MANAGED_CONFIG_SOURCE = 'managed config'Resolver provenance label for a value managed policy decided.
Mirrors configuration.service.MANAGED_SOURCE, which this module cannot
import at module scope without pulling the configuration service onto the
import path of every model_config consumer. test_model_config asserts the
two stay equal, so a rename on either side fails loudly instead of silently
degrading ModelNotAllowedError to generic wording.