railiance-platform/workplans/RPF-WP-0036-platform-service-assurance.md
codex 9f83e426c7 Consolidate platform workplans and assess intent gaps
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
2026-09-05 11:14:42 +02:00

165 lines
7.1 KiB
Markdown

---
id: RPF-WP-0036
type: workplan
title: "Close S3 service assurance and ownership gaps"
domain: financials
repo: railiance-platform
status: ready
owner: codex
created: "2026-09-05"
updated: "2026-09-05"
---
# S3 service assurance and ownership gaps
Source: `history/2026-09-05-platform-intent-workplan-assessment.md`.
Reviewed against current repository evidence. This plan supplies the missing
continuing obligations; it does not reopen completed bootstrap projects or
duplicate incident/lane work. Repository design and read-only implementation
can progress now. Every live drill, scheduler, credential operation or migration
retains its own owner and execution gate.
## Record the portfolio assessment and consolidate source work
```task
id: RPF-WP-0036-T01
status: done
priority: high
```
Completed 2026-09-05. Assessed all 37 existing plans and their 168 task records,
corrected SCOPE, grouped the remaining obligations, consolidated the three
design follow-ups under RPF-WP-0035, archived completed plans with identities
preserved, and recorded owner handoffs and before/after inventory in history.
This certifies the source review, not live service health or external acceptance.
## Publish achievable service guarantees and recovery ownership
```task
id: RPF-WP-0036-T02
status: todo
priority: high
```
For apps-pg, platform-pg, OpenBao and each supported backup delivery lane,
publish a versioned service record: accountable S3/package/operator owners,
consumers, failure domain, availability objective, RPO/RTO, retention, recovery
key/quorum availability, maintenance/abort path and evidence freshness budget.
Separate measured results from accepted targets and unknowns. A 56-second
scratch restore is not an RTO commitment; one replica on one host is not HA.
Reuse `docs/s3-consumer-interfaces.md` and existing package declarations.
**Done when:** every supported service has owner-reviewed numeric targets or
an explicit unsupported guarantee and decision owner; consumer requirements
are compared to the current substrate; any HA/node-loss gap has an exact S1/S2
and package dependency rather than a blanket new-cluster project here.
## Make backup freshness and recurring recovery evidence checkable
```task
id: RPF-WP-0036-T03
status: todo
priority: high
```
Inventory authoritative CNPG backup/PITR, OpenBao snapshot/isolated restore,
encrypted off-host copy and custody-recovery receipts. Reuse existing validators
and package status commands. Define cadence/expiry from T02; return distinct
healthy, stale, missing and unavailable states using metadata only. Schedule
execution only through the accepted execution owner and separately approved
authority. Keep RPF-WP-0015's pending database/reboot experiments as the sole
live tasks for those experiments; RPF-WP-0029 retains provider-key recovery.
**Done when:** a current off-host backup and a current isolated restore receipt
exist for each supported data service, the approved cadence is installed and
its execution is evidenced, and missing/stale/failed evidence reaches a named
operator. A template, dated successful snapshot, or same-PVC reboot does not
pass as restore proof. Record independent recovery-key access without values.
## Produce S3 signals and prove their delivery to the evidence owner
```task
id: RPF-WP-0036-T04
status: todo
priority: high
```
Define service-owned health semantics for backup/WAL age, restore age, seal
state, ESO freshness, connection/memory headroom and consumer ceiling. Reuse
package emitters and the Q2 owner's standard contract; retain an explicit
unmonitored state and named manual checker until transport is accepted.
Request a concrete receiving contract from railiance-telemetry when routing is
authorized; do not implement a competing monitoring plane in S3.
**Done when:** bounded metadata-only samples pass contract validation, a
controlled stale/failure sample reaches a named recipient through the accepted
Q2 route, and missing emission itself is detectable. Local fixture tests may
finish before the receiver, but end-to-end acceptance cannot.
## Reconcile admission, placement and consumer interface drift
```task
id: RPF-WP-0036-T05
status: todo
priority: high
```
Join actual package declarations and authorized metadata to the S3 interface,
tenancy and placement records. Correct stale platform-pg occupancy/co-residency
(Core Hub admission versus older tenant-engine descriptions), distinguish
desired placement from observed placement, and verify the named overflow
targets remain provisionable. Add a bounded check for missing owners,
unsupported retention requests, quota/ceiling drift and stale evidence; consume
package admission checks instead of reimplementing them.
**Done when:** every admitted consumer has one authoritative placement/contract,
capacity and retention disclosures match package source and dated live proof,
and synthetic invalid admissions fail before provisioning. No workload moves
under this task without its own owner-reviewed migration.
## Obtain acceptance for compatibility assets and derived-record cleanup
```task
id: RPF-WP-0036-T06
status: todo
priority: medium
```
Prepare exact source/entry-point inventories and owner-ready handoffs for
Forgejo backup/pruning/image inventory (`railiance-forge`, activity-core
execution), retained OpenBao package wrappers (`rapp-openbao`), and ArgoCD
bootstrap/application manifests (S2/S4/S5 according to artifact). Keep S3
custody contracts and the RPF-WP-0029 exposure obligation here until accepted
closure. No new framework or app-specific helper belongs here by default.
Supply repo-manager/State Hub with the exact legacy alias/source identity map
from the assessment. Their apparent duplicate active records and stale brief
are derived-state defects, not additional workplans. Use scoped reconciliation;
never change managed UUIDs or blanket-acknowledge retirements to clean a view.
**Done when:** each retained compatibility surface has an accepting owner,
canonical replacement and tested callers or a dated retention decision; the
repo-filtered projection and generated brief agree with source identities.
Unaccepted transfer remains explicitly pending. No requests were sent during
the assessment and this task does not assert acceptance for another repo.
## Decide demand and reuse for undeployed stateful capabilities
```task
id: RPF-WP-0036-T07
status: todo
priority: medium
```
Review cache, general object storage and messaging separately with potential
consumers. Inventory existing providers/contracts (including artifact-store
and the external backup bucket) before selecting an engine. Record workload,
durability/latency/retention needs, capacity, tenancy, custody, package owner,
recovery cost and operating owner for any accepted demand. Ask railiance-master
to resolve fleet Q3 ownership through its architecture process; do not assign
it to S3 by implication.
**Done when:** each capability has a dated decision to reuse, defer with a
review trigger, or start a bounded consumer-backed delivery plan with explicit
acceptance criteria. “No accepted demand; keep deploy gated” is a valid result.
No Valkey, MinIO, RabbitMQ or new provider purchase is authorized by this plan.