activity-core/workplans/ACTIVITY-WP-0041-gitops-adoption.md
tegwick c3e449b312
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Record healthy GitOps digest release and remaining automation gates
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
2026-09-27 15:49:14 +02:00

6.9 KiB

id type title domain repo status owner topic_slug created updated state_hub_workstream_id
ACTIVITY-WP-0041 workplan Remove recurring deployment exceptions through governed GitOps adoption infotech activity-core active codex activity-core 2026-09-27 2026-09-27 12798750-3eee-5d81-a411-c3c4c5ce2d2c

Origin: founder asked what must change to avoid the scoped deployment exception for frontend-patterns reporting (ACTIVITY-WP-0040 / FEP-WP-0008). This is the reviewed implementation handoff, not permission to adopt additional live objects. The exception is recorded as State Hub decision e5dd02cb-b5b2-45c8-a600-748ea2ffd31b and does not change estate policy.

Reconcile live state with deployable source and publish reproducible images

id: ACTIVITY-WP-0041-T01
status: done
priority: high
state_hub_task_id: "fadce2e0-67c8-5dab-98cc-3a08d466a39f"

Owner activity-core, with railiance-platform for image distribution. Inventory all resources and external ownership first. Separate runtime declarations from one-shot migration/sync Jobs; prevent hooks from rerunning accidentally. Capture live backup wrappers/mounts and other deliberate patches missing from the main runtime manifest. The 2026-09-27 worker diff preserved live backup mounts through three-way apply; that is not proof a fresh render fully describes the runtime.

Replace workstation-only image imports and mutable/local tags with reproducible CI builds, registry publication and immutable digests. Keep worker/API compatibility checks and pin both independently. Add a projection check that frontend-patterns source definitions exactly match the external-definition ConfigMap. Render and server-dry-run the proposed managed set; no unintended spec change or pruning.

Adopt the declared resource set into railiance01 ArgoCD

id: ACTIVITY-WP-0041-T02
status: progress
priority: high
state_hub_task_id: "af09865d-8cc9-5571-9c34-20ae679a1e4e"

Owner railiance-platform for AppProject/root Application; activity-core for its resource set. Follow RPF-WP-0044's existing per-app adoption procedure in a dedicated activity-core adoption record (activity-core is not one of that plan's four apps). Create a least-privilege project/source allowance and child Application with a pinned revision, initially no automated sync, finalizer or pruning. Verify repo access, metadata-only adoption, healthy worker/API and unchanged existing schedules. Observe at least 24 hours before enabling automation, following the existing policy.

Record namespace/resource-to-binding classification with the MASON-WP-0006 mapping owner. An explicit mapping improves routing; it must not downgrade a production target to bypass the GitOps path. Keep secrets under existing ESO/OpenBao custody. The founder-approved exception covers WP0040 only; adoption activation is a separate one-time governance decision.

Establish standing authority for bounded routine releases

id: ACTIVITY-WP-0041-T03
status: progress
priority: high
state_hub_task_id: "8e2b4ed9-d455-5367-85d9-8e4222ce75f3"

Owner estate governance with activity-core and railiance-platform. ArgoCD adoption alone still leaves manual root/child sync and per-change founder go-ahead under current policy. To meet monthly-only human review, approve once the exact autonomous scope: who may merge which paths, mandatory tests/review, allowed images/definitions, resource/spend ceilings, stop conditions, rollback and audit retention. Bind the execution identity to those grants; do not infer standing authority from one rollout.

Then permit automated promotion/sync within that scope, after the adoption soak; keep pruning disabled until the complete tracked set is proven. Changes to access, secrets, schema/maturity rules, destructive operations or budget ceilings remain in the monthly decision packet. Failed routine checks stop/retry/roll back automatically and produce visible evidence rather than asking the founder to approve each run. Prove one normal release and one failed health-check rollback through Git/ArgoCD.

Acceptance

A normal authorized change builds/tests, publishes a digest, updates reviewed source, merges and reconciles through ArgoCD, verifies health, and records evidence without kubectl apply or a fresh founder exception. Failure recovers through the declared rollback path. Human involvement is limited to the agreed monthly policy review. GLAS-WP-0012/HFACT-WP-0001 readiness remains a separate prerequisite for automated pattern editing; completing this plan does not imply that executor is admitted.

Implementation authorization and scope — 2026-09-27

The founder explicitly requested implementation of these actionable tasks. This supersedes the earlier wait for adoption authorization; it does not waive the 24-hour healthy observation period or invent an unattended release credential. RPF-WP-0048 owns the scoped AppProject/child adoption. Nine runtime resources are reconciled to live state with an empty client diff and successful server dry-run; Jobs/custody/infrastructure are excluded. See docs/gitops-release.md.

Image CI now tests before publishing full-commit tags/digests with pinned build inputs. Local container tests passed. Registry publication/readback must still be observed. The image-only promotion validator has negative fixtures for widened authority, stale/missing evidence, non-digest references and incomplete soak. It is not a credential issuer or proof of an admitted unattended executor.

Verified delivery — 2026-09-27

T01 complete: commit 12e08878d1 passed CI smoke and image publication (runs 307/308). Nine-resource projection and pinned frontend definitions are checked before publication. All three live components now pull immutable registry digests of their exact prior binaries. Registry readback, node pulls, all three rollouts and a Temporal scheduled report passed. Baseline registry tags are protected in the additive live-image retention union.

T02 adoption complete, observation outstanding: metadata-only initial sync at 12:07:35Z; digest release through root/child ArgoCD succeeded at 13:37:56Z. Healthy transition at 13:38:21Z starts the conservative 24-hour window; earliest eligibility is 2026-09-28 15:38:21 Europe/Berlin, conditional on healthy evidence. Automated sync and pruning remain off. RPF-WP-0048 owns observation/admission; its T03 owns general digest-aware registry retention, with current tags protected.

T03 has a tested image-only admission validator and one successful Git/ArgoCD release. Authenticated receipt verification, narrowly bound unattended identity, and failed-health automatic rollback remain required. Producer JSON flags do not provide authority. No executor credential has been invented or broad operator authority delegated. Existing GLAS/HFACT pattern-editing readiness is unchanged.

Evidence: docs/evidence/2026-09-27-gitops-adoption.json. Activation authorization is State Hub decision 78a4b859-dd00-4623-b95b-121b0e1c915d.