railiance-platform/workplans/RPF-WP-0028-durable-live-image-inventory.md
codex f637989a69
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Refuse prune apply when requested image inventories are unavailable
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
2026-09-05 02:00:50 +02:00

1.6 KiB

id type title domain repo status owner created updated
RPF-WP-0028 workplan Make Forgejo image protection survive checkout replacement financials railiance-platform blocked codex 2026-09-05 2026-09-05

Make Forgejo image protection survive checkout replacement

Source: State Hub message 868a2326-cdad-4256-be4c-7cd6c8ec4b5b. Reviewed against current repository state on 2026-09-05. Repository implementation is complete; live closure remains pending.

Implement and verify durable publication

id: RPF-WP-0028-T01
status: done
priority: high

Implemented scripts/refresh_live_images.py and make live-images-refresh. Publication validates exports before mutation, locks concurrent writers, retains all previous cluster entries, and fsyncs an atomic replacement. Offline tests prove repeatability, multi-cluster retention, and preservation on missing, empty, or malformed input.

The local prune CLI was additionally hardened on 2026-09-05 to refuse apply before credential lookup if any explicitly requested export is missing, unreadable, empty, or comment-only. Regression coverage includes a valid file alongside a bad one, proving partial coverage cannot authorize deletion.

Install production projection and rollout refresh

id: RPF-WP-0028-T02
status: wait
priority: high

Requires the production host inventory, activity-core directory mount/configuration update, and cluster rollout hook adoption. Follow docs/forgejo-package-prune.md. Preserve the restored union and worker refusal on missing/empty inventory; do not manually trigger prune. No production migration or live verification occurred in this session.