docs: close inbox snapshot pilot and hand off freshness cutover

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ed7-828d-7ca0-a8d4-0c3e5a0c4102
This commit is contained in:
tegwick 2026-09-05 11:27:04 +02:00
parent 6fb5ce285c
commit 4580e838cc
4 changed files with 229 additions and 3 deletions

View file

@ -0,0 +1,116 @@
{
"date": "2026-09-05",
"scope": "frozen-source-snapshot; no production reader switch",
"source": "state-hub/primary/railiance01",
"captured_at": "2026-09-05T08:38:37.982640+00:00",
"owner_commit": "6fb5ce2",
"package_enable_commit": "6972db5",
"image_digest": "sha256:a3461c0da805ef2b58caa0c862be3dc6562abcca186300d1257df9b96569b4c0",
"endpoint": "GET /ports/projections/statehub-inbox",
"import": {
"runs": [
{
"status": "validated",
"count": 20,
"content_hash": "f952b1fb46469f43bbf8ec7de1041a6feae943708c3496d8b55287428e6ed60d"
},
{
"status": "applied",
"count": 20,
"content_hash": "f952b1fb46469f43bbf8ec7de1041a6feae943708c3496d8b55287428e6ed60d"
},
{
"status": "noop",
"count": 20,
"content_hash": "f952b1fb46469f43bbf8ec7de1041a6feae943708c3496d8b55287428e6ed60d"
}
],
"target_hash": "f952b1fb46469f43bbf8ec7de1041a6feae943708c3496d8b55287428e6ed60d",
"source_count": 20
},
"parity": {
"source_count": 20,
"snapshot_hash": "f952b1fb46469f43bbf8ec7de1041a6feae943708c3496d8b55287428e6ed60d",
"cases": [
{
"params": {},
"count": 19,
"content_hash": "1b3d5beff1d081bec7c552d0c463ffe48999bd75caf5bae1189e421651467295",
"mode": "snapshot-pilot",
"parity": true
},
{
"params": {
"unread_only": "true"
},
"count": 0,
"content_hash": "4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
"mode": "snapshot-pilot",
"parity": true
},
{
"params": {
"from_agent": "activity-core"
},
"count": 8,
"content_hash": "a6fb59f2a35ecc7c9c445bbcd1056955828062179ee52b2c15f497ea76a5656a",
"mode": "snapshot-pilot",
"parity": true
},
{
"params": {
"from_agent": "missing-pilot-sender"
},
"count": 0,
"content_hash": "4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
"mode": "snapshot-pilot",
"parity": true
},
{
"params": {
"limit": "1"
},
"count": 1,
"content_hash": "84a3d3ea5eb407629009eef7440fca14219be63486ab7d61b7e1f2d44adc3bba",
"mode": "snapshot-pilot",
"parity": true
},
{
"params": {
"limit": "1000"
},
"count": 19,
"content_hash": "1b3d5beff1d081bec7c552d0c463ffe48999bd75caf5bae1189e421651467295",
"mode": "snapshot-pilot",
"parity": true
}
],
"no_auth": 401,
"bad_auth": 401,
"post": 405,
"scope": "frozen-source-snapshot"
},
"live_source_check": {
"live_source_api_count": 19,
"live_source_api_hash": "1b3d5beff1d081bec7c552d0c463ffe48999bd75caf5bae1189e421651467295",
"frozen_inbox_hash": "1b3d5beff1d081bec7c552d0c463ffe48999bd75caf5bae1189e421651467295",
"matches_frozen": true
},
"transport_from_state_hub_without_token": 401,
"rollback": {
"configuration_revision": 25,
"rollback_revision": 27,
"readyz": 200,
"disabled_inbox": 404,
"restored_revision": 28,
"parity_repeated": true
},
"checks": {
"hub_core_tests_passed": 116,
"packaging_tests_passed": 11,
"helm_lint": "passed",
"server_dry_run": "passed",
"family_validation": "14 declarations, 0 errors, 1 existing reef-railiance warning",
"verify_live": "passed"
}
}

View file

@ -0,0 +1,38 @@
# Private State Hub inbox snapshot pilot — 2026-09-05
T08 receiving-readiness proof is complete. Hub Core exposes the authenticated,
GET-only `/ports/projections/statehub-inbox` for the literal `state-hub` inbox.
It is private, default-disabled in the chart, and enabled in the current private
production package. State Hub remains the writer; no production reader switched.
A consistent source transaction captured 20 historical rows (including archived
rows and thread closure) at 08:38:37.982640 UTC. Import preserved identities,
timestamps and flags; validation, apply, identical replay/no-op and target hash
all agree. The visible inbox contains 19 rows. Six read cases match ordered IDs
and normalized whole-record hashes, covering unread/sender filters and limits.
The live source inbox also matched the frozen oracle at verification time.
Bodies and credentials are excluded from this evidence.
Missing/bad authentication returns 401; POST returns 405. Scoped NetworkPolicy
admission now permits State Hub API pods to reach the authenticated boundary.
The prior prefix-only probe overlooked existing `/ports/messaging/messages`,
`/ports/events/progress` and named projection ports. Those native envelopes do
not by themselves establish State Hub history/read/archive compatibility.
Image source is `hub-core@6fb5ce2`; package enablement is
`rapp-core-hub@6972db5`. Exact digest and content hashes are in the adjacent JSON.
Helm revision 25 installed the image with the pilot disabled; revision 26 enabled
it after import. Rollback to configuration 25 produced revision 27, readiness
200 and pilot 404. Roll-forward to revision 28 passed the same parity cases and
`make verify-live`. No State Hub image or writer configuration changed.
Validation: 116 owner tests, 11 packaging tests, Helm lint and server dry-run
passed. Family validation passed 14 declarations with zero errors and one
pre-existing reef-railiance warning. The rmgr wrapper lacked jsonschema; the
same family validator succeeded with the State Hub virtualenv interpreter.
Residual **HUB-WP-0011**, tracked by **STATE-WP-0079-T09**, owns ongoing monotonic
freshness/staleness, caller-specific credentials, canonical/alias scope and a
reviewed production reader switch. The operator-authenticated frozen pilot must
not be presented as a fresh inbox. B2/B3 migration and message-writer cutover
remain open; this proof does not retire those families.