Record live digest retention proof and restarted healthy observation
All checks were successful
CI Smoke / host-smoke (push) Successful in 2s
CI Smoke / container-smoke (push) Successful in 4s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
tegwick 2026-09-27 16:07:56 +02:00
parent a12f1169f9
commit 45a8beddd4
3 changed files with 52 additions and 0 deletions

View file

@ -134,3 +134,19 @@ authority delegated. Existing GLAS/HFACT pattern-editing readiness is unchanged.
Evidence: docs/evidence/2026-09-27-gitops-adoption.json. Activation authorization
is State Hub decision 78a4b859-dd00-4623-b95b-121b0e1c915d.
## Retention safeguard release — 2026-09-27
RPF-WP-0048-T03 completed through the existing nine-resource GitOps projection.
The platform-owned retention script is pinned to source commit/hash, CI verified,
and mounted read-only from the existing ConfigMap. ArgoCD synced a12f116 and is
Healthy; live worker hash/readback and a non-destructive rollback planner check
passed. Digest-referenced packages are conservatively protected in full.
No prune was executed. Evidence: docs/evidence/2026-09-27-digest-retention-release.json.
This worker change resets conservative observation: healthy since 14:06:22Z,
earliest eligibility September 28 at 16:06:22 Berlin. T03 still requires the
scoped source/sync broker: ArgoCD Core offers no API-server token lane, and a
Kubernetes Application patch grant cannot restrict fields. Concrete enforcement
contract is platform docs/activity-core-release-admission.md. Authenticated
receipts and automatic rollback proof remain required; no broad token is admitted.