From 4f20e755c4de345ed09b235fdc1690f752903d8d Mon Sep 17 00:00:00 2001 From: codex Date: Sun, 27 Sep 2026 16:08:17 +0200 Subject: [PATCH] Close digest-retention task with verified GitOps runtime projection Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3 --- .../2026-09-27-digest-retention-release.json | 27 +++++++++++++++++++ ...F-WP-0048-activity-core-gitops-adoption.md | 18 ++++++++++++- 2 files changed, 44 insertions(+), 1 deletion(-) create mode 100644 docs/evidence/2026-09-27-digest-retention-release.json diff --git a/docs/evidence/2026-09-27-digest-retention-release.json b/docs/evidence/2026-09-27-digest-retention-release.json new file mode 100644 index 0000000..aeaf8fd --- /dev/null +++ b/docs/evidence/2026-09-27-digest-retention-release.json @@ -0,0 +1,27 @@ +{ + "date": "2026-09-27", + "platform_source": "743def1", + "activity_revision": "a12f1169f9d130058ce767f5b26de0606997916c", + "platform_application_revision": "4b9c4ce", + "tool_sha256": "fa3d4cc8cdcc14ecce509cf6865c6e4726d722f84814b97d40686d68d6ee5bb1", + "tests": { + "platform_retention_and_inventory": 20, + "activity_gitops": 17, + "ci": "all smoke and image build checks passed" + }, + "production": { + "sync": "Synced", + "health": "Healthy", + "finished_at": "2026-09-27T14:06:20Z", + "worker_hash_verified": true, + "real_inventory_digest_protection_verified": true, + "synthetic_rollback_planner_protected": true, + "registry_requests_during_probe": 0, + "deletions": 0 + }, + "healthy_since": "2026-09-27T14:06:22Z", + "earliest_soak_eligibility": "2026-09-28T14:06:22Z", + "automated_promotion": false, + "retention_policy": "all versions of packages referenced by digest in additive live/rollback inventory are protected", + "remaining": "scoped source/sync broker, authenticated receipts and automatic rollback proof; automatic pattern execution readiness unchanged" +} diff --git a/workplans/RPF-WP-0048-activity-core-gitops-adoption.md b/workplans/RPF-WP-0048-activity-core-gitops-adoption.md index 8d336c0..c522db7 100644 --- a/workplans/RPF-WP-0048-activity-core-gitops-adoption.md +++ b/workplans/RPF-WP-0048-activity-core-gitops-adoption.md @@ -56,7 +56,7 @@ activating bounded routine promotion. Destructive pruning remains disabled. ```task id: RPF-WP-0048-T03 -status: progress +status: done priority: high state_hub_task_id: "6c2650a2-5da8-5999-a6e7-b22eb7c655f4" ``` @@ -114,3 +114,19 @@ sync operation; resource-name RBAC alone cannot restrict patch fields. This is concrete implementation work retained here and in ACTIVITY-WP-0041-T03, not a reason to ask the founder to approve each release. Tests in the owner checkout: 20 passed across retention and additive inventory suites. + +## Retention deployed and verified — 2026-09-27 + +T03 complete. Supersedes the earlier pending host-copy installation: the script +is now pinned by source commit and SHA256 in activity-core's existing ConfigMap, +projected read-only over the worker tool path, and reconciled through ArgoCD. +No host checkout mutation, new resource adoption or manual prune was needed. +The pod annotation changes with the script hash to refresh subPath mounts. +CI verifies source bytes against the platform commit. Live worker hash matches; +real additive inventory protects activity-core as a whole package. A synthetic +rollback version is protected by the planner. No registry requests or deletion +were made by this probe. See docs/evidence/2026-09-27-digest-retention-release.json. + +New healthy observation start is 2026-09-27T14:06:22Z after worker rollout; +earliest eligibility is September 28 at 16:06:22 Europe/Berlin. Automation remains +off. T02 still owns the scoped broker/admission and observation requirements.