Record activity-core adoption and track digest retention readiness
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
parent
a01026535a
commit
d49906d59a
2 changed files with 201 additions and 1 deletions
|
|
@ -23,7 +23,7 @@ activation=APPROVED. Existing 24-hour observation requirement remains in force.
|
|||
|
||||
```task
|
||||
id: RPF-WP-0048-T01
|
||||
status: progress
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "a8cafada-385f-58a5-9c05-20d447c40370"
|
||||
```
|
||||
|
|
@ -51,3 +51,37 @@ source validation and the promotion/rollback guard. Root-wide automation is outs
|
|||
this workplan. No unattended merge credential or release executor is assumed just
|
||||
because the Application exists. Confirm the scoped identity and checks before
|
||||
activating bounded routine promotion. Destructive pruning remains disabled.
|
||||
|
||||
## Make registry retention aware of digest-pinned releases
|
||||
|
||||
```task
|
||||
id: RPF-WP-0048-T03
|
||||
status: todo
|
||||
priority: high
|
||||
```
|
||||
|
||||
The package retention parser currently recognizes tags only; digest references
|
||||
must resolve to protected registry versions before routine digest promotion can
|
||||
be unattended. Cover live and rollback digests, preserve fail-closed behavior on
|
||||
incomplete registry/export coverage, and test the resulting deletion plan without
|
||||
deleting packages. Coordinate admission with ACTIVITY-WP-0041-T03. Until this is
|
||||
implemented, release evidence must include protected tag aliases for each digest.
|
||||
|
||||
Immediate mitigation verified: all three activity-core baseline tags are present
|
||||
in the additive live-image union and recognized by the existing owner parser.
|
||||
No retention deletion was run. Future releases must not assume a digest line alone
|
||||
provides package protection.
|
||||
|
||||
## Adoption evidence — 2026-09-27
|
||||
|
||||
AppProject bootstrapped; root selectively synced only activity-core. Initial
|
||||
nine-resource adoption changed tracking metadata only. Then the child pinned
|
||||
12e08878d19e61ce41c534cc10ca56acd0c3efc1 and rolled out registry digests of the
|
||||
same binaries. All three deployments ready; ArgoCD Synced/Healthy; scheduled
|
||||
frontend reporting smoke completed; all three recurring definitions stay enabled.
|
||||
|
||||
See docs/evidence/2026-09-27-activity-core-gitops.json. Conservative healthy soak
|
||||
starts 2026-09-27T13:38:21Z, earliest eligibility 2026-09-28T13:38:21Z subject to
|
||||
healthy observation. T02 stays waiting for this window and authenticated narrowly
|
||||
bound release-identity/rollback proof. Automation and pruning remain disabled.
|
||||
Authorization decision: 78a4b859-dd00-4623-b95b-121b0e1c915d.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue