hub-core/workplans/HUB-WP-0011-statehub-inbox-freshness-and-cutover.md
tegwick 4580e838cc docs: close inbox snapshot pilot and hand off freshness cutover
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ed7-828d-7ca0-a8d4-0c3e5a0c4102
2026-09-05 11:27:04 +02:00

62 lines
1.9 KiB
Markdown

---
id: HUB-WP-0011
type: workplan
title: "State Hub inbox freshness and reader cutover"
domain: infotech
repo: hub-core
status: proposed
owner: codex
topic_slug: infotech
created: "2026-09-05"
updated: "2026-09-05"
origin: residual
origin_ref: HUB-WP-0010
related:
- STATE-WP-0079
- RAPPCOREHUB-WP-0004
---
## Establish ongoing inbox freshness
```task
id: HUB-WP-0011-T01
status: todo
priority: high
```
The deployed inbox reader is an explicitly labeled one-time snapshot pilot.
Define and implement monotonic source revision/cursor semantics, atomic refresh,
read/archive updates, deletes/retention treatment and stale-source signaling.
The initial importer deliberately refuses different existing rows; do not turn
it into an unconditional overwrite loop. Prove recovery and idempotency without
creating a second message writer. Decide the source/destination ownership
boundary before live client traffic moves.
## Admit the actual reader identity and full scope semantics
```task
id: HUB-WP-0011-T02
status: wait
priority: high
```
Replace pilot operator authentication with the reviewed caller-specific access
contract and delivered workload credential. Preserve recipient authorization,
broadcast behavior, repository canonical/alias resolution, source timestamps
and thread/read/archive semantics for the selected reader. The existing pilot
supports only one literal agent and exact sender filters. Never distribute the
operator token as an application credential.
## Execute one reviewed client switch
```task
id: HUB-WP-0011-T03
status: wait
priority: high
```
After T01/T02 pass, produce live freshness and parity receipts for one State Hub
inbox reader; verify rollback to the current State Hub endpoint. Then execute
that bounded reader switch with the concrete deployment authorization. Retire
its compatibility dependency only after metered acceptance. Message-writer
cutover and all other route families remain separate STATE-WP-0079 work.