Advance blocked assurance and operator callback work
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
codex 2026-09-06 14:16:49 +02:00
parent a3ca4b708f
commit 445f1361dc
16 changed files with 505 additions and 144 deletions

View file

@ -0,0 +1,180 @@
{
"observation": {
"schema": "railiance-platform.observation.v1",
"cluster_uid": "a553c742-0115-43d4-99a4-a5ca56fe0786",
"captured_at": "2026-09-06T10:13:09.536959+00:00",
"signals": {
"apps-pg.ready": {
"result": "pass",
"observed_at": "2026-09-06T10:13:01.557274+00:00"
},
"apps-pg.backup": {
"result": "pass",
"observed_at": "2026-09-06T02:15:09Z"
},
"apps-pg.wal": {
"result": "pass",
"observed_at": "2026-09-06T10:13:01.557317+00:00"
},
"apps-pg.headroom": {
"result": "pass",
"observed_at": "2026-09-06T10:12:43Z"
},
"platform-pg.ready": {
"result": "pass",
"observed_at": "2026-09-06T10:13:03.817521+00:00"
},
"platform-pg.backup": {
"result": "pass",
"observed_at": "2026-09-06T02:15:15Z"
},
"platform-pg.wal": {
"result": "pass",
"observed_at": "2026-09-06T10:13:03.817548+00:00"
},
"platform-pg.headroom": {
"result": "pass",
"observed_at": "2026-09-06T10:12:59Z"
},
"platform-pg-2.ready": {
"result": "pass",
"observed_at": "2026-09-06T10:13:06.269440+00:00"
},
"platform-pg-2.backup": {
"result": "pass",
"observed_at": "2026-09-06T02:15:09Z"
},
"platform-pg-2.wal": {
"result": "pass",
"observed_at": "2026-09-06T10:13:06.269464+00:00"
},
"platform-pg-2.headroom": {
"result": "pass",
"observed_at": "2026-09-06T10:12:56Z"
},
"openbao.seal": {
"result": "pass",
"observed_at": "2026-09-06T10:13:08.833110+00:00"
},
"eso.ready": {
"result": "pass",
"observed_at": "2026-09-06T10:13:09.535776+00:00"
},
"eso.refresh": {
"result": "pass",
"observed_at": "2026-09-06T09:13:29Z"
},
"apps-pg.restore": {
"result": "pass",
"observed_at": "2026-09-05T22:30:45.208512+00:00"
},
"forgejo-db.restore": {
"result": "pass",
"observed_at": "2026-09-05T22:55:54.893587+00:00"
}
}
},
"evaluation": {
"schema": "railiance-platform.assurance-signal.v1",
"cluster_uid": "a553c742-0115-43d4-99a4-a5ca56fe0786",
"evaluated_at": "2026-09-06T10:18:41.042228+00:00",
"signals": {
"apps-pg.ready": {
"state": "healthy",
"owner": "railiance-platform"
},
"apps-pg.backup": {
"state": "healthy",
"owner": "railiance-platform"
},
"apps-pg.wal": {
"state": "healthy",
"owner": "railiance-platform"
},
"apps-pg.restore": {
"state": "healthy",
"owner": "railiance-platform"
},
"apps-pg.headroom": {
"state": "healthy",
"owner": "railiance-platform"
},
"platform-pg.ready": {
"state": "healthy",
"owner": "rapp-postgres"
},
"platform-pg.backup": {
"state": "healthy",
"owner": "rapp-postgres"
},
"platform-pg.wal": {
"state": "healthy",
"owner": "rapp-postgres"
},
"platform-pg.restore": {
"state": "missing",
"owner": "rapp-postgres"
},
"platform-pg.headroom": {
"state": "healthy",
"owner": "rapp-postgres"
},
"platform-pg-2.ready": {
"state": "healthy",
"owner": "rapp-postgres"
},
"platform-pg-2.backup": {
"state": "healthy",
"owner": "rapp-postgres"
},
"platform-pg-2.wal": {
"state": "healthy",
"owner": "rapp-postgres"
},
"platform-pg-2.restore": {
"state": "missing",
"owner": "rapp-postgres"
},
"platform-pg-2.headroom": {
"state": "healthy",
"owner": "rapp-postgres"
},
"openbao.seal": {
"state": "healthy",
"owner": "railiance-platform"
},
"openbao.snapshot": {
"state": "missing",
"owner": "railiance-platform"
},
"openbao.restore": {
"state": "missing",
"owner": "railiance-platform"
},
"offsite.upload": {
"state": "missing",
"owner": "railiance-platform"
},
"offsite.restore": {
"state": "missing",
"owner": "railiance-platform"
},
"eso.ready": {
"state": "healthy",
"owner": "railiance-platform"
},
"eso.refresh": {
"state": "stale",
"owner": "railiance-platform"
},
"forgejo-db.restore": {
"state": "healthy",
"owner": "railiance-platform"
}
},
"transport": "unmonitored",
"guarantees": "unsupported",
"threshold_status": "local-diagnostic-only",
"healthy": false
}
}

View file

@ -103,3 +103,15 @@ Source admission checks happen before deployment in the existing apps-pg and
package owner paths; this additional check detects disclosure drift. It does
not apply resources or become a second provisioning engine. Any new consumer
needs an owner entry and a reviewed baseline update, even within free capacity.
## Native recovery receipt adapter
`capture_service_observation.py` loads `assurance/recovery-evidence.json` through
`recovery_evidence.py`. The reviewed SHA-256 pins bind apps-pg and forgejo-db
restore samples to their Scaleway receipts. Original `finished_at` values drive
freshness; recapturing cannot extend their 30-day diagnostic validity. Missing,
changed, invalid or incorrectly scoped receipts yield unavailable samples.
Update pins only after reviewing replacement evidence. Native database recovery
does not attest full application or essentials recovery. Legacy archive receipts
without completion timestamps remain manual evidence; no timestamp is inferred
from file modification time. Automatic cadence and alert delivery remain pending.