Consolidate platform workplans and assess intent gaps
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
parent
9d958f8e09
commit
9f83e426c7
40 changed files with 2985 additions and 295 deletions
165
workplans/RPF-WP-0036-platform-service-assurance.md
Normal file
165
workplans/RPF-WP-0036-platform-service-assurance.md
Normal file
|
|
@ -0,0 +1,165 @@
|
|||
---
|
||||
id: RPF-WP-0036
|
||||
type: workplan
|
||||
title: "Close S3 service assurance and ownership gaps"
|
||||
domain: financials
|
||||
repo: railiance-platform
|
||||
status: ready
|
||||
owner: codex
|
||||
created: "2026-09-05"
|
||||
updated: "2026-09-05"
|
||||
---
|
||||
|
||||
# S3 service assurance and ownership gaps
|
||||
|
||||
Source: `history/2026-09-05-platform-intent-workplan-assessment.md`.
|
||||
Reviewed against current repository evidence. This plan supplies the missing
|
||||
continuing obligations; it does not reopen completed bootstrap projects or
|
||||
duplicate incident/lane work. Repository design and read-only implementation
|
||||
can progress now. Every live drill, scheduler, credential operation or migration
|
||||
retains its own owner and execution gate.
|
||||
|
||||
## Record the portfolio assessment and consolidate source work
|
||||
|
||||
```task
|
||||
id: RPF-WP-0036-T01
|
||||
status: done
|
||||
priority: high
|
||||
```
|
||||
|
||||
Completed 2026-09-05. Assessed all 37 existing plans and their 168 task records,
|
||||
corrected SCOPE, grouped the remaining obligations, consolidated the three
|
||||
design follow-ups under RPF-WP-0035, archived completed plans with identities
|
||||
preserved, and recorded owner handoffs and before/after inventory in history.
|
||||
This certifies the source review, not live service health or external acceptance.
|
||||
|
||||
## Publish achievable service guarantees and recovery ownership
|
||||
|
||||
```task
|
||||
id: RPF-WP-0036-T02
|
||||
status: todo
|
||||
priority: high
|
||||
```
|
||||
|
||||
For apps-pg, platform-pg, OpenBao and each supported backup delivery lane,
|
||||
publish a versioned service record: accountable S3/package/operator owners,
|
||||
consumers, failure domain, availability objective, RPO/RTO, retention, recovery
|
||||
key/quorum availability, maintenance/abort path and evidence freshness budget.
|
||||
Separate measured results from accepted targets and unknowns. A 56-second
|
||||
scratch restore is not an RTO commitment; one replica on one host is not HA.
|
||||
Reuse `docs/s3-consumer-interfaces.md` and existing package declarations.
|
||||
|
||||
**Done when:** every supported service has owner-reviewed numeric targets or
|
||||
an explicit unsupported guarantee and decision owner; consumer requirements
|
||||
are compared to the current substrate; any HA/node-loss gap has an exact S1/S2
|
||||
and package dependency rather than a blanket new-cluster project here.
|
||||
|
||||
## Make backup freshness and recurring recovery evidence checkable
|
||||
|
||||
```task
|
||||
id: RPF-WP-0036-T03
|
||||
status: todo
|
||||
priority: high
|
||||
```
|
||||
|
||||
Inventory authoritative CNPG backup/PITR, OpenBao snapshot/isolated restore,
|
||||
encrypted off-host copy and custody-recovery receipts. Reuse existing validators
|
||||
and package status commands. Define cadence/expiry from T02; return distinct
|
||||
healthy, stale, missing and unavailable states using metadata only. Schedule
|
||||
execution only through the accepted execution owner and separately approved
|
||||
authority. Keep RPF-WP-0015's pending database/reboot experiments as the sole
|
||||
live tasks for those experiments; RPF-WP-0029 retains provider-key recovery.
|
||||
|
||||
**Done when:** a current off-host backup and a current isolated restore receipt
|
||||
exist for each supported data service, the approved cadence is installed and
|
||||
its execution is evidenced, and missing/stale/failed evidence reaches a named
|
||||
operator. A template, dated successful snapshot, or same-PVC reboot does not
|
||||
pass as restore proof. Record independent recovery-key access without values.
|
||||
|
||||
## Produce S3 signals and prove their delivery to the evidence owner
|
||||
|
||||
```task
|
||||
id: RPF-WP-0036-T04
|
||||
status: todo
|
||||
priority: high
|
||||
```
|
||||
|
||||
Define service-owned health semantics for backup/WAL age, restore age, seal
|
||||
state, ESO freshness, connection/memory headroom and consumer ceiling. Reuse
|
||||
package emitters and the Q2 owner's standard contract; retain an explicit
|
||||
unmonitored state and named manual checker until transport is accepted.
|
||||
Request a concrete receiving contract from railiance-telemetry when routing is
|
||||
authorized; do not implement a competing monitoring plane in S3.
|
||||
|
||||
**Done when:** bounded metadata-only samples pass contract validation, a
|
||||
controlled stale/failure sample reaches a named recipient through the accepted
|
||||
Q2 route, and missing emission itself is detectable. Local fixture tests may
|
||||
finish before the receiver, but end-to-end acceptance cannot.
|
||||
|
||||
## Reconcile admission, placement and consumer interface drift
|
||||
|
||||
```task
|
||||
id: RPF-WP-0036-T05
|
||||
status: todo
|
||||
priority: high
|
||||
```
|
||||
|
||||
Join actual package declarations and authorized metadata to the S3 interface,
|
||||
tenancy and placement records. Correct stale platform-pg occupancy/co-residency
|
||||
(Core Hub admission versus older tenant-engine descriptions), distinguish
|
||||
desired placement from observed placement, and verify the named overflow
|
||||
targets remain provisionable. Add a bounded check for missing owners,
|
||||
unsupported retention requests, quota/ceiling drift and stale evidence; consume
|
||||
package admission checks instead of reimplementing them.
|
||||
|
||||
**Done when:** every admitted consumer has one authoritative placement/contract,
|
||||
capacity and retention disclosures match package source and dated live proof,
|
||||
and synthetic invalid admissions fail before provisioning. No workload moves
|
||||
under this task without its own owner-reviewed migration.
|
||||
|
||||
## Obtain acceptance for compatibility assets and derived-record cleanup
|
||||
|
||||
```task
|
||||
id: RPF-WP-0036-T06
|
||||
status: todo
|
||||
priority: medium
|
||||
```
|
||||
|
||||
Prepare exact source/entry-point inventories and owner-ready handoffs for
|
||||
Forgejo backup/pruning/image inventory (`railiance-forge`, activity-core
|
||||
execution), retained OpenBao package wrappers (`rapp-openbao`), and ArgoCD
|
||||
bootstrap/application manifests (S2/S4/S5 according to artifact). Keep S3
|
||||
custody contracts and the RPF-WP-0029 exposure obligation here until accepted
|
||||
closure. No new framework or app-specific helper belongs here by default.
|
||||
|
||||
Supply repo-manager/State Hub with the exact legacy alias/source identity map
|
||||
from the assessment. Their apparent duplicate active records and stale brief
|
||||
are derived-state defects, not additional workplans. Use scoped reconciliation;
|
||||
never change managed UUIDs or blanket-acknowledge retirements to clean a view.
|
||||
|
||||
**Done when:** each retained compatibility surface has an accepting owner,
|
||||
canonical replacement and tested callers or a dated retention decision; the
|
||||
repo-filtered projection and generated brief agree with source identities.
|
||||
Unaccepted transfer remains explicitly pending. No requests were sent during
|
||||
the assessment and this task does not assert acceptance for another repo.
|
||||
|
||||
## Decide demand and reuse for undeployed stateful capabilities
|
||||
|
||||
```task
|
||||
id: RPF-WP-0036-T07
|
||||
status: todo
|
||||
priority: medium
|
||||
```
|
||||
|
||||
Review cache, general object storage and messaging separately with potential
|
||||
consumers. Inventory existing providers/contracts (including artifact-store
|
||||
and the external backup bucket) before selecting an engine. Record workload,
|
||||
durability/latency/retention needs, capacity, tenancy, custody, package owner,
|
||||
recovery cost and operating owner for any accepted demand. Ask railiance-master
|
||||
to resolve fleet Q3 ownership through its architecture process; do not assign
|
||||
it to S3 by implication.
|
||||
|
||||
**Done when:** each capability has a dated decision to reuse, defer with a
|
||||
review trigger, or start a bounded consumer-backed delivery plan with explicit
|
||||
acceptance criteria. “No accepted demand; keep deploy gated” is a valid result.
|
||||
No Valkey, MinIO, RabbitMQ or new provider purchase is authorized by this plan.
|
||||
Loading…
Add table
Add a link
Reference in a new issue