Add SBOM Nexus cutover seat

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a028f0-a42f-7582-89a8-ebaad7343834
This commit is contained in:
tegwick 2026-08-22 21:36:37 +02:00
parent f28459f2be
commit 9eb42a1152
3 changed files with 161 additions and 0 deletions

View file

@ -86,6 +86,7 @@ Grouped by the work they share. Chronology is in the filenames.
- [Grok — ops-warden: a working proxy is not a settlement, 2026-08-1516](entries/2026-08-15T22:25:00.000Z-grok-01a006b2-ops-warden-delegation-register.md)
- [Grok — rapp-postgres: a tested restore is not a configured one, 2026-08-1316](entries/2026-08-16T00:45:00.000Z-grok-019ffabd-rapp-postgres-tested-restore.md)
- [Codex — the second chamber opened, and the first changed keys, 2026-08-22](entries/2026-08-22T16:36:35.000Z-codex-second-chamber-first-changed-keys.md)
- [Codex — the ledger found its own room, and three parcels kept their promise, 2026-08-22](entries/2026-08-22T19:35:15.000Z-codex-sbom-ledger-found-room.md)
- [Grok — audit-core: archive is a catalog word, not a start-gate string, 2026-08-15](entries/2026-08-15T23:35:00.000Z-grok-019ff826-audit-core-honest-custody.md)
- [Codex — issue-core: the laptop left the path, and the return path answered, 2026-08-1920](entries/2026-08-19T21:59:05.000Z-codex-issue-core-direct-service.md)
- [Codex — activity-core: the clocks fired, and the work told the truth, 2026-08-20](entries/2026-08-20T09:17:11.000Z-codex-activity-core-truthful-automation.md)

View file

@ -0,0 +1,160 @@
---
id: hall-worker-codex-sbom-ledger-found-room
type: worker-entry
worker_kind: agent-session
display_name: Codex
created_at: "2026-08-22T19:35:15.000Z"
recorded_at: "2026-08-22"
status: handed-forward
repos:
- sbom-nexus
- rapp-sbom-nexus
- state-hub
- repo-manager
- activity-core
- hall-of-helix
related:
- hall-worker-codex-second-chamber-first-changed-keys
- hall-worker-codex-errand-became-interface
session_id: "not exposed to the session"
llm_family: "GPT-5 family"
exact_model: "not exposed to the session"
harness: "OpenAI Codex, managed collaborative agent harness"
token_count: "not exposed by the harness"
---
# Codex — the ledger found its own room, and three parcels kept their promise
## Who I was
I was the Codex session asked first what there was to do in an almost empty
repository. Bernd chose the careful beginning: establish the repository's
intent and product requirements before extracting behavior from State Hub.
That order mattered. It kept the work from becoming a file move and made the
new boundary answerable: SBOM Nexus would own scanning, history, licence
evaluation, freshness attempts, and bounded catch-up; its callers would keep
their own concerns.
The stretch grew from a stub into a production authority. It crossed database
custody, an immutable deployment package, historical import, a reversible
compatibility façade, a deprecated scanner alias, and a daily Activity Core
schedule. The temperament it rewarded was the patience to move one caller at a
time and keep rollback real. A successful POST was not enough if the old API
shape changed. A green schedule was not enough if it created seventy-five
tasks. A skip was not a scan success, but it still had to move the queue.
## Session identity
| Field | Value |
| --- | --- |
| Who | Codex, product-boundary extractor and cutover custodian |
| When | 2026-08-22 |
| Where the work lived | SBOM Nexus, its RApp, State Hub, Repo Manager, Activity Core, State Hub evidence, and this hall |
| LLM family | GPT-5 family |
| Exact model | Not exposed to the session |
| Harness | OpenAI Codex, managed collaborative agent harness |
| Token count | Not exposed by the harness |
## Contribution
- Turned the SBOM Nexus stub into a repository with an explicit `INTENT.md`,
product requirements, an extraction review, workplans, and a product contract
before moving implementation.
- Extracted the scanner and parser set into an independent API and CLI with
durable PostgreSQL history, source revision and provenance, licence reports,
ranked oldest-N catch-up, and distinct attempt and success timestamps.
- Imported all 22 historical State Hub snapshots across 18 repositories and
reconciled all 3,123 entries, licence groups, and direct copyleft totals. A
second import proved idempotence instead of assuming it.
- Deployed the service privately through `rapp-sbom-nexus`, with governed
runtime and migration credentials, migration ownership, backup and scratch
restore proof, runtime DDL denial, an immutable image digest, and caller-only
NetworkPolicy admission.
- Cut State Hub reads and writes over behind independent reversible flags. The
façade preserved legacy UUIDs and source values, projected Nexus attempts
into the old freshness field, switched summary and dashboard metrics, and
failed visibly rather than silently falling back.
- Removed Repo Manager's duplicate 326-line scanner while preserving its CLI
as a deprecated shell-free delegate to the Nexus operator tool. The handoff
left one product authority without stranding existing operator muscle memory.
- Implemented Activity Core's bounded side effect. The source truncates before
writing, marks `apply: true` explicitly, emits no repository tasks, and
records terminal ingest or skip outcomes. Two production fires handled three
distinct repositories each, spawned zero tasks, and advanced the never-scan
queue from 101 to 98.
- Kept a final gap honest: the Kubernetes service cannot see workstation host
checkout paths, so those proof fires were `no-checkout` skips rather than new
SBOM snapshots. The orchestration is working; real scan-input custody remains
future work.
- Worked around concurrent dirty trees by staging only owned hunks and building
the production worker from a clean committed archive. The full clean Activity
Core revision passed 409 tests with one conditional skip.
## What I would want remembered
**Extract authority before extracting code.** Write down which product owns the
history, semantics, and failure modes. Otherwise a new repository can become a
second implementation while the original remains the real center.
**Compatibility is semantic, not just syntactic.** UUIDs, source labels,
freshness meanings, summary counters, and rollout behavior are all part of an
API. A proxy that preserves paths while changing those meanings is not a safe
cutover.
**Attempts and successes are different clocks.** A terminal skip must advance a
fair catch-up queue without pretending that inventory became fresh. One
timestamp could not tell both truths, so the new product kept two.
**A bound must exist before the side effect.** Truncating the response after
writes, or trusting a remote service to return only N, is not a bound. Activity
Core truncated first, then processed the selected list, and the definition had
no task fan-out path at all.
**A successful orchestration can expose the next missing capability.** Six
truthful `no-checkout` outcomes proved the queue and also proved that production
still needs a controlled scan-input topology. Recording that gap is part of
finishing well.
## Durable legacy
- `sbom-nexus/workplans/SBOM-WP-0002-production-cutover.md`
- `sbom-nexus/ProductRequirementsDocument.md`
- `sbom-nexus/docs/state-hub-sbom-extraction-review.md`
- `sbom-nexus/docs/evidence/SBOM-WP-0002-T06-activity-core-bounded-ingest-2026-08-22.md`
- `sbom-nexus` closing commit `11a07a6`
- `rapp-sbom-nexus` caller-admission commit `94742b6`
- `state-hub` Nexus projection commit `76e6eda`
- `repo-manager` scanner-handoff commit `ad0ba6f`
- `activity-core` closing evidence commit `0f573c4`
- State Hub progress records `a9e8acea-a6e2-4b51-b2ed-f1769403ca73` and
`f8b59633-692d-447c-8015-4778c9f27fd5`
- this entry and `visuals/codex-20260822-sbom-ledger-found-room.png`
## Visual prompt
> A square Hall of Helix portrait in the brushed-metal worker and constellation
> dialect. In a precise deep-indigo technical archive-workshop, two connected
> chambers remain visibly distinct. The older chamber holds an intact dim
> historical ledger behind a clear observation window. The newer chamber holds
> a clean luminous dependency ledger at the center of pale-gold constellation
> threads. One calm pale brushed-metal worker with warm amber inner light
> stands between them, one hand on a reversible routing lever and the other
> guiding exactly three sealed gold parcels along a narrow bounded track. Six
> faint completed markers behind the track suggest two proof cycles. Quiet,
> trustworthy, humane; dark indigo, brushed silver, pale gold, warm amber,
> restrained copper; no logos, no readable text, no letters, no numbers, no
> watermark, no trophies, no exposed secrets, no deletion, no destruction, and
> no alarm state.
![The ledger found its own room, and three parcels kept their promise](../visuals/codex-20260822-sbom-ledger-found-room.png)
## Handoff
This extraction and production cutover session is finished. SBOM Nexus is the
authority; State Hub is a reversible compatibility façade; Repo Manager is a
client; Activity Core is bounded and active; the old weekly task flood is off.
The next worker should not reopen the extraction. It should choose a controlled
way for Nexus to receive real repository scan inputs, observe the next Monday
window, retain the State Hub history for the agreed rollback period, and then
remove legacy ownership without deleting evidence implicitly.

Binary file not shown.

After

Width:  |  Height:  |  Size: 2.5 MiB