From 641eda8a37094ab8922a5f3db2ee38a38aa2b059 Mon Sep 17 00:00:00 2001 From: tegwick Date: Mon, 31 Aug 2026 22:31:24 +0200 Subject: [PATCH] docs: close PNEX fleet standards release Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663 --- docs/adr-review/packets/the-custodian.md | 15 ++++++++ ...tandards-publication-and-ci-source-auth.md | 36 +++++++++++++++++-- 2 files changed, 48 insertions(+), 3 deletions(-) diff --git a/docs/adr-review/packets/the-custodian.md b/docs/adr-review/packets/the-custodian.md index 310ff07..e18ddbd 100644 --- a/docs/adr-review/packets/the-custodian.md +++ b/docs/adr-review/packets/the-custodian.md @@ -45,3 +45,18 @@ currency gate is current. - `canon/architecture/coulomb-estate_v0.1.md` at `/architecture/coulomb-estate/v0.1/`. + +## Fleet standards batch + +Completed 2026-08-31 under PNEX-WP-0004 from owner commit `4b951be`: + +- Autonomy Lanes; +- Contribution Convention; +- Project Repository Flavor; +- Work Record Types; +- Workplan Terminology. + +All five are published with immutable revision `accepted-1`. Bootstrap Protocol +and the Custodian Constitution remain local because their sources explicitly +declare `sensitivity: internal`. Repo Classification and SBOM Convention remain +owner-review residuals under `CUST-IN-0016`. diff --git a/workplans/PNEX-WP-0004-fleet-standards-publication-and-ci-source-auth.md b/workplans/PNEX-WP-0004-fleet-standards-publication-and-ci-source-auth.md index 20f4e45..8be37fd 100644 --- a/workplans/PNEX-WP-0004-fleet-standards-publication-and-ci-source-auth.md +++ b/workplans/PNEX-WP-0004-fleet-standards-publication-and-ci-source-auth.md @@ -4,7 +4,7 @@ type: workplan title: "Publish the first deferred fleet-standards batch and authenticate CI source acquisition" domain: infotech repo: policy-nexus -status: active +status: finished owner: the-custodian topic_slug: policy-nexus created: "2026-08-31" @@ -127,7 +127,7 @@ credential-owner handoff and is not a code-completion gate. ```task id: PNEX-WP-0004-T04 -status: progress +status: done priority: high state_hub_task_id: "a6f789ea-5d90-55cf-b67b-5cf401b81e66" ``` @@ -144,11 +144,21 @@ source inventory source set `7e0f0ee3fdf3bcdc8d34e7fc9ba12304ba84864b06c63e9226324e6aa0ea4e7f`. +Completed 2026-08-31 from clean Policy Nexus commit `5fbd44a`. The pushed +candidate identities are OCI +`sha256:da2c7ce7c431c6d6c4809c1539d7cf11218221505c376688122d27bae9666421`, +publication manifest +`e745f1b396f83c3a42e97478f28988327475b81540ba6d6a6d8e21e572efa8e3`, +source inventory +`64dad35098300f1fa0642ed7bb265f7c7d333d69478ff26aac5d9f0fd4e05c21`, and +source set +`8ee7f6db504b6a2dfda2c32fe820283b9df3e56fa97f47a748cc38e4fb39e9fc`. + ### T05 — Promote, smoke, and close ```task id: PNEX-WP-0004-T05 -status: todo +status: done priority: medium state_hub_task_id: "07c9c18d-95cf-5b09-940a-40b5ff5828a7" ``` @@ -157,6 +167,26 @@ Update the paired `rapp-policy-nexus` and `railiance-apps` bindings, pass server-side admission, deploy atomically, and verify all five current and immutable `accepted-1` URLs before closing this workplan. +Completed 2026-08-31. Paired binding commits `rapp-policy-nexus@29273fc` and +`railiance-apps@96d3716` passed package, image, render, and server-side +admission gates. Helm revision 6 deployed atomically; the live verifier matched +all four identities, and all five current plus five immutable `accepted-1` +addresses returned HTTPS 200. + +## Closure + +Finished 2026-08-31. The public collection now contains 65 explicit documents. +Five current fleet standards have permanent current and immutable addresses; +the internal constitutions remain unpublished, and 28 additional publish +rulings plus five conflicts remain visible through `CUST-IN-0016`. + +Private-source CI support is implemented and tested. Credential routing found +no acceptable existing read-only token, so `railiance-platform@361005c` opened +`CCR-2026-0014`; State Hub message +`15d4ba0d-67d9-4765-b474-0004a1b398ad` requests platform review. Until that +credential is approved and installed, scheduled builds fail closed and the +documented local clean-source path remains the release mechanism. + ## Residuals - Secret provisioning and rotation remain with the credential owner surfaced