railiance-platform/history/2026-09-06-WP-0036-closure-gates.md
codex 31386c8e63
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Validate OpenBao snapshot evidence and record assurance closure gates
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
2026-09-06 15:24:58 +02:00

2.5 KiB

WP-0036 closure review — 2026-09-06

Result: not eligible for completion. T01/T02/T05/T07 are done; T03/T04/T06 retain unmet acceptance criteria. No task criteria were relaxed or moved into new plans to create an apparent closure.

Task Verified local result Remaining acceptance
T03 Native apps-pg/forgejo-db adapters; archive receipt producers; encrypted off-host OpenBao snapshot adapter Fresh isolated recovery for all supported services, independently available recovery custody, approved installed cadence with execution receipts and operator delivery
T04 Bounded metadata capture and local validation Q2 receiving contract, named recipient, controlled failure delivery and missing-emission detection
T06 Exact compatibility inventory and dated retention through October 5 Scoped legacy alias repair and generated brief matching source; retain compatibility until owner acceptance or the recorded retention decision is reviewed

New source checks:

  • railiance-telemetry/README.md explicitly says seeded, no implementation; its only local workplan is proposed RTELE-WP-0001. A receiving contract/runtime is not available in that checkout. S3 must not build a replacement Q2 plane merely to satisfy this plan. Owner response is needed for any newer service.
  • rapp-postgres/docs/evidence/backup-restore-20260813T111651Z-remote.json explicitly identifies same-node scratch MinIO, not the governed off-host target. Its successful drill cannot satisfy the current production recovery acceptance criterion.
  • The August 22 OpenBao snapshot receipt is encrypted, hash-verified and copied off-host. Added its exact SHA-256 to the recovery index and a narrow adapter that validates source identity and custody flags. It reports the original creation time and therefore stale, never healthy by rereading. It does not establish isolated restore or current independent quorum access.

The prepared requests in docs/platform-ownership-handoffs.md remain ready for telemetry, repo-manager/State Hub and compatibility owners. Authorization to send them was requested separately; no message was sent during this review. Sending a request alone would not fulfill the receiving owner's acceptance.

Next closure sequence: obtain the Q2 contract and accepted execution/recipient binding; run fresh owner-authorized recovery and cadence proofs; verify failure and missing-emission delivery; reconcile aliases and regenerate orientation. Existing WP-0015 outage exercises remain separate, with their own prerequisites.