86 lines
4.8 KiB
Markdown
86 lines
4.8 KiB
Markdown
|
|
# Core Hub archive closeout
|
||
|
|
|
||
|
|
Prepared 2026-08-21 for `CORE-WP-0010-T05`. This document is an executable
|
||
|
|
closure packet, not evidence that the time-gated archive has happened.
|
||
|
|
|
||
|
|
## Freeze boundary
|
||
|
|
|
||
|
|
Core Hub is no longer a product-development target. Until archive:
|
||
|
|
|
||
|
|
- accept only stabilization, security, rollback, evidence, or archive changes;
|
||
|
|
- implement new runtime and compatibility behavior in hub-core;
|
||
|
|
- keep Core Hub Ready with an empty writer set;
|
||
|
|
- never enable legacy and hub-core writers concurrently; and
|
||
|
|
- do not delete the legacy schema, immutable image, Helm history, or retained
|
||
|
|
migration evidence during this task.
|
||
|
|
|
||
|
|
The absence of an approved retention expiry blocks destructive cleanup. It
|
||
|
|
does not block scaling the rollback workload to zero or archiving this Git
|
||
|
|
repository read-only after operator approval.
|
||
|
|
|
||
|
|
## Residual ownership
|
||
|
|
|
||
|
|
| Residual | Live owner / record | Archive condition |
|
||
|
|
| --- | --- | --- |
|
||
|
|
| Production runtime, compatibility API, migration code, and future product work | `hub-core`; completed baseline `HUB-WP-0005`, new changes require hub-core workplans | No Core Hub implementation remains authoritative |
|
||
|
|
| Deployment, route map, immutable images, live verification, rollback retirement | `rapp-core-hub`; `RAPPCOREHUB-WP-0002-T05` | Stabilization closes and rollback is scaled down through the package |
|
||
|
|
| `hub_runtime` ownership, grants, and lease behavior | `rapp-postgres`; `RAPP-POSTGRES-WP-0004-T03` | Rotation evidence is closed or remains explicitly owned there |
|
||
|
|
| OpenBao/ESO runtime and migration projections | `railiance-platform`; `RAILIANCE-WP-0023-T02` | Rotation evidence is closed or remains explicitly owned there |
|
||
|
|
| Consumer evidence and hub-port alignment | `activity-core`; `ACTIVITY-WP-0029` | Resolver/evidence path passes on hub-core |
|
||
|
|
| State Hub strangler, remaining development coordination, and retirement | `state-hub`; `STATE-WP-0079` | No State Hub work is silently absorbed into this archive |
|
||
|
|
| Registrar/workstation coupling that prevents authoritative UUID allocation | `state-hub`; `STATE-WP-0081` | Existing missing-UUID warnings remain owned outside this repo |
|
||
|
|
| ops-hub compatibility probe | `ops-hub`; `make interhub-gate` | Public gate passes at closeout |
|
||
|
|
|
||
|
|
The broader intent gaps recorded in `STATE.md`—progress/work projections and
|
||
|
|
durable decision, deployment, and outcome resources—are future hub-core and
|
||
|
|
State Hub retirement scope. They are not unfinished Core Hub migration code
|
||
|
|
and must not be restarted here.
|
||
|
|
|
||
|
|
## Current immutable anchors
|
||
|
|
|
||
|
|
- Public hub-core source/image: `055cf49` /
|
||
|
|
`sha256:adf580d09a4a9139b1663c41d59d46903a007e03a3ae567e09b8a6ec23708ab8`
|
||
|
|
- Core Hub rollback image:
|
||
|
|
`sha256:388a94ec752e13a0031e329a45e970480c41691e969d4e40c31924669e8d0005`
|
||
|
|
- Deployment package: chart 0.4.0, current Helm revision 20
|
||
|
|
- Rehearsed rollback revision: 19
|
||
|
|
- Data and rollback evidence:
|
||
|
|
`docs/evidence/core-hub-hub-core-cutover-2026-08-21.md`
|
||
|
|
|
||
|
|
The final repository revision is intentionally filled in only by the closeout
|
||
|
|
commit immediately before Forgejo is made read-only.
|
||
|
|
|
||
|
|
## Closeout checklist
|
||
|
|
|
||
|
|
Do not check the time- or approval-dependent items early.
|
||
|
|
|
||
|
|
- [ ] Current time is no earlier than `2026-08-28T20:49:50+02:00`
|
||
|
|
- [ ] No unresolved stabilization anomaly or rollback occurred after final promotion
|
||
|
|
- [ ] `make test` passes
|
||
|
|
- [ ] `make stabilization-check` passes
|
||
|
|
- [ ] activity-core public resolver/evidence gate passes
|
||
|
|
- [ ] Counts, identity sets, and canonical hashes remain explained and matching
|
||
|
|
- [ ] Credential rotation tasks are done or retain explicit external owners
|
||
|
|
- [ ] State Hub inbox contains no unhandled Core Hub retirement message
|
||
|
|
- [ ] Final Core Hub Git revision and evidence links are recorded
|
||
|
|
- [ ] Operator approves rollback retirement and read-only archive
|
||
|
|
|
||
|
|
## Ordered closeout
|
||
|
|
|
||
|
|
1. Run the checklist and append dated results to the cutover evidence record.
|
||
|
|
2. Record the operator decision and completion progress in State Hub against
|
||
|
|
`CORE-WP-0010-T05`.
|
||
|
|
3. Through `rapp-core-hub`, scale the Core Hub rollback workload to zero while
|
||
|
|
retaining its immutable image, Helm history, schema, and recovery record.
|
||
|
|
4. Re-run the public consumer and deployment-package gates against hub-core.
|
||
|
|
5. Set `CORE-WP-0010-T05` to `done`, the workplan to `finished`, and update
|
||
|
|
`STATE.md`/`README.md` to point all active development to hub-core.
|
||
|
|
6. Run `statehub fix-consistency`, commit, and push the final revision.
|
||
|
|
7. Route the Forgejo admin credential through `warden route` and set
|
||
|
|
`coulomb/core-hub` read-only/archived. Do not expose the credential.
|
||
|
|
8. Verify anonymous clone/history remains available and pushes are refused.
|
||
|
|
|
||
|
|
If any closeout gate fails, leave the repository writable for evidence fixes,
|
||
|
|
keep the rollback workload Ready with no writers, and record the failed gate
|
||
|
|
and owner. Do not improvise concurrent writers or destructive cleanup.
|