core-hub/docs/deployment/archive-closeout.md
tegwick 7a95a8345c
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 2s
Build and Publish Container Image / build-and-push (push) Successful in 19s
docs: prepare core-hub archive closeout
2026-08-21 21:23:57 +02:00

4.8 KiB

Core Hub archive closeout

Prepared 2026-08-21 for CORE-WP-0010-T05. This document is an executable closure packet, not evidence that the time-gated archive has happened.

Freeze boundary

Core Hub is no longer a product-development target. Until archive:

  • accept only stabilization, security, rollback, evidence, or archive changes;
  • implement new runtime and compatibility behavior in hub-core;
  • keep Core Hub Ready with an empty writer set;
  • never enable legacy and hub-core writers concurrently; and
  • do not delete the legacy schema, immutable image, Helm history, or retained migration evidence during this task.

The absence of an approved retention expiry blocks destructive cleanup. It does not block scaling the rollback workload to zero or archiving this Git repository read-only after operator approval.

Residual ownership

Residual Live owner / record Archive condition
Production runtime, compatibility API, migration code, and future product work hub-core; completed baseline HUB-WP-0005, new changes require hub-core workplans No Core Hub implementation remains authoritative
Deployment, route map, immutable images, live verification, rollback retirement rapp-core-hub; RAPPCOREHUB-WP-0002-T05 Stabilization closes and rollback is scaled down through the package
hub_runtime ownership, grants, and lease behavior rapp-postgres; RAPP-POSTGRES-WP-0004-T03 Rotation evidence is closed or remains explicitly owned there
OpenBao/ESO runtime and migration projections railiance-platform; RAILIANCE-WP-0023-T02 Rotation evidence is closed or remains explicitly owned there
Consumer evidence and hub-port alignment activity-core; ACTIVITY-WP-0029 Resolver/evidence path passes on hub-core
State Hub strangler, remaining development coordination, and retirement state-hub; STATE-WP-0079 No State Hub work is silently absorbed into this archive
Registrar/workstation coupling that prevents authoritative UUID allocation state-hub; STATE-WP-0081 Existing missing-UUID warnings remain owned outside this repo
ops-hub compatibility probe ops-hub; make interhub-gate Public gate passes at closeout

The broader intent gaps recorded in STATE.md—progress/work projections and durable decision, deployment, and outcome resources—are future hub-core and State Hub retirement scope. They are not unfinished Core Hub migration code and must not be restarted here.

Current immutable anchors

  • Public hub-core source/image: 055cf49 / sha256:adf580d09a4a9139b1663c41d59d46903a007e03a3ae567e09b8a6ec23708ab8
  • Core Hub rollback image: sha256:388a94ec752e13a0031e329a45e970480c41691e969d4e40c31924669e8d0005
  • Deployment package: chart 0.4.0, current Helm revision 20
  • Rehearsed rollback revision: 19
  • Data and rollback evidence: docs/evidence/core-hub-hub-core-cutover-2026-08-21.md

The final repository revision is intentionally filled in only by the closeout commit immediately before Forgejo is made read-only.

Closeout checklist

Do not check the time- or approval-dependent items early.

  • Current time is no earlier than 2026-08-28T20:49:50+02:00
  • No unresolved stabilization anomaly or rollback occurred after final promotion
  • make test passes
  • make stabilization-check passes
  • activity-core public resolver/evidence gate passes
  • Counts, identity sets, and canonical hashes remain explained and matching
  • Credential rotation tasks are done or retain explicit external owners
  • State Hub inbox contains no unhandled Core Hub retirement message
  • Final Core Hub Git revision and evidence links are recorded
  • Operator approves rollback retirement and read-only archive

Ordered closeout

  1. Run the checklist and append dated results to the cutover evidence record.
  2. Record the operator decision and completion progress in State Hub against CORE-WP-0010-T05.
  3. Through rapp-core-hub, scale the Core Hub rollback workload to zero while retaining its immutable image, Helm history, schema, and recovery record.
  4. Re-run the public consumer and deployment-package gates against hub-core.
  5. Set CORE-WP-0010-T05 to done, the workplan to finished, and update STATE.md/README.md to point all active development to hub-core.
  6. Run statehub fix-consistency, commit, and push the final revision.
  7. Route the Forgejo admin credential through warden route and set coulomb/core-hub read-only/archived. Do not expose the credential.
  8. Verify anonymous clone/history remains available and pushes are refused.

If any closeout gate fails, leave the repository writable for evidence fixes, keep the rollback workload Ready with no writers, and record the failed gate and owner. Do not improvise concurrent writers or destructive cleanup.