Record healthy GitOps digest release and remaining automation gates
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
parent
12e08878d1
commit
c3e449b312
3 changed files with 210 additions and 2 deletions
166
docs/evidence/2026-09-27-gitops-adoption.json
Normal file
166
docs/evidence/2026-09-27-gitops-adoption.json
Normal file
|
|
@ -0,0 +1,166 @@
|
||||||
|
{
|
||||||
|
"date": "2026-09-27",
|
||||||
|
"workplan": "ACTIVITY-WP-0041",
|
||||||
|
"platform_workplan": "RPF-WP-0048",
|
||||||
|
"authorization_decision": "78a4b859-dd00-4623-b95b-121b0e1c915d",
|
||||||
|
"activity_revision": "12e08878d19e61ce41c534cc10ca56acd0c3efc1",
|
||||||
|
"platform_revision": "a01026535a1fb34d5e9561a26a02dc56b3e3bab4",
|
||||||
|
"initial_adoption": {
|
||||||
|
"revision": "c12a8fbcfbd0624e195a0183f8b7ca5ce2bc07d5",
|
||||||
|
"finished_at": "2026-09-27T12:07:35Z",
|
||||||
|
"diff": "nine tracking annotations only; deployment specs and pod templates unchanged"
|
||||||
|
},
|
||||||
|
"digest_release": {
|
||||||
|
"finished_at": "2026-09-27T13:37:56Z",
|
||||||
|
"sync": "Synced",
|
||||||
|
"health": "Healthy",
|
||||||
|
"phase": "Succeeded",
|
||||||
|
"diff": "only three image references and Never to IfNotPresent; same published baseline binaries"
|
||||||
|
},
|
||||||
|
"resources": [
|
||||||
|
{
|
||||||
|
"kind": "ConfigMap",
|
||||||
|
"name": "actcore-external-activity-definitions",
|
||||||
|
"namespace": "activity-core",
|
||||||
|
"status": "Synced"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "ConfigMap",
|
||||||
|
"name": "actcore-ops-service-inventory",
|
||||||
|
"namespace": "activity-core",
|
||||||
|
"status": "Synced"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "ConfigMap",
|
||||||
|
"name": "actcore-report-schemas",
|
||||||
|
"namespace": "activity-core",
|
||||||
|
"status": "Synced"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "ConfigMap",
|
||||||
|
"name": "actcore-runtime-config",
|
||||||
|
"namespace": "activity-core",
|
||||||
|
"status": "Synced"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "Service",
|
||||||
|
"name": "actcore-api",
|
||||||
|
"namespace": "activity-core",
|
||||||
|
"status": "Synced"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "Service",
|
||||||
|
"name": "actcore-worker-metrics",
|
||||||
|
"namespace": "activity-core",
|
||||||
|
"status": "Synced"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "Deployment",
|
||||||
|
"name": "actcore-api",
|
||||||
|
"namespace": "activity-core",
|
||||||
|
"status": "Synced"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "Deployment",
|
||||||
|
"name": "actcore-event-router",
|
||||||
|
"namespace": "activity-core",
|
||||||
|
"status": "Synced"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "Deployment",
|
||||||
|
"name": "actcore-worker",
|
||||||
|
"namespace": "activity-core",
|
||||||
|
"status": "Synced"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"deployments": [
|
||||||
|
{
|
||||||
|
"name": "actcore-api",
|
||||||
|
"images": [
|
||||||
|
"forgejo.coulomb.social/coulomb/activity-core@sha256:713bddad10a41950f446100a8b370fca8ccdd0b8969cccae751e3870c9c63ccd"
|
||||||
|
],
|
||||||
|
"generation": 50,
|
||||||
|
"observed_generation": 50,
|
||||||
|
"ready": 1,
|
||||||
|
"updated": 1
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "actcore-worker",
|
||||||
|
"images": [
|
||||||
|
"forgejo.coulomb.social/coulomb/activity-core@sha256:77244c3b6977a84888746d1fde5ec9fb5ed576f29df0e6dab2462e6f2ab0e0d7"
|
||||||
|
],
|
||||||
|
"generation": 61,
|
||||||
|
"observed_generation": 61,
|
||||||
|
"ready": 1,
|
||||||
|
"updated": 1
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "actcore-event-router",
|
||||||
|
"images": [
|
||||||
|
"forgejo.coulomb.social/coulomb/activity-core@sha256:cd4e924c2809f0d1d319e53a9ddd20db2e88a1b543d62e6442702c184b7842f4"
|
||||||
|
],
|
||||||
|
"generation": 33,
|
||||||
|
"observed_generation": 33,
|
||||||
|
"ready": 1,
|
||||||
|
"updated": 1
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"ci": {
|
||||||
|
"state": "success",
|
||||||
|
"image_run": "https://forgejo.coulomb.social/coulomb/activity-core/actions/runs/308",
|
||||||
|
"smoke_run": "https://forgejo.coulomb.social/coulomb/activity-core/actions/runs/307",
|
||||||
|
"checks": "pinned frontend projection; release guard; frontend resolver; external definitions; report sink"
|
||||||
|
},
|
||||||
|
"scheduled_smoke": {
|
||||||
|
"activity_id": "99f02c4c-161e-515d-926d-9e5d11d8411e",
|
||||||
|
"activity_name": "Frontend Patterns Daily Review",
|
||||||
|
"mode": "live",
|
||||||
|
"recreate_recurring": false,
|
||||||
|
"recurring_schedule_id": "activity-schedule-99f02c4c-161e-515d-926d-9e5d11d8411e",
|
||||||
|
"smoke_fire_at": "2026-09-27T13:39:09.975262+00:00",
|
||||||
|
"smoke_schedule_id": "activity-smoke-test-99f02c4c-161e-515d-926d-9e5d11d8411e",
|
||||||
|
"smoke_workflow_id_prefix": "activity-99f02c4c-161e-515d-926d-9e5d11d8411e:smoke-20260927T133909Z",
|
||||||
|
"wait_result": {
|
||||||
|
"result": {
|
||||||
|
"run_id": "c81f656f-405e-5773-b4d2-73b8110ee55f",
|
||||||
|
"tasks_spawned": 0
|
||||||
|
},
|
||||||
|
"run_id": "01a0e317-48a8-72d8-98d9-e44cdedb9999",
|
||||||
|
"status": "completed",
|
||||||
|
"workflow_id": "activity-99f02c4c-161e-515d-926d-9e5d11d8411e:smoke-20260927T133909Z-2026-09-27T13:39:09Z"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"schedules": {
|
||||||
|
"daily": "0 2 * * *",
|
||||||
|
"weekly": "0 3 * * 2",
|
||||||
|
"monthly": "0 9 1 * *",
|
||||||
|
"timezone": "Europe/Berlin",
|
||||||
|
"all_enabled_after_release": true
|
||||||
|
},
|
||||||
|
"retention": {
|
||||||
|
"baseline_tags": [
|
||||||
|
"baseline-api-713bddad10a4",
|
||||||
|
"baseline-worker-77244c3b6977",
|
||||||
|
"baseline-router-cd4e924c2809"
|
||||||
|
],
|
||||||
|
"union_sha256": "f0560f5a5e0c8c52154fb5e4d1b04838191d51fcf026df49703d5f3503f61fda",
|
||||||
|
"protection_verified_with_owner_parser": true,
|
||||||
|
"gap": "digest-only refs are not mapped to registry versions; RPF-WP-0048-T03 retains general fix"
|
||||||
|
},
|
||||||
|
"soak": {
|
||||||
|
"healthy_start": "2026-09-27T13:38:21Z",
|
||||||
|
"earliest_eligible": "2026-09-28T13:38:21Z",
|
||||||
|
"completed": false,
|
||||||
|
"requires": "continuous healthy observation, not elapsed time alone"
|
||||||
|
},
|
||||||
|
"automated_sync": false,
|
||||||
|
"pruning": false,
|
||||||
|
"unattended_release_identity_admitted": false,
|
||||||
|
"failed_health_rollback_proven": false,
|
||||||
|
"remaining": [
|
||||||
|
"24-hour healthy observation",
|
||||||
|
"authenticated CI/reviewer/health receipts and narrowly admitted release identity",
|
||||||
|
"automatic failed-health rollback proof",
|
||||||
|
"GLAS-WP-0012/HFACT-WP-0001 executor proof for pattern editing"
|
||||||
|
]
|
||||||
|
}
|
||||||
|
|
@ -64,3 +64,20 @@ and revert its source revision through ArgoCD on failure. Prove both successful
|
||||||
promotion and failed-health rollback before claiming unattended operation.
|
promotion and failed-health rollback before claiming unattended operation.
|
||||||
The 24-hour observation begins with the recorded successful adoption; a stateful
|
The 24-hour observation begins with the recorded successful adoption; a stateful
|
||||||
failure or unintended spec change invalidates that observation.
|
failure or unintended spec change invalidates that observation.
|
||||||
|
|
||||||
|
## Live proof and current gates
|
||||||
|
|
||||||
|
The 2026-09-27 adoption and subsequent digest release are complete and healthy.
|
||||||
|
See [evidence](evidence/2026-09-27-gitops-adoption.json) for exact revisions,
|
||||||
|
images, CI runs, nine-resource inventory, scheduled smoke and retention coverage.
|
||||||
|
All three components now use registry digests of their previous binaries.
|
||||||
|
Conservative healthy observation starts at 13:38:21Z after the digest rollout;
|
||||||
|
earliest eligibility is September 28 at 15:38:21 Berlin, conditional on health.
|
||||||
|
|
||||||
|
The registry retention implementation currently protects tags, not digest-to-version
|
||||||
|
mappings. Three baseline tag aliases have been added to the persistent protection
|
||||||
|
union and checked with the owner parser. Every release must protect aliases for
|
||||||
|
live and rollback digests until RPF-WP-0048-T03 supplies general digest protection.
|
||||||
|
Unattended promotion is not ready merely because the admission fixtures pass:
|
||||||
|
authenticated receipts, identity binding, retention coverage and failed-health
|
||||||
|
rollback proof remain required in ACTIVITY-WP-0041-T03.
|
||||||
|
|
|
||||||
|
|
@ -22,7 +22,7 @@ e5dd02cb-b5b2-45c8-a600-748ea2ffd31b and does not change estate policy.
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: ACTIVITY-WP-0041-T01
|
id: ACTIVITY-WP-0041-T01
|
||||||
status: progress
|
status: done
|
||||||
priority: high
|
priority: high
|
||||||
state_hub_task_id: "fadce2e0-67c8-5dab-98cc-3a08d466a39f"
|
state_hub_task_id: "fadce2e0-67c8-5dab-98cc-3a08d466a39f"
|
||||||
```
|
```
|
||||||
|
|
@ -67,7 +67,7 @@ one-time governance decision.
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: ACTIVITY-WP-0041-T03
|
id: ACTIVITY-WP-0041-T03
|
||||||
status: wait
|
status: progress
|
||||||
priority: high
|
priority: high
|
||||||
state_hub_task_id: "8e2b4ed9-d455-5367-85d9-8e4222ce75f3"
|
state_hub_task_id: "8e2b4ed9-d455-5367-85d9-8e4222ce75f3"
|
||||||
```
|
```
|
||||||
|
|
@ -109,3 +109,28 @@ inputs. Local container tests passed. Registry publication/readback must still b
|
||||||
observed. The image-only promotion validator has negative fixtures for widened
|
observed. The image-only promotion validator has negative fixtures for widened
|
||||||
authority, stale/missing evidence, non-digest references and incomplete soak.
|
authority, stale/missing evidence, non-digest references and incomplete soak.
|
||||||
It is not a credential issuer or proof of an admitted unattended executor.
|
It is not a credential issuer or proof of an admitted unattended executor.
|
||||||
|
|
||||||
|
## Verified delivery — 2026-09-27
|
||||||
|
|
||||||
|
T01 complete: commit 12e08878d19e61ce41c534cc10ca56acd0c3efc1 passed CI
|
||||||
|
smoke and image publication (runs 307/308). Nine-resource projection and pinned
|
||||||
|
frontend definitions are checked before publication. All three live components
|
||||||
|
now pull immutable registry digests of their exact prior binaries. Registry
|
||||||
|
readback, node pulls, all three rollouts and a Temporal scheduled report passed.
|
||||||
|
Baseline registry tags are protected in the additive live-image retention union.
|
||||||
|
|
||||||
|
T02 adoption complete, observation outstanding: metadata-only initial sync at
|
||||||
|
12:07:35Z; digest release through root/child ArgoCD succeeded at 13:37:56Z.
|
||||||
|
Healthy transition at 13:38:21Z starts the conservative 24-hour window; earliest
|
||||||
|
eligibility is 2026-09-28 15:38:21 Europe/Berlin, conditional on healthy evidence.
|
||||||
|
Automated sync and pruning remain off. RPF-WP-0048 owns observation/admission;
|
||||||
|
its T03 owns general digest-aware registry retention, with current tags protected.
|
||||||
|
|
||||||
|
T03 has a tested image-only admission validator and one successful Git/ArgoCD
|
||||||
|
release. Authenticated receipt verification, narrowly bound unattended identity,
|
||||||
|
and failed-health automatic rollback remain required. Producer JSON flags do not
|
||||||
|
provide authority. No executor credential has been invented or broad operator
|
||||||
|
authority delegated. Existing GLAS/HFACT pattern-editing readiness is unchanged.
|
||||||
|
|
||||||
|
Evidence: docs/evidence/2026-09-27-gitops-adoption.json. Activation authorization
|
||||||
|
is State Hub decision 78a4b859-dd00-4623-b95b-121b0e1c915d.
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue