diff --git a/docs/evidence/2026-09-27-digest-retention-release.json b/docs/evidence/2026-09-27-digest-retention-release.json new file mode 100644 index 0000000..aeaf8fd --- /dev/null +++ b/docs/evidence/2026-09-27-digest-retention-release.json @@ -0,0 +1,27 @@ +{ + "date": "2026-09-27", + "platform_source": "743def1", + "activity_revision": "a12f1169f9d130058ce767f5b26de0606997916c", + "platform_application_revision": "4b9c4ce", + "tool_sha256": "fa3d4cc8cdcc14ecce509cf6865c6e4726d722f84814b97d40686d68d6ee5bb1", + "tests": { + "platform_retention_and_inventory": 20, + "activity_gitops": 17, + "ci": "all smoke and image build checks passed" + }, + "production": { + "sync": "Synced", + "health": "Healthy", + "finished_at": "2026-09-27T14:06:20Z", + "worker_hash_verified": true, + "real_inventory_digest_protection_verified": true, + "synthetic_rollback_planner_protected": true, + "registry_requests_during_probe": 0, + "deletions": 0 + }, + "healthy_since": "2026-09-27T14:06:22Z", + "earliest_soak_eligibility": "2026-09-28T14:06:22Z", + "automated_promotion": false, + "retention_policy": "all versions of packages referenced by digest in additive live/rollback inventory are protected", + "remaining": "scoped source/sync broker, authenticated receipts and automatic rollback proof; automatic pattern execution readiness unchanged" +} diff --git a/docs/gitops-release.md b/docs/gitops-release.md index 9f9d481..b9b09a1 100644 --- a/docs/gitops-release.md +++ b/docs/gitops-release.md @@ -81,3 +81,12 @@ live and rollback digests until RPF-WP-0048-T03 supplies general digest protecti Unattended promotion is not ready merely because the admission fixtures pass: authenticated receipts, identity binding, retention coverage and failed-health rollback proof remain required in ACTIVITY-WP-0041-T03. + + +The subsequent retention safeguard rollout is recorded in +[evidence](evidence/2026-09-27-digest-retention-release.json). RPF-WP-0048-T03 is +complete: digest references now protect the whole package conservatively. The +platform source pin and projected bytes are CI-verified; the worker reads the +script from the existing GitOps ConfigMap. New healthy-since is September 27 +14:06:22 UTC, replacing the earlier observation window. Earliest eligibility is +September 28 at 16:06:22 Berlin, conditional on healthy evidence and admission. diff --git a/workplans/ACTIVITY-WP-0041-gitops-adoption.md b/workplans/ACTIVITY-WP-0041-gitops-adoption.md index 0396f26..b0999ed 100644 --- a/workplans/ACTIVITY-WP-0041-gitops-adoption.md +++ b/workplans/ACTIVITY-WP-0041-gitops-adoption.md @@ -134,3 +134,19 @@ authority delegated. Existing GLAS/HFACT pattern-editing readiness is unchanged. Evidence: docs/evidence/2026-09-27-gitops-adoption.json. Activation authorization is State Hub decision 78a4b859-dd00-4623-b95b-121b0e1c915d. + +## Retention safeguard release — 2026-09-27 + +RPF-WP-0048-T03 completed through the existing nine-resource GitOps projection. +The platform-owned retention script is pinned to source commit/hash, CI verified, +and mounted read-only from the existing ConfigMap. ArgoCD synced a12f116 and is +Healthy; live worker hash/readback and a non-destructive rollback planner check +passed. Digest-referenced packages are conservatively protected in full. +No prune was executed. Evidence: docs/evidence/2026-09-27-digest-retention-release.json. + +This worker change resets conservative observation: healthy since 14:06:22Z, +earliest eligibility September 28 at 16:06:22 Berlin. T03 still requires the +scoped source/sync broker: ArgoCD Core offers no API-server token lane, and a +Kubernetes Application patch grant cannot restrict fields. Concrete enforcement +contract is platform docs/activity-core-release-admission.md. Authenticated +receipts and automatic rollback proof remain required; no broad token is admitted.