Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
165 lines
7.1 KiB
Markdown
165 lines
7.1 KiB
Markdown
---
|
|
id: RPF-WP-0036
|
|
type: workplan
|
|
title: "Close S3 service assurance and ownership gaps"
|
|
domain: financials
|
|
repo: railiance-platform
|
|
status: ready
|
|
owner: codex
|
|
created: "2026-09-05"
|
|
updated: "2026-09-05"
|
|
---
|
|
|
|
# S3 service assurance and ownership gaps
|
|
|
|
Source: `history/2026-09-05-platform-intent-workplan-assessment.md`.
|
|
Reviewed against current repository evidence. This plan supplies the missing
|
|
continuing obligations; it does not reopen completed bootstrap projects or
|
|
duplicate incident/lane work. Repository design and read-only implementation
|
|
can progress now. Every live drill, scheduler, credential operation or migration
|
|
retains its own owner and execution gate.
|
|
|
|
## Record the portfolio assessment and consolidate source work
|
|
|
|
```task
|
|
id: RPF-WP-0036-T01
|
|
status: done
|
|
priority: high
|
|
```
|
|
|
|
Completed 2026-09-05. Assessed all 37 existing plans and their 168 task records,
|
|
corrected SCOPE, grouped the remaining obligations, consolidated the three
|
|
design follow-ups under RPF-WP-0035, archived completed plans with identities
|
|
preserved, and recorded owner handoffs and before/after inventory in history.
|
|
This certifies the source review, not live service health or external acceptance.
|
|
|
|
## Publish achievable service guarantees and recovery ownership
|
|
|
|
```task
|
|
id: RPF-WP-0036-T02
|
|
status: todo
|
|
priority: high
|
|
```
|
|
|
|
For apps-pg, platform-pg, OpenBao and each supported backup delivery lane,
|
|
publish a versioned service record: accountable S3/package/operator owners,
|
|
consumers, failure domain, availability objective, RPO/RTO, retention, recovery
|
|
key/quorum availability, maintenance/abort path and evidence freshness budget.
|
|
Separate measured results from accepted targets and unknowns. A 56-second
|
|
scratch restore is not an RTO commitment; one replica on one host is not HA.
|
|
Reuse `docs/s3-consumer-interfaces.md` and existing package declarations.
|
|
|
|
**Done when:** every supported service has owner-reviewed numeric targets or
|
|
an explicit unsupported guarantee and decision owner; consumer requirements
|
|
are compared to the current substrate; any HA/node-loss gap has an exact S1/S2
|
|
and package dependency rather than a blanket new-cluster project here.
|
|
|
|
## Make backup freshness and recurring recovery evidence checkable
|
|
|
|
```task
|
|
id: RPF-WP-0036-T03
|
|
status: todo
|
|
priority: high
|
|
```
|
|
|
|
Inventory authoritative CNPG backup/PITR, OpenBao snapshot/isolated restore,
|
|
encrypted off-host copy and custody-recovery receipts. Reuse existing validators
|
|
and package status commands. Define cadence/expiry from T02; return distinct
|
|
healthy, stale, missing and unavailable states using metadata only. Schedule
|
|
execution only through the accepted execution owner and separately approved
|
|
authority. Keep RPF-WP-0015's pending database/reboot experiments as the sole
|
|
live tasks for those experiments; RPF-WP-0029 retains provider-key recovery.
|
|
|
|
**Done when:** a current off-host backup and a current isolated restore receipt
|
|
exist for each supported data service, the approved cadence is installed and
|
|
its execution is evidenced, and missing/stale/failed evidence reaches a named
|
|
operator. A template, dated successful snapshot, or same-PVC reboot does not
|
|
pass as restore proof. Record independent recovery-key access without values.
|
|
|
|
## Produce S3 signals and prove their delivery to the evidence owner
|
|
|
|
```task
|
|
id: RPF-WP-0036-T04
|
|
status: todo
|
|
priority: high
|
|
```
|
|
|
|
Define service-owned health semantics for backup/WAL age, restore age, seal
|
|
state, ESO freshness, connection/memory headroom and consumer ceiling. Reuse
|
|
package emitters and the Q2 owner's standard contract; retain an explicit
|
|
unmonitored state and named manual checker until transport is accepted.
|
|
Request a concrete receiving contract from railiance-telemetry when routing is
|
|
authorized; do not implement a competing monitoring plane in S3.
|
|
|
|
**Done when:** bounded metadata-only samples pass contract validation, a
|
|
controlled stale/failure sample reaches a named recipient through the accepted
|
|
Q2 route, and missing emission itself is detectable. Local fixture tests may
|
|
finish before the receiver, but end-to-end acceptance cannot.
|
|
|
|
## Reconcile admission, placement and consumer interface drift
|
|
|
|
```task
|
|
id: RPF-WP-0036-T05
|
|
status: todo
|
|
priority: high
|
|
```
|
|
|
|
Join actual package declarations and authorized metadata to the S3 interface,
|
|
tenancy and placement records. Correct stale platform-pg occupancy/co-residency
|
|
(Core Hub admission versus older tenant-engine descriptions), distinguish
|
|
desired placement from observed placement, and verify the named overflow
|
|
targets remain provisionable. Add a bounded check for missing owners,
|
|
unsupported retention requests, quota/ceiling drift and stale evidence; consume
|
|
package admission checks instead of reimplementing them.
|
|
|
|
**Done when:** every admitted consumer has one authoritative placement/contract,
|
|
capacity and retention disclosures match package source and dated live proof,
|
|
and synthetic invalid admissions fail before provisioning. No workload moves
|
|
under this task without its own owner-reviewed migration.
|
|
|
|
## Obtain acceptance for compatibility assets and derived-record cleanup
|
|
|
|
```task
|
|
id: RPF-WP-0036-T06
|
|
status: todo
|
|
priority: medium
|
|
```
|
|
|
|
Prepare exact source/entry-point inventories and owner-ready handoffs for
|
|
Forgejo backup/pruning/image inventory (`railiance-forge`, activity-core
|
|
execution), retained OpenBao package wrappers (`rapp-openbao`), and ArgoCD
|
|
bootstrap/application manifests (S2/S4/S5 according to artifact). Keep S3
|
|
custody contracts and the RPF-WP-0029 exposure obligation here until accepted
|
|
closure. No new framework or app-specific helper belongs here by default.
|
|
|
|
Supply repo-manager/State Hub with the exact legacy alias/source identity map
|
|
from the assessment. Their apparent duplicate active records and stale brief
|
|
are derived-state defects, not additional workplans. Use scoped reconciliation;
|
|
never change managed UUIDs or blanket-acknowledge retirements to clean a view.
|
|
|
|
**Done when:** each retained compatibility surface has an accepting owner,
|
|
canonical replacement and tested callers or a dated retention decision; the
|
|
repo-filtered projection and generated brief agree with source identities.
|
|
Unaccepted transfer remains explicitly pending. No requests were sent during
|
|
the assessment and this task does not assert acceptance for another repo.
|
|
|
|
## Decide demand and reuse for undeployed stateful capabilities
|
|
|
|
```task
|
|
id: RPF-WP-0036-T07
|
|
status: todo
|
|
priority: medium
|
|
```
|
|
|
|
Review cache, general object storage and messaging separately with potential
|
|
consumers. Inventory existing providers/contracts (including artifact-store
|
|
and the external backup bucket) before selecting an engine. Record workload,
|
|
durability/latency/retention needs, capacity, tenancy, custody, package owner,
|
|
recovery cost and operating owner for any accepted demand. Ask railiance-master
|
|
to resolve fleet Q3 ownership through its architecture process; do not assign
|
|
it to S3 by implication.
|
|
|
|
**Done when:** each capability has a dated decision to reuse, defer with a
|
|
review trigger, or start a bounded consumer-backed delivery plan with explicit
|
|
acceptance criteria. “No accepted demand; keep deploy gated” is a valid result.
|
|
No Valkey, MinIO, RabbitMQ or new provider purchase is authorized by this plan.
|