Close live inventory migration and prepare workplan identity repair
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
codex 2026-09-05 10:17:42 +02:00
parent da42f764c0
commit 3dc005df1c
5 changed files with 157 additions and 4 deletions

View file

@ -0,0 +1,46 @@
{
"status": "proposed-requires-exception-to-managed-uuid-rule",
"retain": "workplans/archived/260702-RPF-WP-0021-apps-pg-shared-cluster.md",
"rename_from": "workplans/RPF-WP-0021-core-hub-platform-onboarding.md",
"rename_to": "workplans/RPF-WP-0030-core-hub-platform-onboarding.md",
"mappings": [
{
"record_id": "RPF-WP-0030",
"copied_uuid": "aa7fe3ff-a76c-5f26-a1e0-a35e48b28d60",
"proposed_uuid": "f7a13cc2-7b1f-5644-89a8-b4e9a934b018"
},
{
"record_id": "RPF-WP-0030-T01",
"copied_uuid": "a7cd3fc0-4469-55a6-aed0-a8cacb34c033",
"proposed_uuid": "b561e71e-213e-506f-8eaf-578eef54977f"
},
{
"record_id": "RPF-WP-0030-T02",
"copied_uuid": "7cac453b-2e85-56d9-abae-d983e382246b",
"proposed_uuid": "5ed30960-336c-5650-96c6-9395ea7f2584"
},
{
"record_id": "RPF-WP-0030-T03",
"copied_uuid": "223d5a77-b7c3-5d1a-a93c-4cb9628b457a",
"proposed_uuid": "ad022406-0ae5-58db-9b9d-2e958ab73237"
},
{
"record_id": "RPF-WP-0030-T04",
"copied_uuid": "50713b54-38a8-543d-8c74-0e3fa186fbb8",
"proposed_uuid": "d4c2d69d-186a-5d0d-9ab7-5a4a48cb1e8d"
},
{
"record_id": "RPF-WP-0030-T05",
"copied_uuid": "ba4984f9-c6c5-5eb2-b4c4-83cbec59298c",
"proposed_uuid": "1b608d2e-d660-50dd-8765-c429afbcb14c"
}
],
"reason": "The August onboarding record reused the May apps-pg identity and five task UUIDs. Retain the older archived identity and reidentify the newer record.",
"reference_updates": [
"docs/evidence/core-hub-postgres-capacity-admission-2026-08-20.md",
"docs/evidence/core-hub-postgres-capacity-preflight-2026-08-20.md",
"docs/evidence/core-hub-private-shadow-2026-08-21.md",
"docs/evidence/core-hub-shadow-preflight-2026-08-20.md"
],
"hub_action": "Reconcile pushed source using rmgr sync; review further refusals without blindly acknowledging retirements."
}

View file

@ -0,0 +1,25 @@
{
"platform_commit": "da42f76",
"activity_core_commit": "4083f31",
"host": "railiance01",
"cluster_uid": "a553c742-0115-43d4-99a4-a5ca56fe0786",
"host_inventory": "/home/tegwick/.local/state/railiance-platform/live-images/all.txt",
"worker_inventory": "/var/lib/railiance-platform/live-images/all.txt",
"helper_release": "/home/tegwick/.local/lib/railiance-platform-inventory/da42f76",
"rollout_hook": "/home/tegwick/.local/bin/railiance-live-images-refresh",
"restored_entries": 51,
"merged_entries": 86,
"sha256": "4bfe9d1e5e118670254c2ac0b1e21e1eb6942a2fb287423e8e446b2df6d70595",
"worker_rollout": "successful",
"read_only_mount_verified": true,
"predecessor_tags_preserved": true,
"definition_sync_http": 200,
"definition_sync_errors": [],
"stored_definition_uses_durable_path": true,
"missing_inventory_refused_before_subprocess": true,
"resolver_command_verified_with_mock": true,
"post_rollout_refresh": "successful",
"prune_executed": false,
"platform_tests": 168,
"activity_core_focused_tests": 14
}

View file

@ -67,3 +67,28 @@ no generated repository changes were observed. This confirms a latency issue,
but does not establish that timeout tuning alone is sufficient. State Hub sync
remains pending. A focused State Hub endpoint/query latency investigation is
needed before another full consistency run. No registrar authority was changed.
## Operational migration and precise sync blocker
RPF-WP-0028 is now finished: durable directory and versioned capture hook
installed on railiance01; actcore-worker rolled out; definition synchronized
and read back from the API. All 51 restored entries survive in the 86-entry
union. The worker mount is read-only, and missing input is rejected before
subprocess invocation. No prune was executed. See the dedicated JSON receipt.
Platform code `da42f76`; activity-core integration `4083f31`.
The current State Hub AGENTS.md documents `rmgr sync --path . --push` for fast
projection sync, reserving fix-consistency for deep audits. That command
assigned missing identifiers and pushed `05f315b`, verified primary/railiance01
and the exact Forge commit, then returned a refusal in 5.8 seconds. The blocker
is six duplicated identities shared by the archived May apps-pg plan and the
August Core Hub onboarding plan, both RPF-WP-0021. No projection mutations were
performed. RPF-WP-0031 tracks the exact repair proposal and the required exception
to this repository's managed-UUID editing prohibition. This supersedes the
previous undifferentiated "sync latency" blocker; deep audit latency is separate.
Read-only State Hub source inspection also found eager relationship loading
on RepositorySlug, ManagedRepo, Workplan and Task. Avoiding unrelated relationship
loads is a candidate optimization for the snapshot/identity endpoints, not a
measured root-cause finding. No State Hub service code or deployment was changed.

View file

@ -4,7 +4,7 @@ type: workplan
title: "Make Forgejo image protection survive checkout replacement"
domain: financials
repo: railiance-platform
status: blocked
status: finished
owner: codex
created: "2026-09-05"
updated: "2026-09-05"
@ -14,7 +14,7 @@ state_hub_workstream_id: "622d1208-b085-5ec2-9fb7-5e41f23e1843"
# Make Forgejo image protection survive checkout replacement
Source: State Hub message `868a2326-cdad-4256-be4c-7cd6c8ec4b5b`. Reviewed against current repository state
on 2026-09-05. Repository implementation is complete; live closure remains pending.
on 2026-09-05. Repository implementation and live inventory migration are complete.
## Implement and verify durable publication
@ -36,9 +36,18 @@ alongside a bad one, proving partial coverage cannot authorize deletion.
```task
id: RPF-WP-0028-T02
status: wait
status: done
priority: high
state_hub_task_id: "2d0795ba-ccc0-5ba9-8315-2deb4d0d71a6"
```
Requires the production host inventory, activity-core directory mount/configuration update, and cluster rollout hook adoption. Follow docs/forgejo-package-prune.md. Preserve the restored union and worker refusal on missing/empty inventory; do not manually trigger prune. No production migration or live verification occurred in this session.
Requires the production host inventory, activity-core directory mount/configuration update, and cluster rollout hook adoption. Follow docs/forgejo-package-prune.md. Preserve the restored union and worker refusal on missing/empty inventory; do not manually trigger prune. Completed 2026-09-05: installed the versioned helper outside the checkout,
seeded all 51 restored entries and merged a fresh railiance01 export (86 total),
added the read-only directory mount, rolled out actcore-worker, and synced the
exact definition override. API readback confirms the durable path. The resolver
accepts that path and refuses missing input before subprocess execution; the
command construction check used a mock and did not run prune. A post-rollout
capture succeeded. Activity-core's refresh target delegates to this hook; invoke
it after subsequent cluster rollouts (no new periodic schedule was introduced).
Evidence: `docs/evidence/RPF-WP-0028-live-inventory-2026-09-05.json`.
Source revisions: platform `da42f76`, activity-core `4083f31`.

View file

@ -0,0 +1,48 @@
---
id: RPF-WP-0031
type: workplan
title: "Separate duplicated apps-pg and Core Hub workplan identities"
domain: financials
repo: railiance-platform
status: blocked
owner: codex
created: "2026-09-05"
updated: "2026-09-05"
---
# Separate duplicated workplan identities
## Diagnose and prepare the exact repair
```task
id: RPF-WP-0031-T01
status: done
priority: high
```
The supported `rmgr sync --path . --push` path reached the verified primary
railiance01 projection in 5.8 seconds, but refused six duplicate identities.
Both the May apps-pg archive and August Core Hub onboarding use RPF-WP-0021,
the same workplan UUID, and the same first five task UUIDs. No projection rows
were created, changed, or retired by the refused reconciliation.
`docs/evidence/RPF-WP-0021-collision-repair-proposal.json` fixes the proposed
choice: retain the older archive and reidentify the newer onboarding record as
RPF-WP-0030, with six Repo Manager-derived UUIDs and four evidence-reference
updates. Existing source UUIDs have not been changed.
## Apply the identity repair and reconcile
```task
id: RPF-WP-0031-T02
status: wait
priority: high
```
Requires a one-time user exception to AGENTS.md's prohibition on editing managed
UUID fields. The existing Repo Manager migration command considers only live
workplans and unfinished tasks, so it does not repair these finished records.
After approval, apply the exact proposal, preserve the archived identity and
all completion evidence, check uniqueness across root and archived workplans,
commit/push, and run `rmgr sync`. Inspect any retirement refusal before proceeding;
never blanket-acknowledge unrelated retirements.