Close Vergabe binding and record remaining recovery blockers
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e3b3-11fe-7ba0-a4a3-92331aab0ba1
This commit is contained in:
tegwick 2026-09-27 18:34:05 +02:00
parent 1839c0ba42
commit cfbc95e11d
6 changed files with 136 additions and 36 deletions

View file

@ -6,13 +6,16 @@ backup ownership into `railiance-apps`.
## Current App Data
`vergabe-teilnahme` stores relational app data in `vergabe_db` on the shared
CloudNativePG cluster `apps-pg` in the `databases` namespace. The cluster is an
S3 platform service owned by `railiance-platform`; see
`/home/worsch/railiance-platform/docs/apps-pg.md`.
The live invited pilot uses `vergabe_demo_company` on `databases/apps-pg`,
with runtime Secret reference `vergabe-demo-company/vergabe-demo-env`. It has
separate Bound local-path claims for media (5Gi) and issue state (1Gi). See
[the current binding](vergabe-demo-company-binding.md). Historical `vergabe_db`
and July backup receipts below do not establish this new company's recovery.
The app currently has no durable media PVC enabled. `persistence.media.enabled`
is `false`, so uploaded media is deferred rather than an S5 durability promise.
RAPPS-WP-0014-T03 remains waiting: the September 25 rehearsal proved database
restore and restart, with empty file stores and no off-host upload. A populated,
coherent three-store recovery point and restored workflow are still required.
The CNPG/storage backup mechanisms remain owned by `railiance-platform`.
## Ownership Matrix
@ -45,7 +48,7 @@ If this gate is missing, the app can still be used for smoke, development, or
migration validation, but promotion beyond that should create or link a
`railiance-platform` workplan.
## Production cluster inventory (2026-07-10)
## Historical production cluster inventory (2026-07-10)
Custodian delivery-lane snapshot
(`the-custodian/docs/evidence/vergabe-teilnahme-delivery-lane-20260710.json`)
@ -76,8 +79,9 @@ make cnpg-logical-backup # immediate / daily workstation run
make cnpg-backup-status
```
**Unattended schedule (primary):** workstation cron (cluster pods lack egress to
install `age`; in-cluster CronJobs ship suspended until a prebuilt image exists):
**Historical workstation schedule (superseded):** RAPPS-WP-0002 records the
July 22 move to in-cluster CronJobs on CoulombCore and activity-core on
Railiance01. This old workstation example is not a current pilot backup receipt:
```cron
# Daily 02:30 UTC — Option A multi-cluster logical backup (RPO 24h)
@ -87,7 +91,7 @@ install `age`; in-cluster CronJobs ship suspended until a prebuilt image exists)
Barman `ObjectStore` / CNPG `ScheduledBackup` remain deferred (Phase 2 stubs in
`manifests/cnpg-backup-readiness.yaml`).
## `vergabe-teilnahme` Gate
## Historical `vergabe_db` gate
Current posture (2026-07-12):
@ -145,7 +149,7 @@ When the missing durability item is not local to S5:
1. Keep the S5 task focused on the app release impact.
2. Create or link the platform/forge workplan that owns the missing mechanism.
3. Mark the S5 task `blocked` only when the app release cannot safely continue
3. Mark the S5 task `wait` and its workplan `blocked` when the app release cannot safely continue
without that upstream evidence.
4. Record the State Hub workstream/task id in the app runbook or workplan.
5. Revisit the S5 promotion gate after upstream evidence exists.