Record activity-core adoption and track digest retention readiness

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
codex 2026-09-27 15:49:29 +02:00
parent a01026535a
commit d49906d59a
2 changed files with 201 additions and 1 deletions

View file

@ -0,0 +1,166 @@
{
"date": "2026-09-27",
"workplan": "ACTIVITY-WP-0041",
"platform_workplan": "RPF-WP-0048",
"authorization_decision": "78a4b859-dd00-4623-b95b-121b0e1c915d",
"activity_revision": "12e08878d19e61ce41c534cc10ca56acd0c3efc1",
"platform_revision": "a01026535a1fb34d5e9561a26a02dc56b3e3bab4",
"initial_adoption": {
"revision": "c12a8fbcfbd0624e195a0183f8b7ca5ce2bc07d5",
"finished_at": "2026-09-27T12:07:35Z",
"diff": "nine tracking annotations only; deployment specs and pod templates unchanged"
},
"digest_release": {
"finished_at": "2026-09-27T13:37:56Z",
"sync": "Synced",
"health": "Healthy",
"phase": "Succeeded",
"diff": "only three image references and Never to IfNotPresent; same published baseline binaries"
},
"resources": [
{
"kind": "ConfigMap",
"name": "actcore-external-activity-definitions",
"namespace": "activity-core",
"status": "Synced"
},
{
"kind": "ConfigMap",
"name": "actcore-ops-service-inventory",
"namespace": "activity-core",
"status": "Synced"
},
{
"kind": "ConfigMap",
"name": "actcore-report-schemas",
"namespace": "activity-core",
"status": "Synced"
},
{
"kind": "ConfigMap",
"name": "actcore-runtime-config",
"namespace": "activity-core",
"status": "Synced"
},
{
"kind": "Service",
"name": "actcore-api",
"namespace": "activity-core",
"status": "Synced"
},
{
"kind": "Service",
"name": "actcore-worker-metrics",
"namespace": "activity-core",
"status": "Synced"
},
{
"kind": "Deployment",
"name": "actcore-api",
"namespace": "activity-core",
"status": "Synced"
},
{
"kind": "Deployment",
"name": "actcore-event-router",
"namespace": "activity-core",
"status": "Synced"
},
{
"kind": "Deployment",
"name": "actcore-worker",
"namespace": "activity-core",
"status": "Synced"
}
],
"deployments": [
{
"name": "actcore-api",
"images": [
"forgejo.coulomb.social/coulomb/activity-core@sha256:713bddad10a41950f446100a8b370fca8ccdd0b8969cccae751e3870c9c63ccd"
],
"generation": 50,
"observed_generation": 50,
"ready": 1,
"updated": 1
},
{
"name": "actcore-worker",
"images": [
"forgejo.coulomb.social/coulomb/activity-core@sha256:77244c3b6977a84888746d1fde5ec9fb5ed576f29df0e6dab2462e6f2ab0e0d7"
],
"generation": 61,
"observed_generation": 61,
"ready": 1,
"updated": 1
},
{
"name": "actcore-event-router",
"images": [
"forgejo.coulomb.social/coulomb/activity-core@sha256:cd4e924c2809f0d1d319e53a9ddd20db2e88a1b543d62e6442702c184b7842f4"
],
"generation": 33,
"observed_generation": 33,
"ready": 1,
"updated": 1
}
],
"ci": {
"state": "success",
"image_run": "https://forgejo.coulomb.social/coulomb/activity-core/actions/runs/308",
"smoke_run": "https://forgejo.coulomb.social/coulomb/activity-core/actions/runs/307",
"checks": "pinned frontend projection; release guard; frontend resolver; external definitions; report sink"
},
"scheduled_smoke": {
"activity_id": "99f02c4c-161e-515d-926d-9e5d11d8411e",
"activity_name": "Frontend Patterns Daily Review",
"mode": "live",
"recreate_recurring": false,
"recurring_schedule_id": "activity-schedule-99f02c4c-161e-515d-926d-9e5d11d8411e",
"smoke_fire_at": "2026-09-27T13:39:09.975262+00:00",
"smoke_schedule_id": "activity-smoke-test-99f02c4c-161e-515d-926d-9e5d11d8411e",
"smoke_workflow_id_prefix": "activity-99f02c4c-161e-515d-926d-9e5d11d8411e:smoke-20260927T133909Z",
"wait_result": {
"result": {
"run_id": "c81f656f-405e-5773-b4d2-73b8110ee55f",
"tasks_spawned": 0
},
"run_id": "01a0e317-48a8-72d8-98d9-e44cdedb9999",
"status": "completed",
"workflow_id": "activity-99f02c4c-161e-515d-926d-9e5d11d8411e:smoke-20260927T133909Z-2026-09-27T13:39:09Z"
}
},
"schedules": {
"daily": "0 2 * * *",
"weekly": "0 3 * * 2",
"monthly": "0 9 1 * *",
"timezone": "Europe/Berlin",
"all_enabled_after_release": true
},
"retention": {
"baseline_tags": [
"baseline-api-713bddad10a4",
"baseline-worker-77244c3b6977",
"baseline-router-cd4e924c2809"
],
"union_sha256": "f0560f5a5e0c8c52154fb5e4d1b04838191d51fcf026df49703d5f3503f61fda",
"protection_verified_with_owner_parser": true,
"gap": "digest-only refs are not mapped to registry versions; RPF-WP-0048-T03 retains general fix"
},
"soak": {
"healthy_start": "2026-09-27T13:38:21Z",
"earliest_eligible": "2026-09-28T13:38:21Z",
"completed": false,
"requires": "continuous healthy observation, not elapsed time alone"
},
"automated_sync": false,
"pruning": false,
"unattended_release_identity_admitted": false,
"failed_health_rollback_proven": false,
"remaining": [
"24-hour healthy observation",
"authenticated CI/reviewer/health receipts and narrowly admitted release identity",
"automatic failed-health rollback proof",
"GLAS-WP-0012/HFACT-WP-0001 executor proof for pattern editing"
]
}

View file

@ -23,7 +23,7 @@ activation=APPROVED. Existing 24-hour observation requirement remains in force.
```task ```task
id: RPF-WP-0048-T01 id: RPF-WP-0048-T01
status: progress status: done
priority: high priority: high
state_hub_task_id: "a8cafada-385f-58a5-9c05-20d447c40370" state_hub_task_id: "a8cafada-385f-58a5-9c05-20d447c40370"
``` ```
@ -51,3 +51,37 @@ source validation and the promotion/rollback guard. Root-wide automation is outs
this workplan. No unattended merge credential or release executor is assumed just this workplan. No unattended merge credential or release executor is assumed just
because the Application exists. Confirm the scoped identity and checks before because the Application exists. Confirm the scoped identity and checks before
activating bounded routine promotion. Destructive pruning remains disabled. activating bounded routine promotion. Destructive pruning remains disabled.
## Make registry retention aware of digest-pinned releases
```task
id: RPF-WP-0048-T03
status: todo
priority: high
```
The package retention parser currently recognizes tags only; digest references
must resolve to protected registry versions before routine digest promotion can
be unattended. Cover live and rollback digests, preserve fail-closed behavior on
incomplete registry/export coverage, and test the resulting deletion plan without
deleting packages. Coordinate admission with ACTIVITY-WP-0041-T03. Until this is
implemented, release evidence must include protected tag aliases for each digest.
Immediate mitigation verified: all three activity-core baseline tags are present
in the additive live-image union and recognized by the existing owner parser.
No retention deletion was run. Future releases must not assume a digest line alone
provides package protection.
## Adoption evidence — 2026-09-27
AppProject bootstrapped; root selectively synced only activity-core. Initial
nine-resource adoption changed tracking metadata only. Then the child pinned
12e08878d19e61ce41c534cc10ca56acd0c3efc1 and rolled out registry digests of the
same binaries. All three deployments ready; ArgoCD Synced/Healthy; scheduled
frontend reporting smoke completed; all three recurring definitions stay enabled.
See docs/evidence/2026-09-27-activity-core-gitops.json. Conservative healthy soak
starts 2026-09-27T13:38:21Z, earliest eligibility 2026-09-28T13:38:21Z subject to
healthy observation. T02 stays waiting for this window and authenticated narrowly
bound release-identity/rollback proof. Automation and pruning remain disabled.
Authorization decision: 78a4b859-dd00-4623-b95b-121b0e1c915d.