Close Vergabe binding and record remaining recovery blockers
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e3b3-11fe-7ba0-a4a3-92331aab0ba1
This commit is contained in:
parent
1839c0ba42
commit
cfbc95e11d
6 changed files with 136 additions and 36 deletions
|
|
@ -6,13 +6,16 @@ backup ownership into `railiance-apps`.
|
|||
|
||||
## Current App Data
|
||||
|
||||
`vergabe-teilnahme` stores relational app data in `vergabe_db` on the shared
|
||||
CloudNativePG cluster `apps-pg` in the `databases` namespace. The cluster is an
|
||||
S3 platform service owned by `railiance-platform`; see
|
||||
`/home/worsch/railiance-platform/docs/apps-pg.md`.
|
||||
The live invited pilot uses `vergabe_demo_company` on `databases/apps-pg`,
|
||||
with runtime Secret reference `vergabe-demo-company/vergabe-demo-env`. It has
|
||||
separate Bound local-path claims for media (5Gi) and issue state (1Gi). See
|
||||
[the current binding](vergabe-demo-company-binding.md). Historical `vergabe_db`
|
||||
and July backup receipts below do not establish this new company's recovery.
|
||||
|
||||
The app currently has no durable media PVC enabled. `persistence.media.enabled`
|
||||
is `false`, so uploaded media is deferred rather than an S5 durability promise.
|
||||
RAPPS-WP-0014-T03 remains waiting: the September 25 rehearsal proved database
|
||||
restore and restart, with empty file stores and no off-host upload. A populated,
|
||||
coherent three-store recovery point and restored workflow are still required.
|
||||
The CNPG/storage backup mechanisms remain owned by `railiance-platform`.
|
||||
|
||||
## Ownership Matrix
|
||||
|
||||
|
|
@ -45,7 +48,7 @@ If this gate is missing, the app can still be used for smoke, development, or
|
|||
migration validation, but promotion beyond that should create or link a
|
||||
`railiance-platform` workplan.
|
||||
|
||||
## Production cluster inventory (2026-07-10)
|
||||
## Historical production cluster inventory (2026-07-10)
|
||||
|
||||
Custodian delivery-lane snapshot
|
||||
(`the-custodian/docs/evidence/vergabe-teilnahme-delivery-lane-20260710.json`)
|
||||
|
|
@ -76,8 +79,9 @@ make cnpg-logical-backup # immediate / daily workstation run
|
|||
make cnpg-backup-status
|
||||
```
|
||||
|
||||
**Unattended schedule (primary):** workstation cron (cluster pods lack egress to
|
||||
install `age`; in-cluster CronJobs ship suspended until a prebuilt image exists):
|
||||
**Historical workstation schedule (superseded):** RAPPS-WP-0002 records the
|
||||
July 22 move to in-cluster CronJobs on CoulombCore and activity-core on
|
||||
Railiance01. This old workstation example is not a current pilot backup receipt:
|
||||
|
||||
```cron
|
||||
# Daily 02:30 UTC — Option A multi-cluster logical backup (RPO 24h)
|
||||
|
|
@ -87,7 +91,7 @@ install `age`; in-cluster CronJobs ship suspended until a prebuilt image exists)
|
|||
Barman `ObjectStore` / CNPG `ScheduledBackup` remain deferred (Phase 2 stubs in
|
||||
`manifests/cnpg-backup-readiness.yaml`).
|
||||
|
||||
## `vergabe-teilnahme` Gate
|
||||
## Historical `vergabe_db` gate
|
||||
|
||||
Current posture (2026-07-12):
|
||||
|
||||
|
|
@ -145,7 +149,7 @@ When the missing durability item is not local to S5:
|
|||
|
||||
1. Keep the S5 task focused on the app release impact.
|
||||
2. Create or link the platform/forge workplan that owns the missing mechanism.
|
||||
3. Mark the S5 task `blocked` only when the app release cannot safely continue
|
||||
3. Mark the S5 task `wait` and its workplan `blocked` when the app release cannot safely continue
|
||||
without that upstream evidence.
|
||||
4. Record the State Hub workstream/task id in the app runbook or workplan.
|
||||
5. Revisit the S5 promotion gate after upstream evidence exists.
|
||||
|
|
|
|||
58
docs/evidence/2026-09-27-vergabe-binding-review.md
Normal file
58
docs/evidence/2026-09-27-vergabe-binding-review.md
Normal file
|
|
@ -0,0 +1,58 @@
|
|||
# Vergabe binding and loose-end review — 2026-09-27
|
||||
|
||||
Reviewed every workplan, including archived files. RAPPS-WP-0014 is the only
|
||||
unfinished workplan; all other task blocks are done. No ready or proposed
|
||||
workplan remains. No new workplan or task was created.
|
||||
|
||||
## Binding verification (read-only)
|
||||
|
||||
| Check | Result |
|
||||
| --- | --- |
|
||||
| Node / cluster | Ready, 92.205.62.239; kube-system UID a553c742-0115-43d4-99a4-a5ca56fe0786 |
|
||||
| Helm | vergabe-demo-company / vergabe-teilnahme, deployed revision 3, chart 0.2.1 |
|
||||
| Deployment | Ready 1/1; image sha256:a26444f59c259698159c69ccb96f73dc648a261ece4c86bb2037a9d977870d91 |
|
||||
| Requests / custody reference | 60m CPU, 256Mi memory; envFrom Secret reference vergabe-demo-env |
|
||||
| Media / issue state | vergabe-teilnahme-media 5Gi and vergabe-teilnahme-app-state 1Gi, both Bound, local-path |
|
||||
| TLS / health | vergabe-demo-tls Ready; HTTPS /demo-company/health/ returned 200 |
|
||||
| Chart regression suite | 8 tests passed |
|
||||
| Helm lint | Passed with admitted values plus SSO overlay |
|
||||
|
||||
Commands: `kubectl get nodes -o wide`, explicit namespace/deployment field
|
||||
queries, `kubectl -n vergabe-demo-company get deployment,pvc,certificate`,
|
||||
`helm list -n vergabe-demo-company -o json`, HTTPS health request,
|
||||
`python3 -m unittest discover -s tests -p 'test_vergabe_pilot_chart.py'`, and
|
||||
`helm lint charts/vergabe-teilnahme -f helm/vergabe-demo-company-values.proposed.yaml
|
||||
-f helm/vergabe-demo-company-sso.proposed.yaml`.
|
||||
|
||||
The image/source/CI receipt is
|
||||
[the revision 3 rollout](2026-09-12-account-recovery-live.md).
|
||||
Database/role isolation and initial membership counts retain their dated
|
||||
receipts in [the binding](../vergabe-demo-company-binding.md); no current user
|
||||
list, database contents or Secret values were read for this review.
|
||||
VERGABE-WP-0019 records the September 24 founder sign-in and still waits for
|
||||
the fresh recipient journey and two-user acceptance. T02 can close on its
|
||||
release-binding scope without claiming those separate gates passed.
|
||||
|
||||
## Remaining recovery gate
|
||||
|
||||
[September 25](2026-09-25-vergabe-demo-company-restore.md) proves a database
|
||||
restore and pod restart only. File claims were empty and the encrypted database
|
||||
artifact remained on the workstation. It does not prove populated media/issue
|
||||
state recovery, off-host delivery, restored user workflow or safe rollback.
|
||||
|
||||
`warden route find` and `warden route show railiance-backup-offsite-lane`
|
||||
identify railiance-platform's OpenBao/Nextcloud lane. With the documented local
|
||||
OpenBao tunnel explicitly selected, `tools/check-backup-lane-auth.sh` confirmed
|
||||
OpenBao is unsealed but returned **no valid caller token**. Bernd Worsch's
|
||||
attended authentication is required for this workstation upload path; no secret
|
||||
was fetched. This does not establish the health of separate unattended jobs.
|
||||
|
||||
RAPPS-WP-0014-T03 waits for the company workflow, a coherent off-host recovery
|
||||
point for all three stores, isolated restored workflow, rollback evidence and
|
||||
named support/incident ownership. The workplan is blocked. Existing product
|
||||
owner tasks VERGABE-WP-0019-T04/T06 retain human acceptance. No runtime mutation,
|
||||
substitute user login, backup upload or new recovery claim was made.
|
||||
|
||||
The policy-nexus ArgoCD inbox proposal was read. It belongs to the existing
|
||||
rApp/platform onboarding plans and supplies no unfinished task in this repo;
|
||||
this review does not approve its live adoption or open another plan.
|
||||
|
|
@ -1,7 +1,7 @@
|
|||
# Vergabe demo-company deployment binding
|
||||
|
||||
Updated 2026-09-12 under RAPPS-WP-0014 and VERGABE-WP-0019.
|
||||
Application placement is live; native product sign-in and recovery acceptance remain open.
|
||||
Updated 2026-09-27 under RAPPS-WP-0014 and VERGABE-WP-0019.
|
||||
Release binding is complete (RAPPS-WP-0014-T02). Recovery and invited-recipient acceptance remain open.
|
||||
|
||||
| Item | Current binding |
|
||||
| --- | --- |
|
||||
|
|
@ -18,7 +18,7 @@ Application placement is live; native product sign-in and recovery acceptance re
|
|||
| Database / role | Fresh vergabe_demo_company / vergabe_demo_company, databases/apps-pg |
|
||||
| Runtime custody | vergabe-demo-company/vergabe-demo-env; platform helper receipt in RPF-WP-0039 |
|
||||
| Media / issue state | Separate Bound local-path PVCs, 5Gi / 1Gi; UID/GID/fsGroup 999 |
|
||||
| Authentication | NetKingdom company welcome and OIDC deployed; initial readback zero accounts. Actual recipient login/MFA pending |
|
||||
| Authentication | NetKingdom company welcome and OIDC deployed; founder sign-in recorded September 24. Fresh recipient journey and two-user acceptance remain open |
|
||||
| Remaining handoffs | VERGABE-WP-0019-T06 welcome/SSO; RAPPS-WP-0014-T03 recovery; VERGABE-WP-0019-T04 pilot acceptance |
|
||||
|
||||
## Current SSO rollout
|
||||
|
|
@ -89,10 +89,22 @@ on stdin; the durable credential copies are the two exact Kubernetes Secrets.
|
|||
OpenBao automation remains a later owner improvement. Never rerun historical
|
||||
bootstrap helpers or substitute apps_admin credentials.
|
||||
|
||||
This is the first release in the fresh namespace; there is no previously
|
||||
accepted application image to roll back to. On a failed next upgrade, stop public
|
||||
traffic and reconcile schema/image compatibility before reverting. Retain the
|
||||
Revision 3 is the current binding; revisions 1 and 2 are historical deployment
|
||||
receipts, not demonstrated safe rollback targets. On a failed next upgrade,
|
||||
stop public traffic and reconcile schema/image compatibility before reverting. Retain the
|
||||
claims and database; namespace deletion is not rollback. Pod replacement and
|
||||
isolated restore must still be proven with matched PostgreSQL/media/SQLite data.
|
||||
|
||||
Current recovery rollout: docs/evidence/2026-09-12-account-recovery-live.md.
|
||||
|
||||
|
||||
## Binding review — 2026-09-27
|
||||
|
||||
Read-only deployment, Helm, claim, certificate and HTTPS checks match this
|
||||
binding; see [the verification receipt](evidence/2026-09-27-vergabe-binding-review.md).
|
||||
The September 25 database restore and pod restart passed, but populated media
|
||||
and issue-state recovery, an off-host copy, restored two-user workflow and
|
||||
rollback/support acceptance remain RAPPS-WP-0014-T03. That task is waiting and
|
||||
the workplan is blocked. Earlier dated sections describe their original
|
||||
snapshots; the current binding table and this review supersede their pending
|
||||
DNS, deployment and first-login statements.
|
||||
|
|
|
|||
|
|
@ -9,8 +9,9 @@ the historical deployment is still live.
|
|||
|
||||
Before native admission, record the following non-secret values in the company
|
||||
binding. The user selects a fresh `demo-company` workspace; see
|
||||
[its prepared binding](vergabe-demo-company-binding.md). Native tenant/user/password setup is verified; application hostname admission
|
||||
and product placement remain pending.
|
||||
[its prepared binding](vergabe-demo-company-binding.md). Native tenant/user/password setup, hostname admission and product placement are
|
||||
verified. The binding task closed on 2026-09-27; recovery and recipient
|
||||
acceptance remain blocked in the existing tasks.
|
||||
|
||||
| Binding | Required evidence |
|
||||
| --- | --- |
|
||||
|
|
@ -72,20 +73,21 @@ HA is not claimed.
|
|||
|
||||
## Manual onboarding and acceptance
|
||||
|
||||
Use the existing Django administration via the admitted operator path to create
|
||||
ordinary active members. Keep staff/superuser access with the designated
|
||||
operator. Supply initial credentials over the existing private human channel;
|
||||
never paste them into Git, State Hub, command arguments or chat. Members can
|
||||
change passwords in the UI; operators handle reset and deactivation manually.
|
||||
Do not run `seed_dev` on a pilot/customer database.
|
||||
The current demo-company release uses NetKingdom OIDC and the company welcome
|
||||
flow. Provision ordinary members through the native User Engine journey and
|
||||
have each invited recipient complete their own login/MFA and confirmation.
|
||||
Do not substitute shared Django passwords or staff identities for this gate.
|
||||
The founder's September 24 sign-in is recorded; a fresh recipient journey and
|
||||
two-user acceptance remain VERGABE-WP-0019-T04/T06. Never place credentials or
|
||||
setup links in work records, and do not run `seed_dev` on a pilot database.
|
||||
|
||||
Before admitting the first users, verify HTTPS login, CSRF failure behavior,
|
||||
anonymous document refusal, two separate user sessions and deactivation of an
|
||||
already logged-in account. Complete the tender → lot → task/document → domain
|
||||
approval → submission workflow and feedback with the company contact. Customer
|
||||
support contact, incident routing and backup responsibility must be recorded.
|
||||
Pricing, automated invitation email, SSO and shared tenancy can be considered
|
||||
later; none is implied by this initial pilot contract.
|
||||
Pricing, automated invitation email and shared tenancy remain outside this
|
||||
pilot contract. SSO is deployed; recipient acceptance remains a separate gate.
|
||||
|
||||
## Current inventory — 2026-09-11
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue