Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e3c3-621b-7350-9f77-50a8d3ee7657
136 lines
7 KiB
Markdown
136 lines
7 KiB
Markdown
---
|
|
id: RPF-WP-0048
|
|
type: workplan
|
|
title: "Adopt activity-core application runtime into railiance01 GitOps"
|
|
domain: financials
|
|
repo: railiance-platform
|
|
status: blocked
|
|
owner: codex
|
|
topic_slug: railiance
|
|
created: "2026-09-27"
|
|
updated: "2026-09-27"
|
|
state_hub_workstream_id: "b8cf2fc2-60c2-5d4e-a60a-55f1304d9f54"
|
|
---
|
|
|
|
User authorized implementation of ACTIVITY-WP-0041 on 2026-09-27, after the
|
|
frontend-patterns reporting exception. This explicitly authorizes this adoption;
|
|
it does not widen the earlier one-time exception to unrelated workloads.
|
|
Authority: CONSTRUCT @ activity-core and railiance-platform;
|
|
ADMINISTER @ realm:kubernetes/railiance01 for the scoped bootstrap;
|
|
activation=APPROVED. Existing 24-hour observation requirement remains in force.
|
|
|
|
## Bootstrap a namespace-scoped project and adopt nine runtime resources
|
|
|
|
```task
|
|
id: RPF-WP-0048-T01
|
|
status: done
|
|
priority: high
|
|
state_hub_task_id: "a8cafada-385f-58a5-9c05-20d447c40370"
|
|
```
|
|
|
|
New project permits only activity-core source, activity-core destination, and
|
|
ConfigMap/Service/Deployment kinds. No secrets, Jobs, databases, queues, Temporal,
|
|
llm-connect, edge relay, storage or cluster-scoped resources enter this Application.
|
|
Application source is activity-core k8s/gitops at a pinned reviewed commit; no
|
|
finalizer, automated sync or pruning initially. Root sync must name this child
|
|
only; unrelated pending applications must not be changed. Verify ArgoCD's diff,
|
|
health, resource inventory, schedules and original deployment generations.
|
|
|
|
## Observe adoption and enforce bounded promotion readiness
|
|
|
|
```task
|
|
id: RPF-WP-0048-T02
|
|
status: wait
|
|
priority: high
|
|
state_hub_task_id: "63b44949-39f8-52fd-ab63-e618b67ef992"
|
|
```
|
|
|
|
Keep automated sync off for at least 24 hours after successful adoption. Record
|
|
start and earliest eligibility in evidence. ACTIVITY-WP-0041 owns image publication,
|
|
source validation and the promotion/rollback guard. Root-wide automation is outside
|
|
this workplan. No unattended merge credential or release executor is assumed just
|
|
because the Application exists. Confirm the scoped identity and checks before
|
|
activating bounded routine promotion. Destructive pruning remains disabled.
|
|
|
|
## Make registry retention aware of digest-pinned releases
|
|
|
|
```task
|
|
id: RPF-WP-0048-T03
|
|
status: done
|
|
priority: high
|
|
state_hub_task_id: "6c2650a2-5da8-5999-a6e7-b22eb7c655f4"
|
|
```
|
|
|
|
The package retention parser currently recognizes tags only; digest references
|
|
must resolve to protected registry versions before routine digest promotion can
|
|
be unattended. Cover live and rollback digests, preserve fail-closed behavior on
|
|
incomplete registry/export coverage, and test the resulting deletion plan without
|
|
deleting packages. Coordinate admission with ACTIVITY-WP-0041-T03. Until this is
|
|
implemented, release evidence must include protected tag aliases for each digest.
|
|
|
|
Immediate mitigation verified: all three activity-core baseline tags are present
|
|
in the additive live-image union and recognized by the existing owner parser.
|
|
No retention deletion was run. Future releases must not assume a digest line alone
|
|
provides package protection.
|
|
|
|
## Adoption evidence — 2026-09-27
|
|
|
|
AppProject bootstrapped; root selectively synced only activity-core. Initial
|
|
nine-resource adoption changed tracking metadata only. Then the child pinned
|
|
12e08878d19e61ce41c534cc10ca56acd0c3efc1 and rolled out registry digests of the
|
|
same binaries. All three deployments ready; ArgoCD Synced/Healthy; scheduled
|
|
frontend reporting smoke completed; all three recurring definitions stay enabled.
|
|
|
|
See docs/evidence/2026-09-27-activity-core-gitops.json. Conservative healthy soak
|
|
starts 2026-09-27T13:38:21Z, earliest eligibility 2026-09-28T13:38:21Z subject to
|
|
healthy observation. T02 stays waiting for this window and authenticated narrowly
|
|
bound release-identity/rollback proof. Automation and pruning remain disabled.
|
|
Authorization decision: 78a4b859-dd00-4623-b95b-121b0e1c915d.
|
|
|
|
## Digest retention implementation — 2026-09-27
|
|
|
|
Implemented conservative package-wide protection for live/exported sha256 refs,
|
|
including tag@digest and retained rollback references. This avoids unsafe alias
|
|
mapping assumptions; storage retention increases for those packages. Malformed
|
|
references and incomplete cluster/package inventory refuse apply before deletion.
|
|
Sixteen focused tests pass. Live tool installation/readback remains required;
|
|
existing baseline aliases continue protecting production in the meantime.
|
|
|
|
Credential routing inspection found no ready scoped unattended ArgoCD/Forgejo
|
|
release lane. ACTIVITY-WP-0041-T03 remains the authority/admission owner; no broad
|
|
operator token was copied or delegated. Its concrete executor contract is in
|
|
`docs/activity-core-release-admission.md`.
|
|
|
|
The production worker currently mounts an older platform checkout's script
|
|
(SHA256 0baacfd07b74ddd4317f79aa0de818c25186e15303a67c08d29edc73ad74a870).
|
|
Deploy the new script as a pinned GitOps projection, verify worker readback and a
|
|
non-destructive planner fixture, then close T03. Do not silently overwrite the
|
|
host checkout: it is outside the newly adopted nine-resource projection. Current
|
|
baseline aliases remain protected; no prune was executed during verification.
|
|
|
|
ArgoCD Core has no API-server token/role lane. T02 admission must prove a broker
|
|
that restricts both the platform child revision update and Kubernetes Application
|
|
sync operation; resource-name RBAC alone cannot restrict patch fields. This is
|
|
concrete implementation work retained here and in ACTIVITY-WP-0041-T03, not a
|
|
reason to ask the founder to approve each release. Tests in the owner checkout:
|
|
20 passed across retention and additive inventory suites.
|
|
|
|
## Retention deployed and verified — 2026-09-27
|
|
|
|
T03 complete. Supersedes the earlier pending host-copy installation: the script
|
|
is now pinned by source commit and SHA256 in activity-core's existing ConfigMap,
|
|
projected read-only over the worker tool path, and reconciled through ArgoCD.
|
|
No host checkout mutation, new resource adoption or manual prune was needed.
|
|
The pod annotation changes with the script hash to refresh subPath mounts.
|
|
CI verifies source bytes against the platform commit. Live worker hash matches;
|
|
real additive inventory protects activity-core as a whole package. A synthetic
|
|
rollback version is protected by the planner. No registry requests or deletion
|
|
were made by this probe. See docs/evidence/2026-09-27-digest-retention-release.json.
|
|
|
|
New healthy observation start is 2026-09-27T14:06:22Z after worker rollout;
|
|
earliest eligibility is September 28 at 16:06:22 Europe/Berlin. Automation remains
|
|
off. T02 still owns the scoped broker/admission and observation requirements.
|
|
|
|
## Loose-end review — 2026-09-27
|
|
|
|
The workplan is blocked on T02. Current activity-core remains Synced/Healthy at a12f1169f9d130058ce767f5b26de0606997916c, with health transition 2026-09-27T14:06:22Z. Earliest observation eligibility remains September 28 at 16:06:22 Europe/Berlin. The authenticated bounded broker/admission and rollback proof remain owned jointly with ACTIVITY-WP-0041-T03. Elapsed time is not release-identity admission. T01/T03 remain done; no root automation, pruning or credential delegation was enabled.
|