Record healthy GitOps digest release and remaining automation gates
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
tegwick 2026-09-27 15:49:14 +02:00
parent 12e08878d1
commit c3e449b312
3 changed files with 210 additions and 2 deletions

View file

@ -0,0 +1,166 @@
{
"date": "2026-09-27",
"workplan": "ACTIVITY-WP-0041",
"platform_workplan": "RPF-WP-0048",
"authorization_decision": "78a4b859-dd00-4623-b95b-121b0e1c915d",
"activity_revision": "12e08878d19e61ce41c534cc10ca56acd0c3efc1",
"platform_revision": "a01026535a1fb34d5e9561a26a02dc56b3e3bab4",
"initial_adoption": {
"revision": "c12a8fbcfbd0624e195a0183f8b7ca5ce2bc07d5",
"finished_at": "2026-09-27T12:07:35Z",
"diff": "nine tracking annotations only; deployment specs and pod templates unchanged"
},
"digest_release": {
"finished_at": "2026-09-27T13:37:56Z",
"sync": "Synced",
"health": "Healthy",
"phase": "Succeeded",
"diff": "only three image references and Never to IfNotPresent; same published baseline binaries"
},
"resources": [
{
"kind": "ConfigMap",
"name": "actcore-external-activity-definitions",
"namespace": "activity-core",
"status": "Synced"
},
{
"kind": "ConfigMap",
"name": "actcore-ops-service-inventory",
"namespace": "activity-core",
"status": "Synced"
},
{
"kind": "ConfigMap",
"name": "actcore-report-schemas",
"namespace": "activity-core",
"status": "Synced"
},
{
"kind": "ConfigMap",
"name": "actcore-runtime-config",
"namespace": "activity-core",
"status": "Synced"
},
{
"kind": "Service",
"name": "actcore-api",
"namespace": "activity-core",
"status": "Synced"
},
{
"kind": "Service",
"name": "actcore-worker-metrics",
"namespace": "activity-core",
"status": "Synced"
},
{
"kind": "Deployment",
"name": "actcore-api",
"namespace": "activity-core",
"status": "Synced"
},
{
"kind": "Deployment",
"name": "actcore-event-router",
"namespace": "activity-core",
"status": "Synced"
},
{
"kind": "Deployment",
"name": "actcore-worker",
"namespace": "activity-core",
"status": "Synced"
}
],
"deployments": [
{
"name": "actcore-api",
"images": [
"forgejo.coulomb.social/coulomb/activity-core@sha256:713bddad10a41950f446100a8b370fca8ccdd0b8969cccae751e3870c9c63ccd"
],
"generation": 50,
"observed_generation": 50,
"ready": 1,
"updated": 1
},
{
"name": "actcore-worker",
"images": [
"forgejo.coulomb.social/coulomb/activity-core@sha256:77244c3b6977a84888746d1fde5ec9fb5ed576f29df0e6dab2462e6f2ab0e0d7"
],
"generation": 61,
"observed_generation": 61,
"ready": 1,
"updated": 1
},
{
"name": "actcore-event-router",
"images": [
"forgejo.coulomb.social/coulomb/activity-core@sha256:cd4e924c2809f0d1d319e53a9ddd20db2e88a1b543d62e6442702c184b7842f4"
],
"generation": 33,
"observed_generation": 33,
"ready": 1,
"updated": 1
}
],
"ci": {
"state": "success",
"image_run": "https://forgejo.coulomb.social/coulomb/activity-core/actions/runs/308",
"smoke_run": "https://forgejo.coulomb.social/coulomb/activity-core/actions/runs/307",
"checks": "pinned frontend projection; release guard; frontend resolver; external definitions; report sink"
},
"scheduled_smoke": {
"activity_id": "99f02c4c-161e-515d-926d-9e5d11d8411e",
"activity_name": "Frontend Patterns Daily Review",
"mode": "live",
"recreate_recurring": false,
"recurring_schedule_id": "activity-schedule-99f02c4c-161e-515d-926d-9e5d11d8411e",
"smoke_fire_at": "2026-09-27T13:39:09.975262+00:00",
"smoke_schedule_id": "activity-smoke-test-99f02c4c-161e-515d-926d-9e5d11d8411e",
"smoke_workflow_id_prefix": "activity-99f02c4c-161e-515d-926d-9e5d11d8411e:smoke-20260927T133909Z",
"wait_result": {
"result": {
"run_id": "c81f656f-405e-5773-b4d2-73b8110ee55f",
"tasks_spawned": 0
},
"run_id": "01a0e317-48a8-72d8-98d9-e44cdedb9999",
"status": "completed",
"workflow_id": "activity-99f02c4c-161e-515d-926d-9e5d11d8411e:smoke-20260927T133909Z-2026-09-27T13:39:09Z"
}
},
"schedules": {
"daily": "0 2 * * *",
"weekly": "0 3 * * 2",
"monthly": "0 9 1 * *",
"timezone": "Europe/Berlin",
"all_enabled_after_release": true
},
"retention": {
"baseline_tags": [
"baseline-api-713bddad10a4",
"baseline-worker-77244c3b6977",
"baseline-router-cd4e924c2809"
],
"union_sha256": "f0560f5a5e0c8c52154fb5e4d1b04838191d51fcf026df49703d5f3503f61fda",
"protection_verified_with_owner_parser": true,
"gap": "digest-only refs are not mapped to registry versions; RPF-WP-0048-T03 retains general fix"
},
"soak": {
"healthy_start": "2026-09-27T13:38:21Z",
"earliest_eligible": "2026-09-28T13:38:21Z",
"completed": false,
"requires": "continuous healthy observation, not elapsed time alone"
},
"automated_sync": false,
"pruning": false,
"unattended_release_identity_admitted": false,
"failed_health_rollback_proven": false,
"remaining": [
"24-hour healthy observation",
"authenticated CI/reviewer/health receipts and narrowly admitted release identity",
"automatic failed-health rollback proof",
"GLAS-WP-0012/HFACT-WP-0001 executor proof for pattern editing"
]
}

View file

@ -64,3 +64,20 @@ and revert its source revision through ArgoCD on failure. Prove both successful
promotion and failed-health rollback before claiming unattended operation.
The 24-hour observation begins with the recorded successful adoption; a stateful
failure or unintended spec change invalidates that observation.
## Live proof and current gates
The 2026-09-27 adoption and subsequent digest release are complete and healthy.
See [evidence](evidence/2026-09-27-gitops-adoption.json) for exact revisions,
images, CI runs, nine-resource inventory, scheduled smoke and retention coverage.
All three components now use registry digests of their previous binaries.
Conservative healthy observation starts at 13:38:21Z after the digest rollout;
earliest eligibility is September 28 at 15:38:21 Berlin, conditional on health.
The registry retention implementation currently protects tags, not digest-to-version
mappings. Three baseline tag aliases have been added to the persistent protection
union and checked with the owner parser. Every release must protect aliases for
live and rollback digests until RPF-WP-0048-T03 supplies general digest protection.
Unattended promotion is not ready merely because the admission fixtures pass:
authenticated receipts, identity binding, retention coverage and failed-health
rollback proof remain required in ACTIVITY-WP-0041-T03.

View file

@ -22,7 +22,7 @@ e5dd02cb-b5b2-45c8-a600-748ea2ffd31b and does not change estate policy.
```task
id: ACTIVITY-WP-0041-T01
status: progress
status: done
priority: high
state_hub_task_id: "fadce2e0-67c8-5dab-98cc-3a08d466a39f"
```
@ -67,7 +67,7 @@ one-time governance decision.
```task
id: ACTIVITY-WP-0041-T03
status: wait
status: progress
priority: high
state_hub_task_id: "8e2b4ed9-d455-5367-85d9-8e4222ce75f3"
```
@ -109,3 +109,28 @@ inputs. Local container tests passed. Registry publication/readback must still b
observed. The image-only promotion validator has negative fixtures for widened
authority, stale/missing evidence, non-digest references and incomplete soak.
It is not a credential issuer or proof of an admitted unattended executor.
## Verified delivery — 2026-09-27
T01 complete: commit 12e08878d19e61ce41c534cc10ca56acd0c3efc1 passed CI
smoke and image publication (runs 307/308). Nine-resource projection and pinned
frontend definitions are checked before publication. All three live components
now pull immutable registry digests of their exact prior binaries. Registry
readback, node pulls, all three rollouts and a Temporal scheduled report passed.
Baseline registry tags are protected in the additive live-image retention union.
T02 adoption complete, observation outstanding: metadata-only initial sync at
12:07:35Z; digest release through root/child ArgoCD succeeded at 13:37:56Z.
Healthy transition at 13:38:21Z starts the conservative 24-hour window; earliest
eligibility is 2026-09-28 15:38:21 Europe/Berlin, conditional on healthy evidence.
Automated sync and pruning remain off. RPF-WP-0048 owns observation/admission;
its T03 owns general digest-aware registry retention, with current tags protected.
T03 has a tested image-only admission validator and one successful Git/ArgoCD
release. Authenticated receipt verification, narrowly bound unattended identity,
and failed-health automatic rollback remain required. Producer JSON flags do not
provide authority. No executor credential has been invented or broad operator
authority delegated. Existing GLAS/HFACT pattern-editing readiness is unchanged.
Evidence: docs/evidence/2026-09-27-gitops-adoption.json. Activation authorization
is State Hub decision 78a4b859-dd00-4623-b95b-121b0e1c915d.