railiance-platform/workplans/RPF-WP-0036-platform-service-assurance.md
codex 9f83e426c7 Consolidate platform workplans and assess intent gaps
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
2026-09-05 11:14:42 +02:00

7.1 KiB

id type title domain repo status owner created updated
RPF-WP-0036 workplan Close S3 service assurance and ownership gaps financials railiance-platform ready codex 2026-09-05 2026-09-05

S3 service assurance and ownership gaps

Source: history/2026-09-05-platform-intent-workplan-assessment.md. Reviewed against current repository evidence. This plan supplies the missing continuing obligations; it does not reopen completed bootstrap projects or duplicate incident/lane work. Repository design and read-only implementation can progress now. Every live drill, scheduler, credential operation or migration retains its own owner and execution gate.

Record the portfolio assessment and consolidate source work

id: RPF-WP-0036-T01
status: done
priority: high

Completed 2026-09-05. Assessed all 37 existing plans and their 168 task records, corrected SCOPE, grouped the remaining obligations, consolidated the three design follow-ups under RPF-WP-0035, archived completed plans with identities preserved, and recorded owner handoffs and before/after inventory in history. This certifies the source review, not live service health or external acceptance.

Publish achievable service guarantees and recovery ownership

id: RPF-WP-0036-T02
status: todo
priority: high

For apps-pg, platform-pg, OpenBao and each supported backup delivery lane, publish a versioned service record: accountable S3/package/operator owners, consumers, failure domain, availability objective, RPO/RTO, retention, recovery key/quorum availability, maintenance/abort path and evidence freshness budget. Separate measured results from accepted targets and unknowns. A 56-second scratch restore is not an RTO commitment; one replica on one host is not HA. Reuse docs/s3-consumer-interfaces.md and existing package declarations.

Done when: every supported service has owner-reviewed numeric targets or an explicit unsupported guarantee and decision owner; consumer requirements are compared to the current substrate; any HA/node-loss gap has an exact S1/S2 and package dependency rather than a blanket new-cluster project here.

Make backup freshness and recurring recovery evidence checkable

id: RPF-WP-0036-T03
status: todo
priority: high

Inventory authoritative CNPG backup/PITR, OpenBao snapshot/isolated restore, encrypted off-host copy and custody-recovery receipts. Reuse existing validators and package status commands. Define cadence/expiry from T02; return distinct healthy, stale, missing and unavailable states using metadata only. Schedule execution only through the accepted execution owner and separately approved authority. Keep RPF-WP-0015's pending database/reboot experiments as the sole live tasks for those experiments; RPF-WP-0029 retains provider-key recovery.

Done when: a current off-host backup and a current isolated restore receipt exist for each supported data service, the approved cadence is installed and its execution is evidenced, and missing/stale/failed evidence reaches a named operator. A template, dated successful snapshot, or same-PVC reboot does not pass as restore proof. Record independent recovery-key access without values.

Produce S3 signals and prove their delivery to the evidence owner

id: RPF-WP-0036-T04
status: todo
priority: high

Define service-owned health semantics for backup/WAL age, restore age, seal state, ESO freshness, connection/memory headroom and consumer ceiling. Reuse package emitters and the Q2 owner's standard contract; retain an explicit unmonitored state and named manual checker until transport is accepted. Request a concrete receiving contract from railiance-telemetry when routing is authorized; do not implement a competing monitoring plane in S3.

Done when: bounded metadata-only samples pass contract validation, a controlled stale/failure sample reaches a named recipient through the accepted Q2 route, and missing emission itself is detectable. Local fixture tests may finish before the receiver, but end-to-end acceptance cannot.

Reconcile admission, placement and consumer interface drift

id: RPF-WP-0036-T05
status: todo
priority: high

Join actual package declarations and authorized metadata to the S3 interface, tenancy and placement records. Correct stale platform-pg occupancy/co-residency (Core Hub admission versus older tenant-engine descriptions), distinguish desired placement from observed placement, and verify the named overflow targets remain provisionable. Add a bounded check for missing owners, unsupported retention requests, quota/ceiling drift and stale evidence; consume package admission checks instead of reimplementing them.

Done when: every admitted consumer has one authoritative placement/contract, capacity and retention disclosures match package source and dated live proof, and synthetic invalid admissions fail before provisioning. No workload moves under this task without its own owner-reviewed migration.

Obtain acceptance for compatibility assets and derived-record cleanup

id: RPF-WP-0036-T06
status: todo
priority: medium

Prepare exact source/entry-point inventories and owner-ready handoffs for Forgejo backup/pruning/image inventory (railiance-forge, activity-core execution), retained OpenBao package wrappers (rapp-openbao), and ArgoCD bootstrap/application manifests (S2/S4/S5 according to artifact). Keep S3 custody contracts and the RPF-WP-0029 exposure obligation here until accepted closure. No new framework or app-specific helper belongs here by default.

Supply repo-manager/State Hub with the exact legacy alias/source identity map from the assessment. Their apparent duplicate active records and stale brief are derived-state defects, not additional workplans. Use scoped reconciliation; never change managed UUIDs or blanket-acknowledge retirements to clean a view.

Done when: each retained compatibility surface has an accepting owner, canonical replacement and tested callers or a dated retention decision; the repo-filtered projection and generated brief agree with source identities. Unaccepted transfer remains explicitly pending. No requests were sent during the assessment and this task does not assert acceptance for another repo.

Decide demand and reuse for undeployed stateful capabilities

id: RPF-WP-0036-T07
status: todo
priority: medium

Review cache, general object storage and messaging separately with potential consumers. Inventory existing providers/contracts (including artifact-store and the external backup bucket) before selecting an engine. Record workload, durability/latency/retention needs, capacity, tenancy, custody, package owner, recovery cost and operating owner for any accepted demand. Ask railiance-master to resolve fleet Q3 ownership through its architecture process; do not assign it to S3 by implication.

Done when: each capability has a dated decision to reuse, defer with a review trigger, or start a bounded consumer-backed delivery plan with explicit acceptance criteria. “No accepted demand; keep deploy gated” is a valid result. No Valkey, MinIO, RabbitMQ or new provider purchase is authorized by this plan.