From c3e449b312ffd0ea0550c78b8f8a8b6fa3901fef Mon Sep 17 00:00:00 2001 From: tegwick Date: Sun, 27 Sep 2026 15:49:14 +0200 Subject: [PATCH] Record healthy GitOps digest release and remaining automation gates Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3 --- docs/evidence/2026-09-27-gitops-adoption.json | 166 ++++++++++++++++++ docs/gitops-release.md | 17 ++ workplans/ACTIVITY-WP-0041-gitops-adoption.md | 29 ++- 3 files changed, 210 insertions(+), 2 deletions(-) create mode 100644 docs/evidence/2026-09-27-gitops-adoption.json diff --git a/docs/evidence/2026-09-27-gitops-adoption.json b/docs/evidence/2026-09-27-gitops-adoption.json new file mode 100644 index 0000000..bc4e5d8 --- /dev/null +++ b/docs/evidence/2026-09-27-gitops-adoption.json @@ -0,0 +1,166 @@ +{ + "date": "2026-09-27", + "workplan": "ACTIVITY-WP-0041", + "platform_workplan": "RPF-WP-0048", + "authorization_decision": "78a4b859-dd00-4623-b95b-121b0e1c915d", + "activity_revision": "12e08878d19e61ce41c534cc10ca56acd0c3efc1", + "platform_revision": "a01026535a1fb34d5e9561a26a02dc56b3e3bab4", + "initial_adoption": { + "revision": "c12a8fbcfbd0624e195a0183f8b7ca5ce2bc07d5", + "finished_at": "2026-09-27T12:07:35Z", + "diff": "nine tracking annotations only; deployment specs and pod templates unchanged" + }, + "digest_release": { + "finished_at": "2026-09-27T13:37:56Z", + "sync": "Synced", + "health": "Healthy", + "phase": "Succeeded", + "diff": "only three image references and Never to IfNotPresent; same published baseline binaries" + }, + "resources": [ + { + "kind": "ConfigMap", + "name": "actcore-external-activity-definitions", + "namespace": "activity-core", + "status": "Synced" + }, + { + "kind": "ConfigMap", + "name": "actcore-ops-service-inventory", + "namespace": "activity-core", + "status": "Synced" + }, + { + "kind": "ConfigMap", + "name": "actcore-report-schemas", + "namespace": "activity-core", + "status": "Synced" + }, + { + "kind": "ConfigMap", + "name": "actcore-runtime-config", + "namespace": "activity-core", + "status": "Synced" + }, + { + "kind": "Service", + "name": "actcore-api", + "namespace": "activity-core", + "status": "Synced" + }, + { + "kind": "Service", + "name": "actcore-worker-metrics", + "namespace": "activity-core", + "status": "Synced" + }, + { + "kind": "Deployment", + "name": "actcore-api", + "namespace": "activity-core", + "status": "Synced" + }, + { + "kind": "Deployment", + "name": "actcore-event-router", + "namespace": "activity-core", + "status": "Synced" + }, + { + "kind": "Deployment", + "name": "actcore-worker", + "namespace": "activity-core", + "status": "Synced" + } + ], + "deployments": [ + { + "name": "actcore-api", + "images": [ + "forgejo.coulomb.social/coulomb/activity-core@sha256:713bddad10a41950f446100a8b370fca8ccdd0b8969cccae751e3870c9c63ccd" + ], + "generation": 50, + "observed_generation": 50, + "ready": 1, + "updated": 1 + }, + { + "name": "actcore-worker", + "images": [ + "forgejo.coulomb.social/coulomb/activity-core@sha256:77244c3b6977a84888746d1fde5ec9fb5ed576f29df0e6dab2462e6f2ab0e0d7" + ], + "generation": 61, + "observed_generation": 61, + "ready": 1, + "updated": 1 + }, + { + "name": "actcore-event-router", + "images": [ + "forgejo.coulomb.social/coulomb/activity-core@sha256:cd4e924c2809f0d1d319e53a9ddd20db2e88a1b543d62e6442702c184b7842f4" + ], + "generation": 33, + "observed_generation": 33, + "ready": 1, + "updated": 1 + } + ], + "ci": { + "state": "success", + "image_run": "https://forgejo.coulomb.social/coulomb/activity-core/actions/runs/308", + "smoke_run": "https://forgejo.coulomb.social/coulomb/activity-core/actions/runs/307", + "checks": "pinned frontend projection; release guard; frontend resolver; external definitions; report sink" + }, + "scheduled_smoke": { + "activity_id": "99f02c4c-161e-515d-926d-9e5d11d8411e", + "activity_name": "Frontend Patterns Daily Review", + "mode": "live", + "recreate_recurring": false, + "recurring_schedule_id": "activity-schedule-99f02c4c-161e-515d-926d-9e5d11d8411e", + "smoke_fire_at": "2026-09-27T13:39:09.975262+00:00", + "smoke_schedule_id": "activity-smoke-test-99f02c4c-161e-515d-926d-9e5d11d8411e", + "smoke_workflow_id_prefix": "activity-99f02c4c-161e-515d-926d-9e5d11d8411e:smoke-20260927T133909Z", + "wait_result": { + "result": { + "run_id": "c81f656f-405e-5773-b4d2-73b8110ee55f", + "tasks_spawned": 0 + }, + "run_id": "01a0e317-48a8-72d8-98d9-e44cdedb9999", + "status": "completed", + "workflow_id": "activity-99f02c4c-161e-515d-926d-9e5d11d8411e:smoke-20260927T133909Z-2026-09-27T13:39:09Z" + } + }, + "schedules": { + "daily": "0 2 * * *", + "weekly": "0 3 * * 2", + "monthly": "0 9 1 * *", + "timezone": "Europe/Berlin", + "all_enabled_after_release": true + }, + "retention": { + "baseline_tags": [ + "baseline-api-713bddad10a4", + "baseline-worker-77244c3b6977", + "baseline-router-cd4e924c2809" + ], + "union_sha256": "f0560f5a5e0c8c52154fb5e4d1b04838191d51fcf026df49703d5f3503f61fda", + "protection_verified_with_owner_parser": true, + "gap": "digest-only refs are not mapped to registry versions; RPF-WP-0048-T03 retains general fix" + }, + "soak": { + "healthy_start": "2026-09-27T13:38:21Z", + "earliest_eligible": "2026-09-28T13:38:21Z", + "completed": false, + "requires": "continuous healthy observation, not elapsed time alone" + }, + "automated_sync": false, + "pruning": false, + "unattended_release_identity_admitted": false, + "failed_health_rollback_proven": false, + "remaining": [ + "24-hour healthy observation", + "authenticated CI/reviewer/health receipts and narrowly admitted release identity", + "automatic failed-health rollback proof", + "GLAS-WP-0012/HFACT-WP-0001 executor proof for pattern editing" + ] +} diff --git a/docs/gitops-release.md b/docs/gitops-release.md index 1cd8221..9f9d481 100644 --- a/docs/gitops-release.md +++ b/docs/gitops-release.md @@ -64,3 +64,20 @@ and revert its source revision through ArgoCD on failure. Prove both successful promotion and failed-health rollback before claiming unattended operation. The 24-hour observation begins with the recorded successful adoption; a stateful failure or unintended spec change invalidates that observation. + +## Live proof and current gates + +The 2026-09-27 adoption and subsequent digest release are complete and healthy. +See [evidence](evidence/2026-09-27-gitops-adoption.json) for exact revisions, +images, CI runs, nine-resource inventory, scheduled smoke and retention coverage. +All three components now use registry digests of their previous binaries. +Conservative healthy observation starts at 13:38:21Z after the digest rollout; +earliest eligibility is September 28 at 15:38:21 Berlin, conditional on health. + +The registry retention implementation currently protects tags, not digest-to-version +mappings. Three baseline tag aliases have been added to the persistent protection +union and checked with the owner parser. Every release must protect aliases for +live and rollback digests until RPF-WP-0048-T03 supplies general digest protection. +Unattended promotion is not ready merely because the admission fixtures pass: +authenticated receipts, identity binding, retention coverage and failed-health +rollback proof remain required in ACTIVITY-WP-0041-T03. diff --git a/workplans/ACTIVITY-WP-0041-gitops-adoption.md b/workplans/ACTIVITY-WP-0041-gitops-adoption.md index fc381c4..0396f26 100644 --- a/workplans/ACTIVITY-WP-0041-gitops-adoption.md +++ b/workplans/ACTIVITY-WP-0041-gitops-adoption.md @@ -22,7 +22,7 @@ e5dd02cb-b5b2-45c8-a600-748ea2ffd31b and does not change estate policy. ```task id: ACTIVITY-WP-0041-T01 -status: progress +status: done priority: high state_hub_task_id: "fadce2e0-67c8-5dab-98cc-3a08d466a39f" ``` @@ -67,7 +67,7 @@ one-time governance decision. ```task id: ACTIVITY-WP-0041-T03 -status: wait +status: progress priority: high state_hub_task_id: "8e2b4ed9-d455-5367-85d9-8e4222ce75f3" ``` @@ -109,3 +109,28 @@ inputs. Local container tests passed. Registry publication/readback must still b observed. The image-only promotion validator has negative fixtures for widened authority, stale/missing evidence, non-digest references and incomplete soak. It is not a credential issuer or proof of an admitted unattended executor. + +## Verified delivery — 2026-09-27 + +T01 complete: commit 12e08878d19e61ce41c534cc10ca56acd0c3efc1 passed CI +smoke and image publication (runs 307/308). Nine-resource projection and pinned +frontend definitions are checked before publication. All three live components +now pull immutable registry digests of their exact prior binaries. Registry +readback, node pulls, all three rollouts and a Temporal scheduled report passed. +Baseline registry tags are protected in the additive live-image retention union. + +T02 adoption complete, observation outstanding: metadata-only initial sync at +12:07:35Z; digest release through root/child ArgoCD succeeded at 13:37:56Z. +Healthy transition at 13:38:21Z starts the conservative 24-hour window; earliest +eligibility is 2026-09-28 15:38:21 Europe/Berlin, conditional on healthy evidence. +Automated sync and pruning remain off. RPF-WP-0048 owns observation/admission; +its T03 owns general digest-aware registry retention, with current tags protected. + +T03 has a tested image-only admission validator and one successful Git/ArgoCD +release. Authenticated receipt verification, narrowly bound unattended identity, +and failed-health automatic rollback remain required. Producer JSON flags do not +provide authority. No executor credential has been invented or broad operator +authority delegated. Existing GLAS/HFACT pattern-editing readiness is unchanged. + +Evidence: docs/evidence/2026-09-27-gitops-adoption.json. Activation authorization +is State Hub decision 78a4b859-dd00-4623-b95b-121b0e1c915d.