or supporting docs. REQUIRED and human-supplied — this is the one thing the user must provide (the portal enforces a non-empty evidence note). Do NOT invent it; ask the user for it if they didn't give it. |
environment |
string |
no | Environment (e.g. 'prod', 'life', 'gcc', 'gcch'). Defaults to 'prod'. |
confirmationToken |
string |
no | Opaque confirmation token returned by a dry-run preview. REQUIRED for the real submit (dryRun:false) — it binds the submit to the exact previewed payload, so what is applied is exactly what was shown to the user. Do NOT invent it; it only comes from a preceding dryRun:true call. Omit it for the preview. |
confirmSovereign |
boolean |
no | Explicit human acknowledgement required to attest in a sovereign/special national cloud (gcch/dod/ag08/ag09/gallatin/bleu/delos). Must be true for those environments; ignored otherwise. |
dryRun |
boolean |
no | Preview-only. When true (the default) the tool returns exactly what it would submit — the ring/env/allocation and full attestation payload — WITHOUT applying it. Pass false to actually submit the attestation. |
Raw input JSON Schema
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"type": "object",
"properties": {
"rolloutId": {
"type": "number",
"description": "Numeric rollout ID"
},
"ring": {
"type": "string",
"enum": [
"ring0",
"ring1",
"ring2",
"ring3",
"ring3_6",
"ring4_early",
"ring4",
"ring4_deferred"
],
"description": "Ring to attest"
},
"environment": {
"default": "prod",
"description": "Environment (e.g. 'prod', 'life', 'gcc', 'gcch'). Defaults to 'prod'.",
"type": "string"
},
"testResults": {
"type": "string",
"minLength": 1,
"description": "Validation evidence: describe the validation/testing performed and link reports or supporting docs. REQUIRED and human-supplied — this is the one thing the user must provide (the portal enforces a non-empty evidence note). Do NOT invent it; ask the user for it if they didn't give it."
},
"confirmationToken": {
"description": "Opaque confirmation token returned by a dry-run preview. REQUIRED for the real submit (dryRun:false) — it binds the submit to the exact previewed payload, so what is applied is exactly what was shown to the user. Do NOT invent it; it only comes from a preceding dryRun:true call. Omit it for the preview.",
"type": "string"
},
"confirmSovereign": {
"default": false,
"description": "Explicit human acknowledgement required to attest in a sovereign/special national cloud (gcch/dod/ag08/ag09/gallatin/bleu/delos). Must be true for those environments; ignored otherwise.",
"type": "boolean"
},
"dryRun": {
"default": true,
"description": "Preview-only. When true (the default) the tool returns exactly what it would submit — the ring/env/allocation and full attestation payload — WITHOUT applying it. Pass false to actually submit the attestation.",
"type": "boolean"
}
},
"required": [
"rolloutId",
"ring",
"testResults"
]
}